FORM P-1Privacy Policy

What we keep, and what we don't.

EFFECTIVE 2026-07-21 · ISSUED BY EASTBASE STUDIO

OkayFlow is built so the people who never signed up — your clients — are tracked the least. This policy covers what we collect, why, and who helps us process it.

01The short version

  • We collect what we need to run your account, your projects, and billing — not more.
  • The client review portal, public receipts, and approval packets load no analytics or marketing trackers. They are used by your clients, who never signed up for OkayFlow.
  • Elsewhere, analytics load only if you accept them — see cookies & analytics.
  • We never sell your data or your clients’ data.
  • You can ask us to export or delete your data — see your rights.

02Who we are

OkayFlow is operated by Eastbase Studio, based in Vietnam. This policy explains what personal data we handle when you use the OkayFlow website and app, and when your clients use the review links you share. We are the controller of the account and billing data you give us; for the client and project content you add, you are the controller and OkayFlow processes it on your behalf.

03What we collect

Account data.Your name, email address, and a hashed password (handled by our authentication layer), or — if you choose “Continue with Google” — the basic profile your Google account shares. Plus your workspace name, optional logo URL, and default settings.

Project content you add. Project and deliverable details, the links or text you submit for review, your revision and approval-terms settings, an optional project value and payment link, and the client names and email addresses you enter so we can send review links and notifications.

Client review decisions. When a client approves or requests changes, we record their name, email, the decision, any note, the version reviewed, and the timestamp, plus a hashed IP address and the browser user agent. We keep this as the approval / evidence signal behind the receipt — we do not store raw client IP addresses. Your clients see a short privacy notice next to the decision action explaining this.

Billing data. If you subscribe, our payment processor (Lemon Squeezy) handles your card details — we never see or store them. We keep your plan, subscription status, and renewal dates.

Product and diagnostic data. On the marketing site and the signed-in app, we collect error reports to keep the Service reliable, and — only if you accept analytics — aggregate usage and performance data to improve it (see cookies & analytics).

04How we use it

  • To provide the Service: run your account, projects, and review links.
  • To send transactional email — review notifications, approval alerts, approval-deadline reminders (paid plans), and password resets.
  • To process payments and manage your subscription.
  • To keep the Service secure and reliable: rate limiting, abuse prevention, error monitoring, and an audit log of key actions.
  • To understand product usage in aggregate and improve OkayFlow, where you have accepted analytics.

06Cookies & analytics

Essential cookies. We use a session cookie to keep you signed in, and a small preference cookie to remember your analytics choice. These are required for the app and your choice to work, are not used for advertising, and load without asking.

Analytics (optional). On the marketing site and the signed-in app, product and traffic analytics (PostHog and Vercel) help us understand usage and performance. They do not initialize or set any analytics cookie or storage until you accept — you choose Accept analytics, Reject non-essential, or Manage preferences in the banner, and can change it later.

Analytics never run on the client review portal (/r/…), public receipts, or approval packets (/packets/…), regardless of any choice — those surfaces are deliberately analytics-free because they are used by people who never chose OkayFlow.

We do not use third-party advertising cookies and we do not sell your data.

07Who processes your data

We rely on a small set of trusted providers to run OkayFlow. Each processes data only as needed to provide its part of the Service:

  • NeonManaged PostgreSQL hosting for account, project, approval, and receipt data.
  • Lemon SqueezyMerchant of record for paid plans: checkout, payment processing, invoices, and tax/VAT.
  • ResendTransactional email delivery (review notifications, approval alerts, reminders, password resets).
  • VercelApplication hosting. Also aggregate traffic and performance analytics on the marketing site and signed-in app — loaded only if you accept analytics.
  • PostHogProduct analytics on the marketing site and signed-in app — loaded only if you accept analytics, and never on the client review portal, receipts, or approval packets.
  • SentryError and performance monitoring to keep the service reliable.
  • UpstashRate limiting that protects public links and accounts from abuse.
  • CloudflareTurnstile bot verification on account sign-up and password recovery forms.
  • GoogleSign-in via "Continue with Google", only if you choose it (optional).

08Data retention

We keep your data while your account is active. When you close your account or ask us to delete your data, we delete or anonymize your personal data in our active systems within 30 days.

Copies can linger a little longer in encrypted backups, server and security logs, email-delivery records, and diagnostic data; these are normally overwritten or cleared within about 90 days. We keep some records longer only where we must — billing, tax, and accounting records to meet legal obligations, and records we need to resolve a dispute or protect the security of the Service.

Issued approval receipts are immutable records of a decision that was made. When you delete a project or close your account, we remove your workspace and project data on the schedule above and delete or de-identify the associated receipts, except where we are required to retain a record. Note that any receipt or packet a client has already downloaded, printed, or been sent lives outside OkayFlow, so we cannot recall those copies.

09Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can update most account details in your settings; for export or deletion, email us at support@eastbase.studio and we will action your request.

Because OkayFlow processes your clients’ data on your behalf, if a client asks you to remove their information, you can do so in the app or ask us for help.

10International transfers & children

Our providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for those transfers.

OkayFlow is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16.

11Changes to this policy

We will update this policy as the product and our providers change, and we will revise the effective date above. See also our Terms of Service.

Questions about this document? Email support@eastbase.studio.