FloeSuite Privacy Policy
This Privacy Policy describes how Evelyn Protective Films & Coatings, the publisher of FloeSuite ("FloeSuite", "we", "us", or "our"), collects, uses, stores, discloses, and protects information in connection with the FloeSuite plugin and any related software, tools, features, integrations, documentation, or services (collectively, the "Software").
By installing, accessing, or using the Software, you acknowledge that you have read and understood this Privacy Policy.
1. Scope
This Privacy Policy applies to information processed by the Software within a WordPress environment operated by the user. It does not apply to data collected directly by Intuit, Stripe, or other third parties, which is governed by their own privacy policies.
2. Internal Use and Future Availability
The Software may initially be used internally by Evelyn Protective Films & Coatings or selected authorized users before being made available more broadly. Nothing in this Privacy Policy requires FloeSuite to release the Software publicly or to provide ongoing privacy-related functionality, support, or features beyond what is implemented at any given time.
If and when the Software becomes available to external customers under a hosted, subscription, or commercial offering, this Privacy Policy will be updated to reflect that change, including any data handling differences associated with hosted services.
3. Information Processed by the Software
During normal operation, the Software may process the following categories of information:
- Customer contact details such as name, email address, phone number, and mailing address
- Vehicle information such as year, make, model, trim, colour, and VIN
- Service bookings, scheduling information, package selections, pricing, deposits, balances, and payment status information
- Workflow stages, status changes, internal notes, customer-facing notes, and activity history
- Operational metadata such as timestamps, workflow history, status changes, audit events, synchronization activity, and administrative actions associated with business records
- Invoice and payment data synced to and from Intuit QuickBooks Online
- Payment authorization data, payment links, payment references, and transaction status information from Stripe or other payment providers
- Transactional communications such as booking confirmations, proposal emails, status updates, payment receipts, and review requests
- Administrative user accounts, login activity, and audit-related metadata where applicable
4. How Information is Used
Information processed by the Software is used to:
- Manage bookings, customer records, vehicle records, service records, and workflow stages
- Generate and send proposals, confirmations, invoices, payment requests, receipts, and other transactional communications
- Sync booking, customer, invoice, item, tax, and payment data with Intuit QuickBooks Online for accounting and operational purposes
- Process customer payments through authorized payment processors and record payment outcomes
- Provide administrative reporting, internal notes, customer dashboards, status visibility, and operational history within the user's WordPress installation
- Support troubleshooting, error logging, security review, and operational integrity of the Software
Information processed by the Software is not used for marketing, advertising, behavioural tracking, profiling, data brokerage, or any unrelated purpose.
5. Customer and Business Data Ownership
All customer records, booking information, vehicle information, invoices, notes, payment records, and related business data entered into the Software remain the property of the user or the business responsible for that data. FloeSuite does not claim ownership of user data.
The user or operating business is the data controller of information entered into or processed by the Software. FloeSuite acts as a software provider and does not independently access, host, share, sell, or monetize user data under the current internal-use model.
6. No Sale of Information
FloeSuite does not sell, rent, trade, monetize, license, disclose, or otherwise provide personal information to third parties for advertising, marketing, profiling, data brokerage, or similar commercial purposes.
Information processed by the Software is used solely to provide the operational functionality described in this Privacy Policy.
7. Authorized Access
Information processed by the Software is accessible only to users who have been granted access within the applicable WordPress installation and any connected third-party services authorized by the user.
The user operating the Software is responsible for assigning, managing, reviewing, and removing access permissions for administrators, staff members, contractors, and any other authorized users.
8. Intuit QuickBooks Online Data
When the Software is connected to QuickBooks Online via Intuit's OAuth authorization flow, it gains permission to access QuickBooks data using Intuit's published API. The data the Software may read or write includes:
- Customer records, including names, addresses, and contact information
- Products and services, including items used on invoices
- Invoices, payments, credits, and related transaction details
- Tax codes and tax rates
- Company information necessary to format outgoing data correctly
How Intuit data is handled
- Intuit data is accessed only to deliver the booking, invoicing, customer management, and accounting integration services explicitly requested by the user
- Intuit data is not sold, rented, traded, licensed, monetized, or shared with third parties for advertising, marketing, profiling, or data brokerage purposes
- Intuit data is stored on the user's own WordPress server and is not hosted on FloeSuite-operated infrastructure under the current internal-use model
- Access tokens and refresh tokens issued by Intuit are stored locally within the user's WordPress installation and are not transmitted to, stored by, or accessible through FloeSuite-operated infrastructure
- Intuit data is used only for the integration purposes described in this Privacy Policy and is not used for marketing, advertising, profiling, behavioural tracking, or analytics unrelated to the requested integration
- Users may revoke the Software's access to QuickBooks Online at any time by disconnecting the integration within FloeSuite, where available, or by managing connected apps directly through their Intuit account
- If access is revoked, the Software will stop reading or writing Intuit data, although any data already synced to the user's WordPress installation may remain until manually removed by the user
For information on how Intuit handles your data, see Intuit's Privacy Policy at https://www.intuit.com/privacy/.
