SeerFlow

Privacy Policy

Last updated: 25 August 2026

SeerFlow (“SeerFlow”, “we”, “us”) provides a cash-flow and business-intelligence dashboard for direct-to-consumer (D2C) brands. We read commerce, logistics, and payment data from the platforms a brand connects (such as Shopify, Razorpay, and Shiprocket) to compute cash position, payout timing, return (RTO) risk, and reconciliation insights. This policy explains what we collect, how we use it, who we share it with, and the choices you have. We do not sell personal data.

1. Who this policy applies to

This policy applies to (a) the brands and their authorised users who sign in to and use SeerFlow (“Customers”), and (b) the end-customers of those brands whose order and shipment information is processed by SeerFlow on the brand’s behalf. For end-customer data, the connected brand is the data controller and SeerFlow acts as a data processor.

2. Information we collect

Account information. When you create a SeerFlow account, our authentication provider (Clerk) collects your name and email address, and a password if you choose email/password sign-in. We do not store your password; it is managed by Clerk in hashed form.

Connected platform data. When you connect a provider, we access data through that provider’s API using read-only permissions. Depending on the provider this includes:

  • Shopify — orders, products, and fulfilments (scopes: read_orders, read_products, read_fulfilments). Order records may contain protected customer data such as order value, line items, payment method, fulfilment status, and the delivery pincode.
  • Razorpay — settlements, payouts, and fee data.
  • Shiprocket — shipments, delivery status, and remittance timing.

Usage and device data. We collect basic operational logs (e.g. request timestamps, error events) to keep the service reliable and secure.

Website diagnosis and calculator data. If you use the public problem router or Profit Leak Calculator, we collect the answers and calculator inputs you provide, a diagnosis or session identifier, the page path, bounded campaign parameters, and the origin of the referring site. If you request a reviewed audit, we also collect the contact and brand details you submit. We do not treat a questionnaire result or calculator estimate as a verified fact about your business.

Demo-booking data. If you choose a focused demo, we record the consent time and send you to Calendly using a tracked booking link. Calendly collects the details you enter on its booking page under its own privacy policy. We use those details together with the saved diagnosis only to prepare and administer the requested demo.

We request the minimum data needed to provide the service. We do not request or use end-customer names, emails, or phone numbers for marketing.

3. How we use information

  • Compute cash position, expected inflows/outflows, and cash-flow forecasts.
  • Score return-to-origin (RTO) and delivery risk, and detect financial anomalies.
  • Reconcile orders, settlements, and payouts.
  • Create a ranked website diagnosis, preserve the selected path through signup, and prepare an audit or focused demo you request.
  • Send operational notifications you enable (e.g. a daily summary by email or WhatsApp).
  • Maintain the security, reliability, and integrity of the service.

We use connected-platform data solely to provide these analytics to the brand it belongs to. We never use it for advertising or marketing, and we never sell it.

4. Protected customer data (Shopify)

SeerFlow accesses Shopify protected customer data only as required to deliver cash-flow and risk analytics to the merchant. We follow Shopify’s Protected Customer Data requirements: we apply data minimisation (read-only, only the fields we need), encrypt data in transit and at rest, restrict access to authorised personnel, honour data-subject deletion requests, and retain data only as long as the merchant’s account is active. We never modify a merchant’s store data — access is read-only.

5. Google user data (Google Ads)

When a brand connects Google Ads, SeerFlow uses Google OAuth with a single scope (https://www.googleapis.com/auth/adwords) — the only scope the Google Ads API offers. This section describes exactly how that Google user data is handled.

What we access. With your authorisation we read Google Ads reporting data for the ad accounts you choose: campaign names and identifiers, spend, impressions, clicks, conversions, and account currency and timezone. We do not access Gmail, Drive, Contacts, Photos, or any other Google service, and we request no other Google scopes.

How we use it. Google Ads data is used solely to provide user-facing features inside your own dashboard: showing your ad spend, computing return on ad spend and per-order contribution margin, folding ad spend into your cash-flow forecast, and answering the questions you ask our assistant about your own numbers. We do not use Google user data for advertising, ad targeting, lending or creditworthiness decisions, or any purpose unrelated to these features.

