Privacy Policy
Plainly stated, with the details that matter.
This is a working privacy notice for the Floral Intel Platform. It covers what we collect, how we use it, who else sees it, and how to remove it. If you find anything unclear, the contact page reaches a real person.
Last updated: April 27, 2026.
Who this covers
The Floral Intel Platform ("Floral Intel," "we," "us") is a B2B SaaS platform for independent flower shops. This policy covers how we handle data on the platform and on our marketing site at floral-intel.com.
This policy does not describe the data handling practices of any individual flower shop ("tenant") using the platform. Each tenant operates its own customer relationships and is responsible for its own privacy notices to its customers.
What we collect
From shops using the platform, we collect:
- Account & identity data. Names, email addresses, role assignments, location and tenant metadata for the people you grant workspace access to.
- Order data. Order numbers, recipient details, scheduled dates, status, and any notes attached.
- Photo evidence. Design-stage and delivery-stage photographs your team captures, plus the associated capture timestamp and (where the device provides it) GPS coordinates.
- Audit trail. A tamper-evident log of every meaningful action taken inside the workspace — captures, edits, sign-ins, role changes — used for dispute defense and security incident response.
- Operational telemetry. Server logs, error reports, and aggregate usage metrics needed to keep the platform running.
We do not collect or store cardholder data. The platform is not in PCI scope. Any payments processing — for partner commissions, billing, or referral credit — is handled by separately scoped processors and documented when those modules ship.
How we use it
We use the data above to:
- Run the features your shop has turned on.
- Generate the dispute and recap PDFs your shop requests.
- Surface metrics inside your workspace (orders per day, team activity, etc.).
- Investigate security incidents and resolve support cases.
- Communicate with you about platform updates and (only with consent) marketing.
We do not:
- Sell your data to anyone.
- Broker referrals to third parties using your data.
- Train AI models on your data without an explicit, separate opt-in.
- Use one shop's data to inform another shop's experience without aggregation and anonymization.
Who else sees it
We engage a small set of subprocessors — third parties who handle data on our behalf, under contract — for application hosting, database storage, and edge / DNS / DDoS protection. All current subprocessors are U.S.-domiciled. The current list is available to any tenant on request via the contact page.
We will notify tenants before adding any new subprocessor. If you are a tenant and want notification of subprocessor changes, ask us and we will add you to a changes-only mailing list at no cost.
Beyond subprocessors, we will only share your data when we are legally compelled to (subpoena, court order) or when you explicitly direct us to (e.g., authorizing us to share an order recap with your wire service or payments processor).
Where it lives, how long
Operational data is stored in the United States on managed cloud infrastructure with rolling backups. Backups are retained for thirty days.
Active workspace data persists for the life of your account. If you cancel, we retain your data for 90 days in case you reactivate, after which it is purged from production storage and aged out of backups within the following 30 days.
Photo proof can be deleted from inside the workspace, which removes it from active views immediately while retaining the audit record. To request hard deletion of specific data, contact us — we'll confirm the request and process it within 30 days.
Your rights
As a tenant administrator, you can at any time:
- Export your shop's data via the workspace exports.
- Edit or remove team members.
- Flag photographs and notes for soft-delete.
- Cancel your account.
To exercise rights that aren't self-serve — including hard-deletion of specific records, a copy of all data we hold about your account, or restriction of processing — contact us via the contact page. We will respond within 30 days.
Marketing site & cookies
The marketing site uses essential cookies only — a session cookie when you sign in, and basic load-balancer cookies set by our edge provider. We do not use third-party analytics (Google Analytics, Mixpanel, etc.) on the public site or the workspace today. If we add product analytics later, we will update this policy and announce the change.
Changes to this policy
When we make a material change to this policy, we will email tenant administrators at the address on file and post a notice on the workspace dashboard for at least 14 days before the change takes effect. The "last updated" date at the top reflects the most recent revision.
Contact
For privacy questions, data requests, or to report a potential incident, please use the contact page. If you'd prefer a postal address, contact us via the form and we'll provide one.