1. Who we are and what this policy covers
FloFrame, LLC ("FloFrame," "we," "us") is a software company at 5900 Balcones Drive, Suite 100, Austin, Texas 78731, United States. This policy explains how we handle personal information in two settings:
- The website at floframe.ai, including its contact form (the "Site").
- Our software products (the "Products"), currently TUOCA, The Upload Offline Conversions App, available at uploadofflineconversions.com. As we release further products (Land Manager, Silience, VividSVG), they are covered by this policy unless a product publishes its own notice.
"Personal information" means information that identifies, relates to, or could reasonably be linked with a particular person. This policy does not cover the practices of the third-party platforms our Products connect to (for example Google Ads or CallRail); each is governed by its own privacy policy.
2. In brief
- We do not sell personal information, and we never have.
- The Site uses analytics and may load advertising tags. You can turn the advertising tags off for your browser on Your Privacy Choices, and we honor the Global Privacy Control signal.
- Our Products move our customers' conversion data from their lead-tracking systems to advertising platforms. In that role we act on the customer's instructions as a service provider or processor. We use that data only to provide the service.
- Data we receive from Google, Meta, Microsoft, or TikTok through their APIs is used only to provide the feature the customer connected it for. It is not used for our own advertising, not sold, and not combined with other data for any other purpose.
- Questions and requests: info@floframe.ai.
3. What we collect
3.1 When you visit the Site
Usage data. We use PostHog, a product-analytics service, to understand how the Site is used. PostHog records pages viewed, links clicked, referring page, approximate location derived from IP address, browser and device type, and screen size. It may record a session replay of how a page was used; form inputs are masked in replays. PostHog is loaded through our own domain (floframe.ai/ingest) and stores a first-party identifier in your browser. If you have opted out on Your Privacy Choices or your browser sends the Global Privacy Control signal, PostHog runs without cookies or persistent identifiers, without session replay, and records only aggregate page counts.
Advertising and measurement tags. The Site loads Google Tag Manager, through which we may run Google Analytics 4, Google Ads, Meta (Facebook) Pixel, Microsoft Advertising, and TikTok tags. These providers may set cookies and collect your IP address, page views, and identifiers in order to measure our advertising and to show you FloFrame advertising elsewhere. None of these tags load if you have opted out or your browser sends the Global Privacy Control signal. See section 7.
Contact form. When you write to us through floframe.ai/contact, we collect your name, email address, company (optional), the reason you selected, and your message. With the submission we also record the page you landed on, the referring page, any advertising click identifiers and campaign parameters present in the URL you arrived on (for example gclid, fbclid, msclkid, ttclid, utm_*), and the PostHog identifier for your browser. We use these so we know which of our own advertising brought a genuine inquiry. The form is protected by Cloudflare Turnstile, which evaluates your browser to distinguish people from bots; Cloudflare's processing is described in its privacy policy.
Server logs. Our hosting provider, Cloudflare, logs requests to the Site, including IP address, user agent, and requested URL, for security and operations.
3.2 When you use a Product
Account information. Name, email address, company name, and a password or, if you sign in with Google, the name, email address, and profile picture Google provides. Team roles and invitations sent to colleagues (name and email of the invitee).
Billing information. Paid subscriptions are processed by Stripe. Stripe collects your payment card details directly; we receive your subscription status, plan, billing email, and the last four digits and brand of your card. We do not store full card numbers.
Connection credentials. To connect a Product to your systems you provide API keys (for example for CallTrackingMetrics or CallRail) or authorize us through OAuth (for example for Google Ads, Microsoft Advertising, Meta, TikTok, ServiceTitan, or Jobber). We store the resulting keys and tokens encrypted at rest and use them only to make the requests you have configured. You can revoke a connection at any time inside the Product or from the third-party platform.
Usage and support information. Actions taken in the Product, execution logs for the automations you configure, error reports, device and browser information, and anything you send to us when you ask for help.
Product telemetry. Products may use analytics tooling of the kind described in section 3.1 to understand how features are used.
