1. Scope and roles
Construct Labs operates this website and provides AgencyFlow and related services. This policy applies when you visit our website, contact us, join a pilot, install a product, or use a service that links to this page.
For website inquiries, product accounts, security records, and direct business contacts, Construct Labs generally decides why and how information is processed.
For information processed through a customer’s connected business account, the customer or agency may decide the purpose of processing and Construct Labs may act as a service provider or processor. Requests about that information may need to be handled by the customer that controls the account.
2. Information we collect
Website and contact information
- Your email address, name, company, and the contents of a message when you contact us.
- For a pilot application, the number range of client accounts you manage, your description of the repeated task, and your consent to be contacted about AgencyFlow.
- Basic request data such as IP address, browser type, device type, requested page, referring page, timestamps, and security signals.
AgencyFlow account and installation information
- User, agency, company, application, and client-account identifiers supplied by the connected platform.
- User role, account type, agency-owner status, and the active client-account identifier used to verify access.
- OAuth access and refresh tokens, granted permissions, token expiration, installation status, and reauthorization status.
- Application install and uninstall event identifiers, timestamps, and the minimum routing metadata needed to process those events.
Readiness information
- Counts of workflows, calendars, custom-field definitions, and custom-value definitions.
- Scan identifiers, status, timestamps, and limited failure categories.
The current readiness feature does not request contacts, conversations, messages, appointments, or opportunity records. It does not retain workflow definitions, custom-field names, or custom-value contents.
3. Where information comes from
We receive information directly from you, from your browser or device, from the third-party platform where you install AgencyFlow, and from service providers that help us operate and secure the service.
We do not purchase marketing lists or obtain connected CRM customer records from data brokers.
4. How we use information
We use information to:
- provide installation, authentication, token refresh, portfolio status, and readiness scans;
- respond to support, sales, security, and legal requests;
- protect accounts, investigate failures, prevent abuse, and maintain service reliability;
- measure product operation and improve features using limited technical and aggregate information;
- administer pilots, subscriptions, billing, and business records;
- comply with law and enforce our agreements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use connected account data to train general-purpose models.
5. Legal bases
Where a legal basis is required, we process information as needed to perform a contract, take steps requested before entering a contract, pursue legitimate interests in operating and securing the service, comply with legal obligations, or act with consent.
Our legitimate interests include preventing fraud, maintaining service reliability, answering business inquiries, improving product operation, and protecting customers. You may object to processing based on legitimate interests as described below.
7. Retention
We keep information only for as long as needed for the purposes described here, including service operation, security, dispute resolution, and legal obligations.
| Record | Typical period |
|---|---|
| OAuth state | 10 minutes, followed by automatic expiration. |
| Webhook deduplication record | 7 days. |
| Pilot-form email deduplication hash | 24 hours. The record contains a one-way email hash and expiration, not the submitted form fields. |
| Application logs | 7 days. Pilot-form contents are not logged. |
| Failed queue messages | Up to 14 days. |
| OAuth tokens | While the installation is active. Tokens are removed when an uninstall is processed or reauthorization is required. |
| Installation and readiness metadata | While the service is active, then for a limited period needed for account closure, security, support, and legal records. |
| Pilot applications and business communications | For as long as needed to review the application, manage the inquiry or business relationship, and meet recordkeeping duties. |
Backups and provider-level recovery copies may persist briefly after deletion before normal rotation removes them.
8. Security
We use administrative, technical, and organizational safeguards appropriate to the information we process. Current controls include HTTPS, managed encryption at rest, narrowly scoped access permissions, separate secret storage, short log retention, redacted logs, one-time OAuth state, webhook signature checks, bounded retries, and short-lived embedded sessions kept in browser memory.
No system is completely secure. If you believe information or credentials have been exposed, contact us immediately. Do not send the credentials themselves.
9. International transfers
Construct Labs and its service providers may process information in the United States and other countries. Privacy laws in those locations may differ from the laws where you live. Where required, we use recognized transfer safeguards or another lawful transfer mechanism.
10. Your privacy rights
Depending on where you live, you may have the right to request access, correction, deletion, portability, restriction, or an objection to certain processing. You may also have the right to withdraw consent and appeal a denied request.
We do not discriminate against anyone for exercising a privacy right. We may need to verify your identity and authority before acting. If the request concerns data controlled by your agency or another customer, we may direct the request to that organization.
To submit a request, email [email protected] with the subject “Privacy request.” You may also complain to the data protection authority in your jurisdiction.
United States state notices
During the preceding 12 months, we may have collected identifiers, internet or device activity, professional or business information, commercial or subscription records, and account credentials. We use and disclose these categories for the business purposes described in this policy. We do not sell them or share them for cross-context behavioral advertising.
11. Children
Our website and services are for businesses and adults. They are not directed to children under 18, and we do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy when our products, service providers, or legal duties change. The current version will remain at this URL with an updated effective date. We will provide additional notice when required by law or when a material change affects active customers.
13. Contact
Privacy and security questions can be sent to [email protected].
Construct Labs
United States