Privacy Policy

This policy explains how Floov handles account, billing, product, and form-response data, and how you can exercise your privacy rights.

Last updated:

1. Who We Are and Our Roles

Floov is operated by FLOOV S.R.L., a company registered in Romania under CUI 54655476 and Trade Register number J2026030772003 (“Floov”, “we”, “us”).

We are a controller when we decide why and how to process account, billing, security, support, and our own product analytics data. When a Floov customer uses the service to collect form responses, the customer is normally the controller and Floov is its processor. Our Data Processing Agreement governs that processing. The form owner determines what a form asks, why responses are collected, how long they are kept, and which integrations receive them.

FLOOV S.R.L.

CUI 54655476 · VAT RO54655476 · Trade Register J2026030772003 · Romania

[email protected]

2. Data We Process

Account and Authentication Data

  • Name, email address, email-verification status, profile image, account role, and workspace membership.
  • A one-way password hash when you use password login. We never store your plaintext password.
  • For Google sign-in, the Google account identifier, name, email, and profile image returned for authentication. Login access and refresh tokens are not retained.
  • Pending email-change information and short-lived reauthentication state used to protect sensitive account changes.

Billing, Tax, and Invoice Data

Stripe collects payment-card and billing details directly. Floov stores identifiers and records needed to manage the subscription and reconcile payments, such as Stripe customer, subscription, checkout, invoice, payment, and refund references; plan status and dates; currency and amounts; payment-method brand and last four digits where returned; and billing, tax, and fiscal-invoice information. Floov does not store a complete card number or card security code.

Forms, Responses, Files, and Customer Instructions

We store form designs, settings, published snapshots, responses, partial responses, uploaded files, media-library items, notification settings, integration configuration, and delivery records. A form can request any information selected by its owner, including contact data, free text, addresses, dates, ratings, and uploaded documents. Partial responses are retained until the form owner deletes them. Files chosen during a partial save are not uploaded until final submission.

When a customer enables email notifications, respondent confirmations, webhooks, Google Sheets, Airtable, Notion, Slack, Discord, Zapier, Make, Mailchimp, HubSpot, or another integration, Floov processes or forwards the selected response data on that customer’s instructions.

Google Sheets and Google Workspace API Data

When a workspace owner connects Google Sheets, Floov receives the Google account email used to label the connection, an OAuth access token, and, where Google provides one, a refresh token. The tokens are encrypted at rest and are used only to keep the customer-configured Google Sheets delivery working. Floov requests the drive.file permission and can access only spreadsheets the owner explicitly selects through Google Picker for use with Floov; it does not receive permission to browse all files in the account’s Drive.

For a selected spreadsheet, Floov reads its title, worksheet names, header row, Floov-created column metadata, and existing Floov submission identifiers. It writes the form-response fields selected by the customer, together with configured submission metadata, as rows and maintains Floov column metadata so mappings survive renamed or reordered headers. The selected spreadsheet identifier, title, worksheet, column choices, and connected-account identifier are stored with the form or workspace connection. Floov does not use Google Workspace API data for advertising, credit decisions, surveillance, general-purpose AI model training, or product improvement unrelated to the visible Google Sheets integration.

Workspace owners can disconnect a Google account from Settings > Integrations. Floov removes the local connection immediately and asks Google to revoke the token; temporary provider failures are retained in an encrypted revocation queue and retried. Rows already written to the customer’s spreadsheet remain under the customer’s control and are not deleted by Floov. Form owners may separately clear a form’s saved spreadsheet configuration.

Floov’s use and transfer of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.

AI-Assisted Form Features

When an authenticated workspace member chooses Create with AI, Floov processes the form brief and the selected audience, requested information, tone, language, length, page-layout, and start-page preferences. We send those instructions, together with Floov’s server-controlled generation instructions, to the Google Gemini API to produce a proposed form blueprint. Create with AI does not send form responses, existing form contents, uploaded files, media-library items, integration credentials, or connected-account tokens to Gemini.

When a workspace member uses Edit with AI, Floov sends the member’s edit instruction and bounded context from the current page to Gemini. That context includes the page name and visible title, the allowlisted editable settings and current values of up to 30 editable items, up to eight recent resolved exchanges from the current editor session, and an optional selected-item identifier as a targeting hint. Floov does not send the native form structure, the rest of the form, form responses, uploaded files, media contents, URLs, integrations, or connected-account tokens for this feature. Gemini returns one or more proposed item changes or additions, which the member must review and apply before they become part of the draft.

