Privacy Policy

Effective date: 19 July 2026
Operator: Sharkflow Private Limited (Singapore)
Privacy contact: [email protected]

This policy explains how Sharkflow Private Limited ("Sharkflow", "we", "us") handles personal data when it provides the Sharkflow multi-tenant business operations platform, its websites, and related support (together, the "Service").

Our role

We determine how account, billing, security, and service-administration data is handled. For business records that a customer organization puts into the Service, that organization determines the purpose of processing and Sharkflow generally processes the data on its instructions. If you are an employee, customer, supplier, or other person whose data was provided by a customer organization, contact that organization first; we will support it in responding to your request.

Personal data we handle

  • Account and identity data, such as name, work email, phone number, login and consent records, organization membership, and role.
  • Organization and business data, including company profiles, contacts, documents, finance records, HR and payroll records, schedules, and statutory or compliance records.
  • Communications and commerce data from connected services, including email, support conversations, store customers and orders, shipping details, and integration identifiers.
  • Files and content submitted for storage, OCR, search, automation, or AI-assisted work, including prompts and generated output.
  • Billing data, subscription status, usage records, and payment tokens handled by our payment provider. Sharkflow does not store full payment card numbers.
  • Technical and security data, such as session information, hashed IP addresses, audit events, device information, and service logs.

How we use personal data

  • Provide, secure, administer, and support the Service.
  • Authenticate users and enforce organization access controls.
  • Process customer instructions, including storage, bookkeeping, HR, communications, commerce, automation, OCR, and AI-assisted tasks.
  • Measure usage, bill subscriptions, and prevent fraud or abuse.
  • Diagnose incidents, maintain audit evidence, and comply with legal obligations or enforce our agreements.
  • Improve the Service using operational and product feedback. We do not sell personal data or use customer content for third-party advertising.

AI-assisted processing

When an organization enables AI or OCR features, relevant content may be sent to the provider selected for that task. The provider and model can vary by configuration. We use authenticated commercial API access and available provider privacy controls, and limit the data sent to what the feature needs. However, provider terms, service tiers, features, and settings determine how submitted content is retained and used. Where those terms or settings permit it, a provider may retain content, have authorized reviewers inspect it, or use it to improve or train models. Sharkflow does not control those provider practices and does not promise zero retention or no training. The current providers are identified below.

Sharing and disclosure

We disclose personal data to authorized members of the relevant customer organization, to the subprocessors needed to deliver the Service, and where required to protect the Service, enforce an agreement, complete a corporate transaction, or comply with law. We do not share personal data with third parties for their own advertising.

Subprocessors

The following providers may process customer personal data when their corresponding feature is used. Processing location describes the provider footprint recorded in our current register and is not a promise of exclusive data residency.

ProviderPurposeProcessing location
HetznerCloud infrastructure and hostingGermany / Singapore
CloudflareDNS, edge security, and object storageGlobal
StripeSubscription billing and payment processingGlobal
ResendTransactional email deliveryGlobal
Meta PlatformsInstagram messaging integrationGlobal
ShopifyCommerce integrationGlobal
EasyParcelShipping and logistics integrationMalaysia / SEA
Fireworks AIAI inferenceUnited States
AnthropicAI inferenceUnited States
OpenAIAI inference and embeddingsUnited States
GoogleEmail integration, AI, embeddings, and document processingGlobal
Mistral AIDocument OCRFrance / EU

International transfers

Some providers process data outside Singapore. We use contractual and organizational safeguards intended to require protection comparable to applicable Singapore data-protection requirements. A customer may ask us for current transfer information relevant to its enabled providers.

Retention and deletion

We keep personal data while it is needed to provide the Service, satisfy the customer's documented instructions, secure and audit the platform, resolve disputes, or meet legal obligations. Retention varies by data category. For example, Singapore business and tax records may need to be retained for at least five years from the relevant year of assessment. When data is no longer needed for a business or legal purpose, it is deleted or anonymized under our retention schedule.

Your choices and rights

Depending on the applicable law and our role, you may request access, correction, deletion, or a copy of personal data, or withdraw consent where processing relies on consent. Exceptions can apply, including legal retention and the rights of other people.

Registered users can request an export or deletion from the privacy section of their profile page. Other individuals can follow our data request process or email [email protected]. We may verify identity and coordinate with the customer organization responsible for the data.

Cookies

The Service uses first-party cookies and similar browser storage that are necessary for sign-in, session security, organization selection, and user preferences. We do not currently use third-party advertising pixels or cross-site behavioral advertising cookies. If that changes, this policy and any required consent controls will be updated before the technology is enabled.

Security

We use access controls, tenant isolation, encryption for designated restricted fields, audit logging, secrets management, and operational monitoring. No system is completely secure, and customers remain responsible for their users, connected accounts, and access settings.

Children

The Service is for organizations and is not directed to children. Users must be at least 18 or otherwise able to enter a binding agreement for their organization.

Changes and contact

We may update this policy and will publish the revised effective date. Material changes will be communicated through the Service or another appropriate channel. Questions, requests, or complaints may be sent to [email protected]. You may also contact the Personal Data Protection Commission of Singapore.