Last updated: July 30, 2026 · Applies to https://support.sequenceflow.io
SequenceFlow ("we", "us", "our") operates SequenceFlow Commerce Support at support.sequenceflow.io — an AI-powered customer support workspace that reads incoming customer emails, uses connected commerce context, generates AI draft replies, and lets your team approve and send them.
For questions about this policy, contact us at hallo@sequenceflow.io.
When you sign in via Google OAuth we receive your name, email address, and profile picture from Google. We store your email address and name to identify your account.
To provide the core service, incoming customer emails are imported into Support through your configured inbound setup, such as forwarding or IMAP mailbox access.
Your source mailbox remains untouched: Support reads and stores a service copy of incoming messages. It does not delete, move, archive, or otherwise remove the original customer email from Gmail, Hostinger, or another connected email provider.
What email data we receive: subject line, sender address, email body text, email thread headers (Message-ID, References), and customer-sent attachments when present.
What we do NOT do: We do not sell, rent, transfer, or share your email data with any third party for advertising, analytics, or any purpose beyond providing the Support service.
Sending replies with your Google account: When you choose "Sign in with Google" for your support mailbox, Support asks only for permission to send email on your behalf (gmail.send) and for your email address. It cannot read, search, change, or delete the email in your Gmail account; incoming email reaches Support through forwarding that you set up yourself. Support uses this access only to send the replies you approve (or that you allowed to be sent automatically) and the test emails you request. The access token is stored encrypted, and you can disconnect at any time in Support or in your Google Account settings, which revokes it immediately.
Support's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, do not sell it, do not let people read it except for security, legal compliance, or with your consent, and do not use it to train AI models.
When an organisation connects bol.com or another supported commerce provider, Support retrieves only the order, item, offer, stock, shipment, tracking, and return fields needed to answer a support case. We do not retain full provider API responses or unnecessary customer details. Customer email addresses used for order matching are converted into a tenant-specific pseudonymous key.
The bol.com integration uses merchant-created client credentials and is read-only in its current version. Support stores provider credentials and webhook secrets encrypted. Previously configured WooCommerce connections remain operationally paused unless explicitly re-enabled in a later product version.
When a merchant installs the SequenceFlow Support app from Shopify, Support requests read-only access to orders (read_orders) and the customer email field. It uses this only to show the matching order next to a customer question and to prepare a reply for human review. Support cannot change, cancel, or refund orders.
Shopify access tokens are stored encrypted, expire automatically, and are revoked when the app is uninstalled. Order data is fetched from Shopify when needed and kept as a cache next to the support case; it is deleted together with the case, at the latest 90 days after the case is closed. Support processes Shopify's mandatory privacy requests: customer data requests are answered to the store, customer redaction requests delete that customer's Shopify order data (and, for a workspace created for the store, the related support conversations), and shop redaction requests delete the store's data 48 hours after uninstall.
Email content (subject and body text) is sent to OpenAI's API to generate a suggested reply. OpenAI processes this under their API data usage policy. Data submitted via the API is not used to train OpenAI models.
For customer pain-point analysis, source text is stripped of reply history, signatures, personal data, and order references before processing. Support stores only quote-free aggregate findings, not the sampled source messages.
Ask Support receives aggregate support, analytics, knowledge, answer-style, and commerce context for read-only operational questions. It does not receive raw customer messages in its operational snapshot and cannot change orders, returns, shipments, stock, email, or configuration.
We log service metadata such as the number of emails processed, response latency, routing decisions, and outcomes for reliability, billing limits, and product improvement. These event logs do not contain email subjects, bodies, or draft replies.
On our public website we record first-party campaign parameters, advertising click identifiers, landing-page visits, and button clicks so we can measure which campaigns lead to sign-ups. We do not build cross-site profiles or send this information to advertising platforms through pixels.
Payments are processed by Stripe. We do not store credit card numbers. Stripe shares with us only your subscription status and customer ID.
We use your data only for these stated purposes. Email data is never used for advertising or shared with third parties for their own use.
We take the following technical and organisational measures to protect account and customer-support data:
We share data with the following sub-processors to operate the service:
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase (AWS eu-west) | Database & authentication | All account and ticket data |
| OpenAI | AI reply generation and Ask Support operational analysis | Email subject and body for reply generation; aggregate operational metrics and relevant knowledge snippets for Ask Support |
| Stripe | Payment processing | Billing information only |
| Resend | Transactional and service email | Recipient, subject, and email content |
| Vercel | Hosting & deployment | Request logs (IP, URL) |
| Connected bol.com seller account | Read-only commerce context | Minimum order, item, offer, stock, shipment, tracking, and return fields |
| Shopify (when the app is installed) | Read-only order context and Shopify billing | Order, item, fulfilment, and customer email fields for the installing store |
We do not allow these processors to use customer-support data for their own advertising or unrelated purposes.
Google OAuth is used to authenticate your account. We receive the basic profile information described in section 2.1 and use it only to create, secure, and display your Support account. We do not use Google account data for advertising or credit decisions.
To exercise any of these rights, email hallo@sequenceflow.io. We will respond within 30 days.
We use essential authentication cookies and a first-party attribution cookie that remembers the campaign and landing page associated with a visit for up to 30 days. This cookie supports our own sign-up measurement; it is not used for cross-site tracking or advertising profiles.
We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the app. Continued use of the service after changes constitutes acceptance of the updated policy.
For privacy questions or to exercise your rights: