Flyerworks Privacy Policy
Effective Date: August 10, 2026
Company: Salescore Technologies Pvt Ltd
Product: Flyerworks
1. Information We Collect
We collect the following data to provide and improve Flyerworks:
- Personal Data: Name, phone number, email, store/business name, store address, state/country, organisation category, and billing information during signup and subscription.
- Usage Data: Flyer and shelf-tag creation activity, templates viewed, opened, exported and unlocked, products added to a flyer or shelf tag, layout choices, export counts, daily activity streaks, tutorial and achievement progress, any custom promotional dates you add to your dashboard, and time spent within the app.
- Flyer & Shelf-Tag Composition Data: Every time you export a flyer, we automatically save a complete copy of that flyer’s contents at that moment — including each product name, price, MRP, discount, image and the layout used. These copies are retained (see Section 6). Individual products, prices and discounts from your flyers and shelf tags are additionally extracted into a separate table so they can be analysed, including by applying this extraction retroactively to exports you made before this practice began.
- Product Search Data: The search terms you type when looking for a product image, together with how many results they returned (including searches that returned none), and the products you select or upload. Searches returning no results are specifically retained to identify gaps in our catalogue.
- AI Feature Data: When you use AI header generation, AI caption generation, or background removal, the image or store/product details you supply, the prompt used, the generated output, and related metadata (which model produced it, when, on which plan, how many credits it cost, and whether the attempt succeeded or failed). This includes attempts that fail or that you discard. See Section 3.
- Analytics Data: Aggregated behavior data such as page views, actions, and session frequency, collected via tools like Google Analytics.
- Device & Technical Data: IP address, browser details, user-agent string, device identifiers, and approximate location.
- User-Generated Content: Flyers and shelf tags created, product details added, and photos, logos, brand images and custom font files uploaded by the user. Please read Section 6A — uploaded files are stored at publicly accessible URLs.
- Diagnostic Data: When the app encounters an error, we may record technical details of that error — including a stack trace, the page URL where it occurred, your browser user-agent, a per-session identifier, your account identifier, and limited surrounding context such as the feature in use — to help us fix it. We also record cases where a feature silently underperformed without producing a visible error (for example, an export that could not load one of its images), so that we can detect faults our users would otherwise never report.
- Customer Support Data: Messages, calls, and interactions with our support team.
- Marketing Preferences: Communication preferences and opt-in status.
- Marketing Pixel & Conversion Data: Events tracked via Meta Pixel and Meta Conversions API (server-side) to analyze flyer-related actions for remarketing purposes. See Section 10 for consent handling.
- Payment Data: Payment status and transaction details, processed via Cashfree (for customers in India) or Dodo Payments (for customers elsewhere).
- Communication Metadata: WhatsApp-based messages used for onboarding, reminders, and support.
2. How We Use Your Data
We use your data to:
- Deliver and improve the Flyerworks service.
- Assist with onboarding, training, and customer support.
- Analyze usage patterns to enhance performance and usability.
- Personalise what we show you — for example, ranking templates, recommended products and seasonal or festival suggestions based on your organisation category, location, and what you have previously opened, used or exported.
- Detect faults, including features that degrade silently without raising a visible error.
- Derive aggregated insights across stores (for example, typical products or discounts used by stores in a similar category): always computed from a group of at least 5 stores, so no individual store’s data is identifiable in any aggregate we produce or share.
- Prevent fraud and ensure platform security, including detecting misuse of free-tier or AI generation limits.
- Comply with legal or regulatory requirements.
- Send important account-related communications.
- Market Flyerworks or related services using aggregate or anonymized data.
- Develop new features, templates, or future products.
- Retarget existing users through ad platforms such as Facebook/Instagram (Meta Pixel and Meta Conversions API), where you have given consent.
3. AI Features & Third-Party AI Providers
Flyerworks offers three AI/machine-learning features: AI header image generation, AI-written social captions, and automatic background removal from product photos. Each of these sends data to third-party AI providers outside India, which we disclose here in full:
- Header images: when you generate an AI header variation, the header image is sent to Replicate, Inc. (based in the United States), which routes the request to the underlying model provider currently configured for the feature (at the time of writing, this may be Google’s Nano Banana 2, ByteDance’s Seedream, or Black Forest Labs’ FLUX, depending on availability and quality). This is an international transfer of the image you provide.
