This Privacy Policy explains what FlexOps, LLC ("FlexOps," "we," "us") does with personal information about you — the person holding a FlexOps account and using the Platform.
Three documents, three jobs. Please make sure you are reading the right one:
| If you are… | Read this |
|---|---|
| A FlexOps account holder or user | This Privacy Policy |
| A visitor to our marketing site, or someone who contacted us | Website & Marketing Privacy Notice |
| A business asking how we handle the personal data you upload about your customers | Data Processing Addendum (plain-language summary) |
That last distinction is the important one. For the shipping and order data you put into FlexOps — including your own customers' names and addresses — you are the controller and FlexOps is your processor. This Policy is not about that data; the DPA is. This Policy is about the information we hold about you as our customer.
1. Who We Are
FlexOps, LLC is the controller of the personal information described in this Policy.
FlexOps, LLC 39116 Fremont Hub, PMB 1222 Fremont, CA 94538-1328 privacy@flexops.io
2. Where We Offer the Platform
The Platform is offered to customers established in the United States, for shipments originating in the United States. We are not currently set up to act as a processor for controllers established in the European Economic Area, the United Kingdom, or Switzerland. If you need a data processing agreement under the GDPR or UK GDPR, our DPA is published and includes the Standard Contractual Clauses and the UK Addendum — contact legal@flexops.io before signing up so we can put it in place.
3. Information We Collect About You
3.1 Information you give us
- Account information: name, work email address, password (stored only as a salted one-way hash), phone number, and job or company details you provide.
- Company information: company name, website, business type, industry, shipping volume, company size, and postal address.
- Billing information: billing contact, billing address, tax identifiers, and your plan. Card numbers and bank details go directly to Stripe — see Section 5.
- Support and correspondence: what you write to us, and what we write back.
3.2 Information we generate or observe
- Usage records: labels created, API calls made, quota and overage counts, and the plan those counted against.
- Security and audit records: sign-in events, API key creation and revocation, two-factor challenges, and administrative actions.
- Technical records: IP address, user agent, correlation IDs, timestamps, and request and response sizes.
- Consent records: which version of the Terms of Service you accepted, when, and from which IP address. We keep this because a contract only binds someone who agreed to it, and we have to be able to show that you did.
- Abuse-prevention signals: see Section 4.3.
3.3 What we never store
- Card numbers and bank account details. Payment processing is delegated to Stripe.
- Passwords in readable form. Where you sign in with a FlexOps password we store only a salted, iterated one-way hash produced by ASP.NET Core Identity, from which your password cannot be recovered. Where your organization signs in through Microsoft Entra ID, we store no password of any form.
- Raw API keys. We store only a SHA-256 hash. We cannot retrieve a lost key, only revoke and reissue it.
4. How and Why We Use It
| Purpose | Examples | Our basis |
|---|---|---|
| Provide the Platform | Authenticate you, create labels, meter usage, show your dashboard | Performance of our contract with you |
| Bill you | Charge your plan, apply overage and credits, send receipts | Performance of our contract |
| Keep the Platform secure | Detect intrusion, rate-limit, investigate incidents | Our legitimate interest in a secure service; legal obligation |
| Prevent abuse | See Section 4.3 | Our legitimate interest in protecting the service and honest customers |
| Support you | Answer your questions, reproduce your bugs | Performance of our contract; legitimate interest |
| Improve the Platform | Aggregated, de-identified statistics | Legitimate interest |
| Meet legal obligations | Tax records, carrier claim windows, lawful requests | Legal obligation |
We do not use your personal information for advertising, and we do not build marketing profiles from your Platform usage.
4.3 Abuse prevention, in plain terms
Free plans exist to be tried, and a small number of people try to turn them into an unlimited free service. To stop that, we automatically analyse:
- IP addresses and network ranges, to spot one person running many "separate" free accounts.
- Request patterns, to distinguish an integration from a script rotating through accounts.
- The age of the domain in a newly registered email address, alongside unusual early usage.
- The ratio of address, rate, and tracking calls to labels actually purchased.