Do not paste real respondent or customer records, passwords, access credentials, confidential material, or sensitive personal data into an AI instruction. Floov encrypts AI instructions, context, and generated artifacts at rest. Form-creation content is erased when the generation is cancelled, expires, or is converted into an editable form, and otherwise no later than seven days after the request under the current service configuration. Selected-field edit content is erased when it is accepted, discarded, fails, or expires; an unresolved proposal expires within 24 hours. Its remaining non-content operational row is deleted after 30 days. We retain limited, non-content form-creation status and performance metadata for no longer than 90 days. AI-credit, provider-cost, purchase, refund, and related accounting records are stored separately without the instruction or generated form content and may be retained longer as needed to operate, secure, and account for the feature or meet legal obligations.

Production generation uses Google’s paid Gemini API service. Under Google’s published paid-service terms, prompts and responses are not used to improve Google products. Google may still process and retain prompts, responses, and related information for a limited period for abuse monitoring, legal compliance, and service operation, including in countries where Google or its agents operate. Floov does not opt in to Google’s optional developer prompt logging or dataset sharing for this feature.

Usage, Form Analytics, and Reports

Floov processes first-party view, start, page-reach, and submission signals for published forms. These can include a timestamp, form and page identifiers, device category, referring domain, campaign parameters, and a country inferred by infrastructure. View, start, and page-reach signals update aggregate counters; Floov does not retain individual visitor-event records. The viewer stores limited event-deduplication flags in session storage for the current tab, but they contain no random visitor or response-attempt identifier and are not sent to Floov. Raw IP addresses are not stored in form-analytics records. Daily visitor campaign aggregates are retained for 90 days; other daily and aggregate breakdowns remain while the form exists.

Form owners can publish unlisted, aggregate reports. These reports do not expose individual response rows, contact details, open-text answers, or uploaded-file values. Low-volume hidden-field attribution is suppressed.

Device, Session, Security, and Abuse-Prevention Data

Servers and security systems process IP address, user agent, request metadata, login and session events, CSRF data, rate-limit counters, and security logs. Cloudflare Turnstile processes browser and network signals on protected pages and returns a verification result to Floov. We also measure aggregate response, email, and storage use for security and fair-use review.

Support, Contact, and Legal Notices

If you contact us, we process your name, email, message, attachments or references you provide, and related correspondence. Contact-form messages are delivered to our team by email and are not separately stored in the Floov application database. If you have enabled Marketing technologies, HighLevel external tracking may also store supported site form fields and attribution information in Floov’s CRM. We may keep support, legal, billing-dispute, and illegal-content notice correspondence as needed to resolve the matter and document our response.

Email Verification, Product Analytics, CRM, and Site Tags

Reacher checks whether certain account and recipient email addresses appear deliverable before Floov stores pending changes or sends mail. The address is disclosed for that check. PostHog processes limited, allowlisted product events. Floov also uses Google Tag Manager as a container for Floov-configured analytics and marketing tags. Optional browser tags load only after the visitor enables their matching category; server-side authenticated PostHog events use the internal account identifier rather than name or email. Floov’s own PostHog and Google Tag Manager integrations are not loaded on published-form or public-report pages. Floov’s published Google Tag Manager container currently includes a Google Analytics 4 tag for page and related website and application usage measurement after Analytics consent. After Marketing consent, HighLevel external tracking processes page, referrer, campaign, session, device, IP address, and approximate location information and supported DOM form submissions for lead attribution and customer-relationship management. It can create or update a CRM contact from submitted fields. Separately, after account registration, or when a later sign-in finds no existing CRM association, Floov’s server queues the account name and email for secure transfer to HighLevel. Floov may also apply limited account lifecycle tags covering email verification, initial form creation, publication and response, current Free or Pro access, and subscription cancellation or expiry. These tags support customer-relationship workflows. This server-side account operation does not use optional browser storage and is not performed on published forms. Floov does not currently run Google advertising or retargeting tags on its marketing or application pages.

3. Purposes and Legal Bases

Under the GDPR, we rely on the bases below when Floov acts as controller. Where Floov is a processor, the customer determines the lawful basis for its form processing and Floov acts on documented instructions.