9. Stripe and Payment Processing
Payments processed through the Software may be handled by Stripe or another authorized payment processor. The Software does not store full credit card numbers, CVV codes, or other sensitive payment card data. Payment processors are responsible for processing cardholder data according to their own privacy policies, security practices, and payment-card industry obligations.
For information on how Stripe handles data, see Stripe's Privacy Policy at https://stripe.com/privacy.
10. Other Third-Party Services
The Software may interact with additional third-party services for purposes such as email delivery, hosting, accounting integration, communication, payment processing, analytics strictly related to system operation, or business operations. Each third-party service has its own privacy policy and data handling practices. FloeSuite is not responsible for the privacy practices, security practices, availability, or data handling of any third-party service.
11. Data Storage and Security
All booking, customer, vehicle, invoice, payment, and operational data is stored on the user's own WordPress server in the WordPress database under the current internal-use model. FloeSuite does not host user data on its own infrastructure at this time.
Data transmitted between the Software and third-party services such as Intuit QuickBooks Online, Stripe, and email providers is encrypted in transit using TLS where supported by the applicable third-party service.
FloeSuite may implement reasonable measures intended to support the safe and reliable operation of the Software. However, no software, website, hosting environment, plugin, or third-party integration can be guaranteed to be completely secure, uninterrupted, or error-free.
Shared responsibility
Server security, hosting configuration, backups, SSL certificates, WordPress core updates, plugin updates, administrator passwords, user permissions, and access management are the responsibility of the user operating the WordPress installation. FloeSuite is not responsible for breaches, data loss, unauthorized access, or service interruptions caused by hosting failures, misconfiguration, outdated software, weak passwords, malware, third-party plugin conflicts, or events outside the Software itself.
12. Data Retention
Data entered into the Software is retained on the user's WordPress server until manually deleted by the user or the operating business. Users have control over data retention through WordPress administration tools and may delete or anonymize records where appropriate.
Access tokens, refresh tokens, and integration credentials may be retained within the WordPress installation for as long as the integration remains active. When a third-party connection is disconnected, related credentials are removed where possible.
Certain records may also remain in connected third-party services such as QuickBooks Online, Stripe, hosting providers, email platforms, backup systems, or other integrations according to those providers' retention policies and the user's own legal, tax, accounting, warranty, and business record-keeping obligations.
13. Privacy Rights and Requests
If you are an end customer whose personal information has been entered into a FloeSuite installation, you may have rights under applicable privacy laws, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Depending on your jurisdiction, these rights may include:
- The right to access personal information about you held by the business
- The right to request correction of inaccurate or incomplete information
- The right to request deletion of your personal information, subject to legal, accounting, tax, warranty, fraud-prevention, or business record-keeping requirements
- The right to withdraw consent for certain uses of your personal information, where applicable
- The right to inquire about the collection, use, or disclosure of your information
- The right to make a complaint to the business responsible for your information or to a privacy regulator such as the Office of the Privacy Commissioner of Canada
To exercise these rights, contact the business that operates the FloeSuite installation and maintains the data records. That business is the data controller. For inquiries directed specifically to the publisher of the Software, see the Contact section below.
14. Children's Privacy
The Software is designed for business and commercial operations and is not intended for use by children. We do not knowingly collect personal information directly from children through the Software.
15. International Users and Data Location
The Software operates on the user's own infrastructure. Where customer data is processed depends on where the user operates their WordPress installation, hosting environment, backups, and connected services.
Third-party services used by the Software, including services such as Intuit and Stripe, may process data in jurisdictions outside the user's country of operation. Each third party publishes its own data residency and processing practices.
16. Cookies and Tracking
The Software does not use cookies for marketing, advertising, behavioural tracking, or third-party advertising analytics. Standard WordPress login/session cookies may be used to maintain administrator sessions, and basic WordPress functionality may set cookies that are unrelated to FloeSuite.
17. Breach Notification and Security Incidents
Because the Software operates on the user's own WordPress installation under the current internal-use model, the user or operating business is the primary party responsible for detecting, investigating, documenting, and responding to data breaches affecting their environment in accordance with applicable laws and regulations.
If FloeSuite becomes aware of a vulnerability in the Software that may materially affect the security of user data, FloeSuite will use reasonable efforts to communicate relevant information and, where appropriate, provide updates or guidance. FloeSuite makes no specific commitments regarding the timing, scope, or content of such communications unless required by applicable law.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted at this URL with a revised effective date or last updated date. Material changes will be reflected in the document. Your continued use of the Software after changes are posted constitutes acceptance of the revised Privacy Policy.
19. Relationship to Other Agreements
This Privacy Policy should be read together with the FloeSuite End-User License Agreement, which contains additional terms governing the use of the Software, including licensing, permitted use, disclaimers, limitation of liability, and governing law.
20. Limitations
This Privacy Policy describes the data handling practices of the Software as currently designed and implemented. It does not create any contractual obligation beyond what is required by applicable law. No statement in this Privacy Policy is intended to grant rights or remedies beyond those provided by applicable privacy law.
21. Governing Law
This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of law principles. Any disputes arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of the Province of Ontario.
22. Contact
For privacy-related questions or requests, contact us at: info@evelynprotectivefilms.ca