This is a plain-language summary of our Data Processing Addendum (DPA) designed to help you understand how we handle your data. This summary is provided for convenience only and is not legally binding. Read the full Data Processing Addendum: Full DPA
Looking for something else? This page is about the data your business puts into FlexOps, where we act as your processor. For what FlexOps does with your own account and usage data, see the Privacy Policy. For visitors to our marketing site, see the Website & Marketing Privacy Notice.
- Our Role
- What Data We Process
- What We Do Not Store
- How We Use Your Data
- Subprocessors We Use
- Security Measures
- International Data Transfers
- Your Rights
- Data Retention and Deletion
- Audits
- Changes to This Policy
- Contact Us
Our Role
When you use FlexOps, we process personal data on your behalf as a data processor (or "service provider" under U.S. state privacy laws like CCPA). You remain the data controller — you decide what data is submitted and how it should be handled.
What Data We Process
When you use the FlexOps platform (website, Ship Manager, or API), the following types of personal data may be processed:
| Data Category | Examples |
|---|---|
| Shipping data | Sender and recipient names, addresses, phone numbers, package details |
| Order data | Order identifiers, line items, quantities, fulfillment status |
| Tracking data | Tracking numbers, carrier-provided shipment status events |
| Inventory data | Part numbers, quantities, warehouse locations, serial numbers |
| Financial data | Postage amounts, carrier charges, payment references (processed via Stripe) |
| Authentication data | API key hashes, session tokens |
| Operational metadata | IP addresses, user agents, timestamps, request correlation IDs |
What We Do Not Store
- Credit card numbers or bank account details — all payment processing is handled by Stripe and Plaid.
- API keys in plaintext — we store only SHA-256 hashes.
- User passwords — authentication is managed by Azure AD / Entra ID.
How We Use Your Data
FlexOps processes your data only to provide the services you requested. We will not:
- Sell or share your personal data
- Use your data for purposes outside our business relationship
- Combine your data with unrelated datasets
- Use your data for targeted advertising
We may create anonymized, aggregated data from processing for legitimate business purposes (such as improving service quality). Aggregated data cannot be traced back to you.
Subprocessors We Use
FlexOps uses the following third-party services to deliver the platform:
| Subprocessor | Location | Purpose |
|---|---|---|
| Microsoft Azure | United States / Global | Cloud hosting, compute, storage, database, message bus, key management |
| Microsoft Entra ID | United States / Global | Federated sign-in, where you choose to use it |
| Stripe | United States | Payment processing, billing, subscription management |
| Google (Gmail / Workspace SMTP) | United States | Transactional email — verification, two-factor codes, billing notices |
| Google reCAPTCHA | United States | Spam and abuse protection on website forms |
| Google Analytics | United States | Website usage analytics (marketing site only) |
| Sentry | United States | Application error tracking and performance monitoring |
Configured but switched off: Plaid (financial data connectivity) and Twilio (SMS) have credentials in our configuration but are not enabled, so no data reaches them. We will give notice before turning either on.
Carriers are different. An enabled carrier receives recipient names and addresses when needed to perform a service you request, but it decides how to use that data under its own terms — which makes it an independent controller, not our subprocessor. Data goes to a carrier only when you ask for something involving that carrier: a rate, an address check, a label, or a tracking lookup.
We require all subprocessors to meet data protection obligations substantially similar to ours. We will notify you before adding new subprocessors, and you may object within 30 days on data protection grounds.
Security Measures
We implement industry-standard technical and organizational measures to protect your data:
- Encryption in transit — all data is transmitted over TLS 1.2+
- Encryption at rest — data stored in our systems is encrypted
- Access controls — role-based access with principle of least privilege
- Multi-factor authentication — required for all system access
- Network segmentation — firewalls and segmented environments
- Audit logging — all data access is logged
- Intrusion detection — automated monitoring for suspicious activity
- Redundancy — redundant systems with tested disaster recovery procedures
- Uptime target — 99.95% monthly availability
International Data Transfers
If your data is transferred outside the European Economic Area (EEA) or UK:
- EEA transfers are protected by EU Standard Contractual Clauses (SCCs), Module 2 (Controller to Processor), governed by Irish law.
- UK transfers are protected by the UK International Data Transfer Addendum.
Your Rights
As a data subject under applicable data protection laws, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Port your data to another service
- Object to processing
- Freedom from automated decision-making
To exercise these rights, contact us or your account administrator. FlexOps will assist your organization in responding to data subject requests.
Data Retention and Deletion
- Your data is retained for the duration of your active subscription.
- Upon termination or request, FlexOps will return or delete your personal data.
- We will certify deletion within 30 days if requested.
- Some data may be retained longer if required by law.
Audits
- You may request one audit per year with reasonable written notice.
- SOC 2, ISO, or similar certification reports may be provided in lieu of on-site audits.
- Audit reports are treated as confidential.
Changes to This Policy
We may update this privacy agreement to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email to account administrators.
Contact Us
If you have questions about how we handle your data, please contact us:
FlexOps, LLC
- Privacy: privacy@flexops.io
- Support: support@flexops.io
- Legal: legal@flexops.io
For general inquiries, you can also:
- Visit our Support Center
- Submit a support request
- Review our Terms of Service and Cookie Policy
- Read the Full Data Processing Addendum
Last Updated: August 20, 2026 Effective Date: April 21, 2023