DigiFad Flow

Privacy Policy

This English policy explains how DigiFad processes personal data when you use DigiFad Flow (https://www.digifad.com). It is designed to meet the transparency requirements of the EU GDPR and the ePrivacy Directive (cookie / tracking consent).

Last updated: 26 August 2026

1. Controller

The data controller is DigiFad (product: DigiFad Flow). For privacy requests, contact hello@digifad.io.

2. Scope

This policy applies to our marketing website, account registration / login, the DigiFad Flow web console, billing, and related support communications. It does not cover third-party sites we link to (including Pinterest, Shopify, Stripe, or Google), which have their own policies.

3. Personal data we process

Depending on how you use DigiFad, we may process:

  • Account data — email address, password hash (if you set a password), Google account ID when you sign in with Google, role, and plan status.
  • Billing data — Stripe customer and subscription identifiers, plan and renewal dates. Card details are handled by Stripe and are not stored on our servers.
  • Product / workspace data — Pinterest account connections (OAuth tokens), boards, pin content and schedules, sitemap / product references, AI generation settings, and usage quotas.
  • Technical / security data — IP address, browser type, device signals, and logs needed to operate, secure, and debug the service.
  • Cookie / similar technologies — session and preference cookies (necessary), and analytics cookies only if you consent (see Cookies).

4. Purposes and legal bases (GDPR)

  • Provide the service (create accounts, publish pins, billing) — contract (Art. 6(1)(b)).
  • Security, fraud prevention, abuse legitimate interests (Art. 6(1)(f)).
  • Legal and tax obligations legal obligation (Art. 6(1)(c)).
  • Non-essential analytics cookies (e.g. Google Analytics) — consent (Art. 6(1)(a) GDPR and ePrivacy). You may refuse or withdraw at any time.
  • Product emails about your account — typically contract or legitimate interests; marketing emails (if any) only with consent or as otherwise permitted by law.

5. Cookies and similar technologies

We use a consent banner so you can accept, reject, or customise non-essential cookies before they run.

  • Strictly necessary — authentication / session, CSRF and security, locale preference, and storing your cookie choices. These do not require consent under ePrivacy.
  • Analytics — Google Analytics 4 (measurement ID configured on our site) to understand traffic and improve the product. Loaded only after you opt in. You can change your mind via “Cookie settings” in the footer.

We do not use advertising cookies by default. If we add similar non-essential tools later, they will appear in the cookie banner categories before activation.

6. Processors and recipients

We share data with providers that help us run DigiFad, under appropriate agreements where required:

  • Hosting / infrastructure (e.g. Railway and related cloud storage)
  • Stripe — payments and billing portal
  • Google — OAuth sign-in (if used) and Analytics (if consented)
  • Pinterest — publishing and analytics via their official APIs
  • Shopify — when you use our Shopify app integration
  • AI model providers used to generate pin copy / images as part of the product

We do not sell your personal data. We may disclose information if required by law or to protect rights, safety, and the integrity of the service.

7. International transfers

DigiFad and some processors may process data outside your country, including outside the EEA/UK. Where GDPR applies, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, as provided by the relevant vendor.

8. Retention

We keep account and workspace data while your account is active and for a reasonable period afterward (for backups, disputes, and legal retention). Billing records may be kept longer where required by tax or accounting law. Analytics data follows Google Analytics retention settings when that tool is enabled. You may request deletion subject to legal exceptions.

9. Your rights

If GDPR (or similar laws) apply to you, you may have the right to:

  • Access, rectify, or erase personal data
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with your local supervisory authority

Email hello@digifad.io with the subject “Privacy request”. We may need to verify your identity before fulfilling the request.

10. Children

DigiFad is directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us and we will delete it.

11. Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes that affect cookies will also be reflected in the cookie banner / preferences.

12. Contact

Privacy questions: hello@digifad.io
Website: https://www.digifad.com

← Back to home · Pricing

Privacy Policy | DigiFad