Floov processing purposes and GDPR legal bases
Purpose Legal basis
Create accounts, authenticate users, provide workspaces and forms, and deliver requested support Contract, Article 6(1)(b)
Provide user-requested AI features and meter the workspace owner’s shared AI credit balance Contract, Article 6(1)(b)
Manage subscriptions, AI-credit purchases, payments, cancellations, refunds, and customer-requested billing actions Contract, Article 6(1)(b)
Issue and retain tax and accounting records and respond to lawful requests Legal obligation, Article 6(1)(c)
Secure the service, prevent abuse and fraud, enforce terms, diagnose failures, and defend legal claims Legitimate interests, Article 6(1)(f)
Measure aggregate usage, improve product reliability, and review fair-use outliers Legitimate interests, Article 6(1)(f)
Maintain account and customer-relationship records after registration or sign-in Legitimate interests, Article 6(1)(f)
Load optional browser analytics, lead-attribution or CRM tracking, marketing tags, or owner-configured tracking where Floov’s banner applies Consent, Article 6(1)(a)

Our legitimate interests are maintaining a secure and reliable SaaS service, maintaining account and customer-relationship records, understanding limited product usage, preventing misuse, protecting users, and establishing or defending claims. We balance those interests against the nature of the data, reasonable expectations, safeguards, and available objections. We do not make decisions producing legal or similarly significant effects solely by automated means.

4. Recipients and Service Providers

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose only what is needed to operate Floov, comply with law, protect rights, complete a corporate transaction, or follow a customer’s integration instructions.

Main service providers and the purposes for which they process data
Provider Purpose Data involved
DigitalOcean Application and database hosting Service data stored or transmitted through Floov
Amazon Web Services (S3) Private response-file and public media storage Uploaded files, object metadata, and media
Cloudflare Turnstile bot protection and edge security Network, browser, and verification signals
Scaleway Transactional Email Transactional email delivery Recipient address and email content
Reacher Email deliverability verification Email address and verification result
Stripe Checkout, subscriptions, payments, tax, and billing portal Account, billing, payment, and tax information
Oblio Romanian fiscal invoices and reversals Customer identity, billing, tax, invoice, and refund data
PostHog (EU cloud) Limited product analytics Internal account ID and allowlisted event properties; browser pageviews after consent
Google Tag Manager and optional Google analytics or advertising services Consent-based website and application analytics, advertising measurement, personalized advertising, or remarketing Page, device, campaign, and interaction information after the corresponding Analytics or Marketing consent; Floov-owned tags are excluded from published forms and public reports
HighLevel (including LeadConnector) Consent-based page and campaign attribution, supported site-form capture, server-side account-contact sync, contact lifecycle tagging, contact management, and CRM automation Page URL, referrer, campaign, session, device, browser, IP address, approximate location, and supported submitted-form fields after Marketing consent; separately, account name, email, and limited lifecycle, product-milestone, plan, and subscription-state tags for server-side CRM operations; Floov excludes published forms
Google Optional sign-in and customer-connected Google Sheets Identity data or response data selected by the customer
Google (Gemini API) AI-assisted form creation and bounded page-aware field editing Generation or edit instruction, structured form preferences or bounded current-page editable values, up to eight recent resolved edit exchanges, optional selected-item identifier, Floov’s server instructions, generated blueprint or proposed field changes or additions, and operational request metadata

Separately, customer-selected webhook endpoints and integrations, including Airtable, Notion, Slack, Discord, Zapier, Make, Mailchimp, HubSpot, Google Sheets, Google Analytics, Google Tag Manager, and Meta Pixel, receive data only when the customer configures them. The customer is responsible for the destination, legal basis, disclosures, and consent configuration. Workspace members receive access according to their assigned roles.

5. Cookies, Browser Storage, and Tracking

Floov uses essential cookies for authentication, security, sessions, and CSRF protection. The consent choice itself is stored locally so we can remember it. On Floov’s own site and app, optional browser analytics and marketing technologies are off until the visitor chooses. HighLevel external tracking is part of Marketing and can load on Floov pages other than published forms only after Marketing consent. The published-form tracking choice described below has the narrower scope of GA4, GTM, and Meta Pixel configured by a form owner when that owner enables the form banner.

