01 — Scope and roles
One policy for the website, platform, and apps.
This policy applies to fondationflow.com, app.fondationflow.com, Fondation Flow applications, and related services. “Fondation Flow,” “we,” and “our” mean 9572-9026 QUÉBEC INC., doing business as Fondation Flow, the operator of those services.
We are responsible when we determine the purposes of processing, including demo requests, account administration, security, support, and service improvement. For most lead, customer, employee, and job records, we process information for the customer company under its instructions and settings.
Are you a contractor’s customer or employee? The company that created your record is normally your first point of contact. We assist it with requests concerning information hosted in Fondation Flow.
02 — Information processed
We limit collection to what supports the requested work.
| Category | Examples | Main purposes |
|---|---|---|
| Account and company | Name, email, phone, role, company, language, settings, and authentication information. | Create accounts, verify access, manage roles, provide support, and secure the service. |
| Leads and customers | Contact details, address, source, project, budget, availability, notes, messages, appointments, and history. | Centralize requests, prequalify, follow conversations, prepare estimates, and schedule work. |
| Employees and crews | Contact details, role, skills, availability, assignments, notes, photos, hours, breaks, and approvals. | Plan crews, document work, prepare timesheets, and produce hour reports. |
| Time-clock location | Point-in-time punch location, accuracy, jobsite distance, and zone result. If the employee enables forgotten-punch protection, the phone may arm an on-device work-zone region monitor up to 30 minutes before a scheduled start, without submitting scheduled-start GPS evidence before the start. From 2 through 30 minutes after the start, it may request limited current, point-in-time fixes, normally at the 4-minute checkpoint or a work-zone state change, and it may evaluate background samples during an eligible open shift. The bounded scheduled-start checks are not continuous tracking. Their technical evidence is short-lived and never keeps raw coordinates; the resulting reminder wording may remain in notification history. No route is uploaded or retained. A completed automatic clock-out keeps only limited final evidence with the time entry. | Associate time with the correct job, remind an employee who may have forgotten to clock in or out, complete a verified automatic clock-out, and support human review or correction. |
| Jobs and operating finances | Address, schedule, budget, cost categories, expenses, receipts, labour rates, profitability, and updates. | Run projects, track costs, prepare reports, and show operational profitability. |
| Connected accounting | QuickBooks company name, country and currency; selected customer identity, contact details and billing address; finalized invoice numbers, dates, currency, line descriptions, quantities, rates, taxes and totals; recorded payment amount, date and reference; and limited Intuit entity identifiers and synchronization status. Limited webhook metadata is collected only if a separately reviewed provider-event workflow is enabled. | Verify the connected QuickBooks company and, only after an authorized user reviews and confirms the action, send customers, finalized invoices and recorded payments one way to QuickBooks Online, reconcile results and prevent duplicate transfers. |
| Estimates and signatures | Scope, price, options, taxes, terms, signer, consent, date, and contextual evidence. | Create, send, track, accept, and retain evidence of electronic proposals. |
| Service subscription and billing | Company contact, billing address, selected plan, billing frequency, seat quantity, referral trial, provider customer/subscription identifiers, transaction identifier, status, and billing dates. Full card details and security codes are collected directly by Helcim and are not stored by Fondation Flow. | Create and administer the organization’s Fondation Flow subscription, verify payment, activate paid access, reconcile seats, and maintain billing evidence. |
| Communications | SMS, email, notifications, delivery status, preferences, and unsubscribe requests. | Respond, confirm appointments, send authorized reminders, and preserve relationship context. |
| Optional AI assistance | Prompts and messages; permitted company, customer, lead, project, estimate, schedule, workforce, and financial context; explicitly attached receipts, invoices, photos, or PDFs; and, for enabled lead qualification, lead identity, contact details, messages, and appointment context. | Provide Ask Flow, coaching, document extraction, optional import mapping, lead qualification, and unclear appointment-reply assistance after the applicable explicit consent. |
| Use and security | Technical identifiers, access logs, device, browser, errors, and administrative events. | Prevent unauthorized access, diagnose problems, audit actions, and protect accounts. |
We do not require health insurance numbers, social insurance numbers, or online-banking credentials. Fondation Flow can track subscription and customer-payment status and work hours, but is not a payroll remittance or card-processing service. When a Fondation Flow subscription requires a card, the secure card fields are provided by Helcim rather than Fondation Flow.
03 — Sources and purposes
Information comes from you, your company, or an authorized connection.
We receive information during registration, demo booking, signing, customer or employee use, and support. A customer company may create records for its people and customers. Leads may also arrive through services the customer connects, including advertising or communication services.
