Effective date: August 12, 2026. Operator: FlowState QSR. Contact: admin@flowstateqsr.com.
FlowState QSR (“the App”) is a private team-management tool for the team and leadership of a restaurant. Accounts are created and managed by the restaurant’s operator. This policy explains what the App collects and how it is used.
Information we collect
- Account info: your name, username, and password (passwords are stored only as a secure one-way hash, never in plain text). Your role and store number.
- Profile & contact details you or your store add: a nickname, a profile photo, a phone number, an email address, and your birthday. If your store uses minor-labor protections, your full date of birth is stored to apply break and hours rules for employees under 18.
- Employment & pay data your store's leaders enter: schedules, station assignments, certifications, and (if your store uses the timeclock) clock-in/out punch records and an hourly wage used for payroll exports and waste costing.
- Location-verification signals (timeclock only): if your store turns on clock-in verification and you allow location access, your device sends its coordinates at clock-in; we store only your distance from the store and a near/far flag with the punch, not your coordinates, and never outside of clocking in. If your store doesn't use this or you decline, no location data is processed.
- Work records you and your team create: goals, feedback, shout-outs, messages and channel posts (with attachments), checklists, training interests, uniform & facilities requests, discipline records, safety checks (RSA/FSA), temperature logs, CEM scores, waste logs, car counts, events, and similar operational data.
- Push token (only if you enable notifications): a device identifier used solely to deliver notifications.
- Basic technical logs: session records include IP address and browser/app type for security.
Inside the app, we do not collect your contacts or browsing history, use advertising identifiers, or use any advertising or cross-site tracking tools.
Our public marketing pages are the exception, and only those pages. Our home page, demo page and enquiry confirmation page carry Google's advertising tag, so that we can tell which advertisements are worth paying for. It may set cookies and report your visit to Google. If you arrive from an advertisement, the click identifier is also stored alongside any enquiry you choose to send us and, if you buy a subscription on our website, alongside that purchase, so that we can report the sale to the platform that showed you the advertisement. We keep it in your browser for at most 90 days, and only ever pass it back to the platform it came from.
That tag runs only on those public pages. It is not present anywhere inside the FlowState app: not on the sign-in page, not on any screen you see once signed in, and not in our iPhone or Android apps. Your work records, messages, schedules, timeclock punches and everything else described above are never exposed to it. If you are a team member using FlowState at work, no advertising tag ever runs against your account.
How we use it
We use this information solely to operate the team-management tool for your store: schedules, the timeclock and payroll exports, recognition, food-safety and compliance logs, messaging, and the notifications you opt into. Some features use an AI assistant (see Service providers below); AI features only process store data when someone at your store uses them.
On our public marketing pages only, we record which page was requested, the campaign tag on the link if there is one, and your browser’s user-agent string, which is the short description every browser sends saying what it is. We use it for one thing: telling real visitors apart from automated traffic, so we can tell whether advertising we paid for reached people. On those pages we also keep two random identifiers in your browser's own storage, one for the visitor and one for the visit, so that we can count people and visits rather than page loads. They are random, first-party, tied to nothing about you or your device, never shared, and the records that carry them are deleted after 180 days. We keep a partial network address against these records, never the full one: the last part is dropped, which is enough to see that traffic came from a data centre rather than a person, and not enough to identify you or your household. We also keep an approximate location that our content delivery network works out before the request reaches us: the country, the region or state, the city, and a coordinate rounded to about seven miles. It tells us whether advertising reached the country we sell in. It is not precise enough to place anyone at an address, and we never combine it with anything else to try. If you use the optional “Ask about FlowState” box on those pages, we also keep the question, the answer, and that same partial network address so we can see what operators actually ask. None of this happens anywhere inside the app.
Your team is not our marketing list. We never use a team member’s name, email address or phone number to market anything, to them or to anyone else, and we never build or seed advertising audiences from store data. The only email we send a team member is a password reset they requested. This is written into section 4 of our terms, so it is a contractual commitment rather than a policy statement.