Published-form owners may configure save-and-resume, device-based duplicate prevention, GA4, GTM, or Meta Pixel. GA4, GTM, and Meta Pixel follow the visitor’s selected categories when the owner enables Floov’s form banner. If the owner disables it, configured trackers may load immediately at the owner’s direction, and the owner is responsible for providing any required notice and obtaining any required consent. Save-and-resume, browser-based duplicate prevention, and Floov’s first-party form analytics are separate. See the Cookie Policy.

6. Retention and Deletion

Floov data-retention periods
Data Retention
Account, workspaces, forms, responses, partial responses, media, and aggregate form analytics Until deleted by an authorised user or the account is deleted, subject to exceptions below
Daily visitor campaign aggregates 90 days
AI generation brief and generated preview artifacts stored by Floov Encrypted until cancellation, conversion into an editable form, or expiry, and otherwise no later than seven days after the request under the current service configuration
AI field-edit instruction, bounded recent conversation and current-page editable context, and proposed changes or additions stored by Floov Encrypted until acceptance, discard, failure, or expiry; unresolved proposals expire within 24 hours and the remaining non-content operational row is deleted after 30 days
AI feature, credit reservation and allocation, provider-attempt, cost, performance, purchase, expiry, refund, and failure metadata While the relevant account or workspace exists, or longer where reasonably necessary for security, accounting, disputes, and legal claims
Browser product analytics Up to 12 months, subject to the visitor’s consent choice
HighLevel contact, lifecycle-tag, site-form submission, and attribution records While Floov uses HighLevel and the record is needed for the relevant enquiry, lead, customer relationship, or legal obligation; then deleted or anonymised subject to provider backups and lawful retention
Active server session records Normally expire after two hours of inactivity
Google Sheets OAuth credentials and saved target configuration While the workspace connection or form configuration exists; credentials are removed locally on disconnect, with an encrypted token retained only while a remote revocation requires retry
Billing, tax, invoice, refund, fraud, security, support, and legal records For the period required by law or reasonably necessary for accounting, disputes, security, and legal claims

Account or content deletion removes the active database records and access immediately. Associated storage objects are placed in a durable deletion queue and retried until the storage provider confirms removal, so physical object deletion can complete shortly afterward. Provider backups, security logs, and legally required records may persist for their applicable retention period and are not used for ordinary service delivery. An account deletion cannot be undone.

7. International Transfers and Security

We prefer European hosting regions where available, but some providers operate globally and data may be accessed or transferred outside the EEA. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, the EU–US Data Privacy Framework for an appropriately certified recipient, or another lawful safeguard. A customer remains responsible for transfer safeguards arising from destinations it independently configures.

Safeguards include TLS in transit, password hashing, HTTP-only and SameSite session cookies, CSRF controls, rate limiting, role-based permissions, encrypted OAuth credentials, short-lived owner-authorised file download links, private response-file objects, audit and delivery records, and durable cleanup jobs. No method of transmission or storage is completely secure.

8. Your Privacy Rights

Subject to applicable law and exceptions, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier processing. You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local supervisory authority.

California residents may also request the categories, sources, purposes, recipients, and specific pieces of personal information we hold; correction or deletion; information about sale or sharing; and non-discriminatory treatment. They may use an authorised agent where permitted. Floov does not sell personal information, share it for cross-context behavioural advertising, or use or disclose sensitive personal information for purposes that trigger a right to limit.

Email requests to [email protected]. We may verify identity and authority before responding. We answer within the period required by applicable law, normally one month under GDPR and 45 days under the CCPA, with permitted extensions and notice. If Floov holds form data only for a customer, we will refer the request to that customer or assist it as required by our DPA.

9. Form Respondents and Children

If you submitted a Floov form, contact the person or organisation named on that form first: it normally controls the response. Floov cannot independently decide to disclose, change, or delete processor data contrary to that customer’s instructions, but we will assist the controller with a valid request.

Floov accounts are not intended for children under 16, or a lower age permitted by local law. Customers must not use Floov to collect children’s data without the notices, permissions, and parental authorisation required by law. If you believe account or form data was collected unlawfully from a child, contact the form owner and us.

10. Changes and Contact

We may update this policy to reflect legal, technical, or business changes. We will change the date above and provide additional notice where required. Material changes do not retroactively reduce rights without a lawful basis.

Privacy questions and rights requests may be sent to:

FLOOV S.R.L.

CUI 54655476 · Trade Register J2026030772003 · Romania

[email protected]