Legal
Privacy Policy
What we collect, why we collect it, who we share it with, and the control you keep over it.
Last updated
01Overview
This Privacy Policy explains how FLOWSOFT TECH LIMITED, a company incorporated in the Hong Kong Special Administrative Region and trading as PaydMetrics (“PaydMetrics”, “we”, “us”), collects, uses, shares and protects personal data when you visit our website or use our payment analytics platform (the “Service”).
Our registered office is Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong. As a Hong Kong data user we are subject to the Personal Data (Privacy) Ordinance (Cap. 486), and where we serve customers in other regions we also meet the obligations set out below.
We act in two different capacities. For data about our own customers and website visitors, we are a controller. For the transaction data we ingest from your connected payment providers on your instruction, we are a processor acting on your behalf — you decide why and how it is processed.
02Data we collect
Account data. Name, work email, company name, role, hashed password or identity-provider identifier, and billing contact details.
Connected payment data. When you connect a provider such as Stripe, PayPal or Adyen, we ingest transaction records: charges, refunds, disputes, subscription and plan records, payout and fee records, decline codes, and the customer identifiers attached to them — typically an email address, customer ID, country and a truncated card fingerprint. We do not receive or store full card numbers, CVV codes or bank credentials.
Usage data. Pages and features used, approximate location derived from IP address, device and browser type, referring URL, and timestamps. Collected to secure and improve the Service.
Support and marketing data. Messages you send us, demo requests, and your communication preferences.
03How we use data
We use personal data to:
- provide, operate and maintain the Service, and compute your metrics;
- authenticate users, and detect, prevent and investigate abuse and fraud;
- provide support and respond to your requests;
- bill you, and collect amounts owed;
- send service and security notices, and — where permitted — relevant product updates you can opt out of at any time;
- comply with legal obligations and enforce our agreements;
- produce aggregated, de-identified statistics and benchmarks that cannot reasonably be linked back to you or any individual.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
04Legal bases and local law
Hong Kong. As a data user under the Personal Data (Privacy) Ordinance (Cap. 486), we collect personal data lawfully and for a purpose directly related to our function, take practicable steps to keep it accurate and secure, and use it only for the purposes set out in this policy or a directly related one. We do not use personal data for direct marketing without your consent.
EEA and UK. Where the GDPR or UK GDPR applies, we rely on: contract, to provide the Service you signed up for; legitimate interests, to secure the Service, prevent fraud and improve our product, balanced against your rights; legal obligation, for tax, accounting and compliance; and consent, for optional marketing and non-essential cookies, which you may withdraw at any time.
06International transfers
We are established in Hong Kong and operate infrastructure in the European Union and the United States, so personal data is transferred across borders. Where data leaves the EEA or UK, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), together with supplementary technical measures including encryption in transit and at rest. Transfers out of Hong Kong are made on contractual terms consistent with the Privacy Commissioner’s recommended model clauses. EU data residency is available on the Enterprise plan.
07Retention
We keep account data for as long as your account is active. After termination, Customer Data remains available for export for 30 days and is then deleted or de-identified within 90 days, unless a longer period is required for legal, tax or dispute-resolution purposes. Backups containing deleted data age out on a rolling 35-day cycle. Aggregated, de-identified data may be retained indefinitely.
08Security
We maintain an information security programme aligned to SOC 2 Type II, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access control with mandatory multi-factor authentication for staff, network segmentation, centralised audit logging, dependency and vulnerability scanning, annual third-party penetration testing, and a documented incident response plan. Gateway credentials are stored in a dedicated secrets manager and are read-only by default. No system is perfectly secure, but we will notify you and any relevant regulator of a qualifying breach without undue delay.
09Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. You also have the right to complain to your supervisory authority.
California residents may request disclosure of the categories of personal information collected, used and disclosed, request deletion or correction, and are entitled not to receive discriminatory treatment for exercising these rights.
Hong Kong residents additionally have the right under the Personal Data (Privacy) Ordinance to request access to, and correction of, their personal data, and we may charge a reasonable fee for complying with a data access request as that Ordinance permits.
To exercise a right, use our contact form and select “Something else”. We will verify your identity and respond within the period required by law. If your request concerns data we process on behalf of one of our customers, we will refer you to that customer.
11Children
The Service is a business product and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12Changes and contact
We may update this policy as our product and obligations change. We will post the revised version here with a new “last updated” date, and give notice by email or in-product where the change is material.
Privacy enquiries, security reports and data-subject requests all go through our contact form, which reaches the team directly. Written correspondence can be sent to our data protection officer at FLOWSOFT TECH LIMITED, Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong.
See also our Terms of Service.