During company onboarding or a paid-seat change, Helcim receives the billing contact, address, amount, and card information needed to process the authorized transaction or recurring subscription. Fondation Flow receives only the provider identifiers, status, amount, dates, and other limited evidence needed to verify and administer access. Helcim’s processing is governed by the Helcim Privacy Policy.
When an authorized Customer connects QuickBooks Online, Fondation Flow uses Intuit’s authorization and accounting services to verify the selected company and perform the transfers the user explicitly reviews and confirms. Fondation Flow may read the QuickBooks company identity, country, home currency, relevant product or service items, tax configuration, matching provider records, identifiers and synchronization metadata needed to prepare or reconcile that transfer. The initial integration sends selected customers, finalized invoices and recorded payments from Fondation Flow to QuickBooks one way; it does not continuously or bulk-import the Customer’s QuickBooks file. The connection is isolated to the Customer’s Fondation Flow company and is not used to provide another customer with accounting data. Intuit’s processing is governed by the Intuit Privacy Statement.
Address search and selection use Google Maps Platform APIs, including Places SDK for iOS. Those features may send Google the entered search, selected address, and technical or location information needed to fulfil the request. They are also subject to the Google Maps Platform Terms and the Google Privacy Policy.
Optional AI features use Anthropic. Before any customer, lead, workforce, financial, prompt, message, or attached-document content is sent to Anthropic, Fondation Flow displays the provider, purpose, and data categories and records explicit, versioned permission from the authenticated user or, for automated lead qualification, the company owner. When enabling automated lead processing, the owner must also confirm that the company has authority to share the listed company, lead, and customer data with Anthropic for that purpose. Permission may be declined or revoked in Settings; non-AI features continue to work. See the Anthropic Privacy Policy.
- Provide, configure, maintain, and support the services selected by the customer company.
- Authenticate users, enforce permissions, and keep each company’s information appropriately separated.
- Connect leads, estimates, appointments, jobs, crews, costs, and profit to the correct file.
- Produce AI-assisted drafts, summaries, or recommendations when a user activates the feature.
- Transmit operational and, where permitted, commercial communications.
- Prevent abuse, investigate errors, document sensitive actions, and respond to incidents.
04 — Location, AI, and communications
Sensitive functions require context and control.
Normal GPS validation uses one location when an employee clocks in or out. On supported Apple and Android devices, an employee may separately enable optional forgotten-punch protection. The phone may arm an on-device work-zone region monitor up to 30 minutes before a scheduled assignment, but it does not submit scheduled-start GPS evidence before the start. From 2 through 30 minutes after the start, it may request and submit limited current, point-in-time fixes, normally at the 4-minute checkpoint or a work-zone state change. The server retains only short-lived derived on-site, off-site, or unverified evidence, accuracy, distance, and time for at most one missed clock-in reminder beginning five minutes after start—not the raw coordinates. These bounded scheduled-start checks are not continuous tracking, missing or unreliable location produces neutral wording, and no route is uploaded or retained. During an eligible open shift, the phone can display a local reminder, when notifications are allowed, after repeated accurate readings more than 100 metres beyond the saved work zone and request an automatic clock-out after the employee remains more than 200 metres beyond it for at least 30 seconds. Only limited final automatic-punch evidence is saved with the time entry. See the specific location notice for the full controls and limitations.
AI can organize information, draft text, or help qualify a lead, but users remain responsible for reviewing important outputs and decisions. AI data sharing is optional and remains blocked server-side unless the current Anthropic consent version is active.
Customer companies are responsible for having an appropriate legal basis and authority for the customer and lead information they collect, configure for automated AI processing, or send; for giving any notices and obtaining any consent required by applicable law; and for communication recipients, timing, and unsubscribe handling. Fondation Flow’s in-product owner authorization does not replace those obligations. See the specific location and AI communications notices for more detail.
Optional connected Gmail and Microsoft mailboxes.
Where this feature is enabled, you may connect a Gmail, Google Workspace, Outlook.com or Microsoft 365 mailbox to send email from your own address through Fondation Flow. The initial review is limited to an isolated test account and messages sent to the connected address itself. Connecting a mailbox does not enable this feature for other company accounts.
Google permissions are limited to OpenID identity, your verified email address and gmail.send. Microsoft permissions identify the signed-in mailbox and allow email sending and renewal of the connection. We process the provider account identifier, email address, authorization tokens and connection status. This integration does not request permission to read or import your inbox, contacts, calendar or existing messages.
When you request a send, Fondation Flow transmits the sender, recipient, subject, message body and any included attachment to the connected provider for delivery. We retain limited delivery evidence, including an operation identifier, a message fingerprint, provider message identifier when available, status and timestamp, to report the result and prevent duplicate sends. We do not retrieve the delivered message from your mailbox.
