FlowState QSR

Privacy Policy

What we collect, why, and what you can do about it.

Home · Help Center

Effective date: August 12, 2026. Operator: FlowState QSR. Contact: admin@flowstateqsr.com.

FlowState QSR (“the App”) is a private team-management tool for the team and leadership of a restaurant. Accounts are created and managed by the restaurant’s operator. This policy explains what the App collects and how it is used.

Information we collect

Inside the app, we do not collect your contacts or browsing history, use advertising identifiers, or use any advertising or cross-site tracking tools.

Our public marketing pages are the exception, and only those pages. Our home page, demo page and enquiry confirmation page carry Google's advertising tag, so that we can tell which advertisements are worth paying for. It may set cookies and report your visit to Google. If you arrive from an advertisement, the click identifier is also stored alongside any enquiry you choose to send us and, if you buy a subscription on our website, alongside that purchase, so that we can report the sale to the platform that showed you the advertisement. We keep it in your browser for at most 90 days, and only ever pass it back to the platform it came from.

That tag runs only on those public pages. It is not present anywhere inside the FlowState app: not on the sign-in page, not on any screen you see once signed in, and not in our iPhone or Android apps. Your work records, messages, schedules, timeclock punches and everything else described above are never exposed to it. If you are a team member using FlowState at work, no advertising tag ever runs against your account.

How we use it

We use this information solely to operate the team-management tool for your store: schedules, the timeclock and payroll exports, recognition, food-safety and compliance logs, messaging, and the notifications you opt into. Some features use an AI assistant (see Service providers below); AI features only process store data when someone at your store uses them.

On our public marketing pages only, we record which page was requested, the campaign tag on the link if there is one, and your browser’s user-agent string, which is the short description every browser sends saying what it is. We use it for one thing: telling real visitors apart from automated traffic, so we can tell whether advertising we paid for reached people. On those pages we also keep two random identifiers in your browser's own storage, one for the visitor and one for the visit, so that we can count people and visits rather than page loads. They are random, first-party, tied to nothing about you or your device, never shared, and the records that carry them are deleted after 180 days. We keep a partial network address against these records, never the full one: the last part is dropped, which is enough to see that traffic came from a data centre rather than a person, and not enough to identify you or your household. We also keep an approximate location that our content delivery network works out before the request reaches us: the country, the region or state, the city, and a coordinate rounded to about seven miles. It tells us whether advertising reached the country we sell in. It is not precise enough to place anyone at an address, and we never combine it with anything else to try. If you use the optional “Ask about FlowState” box on those pages, we also keep the question, the answer, and that same partial network address so we can see what operators actually ask. None of this happens anywhere inside the app.

Your team is not our marketing list. We never use a team member’s name, email address or phone number to market anything, to them or to anyone else, and we never build or seed advertising audiences from store data. The only email we send a team member is a password reset they requested. This is written into section 4 of our terms, so it is a contractual commitment rather than a policy statement.

How it’s shared: service providers (subprocessors)

Job applications

A store can take job applications through a link of its own on this site. If you apply, the store receives what you enter on the form and the video you record or upload. It is stored for that store, encrypted at rest, and only the store's directors can see it. Applications and the video are kept for one year (a store may set a shorter window for the video), or longer while the store keeps one for a legal reason, and can be deleted sooner by the store. If you give an email address, we send one message confirming the store received your application, and nothing else is ever sent to it. No advertising tag runs on the application page. To have an application removed, ask the store, or email us.

Tracking

The App does not track you across other companies’ apps or websites.

Data retention & deletion

Your information is kept while your account is active. Chat messages are deleted after one year. Timeclock records are retained for the period required by wage-and-hour law. You can export your personal data and delete your account from My Account in the app. Deletion disables the account, removes your profile details, and signs out all devices; some operational records your store is required to keep (for example time records) are retained per the schedule above. You can also ask your store operator, or email us, to correct or delete your information.

Security

Passwords are hashed, data is encrypted in transit (HTTPS) and, where configured, at rest (AES-256), and access is limited to logged-in members of your store by role.

Permissions on your device

Employees under 18

The App is a workplace tool and is not directed to children under 13. Stores may employ workers aged 14–17; for them, the App stores date of birth so break and hours protections for minors can be applied automatically. Parents or guardians of an employed minor can contact the store operator, or email us, with questions about their teen's information.

Changes

We may update this policy; the effective date above reflects the latest version.

Contact

Questions about this policy, or a request about your own data? Email admin@flowstateqsr.com. For help using the app, email support@flowstateqsr.com.

Terms of Service

← Back to the app

FlowState QSR is an independent product and is not affiliated with, endorsed by, or sponsored by Chick-fil-A, Inc. or any restaurant brand. All trademarks are the property of their respective owners.