Legal
Privacy policy
What we collect, why we collect it, and what you can make us do with it.
Last updated 15 August 2026
Draft — not yet legally reviewed
This document describes how the service actually works, but it has not been checked by a lawyer and the operating entity is not yet named. Have it reviewed for your jurisdiction before you rely on it. This notice disappears once the registered company details are filled in.
FlowRefund pursues refund claims for you, receives the money when a claim succeeds, and pays it out when you ask. Doing that means holding information about you, about the transaction you are disputing, and about where you want your money sent. This page describes exactly what that is — it is written against how the system actually works, not from a template.
Who is responsible for your data
«Registered legal entity» («Company registration number»), «Registered address», is the controller of the personal data described here. For privacy questions and rights requests, contact privacy@securerefund.online.
What we collect
Information you give us
- Account details — your email address, and optionally your name, display name, phone number, country, language and timezone.
- Claim details — the merchant, the transaction date, the amount and currency, how you paid, an optional transaction reference, and whatever you tell us about what went wrong.
- Evidence you upload — receipts, invoices, order confirmations, statements, correspondence, screenshots, shipping proof, and where a claim requires it, proof of identity.
- Payout destinations — for a bank, the bank name and the last four digits; for crypto, the network and your receiving address; for a payment service, the name and the email or phone on that account.
- Messages you exchange with your case handler.
What we deliberately do not collect
We never ask for, and the system has nowhere to store, a full card number, a CVV, a full bank account number or IBAN, the credentials to your online banking, or a crypto private key or recovery phrase. The payment identifiers we keep are a 4-digit suffix and, for crypto, a public receiving address — neither of which can move money on its own. This is enforced by the database schema, not merely by policy.
Information collected automatically
- Authentication records — sign-in times, the method used, and IP address, kept by our authentication provider.
- A financial ledger — every credit and debit on your balance, with its reason and timestamp. This is append-only: entries are never edited or deleted, so your balance can always be reconstructed.
- An audit trail — every change to a claim, a balance, a payout or a permission, with who did it and when. It exists so decisions about your money can be evidenced, and it is not used for profiling or advertising.
Why we are allowed to hold it
| What | Why | Lawful basis |
|---|---|---|
| Account details | To give you an account and let you sign in | Performance of a contract |
| Claim details and evidence | To prepare and file your claim | Performance of a contract |
| Payout destinations | To send you money you have asked us to send | Performance of a contract |
| Identity verification | Anti-money-laundering and sanctions obligations | Legal obligation |
| Ledger and audit trail | To evidence what happened to your money | Legal obligation; legitimate interests |
| Marketing emails | Occasional notes on refund rights | Consent — and only if you opt in |
A specific note about crypto addresses
A blockchain address is pseudonymous, not anonymous. Once we send funds to an address you give us, that transfer is recorded on a public ledger that anyone can read, permanently. If that address is linkable to you elsewhere, the payment becomes linkable to you too. That is a property of the technology, not of this service — but you should know it before choosing crypto, and you may prefer a fresh receiving address.
Who else sees it
- The merchant, your bank, or the card scheme — the claim and its supporting evidence go to whoever can reverse the charge. Nothing is sent before you submit the claim.
- Payment providers — the details needed to execute a withdrawal you have requested.
- Our infrastructure providers — hosting, database and authentication from Supabase; email delivery from our mail provider. They process data on our instructions only.
- Regulators and law enforcement — where we are legally required to report or disclose. In some cases the law prohibits us from telling you that we have.
- Nobody else. We do not sell your data, share it with advertisers, or use it to build profiles.
How it is protected
Access is enforced at the database level rather than only in the application: every table carries row-level security policies, so one claimant's records — including their balance and their payout destinations — are not reachable by another even if the application were bypassed. Evidence files sit in private storage namespaced per user and per claim. Opening a proof-of-identity document requires a member of staff to have passed a second authentication factor, and every such access is recorded.
More detail is on the security page.
How long we keep it
- Claims and their evidence — for the life of the claim plus the period we are required to retain records, then deleted.
- Proof-of-identity documents — kept only as long as the claim or our verification obligations require.
- Financial records — the ledger, payouts and the destinations they went to are retained for the period anti-money-laundering and accounting law requires, typically several years after the account closes. These we cannot delete on request.
- Audit records — retained for seven years.
- Your account — until you ask us to delete it.
Your rights
Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. You can withdraw marketing consent at any time from your notification settings, and that will not affect anything to do with your claims or your balance.
Email privacy@securerefund.online and we will respond within one month. If you are not satisfied you can complain to your data protection authority — in the UK that is the Information Commissioner's Office.
Two limits worth stating plainly. If you ask us to delete a claim while it is still with a provider, we may not be able to withdraw what has already been filed. And we cannot delete financial records we are legally required to keep, even after you close your account — so a deletion request will remove your profile and claims but leave the ledger entries that evidence money we received and paid out.
Children
The service is not intended for anyone under 18, and we do not knowingly create accounts for them.
Changes
If we change this policy materially we will say so on this page and, where the change affects you, by email.
Questions about this page? Email support@securerefund.online.
