Effective Date: September 28, 2025
1. Introduction
Pocketsflow (“we,” “us,” or “our”) is committed to protecting your privacy and safeguarding your personal data. This comprehensive Privacy Policy explains our practices regarding the collection, use, storage, processing, sharing, and protection of your personal information when you access or use our digital marketplace platform at https://pocketsflow.com and related services (collectively, the “Platform”).
This policy is designed to comply with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy regulations. We implement a privacy by design approach and maintain the highest standards of data security throughout our operations.
2. Data Controller Information
Pocketsflow operates as the data controller for personal information we collect and process. The Platform is operated by Pocketsflow, Inc., a company registered in Delaware, USA.
For all privacy related inquiries, data protection concerns, or to exercise your rights under applicable data protection laws, please contact us at: chain@pocketsflow.com
3. Information We Collect
We collect information through various methods to provide, improve, and secure our services. The data we collect falls into the following categories:
3.1 Personal Information You Provide
- Account Information: Full name, email address, username, password (encrypted), account preferences, and profile settings
- Contact Information: Email address for communications, billing address for tax compliance and fraud prevention
- Payment Information: Credit card details, PayPal information, bank account details, and billing information (processed securely via third party payment processors)
- Profile and Business Information: Profile pictures, biographical information, seller descriptions, business details, product information, and creator page content
- Product and Content Data: Digital product listings, descriptions, pricing, categories, tags, and associated metadata
- Communications Data: Messages sent through our platform, support tickets, customer service interactions, reviews, ratings, and feedback
- Identity Verification Data: Government issued identification documents, business registration documents, tax identification numbers, and other verification materials (for sellers and high value transactions)
- Survey and Research Data: Responses to surveys, feedback forms, and user research activities
3.2 Information We Collect Automatically
- Device and Technical Information: IP address, browser type and version, operating system, device identifiers, screen resolution, and technical specifications
- Usage and Behavioral Data: Pages visited, time spent on pages, click patterns, search queries, navigation paths, session duration, and interaction patterns
- Location Data: General geographic location based on IP address, timezone information, and country/region data
- Performance and Analytics Data: Page load times, error reports, performance metrics, and usage statistics
- Security and Fraud Prevention Data: Security logs, failed login attempts, suspicious activity patterns, and fraud detection signals
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixels, local storage, and similar technologies as detailed in our Cookie Policy
3.3 Information from Third Parties and Partners
- Payment Processors: Payment processing data, transaction verification, identity verification results, fraud detection signals, and compliance screening results
- Analytics and Marketing Providers: Website analytics, user behavior insights, marketing campaign performance, and audience demographics
- Security Services: Fraud prevention data, security threat intelligence, and risk assessment information
- Verification Services: Identity verification results, business verification data, and compliance screening information
- Social Media Platforms: Public profile information when you link or interact with our social media accounts
- Other Users: Information about you provided by other users through reviews, reports, or other interactions
4. Legal Basis for Processing (GDPR Compliance)
We process personal data based on the following lawful bases under the General Data Protection Regulation (GDPR) and other applicable laws:
4.1 Performance of Contract (Article 6(1)(b) GDPR)
- Creating, maintaining, and managing user accounts
- Processing transactions and facilitating payments
- Delivering digital products and services
- Providing customer support and dispute resolution
- Implementing our Terms & Conditions
- Managing seller onboarding and approval processes
4.2 Consent (Article 6(1)(a) GDPR)
- Marketing and promotional communications
- Nonessential cookies and tracking technologies
- Optional data collection for service enhancement
- Participation in surveys and research activities
- Newsletter subscriptions and product updates
4.3 Legal Obligation (Article 6(1)(c) GDPR)
- Tax reporting and compliance with tax laws
- Anti money laundering (AML) and Know Your Customer (KYC) requirements
- Compliance with court orders and legal process
- Regulatory reporting and compliance obligations
- Data breach notifications to authorities
4.4 Legitimate Interests (Article 6(1)(f) GDPR)
- Platform security and fraud prevention
- System analytics and platform improvement
- Customer service optimization
- Business intelligence and operational efficiency
- Risk assessment and management
- Protecting intellectual property rights
- Direct marketing to existing customers (where permitted by law)
5. How We Use Your Information
We use your personal information for the following purposes, always in accordance with applicable law and our privacy principles:
5.1 Core Platform Services
- Provide and maintain our digital marketplace platform
- Process transactions, payments, and refunds
- Deliver digital products and services
- Manage user accounts and authentication
- Facilitate communication between buyers and sellers
- Provide creator page functionality and link in bio tools
5.2 Communication and Support
- Send transactional communications (order confirmations, receipts, etc.)
