Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how Lynq & Flow LLC, a limited liability company formed under the laws of the State of Wyoming, United States of America (“Company”, “we”, “us”, or “our”), collects, uses, discloses, and protects personal data when providing the Lynq & Flow Shopify application, related integrations, websites, dashboards, and support services (collectively, the “Service”).
This Privacy Policy applies to:
- merchants and authorised users who install or use the Service;
- visitors to our website or communication channels;
- end customers of merchants, where their data is processed through the Service on behalf of merchants.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
1. Data Controller and Contact Details
Data Controller:
Lynq & Flow LLC
Registered Agent: Registered Agents Inc
30 N Gould St Ste R
Sheridan, WY 82801
Wyoming, USA
Support Email: info@lynqagency.com
Data Protection Contact: Company administrative contact
We act as a data controller when we determine the purposes and means of processing personal data (e.g. account management, billing, analytics, support, and marketing).
We act as a data processor when processing Shopify merchant or end-customer data on behalf of our customers under a Data Processing Agreement (“DPA”).
2. Categories of Personal Data We Process
We may process the following categories of personal data:
- Account Data
- Name, email address, company name, user role, login credentials, and authentication data.
- Billing Data
- Billing history, transaction identifiers, subscription plan details, and limited payment metadata (processed via Shopify or payment providers).
- Shopify Store Data (Processor Context)
- Customer names, email addresses, order details, shipping information, and communication history processed strictly on behalf of merchants.
- Usage Data
- Feature usage, logs, workflow activity, timestamps, system interactions, and performance diagnostics.
- Support Data
- Messages, attachments, and communication history from support requests.
- Technical Data
- IP address, browser type, device information, operating system, and cookies.
We do not intentionally collect or process special categories of personal data (sensitive data).
3. Purposes and Legal Bases of Processing
We process personal data for the following purposes:
- Service provision and account management (Art. 6(1)(b) GDPR)
- Billing and compliance (Art. 6(1)(b), 6(1)(c) GDPR)
- Service security and fraud prevention (Art. 6(1)(f) GDPR)
- Product improvement and analytics (Art. 6(1)(f) GDPR)
- Customer support (Art. 6(1)(b), 6(1)(f) GDPR)
- Marketing communications (Art. 6(1)(a), 6(1)(f) GDPR) — does not apply to data obtained via Google APIs
- Legal obligations and dispute handling (Art. 6(1)(c), 6(1)(f) GDPR)
- Processing on behalf of merchants (Shopify data) (Art. 6(1)(b) GDPR)
We rely on legitimate interest where necessary to operate, secure, and improve the Service, including preventing abuse and ensuring system stability.
4. Data Retention
We retain personal data only as long as necessary:
- Account data: duration of relationship + up to 6 years
- Billing data: according to legal accounting requirements
- Logs and usage data: up to 12 months
- Support data: up to 24 months
- Marketing data: until consent is withdrawn
- Shopify merchant and end-customer data: according to merchant instructions and DPA terms
After expiry, data is securely deleted or anonymised unless required by law.
5. Data Sharing and Recipients
We may share data with:
- hosting and infrastructure providers
- Shopify and integration partners
- payment processors
- analytics providers
- professional advisers (legal, accounting, audit)
- public authorities where legally required
All third parties are bound by confidentiality and data protection obligations.
6. International Transfers
Personal data is primarily processed within the United States and other jurisdictions where our service providers operate.
Where personal data is transferred from the European Economic Area (EEA) to countries not deemed to provide an adequate level of protection, we ensure appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- other lawful transfer mechanisms under GDPR
Copies of safeguards can be provided upon request.
7. Data Subject Rights
You have the right to:
- access your personal data
- correct inaccurate data
- request deletion
- restrict processing
- data portability
- object to processing
- withdraw consent
Requests can be submitted to: info@lynqagency.com
We may require identity verification and respond within statutory timeframes.
For Shopify end-customer data, requests should be directed to the relevant merchant.
8. Security
We implement appropriate technical and organisational measures including:
- encryption in transit and at rest
- access control mechanisms
- monitoring and logging
- regular security testing
- restricted employee access
Security measures are continuously updated to ensure compliance with GDPR Article 32.
9. AI and Automated Processing
The Service includes AI-assisted features that help automate workflows and communication.
Key points:
- AI outputs are assistive and require human oversight
- no fully autonomous decisions with legal effects are made without human review
- input data is processed via secure APIs
- you must not include sensitive personal data in AI inputs
Where data is processed by third-party AI providers, it is used solely for generating outputs and is not used for training models.
9a. Google User Data
Where the Service accesses data through Google APIs (including Gmail), our use and transfer of that information adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Data obtained via Google APIs is used solely to provide and improve the specific Service features you have enabled (e.g. email-based workflow automation).
- Such data is never used for advertising or marketing purposes.
- Such data is never sold, rented, or transferred to third parties for advertising purposes.
- Such data is never used to train generalised AI or machine learning models.
- Human access to this data is limited to cases necessary for security purposes, to comply with applicable law, or with your explicit consent, and is subject to internal access controls.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated via:
- the Service interface, or
- email notification
Continued use of the Service constitutes acceptance of updates.
12. Contact and Complaints
If you have questions about this Privacy Policy or your data, contact:
You also have the right to lodge a complaint with your local data protection authority.
