Thank you for using QuoteSaver (the “App”). Our number one priority is keeping you in control of your data. This privacy policy for FlowShark LLC (doing business as FlowShark) (“we”, “us” or “our”) explains how we collect, use, and disclose your personal information when you use our App. By using the App, you consent to the practices described in this policy.
1. Information we collect
1.1 Personal information: We collect limited personal information that you provide to us voluntarily, such as your email address. We strive to minimize the collection of personal information whenever possible, while ensuring that the App’s functionality remains intact.
1.2 Payment Data: We may collect data necessary to process your payment, if you make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is stored by Apple. You may find their privacy policy here: www.apple.com/legal/privacy/data/en/app-store
1.3 Usage Information: We may automatically collect certain information about your use of the App, including your device type, operating system, unique device identifiers, IP address, and usage statistics. This information helps us improve the App's performance and functionality.
2. How We Use Your Information
2.1 Providing Services: We use your personal information to provide you with the services and features of the App, including saving, categorizing, and viewing quotes. We may process your information so you can create and log into your account, as well as to keep your account in working order.
2.2 Personalization: We may use your information to personalize your App experience, including tailored insights, recommendations, and notifications based on your usage data.
2.3 Communication: We may use your email address to send you important updates, announcements, and relevant information about the App. You can opt out of receiving non-essential communications.
2.4 Aggregated Data: We may aggregate and anonymize your personal information to generate statistical and analytical insights. Aggregated data does not identify you personally and may be used internally for research, development, or marketing purposes.
3. Legal Bases We Rely on to Process Your Information
If you are located in the EU or UK, this section applies to you
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
3.1 Consent: We may process your personal information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent any time by contacting us using the contact information provided at the end of the privacy policy.
3.2 Performance of a Contract: We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our services or, at your request, prior to entering into a contract with you.
3.3 Legitimate interests: We may process your personal information when we believe it is reasonably necessary to achieve our legitimate business interests, and those interests do not outweigh your interests and fundamental rights and freedoms.
3.4 Legal Obligations: We may process your personal information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
3.5 Vital Interests: We may process your personal information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
If you are located in Canada, this section applies to you
3.6 We may process your information if you have given us specific permission (i.e., express consent) to use your information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time by contacting us.
3.7 In some exceptional cases, we may be legally permitted, under applicable law, to to process your information without your consent including, for example:
• If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
• For investigations and fraud detection and prevention
• For business transactions, provided certain conditions are met
• If it is contained in a witness statement and the collection is necessary to asses, process, or settle an insurance claim
• For identifying injured, ill, or deceased persons and communicating with next of kin
• If we have reasonable grounds to believe an individual has been, is, or may be a victim of financial abuse
• If it is reasonable to expect collection and use with consent would compromise the availability or accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
• If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
• If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
• If the collection is solely for journalistic, artistic, or literary purposes
• If the information is publicly available and is specified by the regulations
4. Sharing and Disclosure of Your Information
We do not share your personal information with any third party except as outlined below:
4.1 MongoDB: We store your account data and quotes via MongoDB Realm. MongoDB has access to your personal information only as necessary to perform its functions and is obligated to maintain its confidentiality. MongoDB may store your data on servers operated by Amazon AWS.
4.2 Apple: We may share certain information, such as personal identifiers and payment and banking information, with Apple in order to collect and process payments for your subscription to the App.
4.3 Special Circumstances: We may be required by law to disclose your information in response to subpoenas, court orders, or legal processes. We may also do so if we believe, in good faith, that such disclosure is necessary to comply with legal obligations, protect our rights or safety, or investigate fraud. Additionally, in the event that we go through a merger, acquisition, or other business transition, your data may be included in the assets transferred.
5. Where your information is stored
5.1 Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries. If you are located in the European Economic Area (EEA) or United Kingdom (UK), then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country of residence. However, we will take all necessary measures to protect your personal information in accordance with this privacy policy and applicable law.
5.2 European Commission's Standard Contractual Clauses: We have implemented measures to protect your information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between us and our third-party providers. These clauses require all participants to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations.
6. How We Protect Your Information
6.1 Security Measures: We employ industry-standard security measures to protect your personal information from unauthorized access, use, or disclosure. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6.2 Data Retention: We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. You may delete your data at any time by contacting us at quotesaver@flowshark.app.
7. Your Choices and Rights
7.1 Opt-out: You can choose not to provide certain information or opt out of receiving non-essential communications from us. However, please note that opting out may limit your access to certain features of the App.
7.2 Access and Correction: You have the right to access and update your personal information held by us. You can review and modify your information within the App or by contacting us directly.
7.3 Deletion: You may delete your data at any time and for any reason. You can do so via the App or by contacting us.
7.4 California: California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request to us in writing using the contact information provided below. If you are under 18 years of age, reside in California, and have a registered account with the App, you have the right to request removal of unwanted data that you publicly post on the App. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account along with a statement that you reside in California. We will make sure the data is not publicly displayed on the App, but please be aware that the data may not be completely or comprehensively removed from all our systems.