- Provide customer support and resolve disputes
- Send important platform updates and policy changes
- Respond to inquiries and support requests
- Conduct user surveys and collect feedback
5.3 Security and Compliance
- Prevent fraud, abuse, and security breaches
- Conduct identity and business verification
- Comply with legal obligations and regulatory requirements
- Investigate suspicious activities and policy violations
- Maintain platform integrity and safety
- Perform risk assessment and management
5.4 Analytics and Improvement
- Analyze platform usage and user behavior
- Improve our services, features, and user experience
- Develop new products and services
- Conduct research and analytics
- Optimize platform performance and functionality
5.5 Marketing and Personalization
- Send marketing communications (with proper consent)
- Personalize content and recommendations
- Conduct targeted advertising campaigns
- Analyze marketing campaign effectiveness
- Provide personalized user experiences
6. Data Sharing and Disclosure
We may share your personal information with third parties only in the following circumstances and always with appropriate safeguards in place:
6.1 Service Providers and Business Partners
- Payment Processors: We share payment and identity verification data with our payment processors to facilitate transactions. These processors operate under strict data protection agreements and their own privacy policies.
- Cloud Infrastructure Providers: We use secure cloud hosting services to store and process data with appropriate technical and organizational measures.
- Analytics and Marketing Services: We share aggregated, anonymized data with analytics providers to improve our services and understand user behavior.
- Customer Support Platforms: We may use third party tools to provide customer support while maintaining data security standards.
- Email Service Providers: We use secure email services to send transactional and marketing communications.
- Security and Fraud Prevention Services: We share data with specialized security providers to protect against fraud and abuse.
6.2 Legal and Compliance Requirements
- When required by law, regulation, or court order
- To comply with tax reporting obligations
- In response to lawful requests from government authorities
- To investigate and prevent illegal activities
- To enforce our Terms & Conditions and protect our rights
- For national security or law enforcement purposes (where legally required)
6.3 Business Transfers and Corporate Transactions
In the event of a merger, acquisition, corporate restructuring, or sale of assets, personal data may be transferred to the acquiring entity with appropriate safeguards and user notification.
6.4 User Directed Sharing
- Information you choose to make public through your profile or link in bio pages
- Product information and seller details visible on the platform
- Reviews and ratings you provide
- Information shared through platform messaging features
7. Your Privacy Rights
We respect your privacy rights and provide comprehensive controls over your personal data. Depending on your location, you may have the following rights:
7.1 GDPR Rights (EU/EEA Residents)
- Right of Access (Article 15): Request copies of your personal data and information about how we process it
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data
- Right to Erasure (Article 17): Request deletion of your personal data under certain circumstances
- Right to Restrict Processing (Article 18): Request limitation of how we process your personal data
- Right to Data Portability (Article 20): Request transfer of your data to another service provider
- Right to Object (Article 21): Object to processing based on legitimate interests or for marketing purposes
- Rights Related to Automated Decision Making (Article 22): Protection against automated decision making and profiling
- Right to Withdraw Consent: Withdraw consent for processing based on consent at any time
7.2 CCPA Rights (California Residents)
- Right to know what personal information we collect, use, and share
- Right to delete personal information we hold about you
- Right to opt out of the sale of personal information
- Right to nondiscrimination for exercising privacy rights
7.3 Exercising Your Rights
To exercise any of these rights, please contact us at chain@pocketsflow.com with your request. We will respond within the timeframes required by applicable law (typically 30 days for GDPR requests). We may need to verify your identity before processing your request to ensure data security.
8. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, and resolve disputes. Our retention periods are as follows:
- Account Data: Retained until account deletion, then archived for 7 years for legal compliance and dispute resolution
- Transaction and Financial Data: Retained for 7 to 10 years for tax compliance, audit requirements, and regulatory obligations
- Identity Verification Data: Retained for 5 years after account closure for compliance with KYC/AML regulations
- Marketing and Communication Data: Retained until consent is withdrawn or account is deleted
- Support and Communication Data: Retained for 3 to 5 years after case closure for quality assurance and legal purposes
- Analytics and Usage Data: Aggregated data retained for 26 months, with personal identifiers removed after 14 months
- Security and Fraud Prevention Data: Retained for up to 7 years for security analysis and fraud prevention
- Legal and Compliance Data: Retained as required by applicable laws and regulatory requirements
9. Data Security Measures
We implement comprehensive technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security framework includes:
9.1 Technical Safeguards
- Encryption: End to end encryption for data in transit using TLS 1.3 and strong encryption for data at rest using AES 256
- Access Controls: Multifactor authentication, role based access controls, and principle of least privilege
- Network Security: Firewalls, intrusion detection systems, and network segmentation
- Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning
- Secure Development: Security by design principles, code reviews, and secure coding practices
- Data Loss Prevention: Automated systems to prevent unauthorized data access and exfiltration
9.2 Organizational Measures
- Employee Training: Regular security awareness training and privacy education for all staff
- Access Management: Strict employee background checks and confidentiality agreements
- Incident Response: Comprehensive incident response plan with 24/7 monitoring and rapid response capabilities
- Data Governance: Clear data handling policies and procedures with regular compliance audits
- Third Party Security: Due diligence and security assessments for all service providers and partners
- Business Continuity: Disaster recovery and business continuity plans to ensure data availability and integrity
9.3 Continuous Improvement
- Regular security audits and compliance assessments
- Continuous monitoring of security threats and vulnerabilities
- Implementation of emerging security technologies and best practices
- Participation in industry security initiatives and information sharing
10. International Data Transfers
As we operate globally, your personal data may be transferred to and processed in countries outside your residence, including countries that may not have the same level of data protection as your home country. For EU/EEA residents, we ensure adequate protection through:
- Adequacy Decisions: Transfers to countries with adequate protection as determined by the European Commission
- Standard Contractual Clauses: EU approved contractual terms ensuring appropriate data protection safeguards
- Binding Corporate Rules: Internal policies ensuring consistent data protection across our organization
- Certification Schemes: Adherence to recognized privacy certification programs
- Additional Safeguards: Technical and organizational measures to ensure data security during transfers
11. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, local storage, and similar technologies to enhance your experience, analyze usage, and provide personalized content. Our use of these technologies includes:
11.1 Types of Cookies
- Essential Cookies: Necessary for platform functionality and security
- Performance Cookies: Collect information about platform usage and performance
- Functionality Cookies: Remember your preferences and personalize your experience
- Marketing Cookies: Used for advertising and marketing purposes (with consent)
11.2 Cookie Management
You can manage your cookie preferences through our cookie consent banner and your browser settings. Please note that disabling essential cookies may impact platform functionality. For detailed information about our cookie practices, please review our separate Cookie Policy.
12. Children’s Privacy Protection
Our Platform is not intended for children under the age of 16 (or the relevant digital consent age in your jurisdiction). We do not knowingly collect, use, or share personal information from children under this age. If we become aware that we have inadvertently collected personal information from a child under 16, we will:
- Immediately delete the information from our systems
- Terminate the associated account
- Notify the parents or guardians if required by law
- Implement additional safeguards to prevent future occurrences
Parents and guardians who believe their child has provided personal information to us should contact us immediately at chain@pocketsflow.com.
13. Third Party Services and Links
Our Platform may contain links to third party websites, services, or applications that are not owned or controlled by us. This Privacy Policy does not apply to third party services. We encourage you to review the privacy policies of any third party services you access through our Platform. We are not responsible for the privacy practices of external services.
14. Data Breach Notification
In the unlikely event of a data breach that poses a risk to your privacy, we will:
- Notify relevant supervisory authorities within 72 hours where required by law
- Inform affected users without undue delay if the breach is likely to result in high risk to their rights and freedoms
- Provide clear information about the nature of the breach and steps being taken to address it
- Offer appropriate support and assistance to affected individuals
- Conduct a thorough investigation and implement measures to prevent future breaches
15. Privacy Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy
- Notify users via email or prominent platform notification
- Provide a summary of key changes
- Obtain renewed consent where required by law
- Allow a reasonable transition period for users to review changes
Continued use of the Platform after policy updates constitutes acceptance of the revised terms, unless additional consent is required by law.
16. Contact Information and Data Protection Officer
For all privacy related inquiries, requests, or concerns, please contact us:
- Email: chain@pocketsflow.com
- Subject Line: Please use “Privacy Request” for data protection inquiries
- Response Time: We aim to respond to all privacy requests within 30 days
Our privacy team is available to assist with any questions about this Privacy Policy, your privacy rights, or our data protection practices.
17. Supervisory Authority Rights
If you are located in the EU/EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. You can find contact information for EU supervisory authorities at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
18. Additional Regional Privacy Rights
Depending on your location, you may have additional privacy rights under local laws. We are committed to complying with all applicable privacy regulations and will honor your rights as required by law. Please contact us at chain@pocketsflow.com to learn more about your specific rights in your jurisdiction.
This Privacy Policy represents our commitment to transparency and your privacy rights. We continuously work to enhance our privacy practices and welcome your feedback.