Privacy Policy
Last updated: 12 August 2026
This policy explains how Flotto (“Flotto”, “we”, “us”) handles personal data. We are based in India and follow the Digital Personal Data Protection Act, 2023. Because we serve customers in the UK and EU, we also follow the UK and EU GDPR where they apply.
1. Scope and roles
Your account data.We decide how this is used, so we are the controller (a “Data Fiduciary” under the DPDP Act). This policy covers it.
Your leads’ data. When someone fills in a page you publish, you decide what happens to their information — you are the controller and we only hold it for you. This is covered by our Data Processing Agreement. If you are a lead and wish to have your data removed, contact the business whose page you completed.
2. Contact
For anything in this policy, or to exercise your rights, write to hello@flotto.co.
Grievances. If you are in India and wish to raise a formal grievance, write to hello@flotto.co marked for the attention of the Grievance Officer. We acknowledge within 72 hours and aim to resolve within 30 days. We are not a Significant Data Fiduciary and so are not required to appoint a Data Protection Officer.
3. What we collect
- Account — your name, email address and a password we store only in hashed form.
- Workspace — what you tell us about your business, and the pages, links and files you create.
- Billing — your plan and subscription reference. Card details go to Paddle and are never seen or stored by us.
- Usage — page views, clicks and scans, derived country, and broad device and browser type. IP addresses are not retained: they are used momentarily to derive a country and detect bots, then discarded.
We do not ask for special category data, and we do not sell personal data.
4. Why we use it
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Running the Service and your account | Performance of a contract |
| Taking payment and preventing fraud | Contract; legal obligation |
| Service and security emails | Performance of a contract |
| Measuring usage and improving the product | Legitimate interests |
| Preventing abuse and enforcing our Terms | Legitimate interests |
| Accounting and tax records | Legal obligation |
Under the DPDP Act these are undertaken on the basis of your consent or as a legitimate use connected to the service you have asked for. We do not make automated decisions with legal or similarly significant effects.
5. Cookies
We use a single cookie, which keeps you signed in. We do not use advertising cookies, third-party analytics scripts or cross-site tracking, either on this site or on the pages we host for you. Usage is counted on our servers and does not involve storing anything on your device.
6. Who we share it with
Only the providers below, each under contract and only for the purpose shown. We do not sell personal data. We may also disclose data where required by law, or as part of a sale of the business.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, edge delivery, file storage, bot protection | Global |
| Neon | Database (accounts, pages, captured leads) | United States |
| Paddle | Payments — merchant of record; handles billing and tax | United Kingdom / EU |
| Resend | Transactional email (account mail and delivery email) | United States |
| OpenRouter | AI page authoring and content-safety checks. Page content only — never captured leads | United States |
| Your email platform | Whichever provider YOU connect (Kit, Mailchimp, beehiiv, MailerLite, Brevo, ActiveCampaign). Leads are sent there at your instruction | Per provider |
7. Where data is held
Data is held principally in the United States. Transfers of UK or EEA data rely on an adequacy decision or, where none applies, the Standard Contractual Clauses or the UK Addendum. Transfers out of India are made in line with section 16 of the DPDP Act.
8. How long we keep it
- Account and workspace data — while your account exists, then deleted.
- Billing records — as long as tax law requires, which may be longer than the account.
- Leads — until you delete them or your account. Deleting a page does not delete the leads it captured; those stay yours until you remove them.
9. Security
Everything is encrypted in transit. Customer environments are separated. Credentials you give us for other services are encrypted at rest and never shown back in full or included in exports. Access to production data is limited to those who need it. No method of storage or transmission is completely secure.
10. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or transfer it elsewhere. Where we rely on consent you can withdraw it at any time. Under the DPDP Act you may also nominate someone to exercise these rights for you if you die or become incapacitated.
Account holders may export their data at any time from within the Service without submitting a request. For anything else, write to hello@flotto.co; we respond within one month.
11. Complaints
Complaints should be raised with us in the first instance. If you remain unsatisfied, you may complain to the Data Protection Board of India or, if you are in the UK or EEA, to the supervisory authority where you live or work.
12. Children
The Service is not directed to children and we do not knowingly collect data from anyone under 18. Where we become aware that we have, we delete it.
13. Changes
Where a change to this policy materially affects you, we will notify you by email before it takes effect. The date of the current version appears at the top of this page.