Cookie Policy
DRAFT v1.0 — prepared for review by qualified counsel before publication. Replace bracketed placeholders.
Version: 1.0 Effective date: [EFFECTIVE DATE] Published at: flowagenci.com/legal/cookies
This Cookie Policy explains how [FLOWAGENCI LLC LEGAL NAME] ("FlowAgenci", "we") uses cookies and similar technologies on the following:
- our website (flowagenci.com)
- the Flow application (app.flowagenci.com)
- Client Portals (
<slug>.flowagenci.comor a Customer's custom domain)
Together these make up the "Service". It supplements our Privacy Policy and the Terms of Service.
1. Summary
- We only use strictly necessary cookies. They keep you signed in, protect forms and sign-in flows against attacks and bots, and keep the Service secure.
- We do not use advertising cookies, cross-site tracking cookies or third-party marketing pixels.
- Our analytics are cookieless. We use Cloudflare Web Analytics and first-party usage events recorded by our own servers. Neither sets cookies or tracks you across websites.
- Because we only use strictly necessary cookies, we do not show a cookie consent banner. If we ever introduce non-essential cookies, we will ask for your consent before setting them and update this policy.
2. What are cookies?
Cookies are small text files that a website stores in your browser. Similar technologies include local storage and session storage. "Strictly necessary" cookies are those required to provide a service you have requested, such as keeping you signed in. Under most privacy and e-privacy laws, including the EU ePrivacy rules and similar laws in Latin America, they do not require consent.
3. Cookies we use
| Name | Set on | Purpose | Type | Duration |
|---|---|---|---|---|
fa_app.* (session cookies) |
app.flowagenci.com and Customers' custom app domains | Keeps Authorized Users signed in to the team application | Strictly necessary, first-party. Host-only, HttpOnly, Secure, SameSite=Lax |
30 days, extended while you use the Service |
fa_portal.* (session cookies) |
Client Portal hosts (<slug>.flowagenci.com or custom portal domains) |
Keeps Portal Users signed in to a Client Portal | Strictly necessary, first-party. Host-only, HttpOnly, Secure, SameSite=Lax |
30 days, extended while you use the Service |
Sign-in state / CSRF cookie (e.g. fa_app.state, fa_portal.state) |
The host where you sign in | Protects sign-in flows (for example, Google sign-in and magic links) against cross-site request forgery and replay | Strictly necessary, first-party | Up to 10 minutes, or deleted at the end of sign-in |
Cloudflare Turnstile (cf_clearance and related) |
Public forms (/f/…) and sign-in pages, via challenges.cloudflare.com |
Distinguishes humans from bots to protect forms and sign-in against spam and abuse | Strictly necessary, third-party (Cloudflare) | Session to 30 minutes |
__cf_bm |
Any Service host, where applicable | Cloudflare bot management: identifies and mitigates automated traffic | Strictly necessary, third-party (Cloudflare) | 30 minutes |
Exact cookie names may carry a suffix, such as a session token or chunk index, and may change as we update the Service. Their purpose and category will stay the same.
Local storage
The application stores non-identifying interface preferences in your browser's local storage. Examples are whether the sidebar is collapsed, your light or dark theme, and table column widths. This data never leaves your device unless you save it as an account preference, and it is not used for tracking.
4. Analytics without cookies
We measure how the website and the Service are used in two ways, neither of which sets cookies:
- Cloudflare Web Analytics. Privacy-focused, cookieless page-view analytics. It does not use fingerprinting or track individuals across sites.
- First-party usage events. Our own servers record events inside the Service, such as "proposal sent" or "invoice created", to improve the product. These events are processed as described in our Privacy Policy and are never shared with advertisers.
5. Custom domains
When a Customer connects a custom domain to its Client Portal or application, the same cookies are set on that domain. They are set as host-only cookies, which means they are never shared with the Customer's other websites or with flowagenci.com. Each Client Portal has its own separate session.
6. How to control cookies
You can block or delete cookies in your browser settings. Because we only use strictly necessary cookies, blocking them will prevent you from signing in to the application or the Client Portal, and may prevent public forms from being submitted.
7. Changes to this policy
If we change the cookies we use, we will update this policy and the "Effective date" above. If we introduce any cookie that is not strictly necessary, we will ask for your consent before setting it.
8. Contact
Questions about this Cookie Policy can be sent to privacy@flowagenci.com.