Privacy Policy
Last Modified: January 9, 2026
1. Introduction
Welcome to www.iotflows.com (the "Site"), owned and operated by IoTFlows Inc., a Delaware corporation ("IoTFlows," "we," "us," or "our"). IoTFlows is committed to protecting your privacy and handling your personal information with care and respect.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our Services (including our industrial IoT monitoring solutions, hardware devices, cloud platform, and related services), create an account, or make a purchase. This Privacy Policy applies to all users, including visitors, customers, organization administrators, and team members.
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, you must not access or use our Services.
2. Information We Collect
We collect several types of information from and about users of our Services, including:
2.1 Information You Provide to Us
We collect information that you voluntarily provide to us when you:
- Create an Account: Full name, email address, phone number, password, and organization affiliation
- Make a Purchase: Billing and shipping address, company name, phone number, email address, and payment information (processed securely through Stripe)
- Request a Demo or Contact Us: Name, work email, company website, job title, number of machines to optimize, timeline for implementation, product interests, and any additional information you choose to provide
- Use Our Platform: IoT device data, sensor readings, production data, machine health metrics, configuration settings, alert preferences, and custom dashboard configurations
- Communicate with Support: Messages, support tickets, feedback, feature requests, and any information you provide in correspondence with our customer support team
- Participate in Surveys or Promotions: Responses to surveys, questionnaires, contest entries, and promotional activities
2.2 Information Collected Automatically
When you access and use our Services, we automatically collect certain information about your device, browsing actions, and usage patterns, including:
- Device Information: IP address, browser type and version, operating system, device type, unique device identifiers, mobile network information
- Usage Data: Pages visited, features used, time spent on pages, links clicked, search queries, access times and dates, referring website addresses
- Location Information: General location (city, state, country) derived from your IP address
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixels, and similar technologies (see our Cookie Policy for details)
- Analytics Data: Data collected through Google Analytics (analytics and performance metrics) and Facebook Pixel (advertising and conversion tracking)
2.3 IoT Device and Sensor Data
Our Services are designed to collect, process, and analyze data from IoT devices and industrial sensors. This may include:
- Sensor Readings: Vibration data, acoustic measurements, temperature readings, laser distance measurements, production counts
- Machine Health Metrics: Equipment status, utilization rates, downtime events, maintenance predictions, anomaly detections
- Device Metadata: Device serial numbers, firmware versions, connectivity status, location assignments, configuration parameters
- Production Data: Production cycles, output quantities, efficiency metrics, quality measurements
2.4 Information from Third Parties
We may receive information about you from third-party sources, including:
- Payment Processors: Transaction confirmation and payment status from Stripe
- Authentication Services: Account information from AWS Cognito when you create or access your account
- Advertising Partners: Campaign performance data and conversion tracking from Facebook and Google
- Email Verification Services: Email validation results to prevent spam and ensure data quality
- Scheduling Services: Appointment booking information from Calendly when you schedule a demo
3. How We Use Your Information
We use the information we collect for various purposes, including:
3.1 To Provide and Maintain Our Services:
- Create and manage your account
- Process and fulfill orders for hardware and subscriptions
- Deliver cloud platform services, real-time dashboards, and analytics
- Process IoT device data and generate insights, alerts, and reports
- Provide customer support and respond to inquiries
- Manage subscriptions, billing, and payment processing
- Store and retain your data according to your subscription plan (2 years for Essential, 5 years for Enterprise)
3.2 To Improve and Optimize Our Services:
- Analyze usage patterns and performance metrics to improve our platform
- Develop new features, products, and services
- Conduct research and development, including machine learning and AI model training
- Test and troubleshoot new features
- Create anonymized, aggregated data for analytics and benchmarking
3.3 To Communicate with You:
- Send service-related notifications, updates, and security alerts
- Respond to demo requests and schedule product demonstrations
- Provide technical support and customer service
- Send billing notifications.
