Skip to content
Construct Labs
ProductsPlatformsCompanySupport
Contact

Legal

Privacy Policy

Effective July 26, 2026

This policy explains what Construct Labs collects through its website and products, including AgencyFlow.

On this pageScopeInformationSourcesHow we use itLegal basesSharingRetentionSecurityTransfersYour rightsChildrenChangesContact

1. Scope and roles

Construct Labs operates this website and provides AgencyFlow and related services. This policy applies when you visit our website, contact us, join a pilot, install a product, or use a service that links to this page.

For website inquiries, product accounts, security records, and direct business contacts, Construct Labs generally decides why and how information is processed.

For information processed through a customer’s connected business account, the customer or agency may decide the purpose of processing and Construct Labs may act as a service provider or processor. Requests about that information may need to be handled by the customer that controls the account.

2. Information we collect

Website and contact information

  • Your email address, name, company, and the contents of a message when you contact us.
  • For a pilot application, the number range of client accounts you manage, your description of the repeated task, and your consent to be contacted about AgencyFlow.
  • Basic request data such as IP address, browser type, device type, requested page, referring page, timestamps, and security signals.

AgencyFlow account and installation information

  • User, agency, company, application, and client-account identifiers supplied by the connected platform.
  • User role, account type, agency-owner status, and the active client-account identifier used to verify access.
  • OAuth access and refresh tokens, granted permissions, token expiration, installation status, and reauthorization status.
  • Application install and uninstall event identifiers, timestamps, and the minimum routing metadata needed to process those events.

Readiness information

  • Counts of workflows, calendars, custom-field definitions, and custom-value definitions.
  • Scan identifiers, status, timestamps, and limited failure categories.

The current readiness feature does not request contacts, conversations, messages, appointments, or opportunity records. It does not retain workflow definitions, custom-field names, or custom-value contents.

3. Where information comes from

We receive information directly from you, from your browser or device, from the third-party platform where you install AgencyFlow, and from service providers that help us operate and secure the service.

We do not purchase marketing lists or obtain connected CRM customer records from data brokers.

4. How we use information

We use information to:

  • provide installation, authentication, token refresh, portfolio status, and readiness scans;
  • respond to support, sales, security, and legal requests;
  • protect accounts, investigate failures, prevent abuse, and maintain service reliability;
  • measure product operation and improve features using limited technical and aggregate information;
  • administer pilots, subscriptions, billing, and business records;
  • comply with law and enforce our agreements.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use connected account data to train general-purpose models.

5. Legal bases

Where a legal basis is required, we process information as needed to perform a contract, take steps requested before entering a contract, pursue legitimate interests in operating and securing the service, comply with legal obligations, or act with consent.

Our legitimate interests include preventing fraud, maintaining service reliability, answering business inquiries, improving product operation, and protecting customers. You may object to processing based on legitimate interests as described below.

6. When information is shared

We disclose information only as needed for the following purposes:

  • Infrastructure and security. Amazon Web Services hosts the application, database, queues, secrets, and logs. Cloudflare provides website delivery, DNS, and security services.
  • Connected platform. AgencyFlow exchanges information with the platform where the application is installed so that requested functions can run.
  • Communications and business operations. Our email, support, billing, accounting, and professional advisers receive only the information needed for their work.
  • Legal and safety. We may disclose information when required by law or when reasonably necessary to protect rights, safety, accounts, or the service.
  • Business transaction. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

Service providers are permitted to process information only for the services they provide to us and under applicable contractual duties.

7. Retention

We keep information only for as long as needed for the purposes described here, including service operation, security, dispute resolution, and legal obligations.

RecordTypical period
OAuth state10 minutes, followed by automatic expiration.
Webhook deduplication record7 days.
Pilot-form email deduplication hash24 hours. The record contains a one-way email hash and expiration, not the submitted form fields.
Application logs7 days. Pilot-form contents are not logged.
Failed queue messagesUp to 14 days.
OAuth tokensWhile the installation is active. Tokens are removed when an uninstall is processed or reauthorization is required.
Installation and readiness metadataWhile the service is active, then for a limited period needed for account closure, security, support, and legal records.
Pilot applications and business communicationsFor as long as needed to review the application, manage the inquiry or business relationship, and meet recordkeeping duties.

Backups and provider-level recovery copies may persist briefly after deletion before normal rotation removes them.

8. Security

We use administrative, technical, and organizational safeguards appropriate to the information we process. Current controls include HTTPS, managed encryption at rest, narrowly scoped access permissions, separate secret storage, short log retention, redacted logs, one-time OAuth state, webhook signature checks, bounded retries, and short-lived embedded sessions kept in browser memory.

No system is completely secure. If you believe information or credentials have been exposed, contact us immediately. Do not send the credentials themselves.

9. International transfers

Construct Labs and its service providers may process information in the United States and other countries. Privacy laws in those locations may differ from the laws where you live. Where required, we use recognized transfer safeguards or another lawful transfer mechanism.

10. Your privacy rights

Depending on where you live, you may have the right to request access, correction, deletion, portability, restriction, or an objection to certain processing. You may also have the right to withdraw consent and appeal a denied request.

We do not discriminate against anyone for exercising a privacy right. We may need to verify your identity and authority before acting. If the request concerns data controlled by your agency or another customer, we may direct the request to that organization.

To submit a request, email [email protected] with the subject “Privacy request.” You may also complain to the data protection authority in your jurisdiction.

United States state notices

During the preceding 12 months, we may have collected identifiers, internet or device activity, professional or business information, commercial or subscription records, and account credentials. We use and disclose these categories for the business purposes described in this policy. We do not sell them or share them for cross-context behavioral advertising.

11. Children

Our website and services are for businesses and adults. They are not directed to children under 18, and we do not knowingly collect personal information from children.

12. Changes to this policy

We may update this policy when our products, service providers, or legal duties change. The current version will remain at this URL with an updated effective date. We will provide additional notice when required by law or when a material change affects active customers.

13. Contact

Privacy and security questions can be sent to [email protected].

Construct Labs
United States

Construct Labs

Business software for established platforms.

ExploreProductsPlatforms
CompanyAboutContact
HelpSupportSecurityEmail

© 2026 Construct Labs

TermsPrivacyCookies