- Captions: when you generate an AI social caption, your store name and the product/offer details on your flyer are sent to Google’s Gemini model (also routed via Replicate) to generate the caption text.
- Background removal: when you upload a product photo with background removal enabled, that photo is sent to Replicate, Inc. (United States) and processed by a background-removal model (at the time of writing, 851-labs/background-remover, with lucataco/remove-bg as an automatic fallback). This applies to any photo you upload with the feature enabled, including photos you took yourself, and is an international transfer of that image. Background removal is not metered by AI credits, but it is an AI feature and this Section governs it.
- These providers process your data to fulfil the generation request. We do not control, and cannot fully guarantee, how each underlying model provider handles data on its own infrastructure beyond what its own terms state; we choose providers with commercially reasonable data-handling practices, and we may change which provider is used at any time to improve quality, cost, or reliability, without that being a change to this policy.
- Generated header images are stored permanently in our own storage (not deleted after generation) so you can revisit past variations. You may request deletion at any time (see Section 6).
- AI generation is metered by a monthly credit allowance tied to your plan. Generation attempts (including failed ones) are logged with the model used, the preset/prompt used, and which plan you were on at the time, so we can diagnose problems and prevent abuse of the feature.
4. Legal Basis for Processing
We process your data based on:
- Your consent (e.g., marketing or pixel tracking, and choosing to use AI features).
- Contractual necessity (e.g., fulfilling your subscription, processing your AI generation requests).
- Legitimate interests (e.g., fraud prevention, analytics, service improvements, aggregated cross-store insights subject to the minimum-group-size safeguard in Section 2).
5. Data Sharing & Disclosure
Your data may be shared only with the following categories of recipients, under contractual confidentiality obligations:
- Supabase (database and file storage hosting).
- Vercel (application hosting).
- Replicate, Inc. and the AI model providers it routes to (Section 3), for AI feature requests only.
- Cashfree (India payments) or Dodo Payments (international payments), for the transaction you initiate.
- Meta (Facebook/Instagram Pixel and Conversions API) and Google (Analytics, Ads), for marketing analytics, where you have consented.
- Gupshup, for WhatsApp-based OTP login and notifications.
- Our affiliate and referral platform (operated by us on separate infrastructure), where you arrive via a referral or affiliate link, or redeem a referral, promotional or affiliate code. Visiting a link containing an affiliate code registers that visit against the code. If you subsequently subscribe, the fact of that subscription is recorded against the referring account so that its reward or commission can be calculated. The referring affiliate is not given your personal contact details.
- Legal or regulatory authorities, if required by law.
- Our own authorised personnel may access account and usage data through internal administrative tools, restricted to a named allowlist, for support, billing, moderation and fault diagnosis.
- We do not sell or rent your personal data.
6. Data Retention
We keep different categories of data for different lengths of time, reflecting why we collected it:
- Account and profile data: retained while your account is active, and for a reasonable period afterward in case you wish to reactivate, unless you request earlier deletion.
- Flyers, shelf tags, and AI-generated headers: retained indefinitely so you can access your own past work, unless you delete them yourself or request account deletion.
- Export copies and share links: the copy of a flyer saved at each export, and any public share link created from one, are retained indefinitely unless you ask us to delete them. Deleting a flyer in the app does not automatically revoke a share link previously created from it — see Section 6A.
- Product, template and search interaction records: retained on an ongoing basis to operate recommendations and improve the catalogue.
- Diagnostic and error logs: retained for a limited period sufficient to diagnose and fix issues, then routinely cleared.
- Payment records: retained as required by applicable tax and financial regulations, typically several years.
- You may request deletion, correction, or export of your personal data at any time by emailing support@flyerworks.app or by contacting our Grievance Officer (Section 12).
- If you withdraw consent for a particular use (e.g., marketing tracking), we stop that use going forward; some features may be restricted where the underlying data was necessary for them.
6A. Publicly Accessible Content & Share Links
Some content is, by design, reachable by anyone holding its web address, without signing in. This is how the product works and you should read this section before uploading anything sensitive or sharing a link:
- Uploaded files are served from public URLs. Logos, product photos, brand images, AI-generated headers and custom font files you upload are stored with our hosting provider and served from a public, unguessable web address. Anyone who has that address — for example, because you or a recipient forwarded a flyer, a link, or the file itself — can open it without logging in. Do not upload anything you would not be willing to have accessible in this way.