This is automated analysis, and it can result in throttling, key revocation, or suspension of a Workspace. It is not automated decision-making producing legal effects in the GDPR sense, and a human reviews any suspension you dispute. If you believe a decision was wrong, write to support@flexops.io and we will look at it ourselves.
5. Who We Share It With
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months.
We disclose personal information to service providers who process it on our instructions:
| Recipient | What they get | Why |
|---|---|---|
| Microsoft Azure | Everything we host | Cloud hosting, database, cache, message bus, key management |
| Microsoft Entra ID | Sign-in identifiers, where you federate | Authentication |
| Stripe | Billing contact, amounts, payment method (held by Stripe) | Payments and subscriptions |
| Google (Gmail / Workspace SMTP) | Your email address and message contents | Verification codes, two-factor codes, billing and usage notices |
| Google reCAPTCHA | IP address and interaction signals on our forms | Spam and abuse protection |
| Google Analytics | Marketing-site usage only | Website analytics |
| Sentry | Error diagnostics, which can include identifiers | Error tracking |
Configured but switched off: Plaid and Twilio have credentials in our configuration but are disabled, so nothing reaches them. We will update this Policy before enabling either.
Carriers are not our processors. When you buy a label, validate an address, or track a shipment through an enabled carrier, that carrier receives the sender and recipient details needed to perform the requested service. Carriers decide how to use that data under their own terms of carriage, which makes them independent controllers. Their handling is governed by their privacy policies, not ours.
We may also disclose information where required by law, to enforce our agreements, or in connection with a merger or sale of assets — in which case we will tell you before your information becomes subject to a different policy.
6. How Long We Keep It
| Category | Retention |
|---|---|
| Account and company records | For the life of your account, then 90 days |
| Label and shipment records | Life of your subscription, then 7 years (carrier claim windows and tax records) |
| Billing records | 7 years |
| Security and audit logs | 2 years |
| Terms acceptance records | 7 years after the account closes — this is the proof of what you agreed to |
| Usage metrics | Detailed counters roll monthly; aggregated summaries 24 months |
| Support correspondence | 3 years |
A legal, regulatory, or litigation hold suspends deletion of the affected records until it lifts. These are maximums — we delete earlier where we no longer need the data.
7. Your Rights
Wherever you live, you can ask us to:
- Know what we hold about you and get a copy.
- Correct anything inaccurate.
- Delete your personal information, subject to the retention periods in Section 6 and to records we must keep.
- Export your data before you close your account.
- Opt out of non-essential analytics — see the Cookie Policy.
- Complain, without us retaliating against you for exercising any of these rights.
If you are a California resident, the CCPA/CPRA rights to know, delete, correct, and to opt out of sale or sharing all apply. We do not sell or share personal information, so there is no opt-out to exercise, but the right to say so is yours. You may use an authorised agent.
To exercise any of these, email privacy@flexops.io. We will verify your identity through your account and respond within 45 days, extending once by a further 45 days if we genuinely need to and telling you why.
Most of this you can also do yourself: your profile, your data export, and account closure are all in your Workspace settings.
8. Security
We protect your information with TLS 1.2 or higher in transit and encryption at rest, per-Workspace data scoping enforced at the authorization, query, and database layers, hashed passwords and API keys, two-factor authentication, and audited administrative access. Full technical and organizational measures are in Annex II of the DPA.
No system is perfectly secure. If we confirm a breach affecting your data, we will notify your Workspace administrators without undue delay and in any event within 72 hours of confirming it, with what we know and what we are doing about it.
To report a vulnerability, write to security@flexops.io.
9. Children
The Platform is a business tool and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect personal information from anyone under 18; if we learn we have, we delete it.
10. Changes to This Policy
We will post any change here and update the version date above. If a change is material, we will give at least 30 days' notice by email to your Workspace administrators and in the Platform before it takes effect. We keep superseded versions and will send you one on request.
11. Contact Us
- Privacy questions and rights requests: privacy@flexops.io
- Security reports: security@flexops.io
- Legal: legal@flexops.io
- Support: support@flexops.io
FlexOps, LLC 39116 Fremont Hub, PMB 1222 Fremont, CA 94538-1328
Last Updated: August 20, 2026 Effective Date: August 20, 2026