3.3 Customer Data our Products process on your behalf
TUOCA exists to carry conversion records from a customer's lead-tracking and job-management systems to the advertising platforms the customer advertises on. The records it handles ("Customer Data") typically describe the customer's own leads and clients: phone numbers, names, email addresses, postal addresses, call times and durations, call recordings' metadata (not the recordings themselves), job or invoice values, and advertising click identifiers. Customer Data also includes anything a customer uploads by file or sends to a Product's webhook endpoint.
For Customer Data, our customer is the controller or business and FloFrame is the processor or service provider. We process Customer Data only to provide the Product as the customer has configured it, to secure and maintain the service, and as required by law. We do not use Customer Data to build profiles, for our own marketing, or to benefit anyone other than the customer. Individuals whose information appears in Customer Data should direct requests to the business they dealt with; we help our customers respond.
Before conversion records reach an advertising platform, personal fields such as email address, phone number, name, and address are normalized and hashed with SHA-256 according to that platform's specification (Google's Enhanced Conversions, Meta's Conversions API, Microsoft's and TikTok's equivalents). Raw values are not sent to advertising platforms.
4. How we use personal information
- To provide the Site and Products: create and secure accounts, run the automations you configure, upload conversions to the platforms you connect, send notifications about your account and connection health, and respond when you contact us.
- To bill for paid subscriptions through Stripe and keep the records that tax and accounting law require.
- To understand and improve the Site and Products, using analytics and aggregate usage data.
- To market FloFrame: measure our own advertising, and, unless you opt out, show FloFrame advertising to people who have visited the Site. We may email people who have contacted us or hold an account about FloFrame products; every marketing email includes an unsubscribe link.
- To protect the Site, Products, our customers, and others: detect abuse and fraud, enforce our terms, and defend legal claims.
- To comply with law and respond to lawful requests.
Where the GDPR or a similar law applies, our legal bases are performance of a contract (providing the Site and Products), our legitimate interests (security, analytics, marketing to business contacts, defending claims), consent where we ask for it (advertising tags where consent is required), and compliance with legal obligations.
5. Data from advertising and business platforms
Our Products receive data from third-party platforms through their APIs after a customer authorizes the connection. This section states the limits we hold ourselves to for that data.
Google. FloFrame's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Through the Google Ads API we read the list of accounts and conversion actions the connected user can access and write conversion records the customer has configured. Through Google Sign-In we receive basic profile information to create and secure an account. We use Google user data only to provide and improve the user-facing features the customer connected; we do not use it to serve advertising, do not sell it, do not transfer it except as needed to provide the feature, for security, or as required by law, and do not allow humans to read it except with the user's consent, for security purposes, to comply with law, or when it is aggregated for internal operations.
Meta, Microsoft, and TikTok. Data received through the Meta Marketing and Conversions APIs, the Microsoft Advertising API, and the TikTok Events and Marketing APIs is used only to list the connected accounts and conversion events and to send the conversion records the customer has configured. We handle it under those platforms' developer and platform terms, and we do not use it for any other purpose.
Source platforms. Data read from CallTrackingMetrics, CallRail, ServiceTitan, Jobber, and similar sources is Customer Data (section 3.3) and is used only to build the conversion records the customer has configured.
6. When we disclose personal information
We disclose personal information only in these cases:
- Service providers that process it for us under contract and only on our instructions. At present: Cloudflare (hosting, security, edge storage); Google Cloud (application hosting and storage for the Products); Stripe (billing); Resend and SMTP2GO (email delivery); PostHog (analytics); Google (Tag Manager, Analytics, Sign-In).
- Advertising platforms and business systems you connect, at your direction. When a customer configures TUOCA to upload conversions to Google Ads, Microsoft Advertising, Meta, or TikTok, we send those records to that platform. When you visit the Site with advertising tags enabled, those providers receive the information described in section 3.1; this may be considered "sharing" for cross-context behavioral advertising under California law, and you may opt out.
