StormFlow

Privacy notice

This notice explains how StormFlow handles information when authorized organizations and their personnel use the web and mobile applications.

Effective July 16, 2026

Information we process

StormFlow processes information supplied by an organization or its authorized users, including:

  • Account details such as name, work email, organization, role, and Site access.
  • Facility and environmental compliance records, permits, tasks, inspections, forms, measurements, corrective actions, reports, and audit history.
  • Documents, photographs, signatures, notes, and other evidence a user chooses to upload.
  • Device, session, security, synchronization, and diagnostic information needed to operate and protect the service.
  • Location information only when a user grants permission and uses a field workflow that captures inspection location.

How information is used

We use this information to provide the service, enforce organization and Site permissions, synchronize offline work, deliver requested notifications, generate authorized reports and exports, support users, prevent abuse, and maintain an auditable compliance record.

StormFlow does not sell personal information and does not use customer compliance data for advertising.

Service providers and integrations

We use contracted infrastructure, authentication, storage, email, monitoring, and mobile-delivery providers to operate StormFlow. An organization may also enable integrations that send or receive data from its approved systems. Providers and integrations receive only the access needed for the configured service and are subject to applicable agreements and access controls.

Retention and organization control

The customer organization controls its users, Sites, records, exports, and configured retention requirements. We retain information while the service is active and as required by the customer agreement, regulatory obligations, security needs, or law. Authorized administrators can manage access and submit governed organization-deletion requests in StormFlow.

Security

StormFlow uses tenant and Site authorization, encrypted network transport, private object storage, audit records, scoped credentials, and operational monitoring. No system can guarantee absolute security; suspected incidents should be reported promptly.

Your choices

Users can decline optional camera, photo-library, location, and notification permissions through their device settings. Some field features will be unavailable without the related permission. Account and data requests should be directed first to the user's organization administrator.

Contact

For privacy, access, correction, deletion, or security questions, contact StormFlow at support@stormflow.app.