How it’s shared: service providers (subprocessors)
- Within your store: teammates see information according to their permission level (leaders and the operator see more than team members). The operator administers the system.
- Render (USA): application hosting and data storage.
- Cloudflare (R2 object storage): the interview videos applicants record through a store's application link, when the store's videos are kept in a bucket. Played back on short-lived signed links only.
- Apple: push notifications (APNs) on iOS: device token and notification text; Sign in with Apple if you link it; App Store purchases.
- Google Play: subscription purchases if you subscribe on Android.
- Google Firebase Cloud Messaging: push notifications on Android: device token and notification text.
- Stripe (USA): card payments for web subscriptions. We do not receive or store your full card details.
- Google (advertising tag): only on public marketing pages, so we can tell which advertisements are worth paying for. It is not present inside the app.
- Resend: transactional email such as a password reset you requested. Never used to market to a teammate.
- Anthropic (USA): powers the optional in-app AI features (the "Ask your store" assistant, checklist extraction from uploaded documents, schedule-photo import, and AI-drafted coaching/write-up text). When your store uses these, the relevant store data (for example, an uploaded schedule photo, or the names and records involved in the question) is sent to Anthropic's API to generate the response. Anthropic does not train on this API data.
- xAI (USA): powers the optional public “Ask about FlowState” box on marketing pages only. The question text is sent to generate the answer. It does not receive store data, wages, or anything from a signed-in account. This feature is off unless we have configured it.
- RevenueCat: subscription purchase processing for the store's plan (no employee data; purchase identifiers only).
- Sentry: error reporting (operational error context only; configured to exclude personal data and wages).
- Encrypted off-site backups may be stored with an S3-compatible storage provider.
- We do not sell your information and do not share it for advertising or cross-app/website tracking.
Job applications
A store can take job applications through a link of its own on this site. If you apply, the store receives what you enter on the form and the video you record or upload. It is stored for that store, encrypted at rest, and only the store's directors can see it. Applications and the video are kept for one year (a store may set a shorter window for the video), or longer while the store keeps one for a legal reason, and can be deleted sooner by the store. If you give an email address, we send one message confirming the store received your application, and nothing else is ever sent to it. No advertising tag runs on the application page. To have an application removed, ask the store, or email us.
Tracking
The App does not track you across other companies’ apps or websites.
Data retention & deletion
Your information is kept while your account is active. Chat messages are deleted after one year. Timeclock records are retained for the period required by wage-and-hour law. You can export your personal data and delete your account from My Account in the app. Deletion disables the account, removes your profile details, and signs out all devices; some operational records your store is required to keep (for example time records) are retained per the schedule above. You can also ask your store operator, or email us, to correct or delete your information.
Security
Passwords are hashed, data is encrypted in transit (HTTPS) and, where configured, at rest (AES-256), and access is limited to logged-in members of your store by role.
Permissions on your device
- Camera & Photos: requested only when you choose to add a photo (a profile photo, a chat attachment, or a document/schedule upload).
- Location: requested only if your store uses clock-in verification, and only at clock-in (see above).
- Notifications: requested so we can send you work notifications you opt into. You can turn these off anytime in Settings.
- Face ID / Touch ID: used to unlock the app and, if you turn it on, to sign you in. A revocable sign-in token (not your password) is kept in the device's encrypted Keychain and never leaves your device. The biometric check happens entirely on your device, and we never receive your face or fingerprint data.
Employees under 18
The App is a workplace tool and is not directed to children under 13. Stores may employ workers aged 14–17; for them, the App stores date of birth so break and hours protections for minors can be applied automatically. Parents or guardians of an employed minor can contact the store operator, or email us, with questions about their teen's information.
Changes
We may update this policy; the effective date above reflects the latest version.
Contact
Questions about this policy, or a request about your own data? Email admin@flowstateqsr.com. For help using the app, email support@flowstateqsr.com.