- Send marketing communications about our products and services (with your consent or as permitted by law)
- Request feedback and conduct customer satisfaction surveys
3.4 For Marketing and Advertising:
- Display targeted advertisements through Google Analytics and Facebook Pixel
- Measure advertising campaign effectiveness and conversion rates
- Identify and showcase customer success stories (with your approval)
- Promote our products and services to prospective customers
- Track referral sources and marketing attribution
3.5 For Legal and Security Purposes:
- Comply with legal obligations, court orders, and regulatory requirements
- Protect our rights, privacy, safety, and property
- Detect, prevent, and address fraud, security incidents, and technical issues
- Enforce our Terms and Conditions
- Verify identity and prevent unauthorized access
- Monitor for spam and abusive behavior using reCAPTCHA v3
3.6 To Create Anonymized Data:
We may create aggregated, de-identified, or anonymized data from your personal information by removing identifying information. We use this anonymized data for research, analytics, benchmarking, and to improve our Services. Anonymized data is not considered personal information under this Privacy Policy.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers: We share information with third-party service providers who perform services on our behalf, including:
- Stripe: Payment processing and subscription management (card data is processed directly by Stripe and not stored on our servers)
- Amazon Web Services (AWS): Cloud hosting, authentication (AWS Cognito), and file storage (AWS S3)
- Google: Analytics (Google Analytics) for website performance and user behavior analysis
- Facebook: Advertising and conversion tracking (Facebook Pixel)
- Calendly: Demo appointment scheduling and calendar management
- Email Service Providers: Transactional and marketing email delivery
- Google reCAPTCHA: Spam and abuse prevention
These service providers have access to your information only to perform specific tasks on our behalf and are obligated to protect your information and not use it for other purposes.
4.2 Within Your Organization: If you are part of an Organization account, your information and device data may be accessible to Organization Owners and team members with appropriate permissions within your organization.
4.3 Business Transfers: If IoTFlows is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Site of any change in ownership or use of your personal information.
4.4 Legal Requirements: We may disclose your information when required by law, regulation, legal process, or governmental request, including to:
- Comply with subpoenas, court orders, or legal obligations
- Respond to lawful requests from law enforcement or government authorities
- Protect our rights, property, or safety, or that of our users or the public
- Detect, prevent, or investigate fraud, security incidents, or illegal activity
- Enforce our Terms and Conditions or other agreements
4.5 With Your Consent: We may share your information for any other purpose with your explicit consent or at your direction. This includes featuring your organization in customer case studies, success stories, or marketing materials (we will seek your approval before publishing detailed case studies).
4.6 Aggregated or Anonymized Data: We may share aggregated or anonymized data that does not identify you personally with third parties for research, marketing, analytics, and other business purposes.
5. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing activities and improve your experience on our Site. These technologies help us understand how you use our Services, remember your preferences, and deliver relevant content and advertisements.
Types of Cookies We Use:
- Strictly Necessary Cookies: Essential for the operation of our Site and Services, including authentication (AWS Cognito session cookies) and security
- Analytics Cookies: Google Analytics cookies that help us understand how visitors use our Site
- Marketing Cookies: Facebook Pixel cookies used for targeted advertising and measuring ad campaign effectiveness
For detailed information about the specific cookies we use, their purpose, duration, and how to manage them, please see our Cookie Policy.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using SSL/TLS protocols
- Secure authentication through AWS Cognito with industry-standard security practices
- Payment data processing through PCI DSS-compliant payment processor (Stripe)
- Regular security audits and vulnerability assessments
- Access controls and authentication mechanisms to limit access to personal information
- Secure cloud infrastructure through AWS with redundancy and backup systems
- Employee training on data protection and security best practices
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You acknowledge that you provide your personal information at your own risk.
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Specific Retention Periods:
- IoT Device Data and Sensor Readings: 2 years for Essential Plan customers; 5 years for Enterprise Plan customers (as specified in your subscription)
- Account Information: Retained for the duration of your active subscription and for 30 days after account termination or cancellation
- Payment and Transaction Records: Retained for at least 7 years to comply with tax, accounting, and legal requirements
- Marketing and Communication Data: Until you withdraw consent or request deletion, or as required for legitimate business purposes
- Support Tickets and Correspondence: Retained for 3 years for quality assurance and service improvement
- Analytics and Usage Data: Typically retained for 26 months (Google Analytics standard retention)
Upon termination of your subscription, we will retain your data for 30 days before deletion, allowing you time to export your data or reactivate your account. After this period, your data will be permanently deleted, except for information we are required to retain by law.
8. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
8.1 GDPR Rights (European Union Users)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right to Access (Art. 15 GDPR): Request confirmation of whether we process your personal data and obtain a copy of your data
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data
- Right to Erasure / "Right to Be Forgotten" (Art. 17 GDPR): Request deletion of your personal data under certain circumstances
- Right to Restriction of Processing (Art. 18 GDPR): Request limitation of how we use your personal data
- Right to Data Portability (Art. 20 GDPR): Request a copy of your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller
- Right to Object (Art. 21 GDPR): Object to our processing of your personal data, particularly for direct marketing purposes
- Right to Withdraw Consent: Withdraw your consent at any time where we rely on consent to process your data
- Right to Lodge a Complaint: File a complaint with your local data protection authority (Art. 77 GDPR)
8.2 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources from which we collected it, our business purposes for collecting it, and the categories of third parties with whom we share it
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: Opt out of the sale of your personal information (note: we do not sell personal information)
- Right to Non-Discrimination: Exercise your privacy rights without receiving discriminatory treatment
- Right to Correct: Request correction of inaccurate personal information
California "Shine the Light" Law: California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, contact us at support@iotflows.com with "Shine the Light" in the subject line.