Transfer. We do not sell Google user data and do not transfer it to third parties, including data brokers or advertisers. It is processed only by the infrastructure sub-processors that host SeerFlow (cloud hosting and managed databases) acting on our instructions, or if disclosure is required by law.

Protection. Google Ads data is encrypted in transit (TLS) and OAuth tokens are stored encrypted at rest. Access is scoped to your own brand: no other tenant, and no SeerFlow feature outside your workspace, can read it.

Retention & deletion. We retain Google Ads data while your Google Ads connection is active. Disconnecting the integration in SeerFlow deletes the stored OAuth token immediately and associated ads data within 30 days; deleting your SeerFlow account does the same. You can also revoke SeerFlow’s access at any time from your Google Account security settings.

AI/ML. Google user data is not used to develop, improve, or train generalised AI or machine-learning models, and is not transferred to third-party AI services for model training. Our assistant reads your already-computed figures to answer your questions about your own business only.

SeerFlow’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. How we share information

We share data only with sub-processors that help us run the service, each under contractual confidentiality and security obligations:

  • Infrastructure & database — cloud hosting and a managed PostgreSQL database for storing normalised analytics data.
  • Authentication — Clerk, for sign-in and account management.
  • Communications — an email provider (Resend) and a WhatsApp Business provider (Interakt) for notifications you enable.
  • Scheduling — Calendly, when you choose to book a demo and enter information on its booking page.
  • Website measurement — Meta Pixel, for basic page-view and calculator-engagement measurement on the public website. We do not send problem-router answers or connected-platform records to Meta.
  • Payments — Shopify Billing, for SeerFlow subscription billing (charged through your Shopify account).
  • AI providers — to generate written explanations of already-computed figures. We send only the computed summary values needed for the explanation, never raw customer records.

We may also disclose information if required by law, or to protect the rights, safety, or security of SeerFlow, our Customers, or the public. We do not sell personal data and we do not share it for third-party advertising.

7. Data security

We encrypt data in transit using TLS and at rest in our managed database. Provider credentials (API keys and access tokens) are stored encrypted. Access is governed by role-based access control, and each brand’s data is isolated per tenant. We follow least-privilege practices and maintain audit records of data imports and deliveries.

8. Data retention & deletion

We retain connected-platform data only while the relevant provider is connected and the brand’s account is active. When you disconnect a provider, delete your account, or request deletion, we delete the associated data (and honour end-customer deletion requests forwarded by the brand), subject to any limited retention required by law. Uninstalling the SeerFlow app from Shopify revokes our access and triggers deletion of the associated store data.

Browser session identifiers used by the public diagnosis and calculator are kept in session storage until that browser session ends; the local marker that prevents a repeated prompt remains until you clear site data. Server-side diagnosis events and calculator-audit contact records remain until the related lead or account is deleted, or until you ask us to delete them, subject to limited retention needed for security, dispute handling, or law. If you did not create an account, you can request deletion using the contact address below. Calendly retains booking data under its own published retention and deletion terms.

9. Your rights

Depending on your jurisdiction (including India’s DPDP Act and the EU/UK GDPR), you may have rights to access, correct, export, or delete your personal data, and to withdraw consent. To exercise these rights, contact us at help@seerflow.in. End-customers of a connected brand should direct requests to that brand; we will assist the brand in fulfilling them.

10. International transfers

We and our sub-processors may process data in countries other than where you are located. Where we transfer personal data across borders, we rely on appropriate safeguards and apply the protections described in this policy.

11. Cookies

The SeerFlow application uses essential cookies for authentication and session management. The public website also uses browser session or local storage to remember whether the problem router was shown, keep a non-sensitive routing identifier through signup, and avoid repeating the calculator or questionnaire path during the same visit. Meta Pixel may use cookies or similar technology for the website-measurement purpose described above. You can restrict cookies and browser storage in your browser settings, although essential sign-in and handoff features may then work differently.

12. Children

SeerFlow is a business tool not directed to individuals under 18, and we do not knowingly collect their personal data.

13. Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide notice through the service.

14. Contact us

For any privacy questions or requests, contact us at help@seerflow.in.

© 2026 SeerFlow. This policy is provided for transparency and does not constitute legal advice.