Privacy & Cookies
Last updated 2026-05-10
This page explains what data A FLOG collects, why, and what cookies it uses.
We aim to keep this short and accurate. If something is missing or unclear,
please contact us.
Cookies we set
We only set cookies that are strictly necessary for the service you have
explicitly requested. We do not use any analytics, advertising, or
cross-site tracking cookies, so no consent banner is shown.
auth, userId, firstName,
lastName — set after a successful login. Used to
keep you signed in. Cleared on logout.
demo_session — set only after you click
Explore the demo on the public landing page. Lets the
demo organisation persist while you browse it. Cleared when the
browser closes or when you log out.
- PHP session cookies — standard server-side session, used for
login and CSRF protection.
What we log
- User actions inside the app — e.g. profile changes,
document uploads, billing events. Tied to your user id, used for
audit and support. Stored in
user_audit_logs.
- Demo visitor counter — when the public landing
page is opened, or when a visitor first enters the demo
organisation, we record the time, browser user-agent, and a
one-way hash of your IP + browser + day. We do not store the IP
itself. The hash lets us collapse reloads on the same day
without identifying you. Super-user browsing is excluded.
- Server logs — standard request logs (status
codes, timings) kept for short-term operational diagnosis.
Third parties
- Stripe — used to take payments. When you check
out you are redirected to Stripe's domain; their privacy policy
applies there.
- Xero — optional accounting integration,
connected per organisation. Only invoice data flows there.
- Amazon S3 — used to store organisation
documents and user documents. Files are private and accessed
only via signed URLs.
- Web fonts are self-hosted; no requests are
made to Google Fonts or any other CDN.
Your rights
If you have an account, you can review and edit most of your data
from My Account. To request export or deletion of your
data, contact your organisation administrator or our support
address.
Changes
If we change what we collect we will update this page and note the
date above. Material changes will also be communicated in-app.
← Back