8.3 How to Exercise Your Rights
To exercise any of the above rights, please contact us at:
- Email: support@iotflows.com or legal@iotflows.com
- Phone: 404-390-2110
- Mail: IoTFlows Inc., 1 Concourse Pkwy Suite 800, Atlanta, GA 30328
We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request to protect your privacy and security. You may designate an authorized agent to make requests on your behalf, in which case we will require proof of authorization.
9. International Data Transfers
IoTFlows is based in the United States, and our Services are hosted on servers located in the United States (AWS US-East-1 region). If you access our Services from outside the United States, your information will be transferred to, stored in, and processed in the United States.
The United States may have data protection laws that differ from those in your country of residence. By using our Services, you consent to the transfer of your information to the United States and other countries where we or our service providers operate.
For users in the European Union, we implement appropriate safeguards to protect your personal data when it is transferred internationally, including:
- Standard Contractual Clauses approved by the European Commission
- Ensuring our service providers (such as AWS) comply with GDPR requirements and provide adequate data protection
- Implementing technical and organizational security measures to protect data in transit and at rest
10. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are under 18 years of age, you may only use our Services with the involvement, consent, and supervision of a parent or legal guardian who agrees to be bound by our Terms and Conditions.
If we learn that we have collected personal information from a child under 18 without proper parental consent, we will delete that information as quickly as possible. If you believe we may have collected information from a child under 18, please contact us immediately at support@iotflows.com.
Compliance with COPPA: We aim to comply with the Children's Online Privacy Protection Act (COPPA) and similar laws protecting children's privacy.
11. Third-Party Links and Services
Our Site and Services may contain links to third-party websites, applications, or services that are not owned or controlled by IoTFlows. This Privacy Policy does not apply to these third-party services. We are not responsible for the privacy practices or content of third-party websites or services.
We encourage you to review the privacy policies of any third-party services before providing them with your personal information. Third-party services we integrate with include:
- Stripe (payment processing) - Privacy Policy
- Amazon Web Services - Privacy Policy
- Google Analytics - Privacy Policy
- Facebook - Privacy Policy
- Calendly - Privacy Policy
- Google reCAPTCHA - Privacy Policy
12. Marketing Communications and Your Choices
We may send you marketing communications about our products, services, promotions, and events if you have provided consent or if permitted by applicable law. You have choices regarding these communications:
Email Marketing: You can opt out of receiving marketing emails by clicking the "unsubscribe" link at the bottom of any marketing email or by contacting us at support@iotflows.com. Even if you opt out of marketing communications, we will still send you transactional and service-related messages (such as order confirmations, billing notifications, and important account updates).
Cookies and Tracking: You can manage your cookie preferences through your browser settings. See our Cookie Policy for more information on how to control cookies.
Targeted Advertising: You can opt out of interest-based advertising by:
- Visiting the Network Advertising Initiative opt-out page: http://www.networkadvertising.org/choices/
- Visiting the Digital Advertising Alliance opt-out page: http://www.aboutads.info/choices/
- Adjusting your Google Ads settings: https://adssettings.google.com/
- Adjusting your Facebook Ads preferences: https://www.facebook.com/ads/preferences/
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on this page with a new "Last Modified" date
- Sending an email notification to the email address associated with your account
- Displaying a prominent notice when you log in to your account
Changes will be effective 30 days after we post the updated Privacy Policy or send email notification (or immediately upon posting for non-material changes). Your continued use of our Services after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Services and close your account. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
IoTFlows Inc.
1 Concourse Pkwy Suite 800
Atlanta, GA 30328
United States
Email: support@iotflows.com (General inquiries)
Legal/Privacy: legal@iotflows.com
Phone: 404-390-2110
Website: www.iotflows.com
We will respond to your inquiry within a reasonable timeframe, typically within 30 days.
15. Additional Information
Data Controller: IoTFlows Inc. is the data controller responsible for the processing of your personal information as described in this Privacy Policy.
Legal Basis for Processing (GDPR): We process your personal information on the following legal bases:
- Contract Performance: To provide our Services and fulfill our contractual obligations to you
- Legitimate Interests: To improve our Services, conduct marketing, prevent fraud, and ensure security
- Consent: Where you have provided explicit consent for specific processing activities (e.g., marketing communications)
- Legal Obligation: To comply with applicable laws and regulations
Automated Decision-Making: We may use automated decision-making and profiling for purposes such as fraud detection, spam filtering (using reCAPTCHA), and predictive analytics for machine health monitoring. These automated processes are designed to improve our Services and protect users. You have the right to request human review of automated decisions that significantly affect you.