- Within a customer's account, to the team members the account owner has authorized.
- Legal and safety: to comply with law, a court order, or a lawful government request; to enforce our terms; or to protect the rights, property, or safety of FloFrame, our customers, or others.
- Business transfers: if FloFrame or a product line is acquired, merged, or reorganized, personal information may transfer to the successor, who will remain bound by this policy until it is changed under section 13.
We do not sell personal information and have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under sixteen.
7. Cookies, tags, and your choices
The Site uses first-party storage to remember your privacy choice and to give PostHog a stable identifier for your browser. Advertising and measurement providers loaded through Google Tag Manager may set their own cookies and pixels.
Opting out. On Your Privacy Choices you can switch advertising tags off for the browser you are using; PostHog then runs without cookies or replay. The choice is stored on that browser only.
Global Privacy Control. If your browser sends the GPC signal, we treat it as a request to opt out of sale, sharing, and targeted advertising for that browser, and no advertising tags load. We do not respond to other "Do Not Track" signals.
Browser controls. You can also block or delete cookies in your browser settings. Blocking cookies does not affect the Site's content.
Provider-side opt-outs are available from Google Analytics, Google Ads, Meta, Microsoft, and TikTok.
8. How long we keep personal information
We keep personal information for as long as it is needed for the purpose it was collected for, and then delete or de-identify it. In practice:
- Contact-form submissions are kept while we are in conversation with you and for a reasonable period afterward so we can follow up.
- Account information and Customer Data are kept while the account is active. When an account is deleted, or a reasonable period after a subscription ends without reactivation, we delete the account's data and destroy the encryption key that protected it. Connection credentials are deleted when you remove the connection or when the account is deleted.
- Billing records are kept for the period tax and accounting law requires, generally seven years.
- Analytics data is kept for the retention period configured in our analytics tooling and is otherwise aggregated. Session replays are kept for thirty days.
- Logs are kept for a short, rolling period for security and troubleshooting.
We may keep information longer where a legal obligation, a dispute, or the enforcement of our terms requires it.
9. How we protect it
Data is encrypted in transit with TLS and at rest. Every record a Product stores carries the identity of its owner and of the users authorized to read it, and that check is enforced at the storage layer, so one customer's data is not reachable from another's account. Connection credentials are encrypted with keys specific to the account that owns them. Access by FloFrame staff is limited to those who need it for support or operations and is protected by multi-factor authentication. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and the relevant authorities as applicable law requires.
10. Your rights
Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to certain processing, to withdraw consent, to opt out of sale, sharing, or targeted advertising, and not to be discriminated against for exercising these rights. Regional specifics are in the addenda linked at the top of this page.
To exercise a right, email info@floframe.ai or write to the address in section 14. We will need to verify that the request comes from you (or from an agent you have authorized), typically by confirming the email address on file. We respond within the time applicable law allows, usually within forty-five days. If we decline a request we will say why, and you may appeal by replying to our response.
If your information reached us inside a customer's Customer Data (section 3.3), the customer decides how it is used and your request should go to them. Tell us if you are unsure who that is and we will help.
Account holders can update account details and delete connections inside the Product, and can request account deletion from within the Product or by email.
11. Where we process information
FloFrame operates from the United States and our service providers process information in the United States. If you are outside the United States, your information is transferred here. Where the GDPR, UK GDPR, or a similar law applies to a transfer, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another mechanism recognized under that law.
12. Children
The Site and Products are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under eighteen. If you believe a child has provided information to us, email info@floframe.ai and we will delete it.
13. Changes to this policy
We will post any revision here and update the effective date at the top. If a change materially reduces your rights or expands what we do with information already collected, we will give notice in advance by email to account holders or by a notice on the Site.
14. Contact
FloFrame, LLC
5900 Balcones Drive, Suite 100
Austin, Texas 78731, United States
info@floframe.ai
If you are in the European Economic Area or the United Kingdom and are not satisfied with our response, you may lodge a complaint with your local supervisory authority. Contacts for other regions are in the addenda.