Privacy notice
This notice explains how StormFlow handles information when authorized organizations and their personnel use the web and mobile applications.
Effective July 16, 2026
Information we process
StormFlow processes information supplied by an organization or its authorized users, including:
- Account details such as name, work email, organization, role, and Site access.
- Facility and environmental compliance records, permits, tasks, inspections, forms, measurements, corrective actions, reports, and audit history.
- Documents, photographs, signatures, notes, and other evidence a user chooses to upload.
- Device, session, security, synchronization, and diagnostic information needed to operate and protect the service.
- Location information only when a user grants permission and uses a field workflow that captures inspection location.
How information is used
We use this information to provide the service, enforce organization and Site permissions, synchronize offline work, deliver requested notifications, generate authorized reports and exports, support users, prevent abuse, and maintain an auditable compliance record.
StormFlow does not sell personal information and does not use customer compliance data for advertising.
Service providers and integrations
We use contracted infrastructure, authentication, storage, email, monitoring, and mobile-delivery providers to operate StormFlow. An organization may also enable integrations that send or receive data from its approved systems. Providers and integrations receive only the access needed for the configured service and are subject to applicable agreements and access controls.
Retention and organization control
The customer organization controls its users, Sites, records, exports, and configured retention requirements. We retain information while the service is active and as required by the customer agreement, regulatory obligations, security needs, or law. Authorized administrators can manage access and submit governed organization-deletion requests in StormFlow.
Security
StormFlow uses tenant and Site authorization, encrypted network transport, private object storage, audit records, scoped credentials, and operational monitoring. No system can guarantee absolute security; suspected incidents should be reported promptly.
Your choices
Users can decline optional camera, photo-library, location, and notification permissions through their device settings. Some field features will be unavailable without the related permission. Account and data requests should be directed first to the user's organization administrator.
Contact
For privacy, access, correction, deletion, or security questions, contact StormFlow at support@stormflow.app.