7.5 Miscellaneous: If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
8. CCPA Privacy Notice
The California Code of Regulations defines a “resident” as:
(1) Every individual who is in the State of California for other than a temporary or transitory purpose and
(2) Every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose
All other individuals are defined as “non-residents”.
If this definition of “resident” applies to you, we must adhere to certain rights and obligations regarding your personal information.
We have collected the following categories of personal information in the past twelve (12) months:
We will use and retain the collected personal information as needed to provide the Services or for as long as the user has an account with us.
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
• Receiving help through our customer support channels
• Participation in customer surveys or contests
• Facilitation in the delivery of our Services and to respond to your inquiries
More information about our data collection and sharing practices can be found in this privacy policy. You may contact us by referring to the contact details at the bottom of this document. If you are using an authorized agent to exercise your right to opt out, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Each service provider is a for profit entity that processes the information on our behalf, following the same strict privacy protection obligations mandated by the CCPA.
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be “selling” of your personal information.
FlowShark LLC has not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. FlowShark LLC has disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:
• Category A
• Category B
• Category D
The third parties to whom we disclosed personal information for a business or commercial purpose can be found under “Sharing and Disclosure of Your Information” (section 4)
Right to request deletion of data
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.
Right to be informed
Depending on the circumstances, you have a right to know:
• Whether we collect and use your personal information
• The categories of personal information that we collect
• The purposes for which the collected personal information is used
• Whether we sell or share information to third parties
• The categories of personal information that we sold, shared, or disclosed for a business purpose
• The business or commercial purpose for collecting, selling, or sharing personal information
• The specific pieces of personal information we collected about you
In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
Right to non-discrimination for the exercise of a consumer’s privacy rights
We will not discriminate against you if you exercise your privacy rights.
Right to limit use and disclosure of sensitive personal information
If the business collects any of the following:
• Social security information, drivers’ licenses, state ID cards, passport numbers
• Account login information
• Credit card numbers, financial account information, or credentials allowing access to such accounts
• Precise geolocation
• Racial or ethnic origin, religious or philosophical beliefs, union membership
• The contents of email and text, unless the business is the intended recipient of the communication
• Genetic data, biometric data, and health data
• Data concerning sexual orientation and sex life
you have the right to direct that business to limit its use of your sensitive personal information to that use which is necessary to perform the Services.
Once a business receives your request, they are no longer allowed to use or disclose your personal information for any other purpose unless you provide consent for the use or disclosure of sensitive personal information for additional purposes.
To exercise your right to limit use and disclosure of sensitive personal information, please email us using the contact information provided below.
Verification process
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. We may also contact you through a communication method that you previously provided to us.
Other privacy rights
• You may object to the processing of your personal information.
• You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.
• You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.
• You may request to opt out from future selling or sharing of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.
To exercise these rights, you can email us using the contact information provided at the end of this document. If you have a complaint about how we handle your data, we would like to hear from you.
9. Virginia CDPA Privacy Notice
Under the Virginia Consumer Data Protection Act (CDPA):
“Consumer” means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context.
“Personal data” means any information that is linked or reasonably linkable to an identified or identifiable natural person. “Personal data” does not include de-identified data or publicly available information.
“Sale of personal data” means the exchange of personal data for monetary consideration.
If this definition of “consumer” applies to you, we must adhere to certain rights and obligations regarding your personal data.
The information we collect, use, and disclose about you will vary depending on how you interact with FlowShark LLC and our Services. To find out more, please read the following sections of this privacy statement:
• 1. Information we collect
• 2. How We Use Your Information
• 4. Sharing and Disclosure of Your Information
Your rights with respect to your personal data
• Right to be informed whether or not we are processing your personal data
• Right to access your personal data
• Right to correct inaccuracies in your personal data
• Right to request deletion of personal data
• Right to obtain a copy of the personal data you previously shared with us
• Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects (“profiling”)
FlowShark LLC has not sold any personal data to third parties for business or commercial purposes. FlowShark LLC will not sell personal data in the future belonging to website visitors, users, and other consumers.
More information about our data collection and sharing practices can be found in this privacy policy. You may contact us using the contact information found at the bottom of this document.
Verification process
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have information in our system. These verification efforts may require us to ask you to provide information so that we can match it with information you have previously provided us. We may also contact you through a communication method that you previously provided to us.
Upon receiving your request, we will respond without undue delay, but in all cases within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within the initial 45-day response period, together with the reason for the extension.
Right to appeal
If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please email us using the contact information provided below. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.
10. Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We encourage you to review this Policy periodically for any updates. Your continued use of the App after the revised Privacy Policy has been posted will signify your acceptance of the changes.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us at quotesaver@flowshark.app