- Share links are public to anyone holding them. If you use "Get shareable link", we create a public web page containing that flyer as it stood when you generated the link — including your store name, address and phone number if they appear on the flyer, and every product, price and offer on it. The link's unguessable identifier is the only access control: there is no password and no sign-in. Anyone you send it to can forward it to anyone else. Treat a share link as public.
- We count views on share links. Each time a shared flyer page is opened we increment a view counter for that link. We do not record who viewed it.
- Link previews. When a share link is pasted into a messaging or social app, that app may fetch a preview image generated from the flyer, which can include your store name and flyer title. This is performed by the recipient's app, not by us.
- Revoking access. A share link stays live until the underlying flyer copy is deleted. To revoke one, contact support@flyerworks.app or our Grievance Officer (Section 12) and we will remove it.
- Search engines. Shared flyer pages are marked so that search engines should not index them. We cannot guarantee every crawler honours that instruction, so it is not a substitute for treating the link as public.
7. Data Security
- We follow industry-standard security practices including encrypted storage and transmission, access controls, and routine security review of our hosting environments.
- No system is completely immune to breaches. Use of the service is at your own risk, and we will notify affected users as required by applicable law in the event of a data breach materially affecting their personal data.
8. User Rights
Depending on where you are located, you may have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Restrict or object to certain processing.
- Withdraw consent at any time.
- Request portability of your data in a machine-readable format.
- If you are in India, you may also raise a complaint with our Grievance Officer (Section 12) under the Digital Personal Data Protection Act, 2023.
- If you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with your local data protection supervisory authority.
- If you are a California resident, see Section 13 for your rights under the CPRA.
9. International Data Transfers
- Some data, including AI feature requests (Section 3) and data processed by our hosting and analytics providers, may be processed outside India, including in the United States.
- Where we transfer personal data internationally, we rely on the service provider’s own compliance with applicable safeguards (such as standard contractual clauses or equivalent mechanisms) as required under applicable law.
10. Cookies & Tracking
- We use first-party cookies and Google Analytics (with Google’s Consent Mode) to understand usage. Depending on your cookie choice, analytics tracking may be limited or disabled.
- We use Meta Pixel and Meta Conversions API (a server-side tracking method) for remarketing. Where available, the Conversions API sends Meta a cryptographically hashed (SHA-256) form of your email address, phone number, first and last name, city, state, country and postal code, so Meta can match the event to an existing profile. We send these as hashes rather than in plain text, but hashing is a matching mechanism, not anonymisation.
- Both Meta Pixel and the Conversions API are gated on your explicit consent choice in our cookie banner: selecting anything other than "Accept All" (including rejecting, or not yet making a choice) means neither will send any data about you.
- Where enabled, we also pass a hashed form of your email address and phone number to Google for enhanced conversion measurement in Google Ads, subject to Google Consent Mode and the same consent choice.
- You may manage or withdraw your cookie choice at any time via the cookie preferences banner, or by clearing your browser’s local storage; some features may be limited without analytics/marketing cookies enabled.
11. Changes to This Privacy Policy
- We may update this policy periodically to reflect changes to the product, our data practices, or applicable law.
- Material changes will be communicated via email or an in-app notice with reasonable advance notice.
- Continued use of Flyerworks after a change takes effect constitutes acceptance of the updated policy.
12. Grievance Officer (India)
- In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the following Grievance Officer may be contacted for any complaints, privacy concerns, or content-related requests (see also Section 10 of our Terms & Conditions for content takedown requests):
- Name: Arif Ashraf
- Email: arif@flyerworks.app
- We will acknowledge a grievance within 24 hours and endeavor to resolve it within 15 days, as required under applicable Indian law.
13. Your California Privacy Rights (CPRA)
- If you are a California resident, our use of Meta Conversions API to share hashed identifiers with Meta for advertising purposes may be considered "sharing" for cross-context behavioral advertising under the CPRA.
- You can opt out of this sharing at any time via our cookie preferences banner (selecting anything other than "Accept All"), which controls the same consent flag that gates this feature (Section 10).
14. Contact
- For general privacy-related queries:
- support@flyerworks.app
- Salescore Technologies Private Limited