HouseFlow privacy policy

Your house project is private by design.

This policy describes how information is handled when HouseFlow is used to organise a home project.

Last updated: 31 August 2026

1. About this policy

HouseFlow is a private home-project management tool operated by the owner of this Site. It helps organise tasks, products and services, supplier quotes, payments and project documents.

This policy explains what information HouseFlow handles, why it is used, how it is protected and the choices available to people whose information appears in the tool.

2. Information HouseFlow handles

HouseFlow may store the following categories of information:

  • Project information: house areas, tasks, priorities, statuses, comments, budgets, products, services and planned work.
  • Supplier information: business names, trades, contact people, phone numbers, email addresses, ratings and notes.
  • Quote and payment information: prices, VAT status, deposits, balances, payment dates, invoices and proof-of-payment metadata.
  • Documents: uploaded quotes, plans, photographs, warranties, contracts, certificates and related filenames or links.
  • Access and security information: password-protected session data, API-token names, token prefixes, expiry dates and last-used times. Full API tokens are shown once and stored as cryptographic hashes.
  • Technical information: hosting and security providers may process IP addresses, browser details, request times and diagnostic or security logs when the Site is accessed.

3. How information is used

Information is used to operate HouseFlow and provide its project-management features, including:

  • organising and tracking house-project work;
  • comparing products, services and supplier quotes;
  • managing project documents and payment records;
  • maintaining password and API access;
  • preventing abuse, investigating errors and protecting the Site; and
  • improving the accuracy and usefulness of the project records.

HouseFlow does not sell personal information or use project records for third-party advertising.

4. Sharing and service providers

Information is shared only when needed to operate the Site, comply with a lawful requirement, protect the Site or follow the owner’s instructions. Hosting, database, file-storage, security and infrastructure providers may process information on behalf of HouseFlow to provide those services.

Anyone who receives an API token may access and change HouseFlow records within the token’s permissions. Tokens should therefore be shared only with trusted integrations and people.

5. Storage and security

Structured project records are stored in a managed database, while uploaded files are stored separately in managed object storage. The dashboard is password protected, sessions expire, repeated login attempts are limited, and API tokens can expire or be revoked.

No online system can guarantee absolute security. The owner should use strong access controls, revoke unused tokens and avoid uploading information that is not needed for the project. Quote documents may contain addresses, signatures or banking details; redact unnecessary sensitive information before uploading where practical.

6. Cookies and similar technology

HouseFlow uses an essential session cookie to keep the dashboard unlocked after a successful password check. The session expires automatically. Hosting and security providers may also set strictly necessary cookies to protect and deliver the Site.

HouseFlow does not use advertising cookies in the application.

7. API tokens and URL access

API tokens grant full create, read, update and delete access to HouseFlow data. Header-based authentication is recommended. URL-based tokens are supported for compatible tools, but URLs can appear in browser history, copied links and access logs.

Create a separate token for each integration, choose an appropriate expiry date and revoke a token immediately if it may have been exposed.

8. Retention and deletion

Project records and files are kept for as long as the owner needs them to manage the house project or maintain related records. Individual records and documents can be deleted from HouseFlow. Revoked-token records may be retained for security and audit purposes.

Backups, logs or cached copies may remain for a limited period before being overwritten or deleted by the relevant infrastructure provider.

9. Access, correction and choices

The Site owner can review, correct, export or delete HouseFlow records using the dashboard or API. Suppliers and other people whose contact information appears in HouseFlow may ask the owner to correct or remove inaccurate information, subject to any records the owner must reasonably retain.

Depending on the applicable law and circumstances, individuals may also have rights to request access, correction, deletion, restriction or objection, or to complain to the relevant privacy authority.

10. Children’s information

HouseFlow is not designed for children and the owner should not intentionally add children’s personal information unless it is genuinely necessary and handled with appropriate permission and care.

11. Changes to this policy

This policy may be updated when HouseFlow’s features, service providers or information practices change. The latest version will be published on this page with a revised update date.

12. Contact

For privacy questions or requests, contact the HouseFlow Site owner through the same communication channel used to receive access to the Site. Include enough detail for the owner to identify the relevant record without sending unnecessary sensitive information.