Connection credentials are encrypted at rest and used by our protected backend over encrypted connections. Access is restricted to the connected user and company through server-side controls. Hosting providers process this information only as needed to operate the service. Google processes mail under the Google Privacy Policy; Microsoft does so under the Microsoft Privacy Statement.
Data obtained through this integration is used only to provide the connected-mailbox feature and protect its operation. It is not sold, used for advertising, used to assess creditworthiness, or shared with AI providers or used to train AI models. Human access to Google user data is limited to your specific consent, necessary security investigations or legal obligations. These limits take precedence over broader descriptions elsewhere in this policy. Fondation Flow’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements.
You may disconnect in Settings → Email connections. Disconnecting removes the active connection and its locally stored tokens and invalidates pending connection attempts. It does not revoke the grant in your provider account; you can also remove access in Google Account connections or your Microsoft account’s app permissions. Disconnecting does not delete messages already sent, existing business records or the limited authorization and delivery evidence retained for security and duplicate prevention. These records follow the retention principles below; you can request deletion of connected-mailbox data at legal@fondationflow.com, subject to identity verification and applicable retention obligations.
05 — Disclosures and transfers
Access follows the service and a legitimate need.
Information may be disclosed to authorized users of the customer company, service providers supporting functions requested by the customer, professional advisers under confidentiality, a successor in a permitted transaction, or authorities where required by law.
Some processing may occur outside Quebec or Canada. Before a transfer, we assess relevant privacy factors and use contractual or organizational protections appropriate to the risk. Information may then be subject to lawful access in the other jurisdiction.
06 — Retention and safeguards
Information is retained for a defined business or legal need.
Retention depends on the record, account status, customer instructions, legal requirements, dispute needs, security, and backup cycles. Information is deleted, anonymized, or returned when the applicable purpose and retention period end, subject to reasonable technical and legal limits.
While QuickBooks is connected, a bounded scheduled cleanup makes expired authorization attempts eligible for removal once they are more than one day old, settled outbound payloads—and signed webhook metadata if that separately reviewed workflow is enabled—once they are more than 30 days old, and minimal non-payload audit events once they are more than 400 days old. A transfer with an unknown result is retained only until it is reconciled or the connection is removed so that retrying cannot create a duplicate.
When an authorized user disconnects QuickBooks from within Fondation Flow, Fondation Flow first asks Intuit to revoke the authorization, then removes the active OAuth credentials, provider identifiers, record mappings, transfer payloads, pending authorization state, webhook metadata, and live connection. If the user disconnects through QuickBooks instead, Intuit invalidates the authorization; the user must then sign in to Fondation Flow and use Disconnect from QuickBooks to finish removing the locally stored connection data. Until that cleanup or a verified deletion request, the encrypted credentials can no longer be used with Intuit and the inactive connection data is kept only to support safe cleanup or reconnection. Disconnecting does not delete the Customer Data kept in Fondation Flow or customers, invoices or payments already created in QuickBooks. Fondation Flow retains only a non-displayable company-ownership digest while the Fondation Flow company account exists, to prevent accounting data from being routed across customers, and a minimal non-payload disconnection audit event that becomes eligible for removal once it is more than 400 days old.
We use organizational and technical safeguards appropriate to the sensitivity, amount, purpose, and access context. No method is risk-free; customers also play an essential role by using individual accounts, suitable permissions, and protected devices.
07 — Your rights
Access, correction, withdrawal, and questions.
Subject to applicable law, you may ask whether we hold personal information about you, request access or correction, withdraw consent where processing depends on consent, or ask about a decision based exclusively on automated processing. Some limits and identity verification may apply.
When a customer company controls the record, send the request to that company first. You may also write to us about a privacy or deletion request, including a request concerning QuickBooks connection records, at legal@fondationflow.com. We will route and assist with the request according to our role, subject to identity verification and any applicable retention obligation.
Privacy requests
9572-9026 QUÉBEC INC., doing business as Fondation Flow
Registered office
555 Rue Chabanel O, Suite 1541
Montréal, QC H2N 2J2
Canada
08 — Updates and complaints
A material change is explained before it takes effect.
We may update this policy as the service, practices, or law evolve. The effective date is shown on the page, and material changes receive an appropriate notice. A person may submit a complaint to our privacy officer and may also contact the competent privacy authority.
Privacy requests
A question, complaint, or access request?
Write to Fondation Flow about a privacy question or request. We may need to confirm your identity before disclosing or correcting information.
9572-9026 QUÉBEC INC.
Registered office
555 Rue Chabanel O, Suite 1541
Montréal, QC H2N 2J2
Canada