Privacy Policy
Effective August 9, 2026
NexaFlow OS processes account details, business configuration, customer conversations, leads, bookings, knowledge documents, and integration metadata to provide the service selected by each workspace.
Authentication and connected services
Authentication is provided through Supabase. When you connect Google or another provider, NexaFlow requests only the scopes shown on that provider’s consent screen. Access and refresh tokens are stored encrypted and are used only to deliver the connected feature.
Data use and sharing
Workspace data is used to operate, secure, troubleshoot, and improve the service. Data is shared with infrastructure and integration providers only as needed to perform requested operations. NexaFlow does not sell customer data.
Retention and control
Workspace administrators control the information they upload and the providers they connect. Deletion and access requests can be submitted through the account owner or service administrator. Some security, billing, and audit records may be retained where required for fraud prevention or legal compliance.
Security
The service uses tenant-level authorization, encrypted provider credentials, signed webhooks, HTTPS security headers, and restricted server-side secrets. No online service can promise absolute security, so administrators should rotate credentials and remove integrations they no longer use.
Changes
Material changes will be reflected on this page with a revised effective date. Continued use after a change means the updated policy applies.