ArchFlow
PrivacyTerms
Sign InView plans

Last updated 17 September 2026

Privacy Policy

This policy explains how ArchFlow (“we”, “us”) handles personal information when you visit archflowsolutions.com, create a firm account, use the practice workspace, talk to Archie on the web or WhatsApp, connect a mailbox, pay for a plan, or open a client portal link. It covers firm users and the people whose details a firm stores in ArchFlow (clients, contractors, and team members).

Privacy questions and requests: sales@archflowsolutions.com. The Terms of Service sit alongside this policy.

Who we areWho this coversWhat we collectHow we use itArchie and AIGoogle user dataConnected emailWhatsAppClient portalPaymentsProcessorsCookies and device storageHow long we keep itWhen we share itInternational transfersSecurityYour rightsChildrenChanges

1. Who we are

ArchFlow is a practice operating system for architecture firms. The public site and product are operated at archflowsolutions.com. We do not publish a street address on this page. Write to sales@archflowsolutions.com and we will handle the request, including a postal address when the law requires us to give one.

If you are in the European Economic Area or United Kingdom, ArchFlow is the controller of account, billing, and website data. For client, contractor, and project records a firm types into ArchFlow, the firm is the controller and we process that information on the firm’s instructions. If you are in South Africa, we process personal information as a responsible party for our own account data and as an operator for the firm’s practice records, under POPIA.

2. Who this covers

  • Visitors to the marketing site, login, signup, and these legal pages.
  • Firm owners and team members with an ArchFlow seat.
  • People you invite to a firm.
  • Clients, contractors, and other contacts whose names, emails, phones, and files a firm stores. Those people usually do not have their own ArchFlow account.
  • Anyone who opens a client portal link a firm sends them.

3. What we collect

Account and firm

Name, email, password or Google sign-in tokens, phone number if you add one, firm name, address, currency, logo, theme preference, team roles, and permissions.

Practice records the firm enters

Clients and contractors (including email and phone), projects, fees, proposals, invoices, expenses, permits, drawings and revisions, RFIs, snags, variations, tasks, notes, time entries if the firm turns time tracking on, uploaded files, and portal settings.

Archie

Messages you send Archie in the web app or on WhatsApp, short conversation history used to answer follow-ups, and tool results (for example the client record Archie just updated). The browser may also keep the last day’s Archie thread on your device so changing menus does not wipe the chat.

Connected mailbox

If you connect Gmail or Outlook, we receive OAuth tokens and the mailbox address. We request send and read scopes so Archie can send mail you approve and can surface inbound mail that matches a client or contractor already on the firm. We do not use the mailbox to advertise to your contacts.

WhatsApp

If you link a number, Meta delivers the message text, media, and your WhatsApp identifier to our bot. Replies go back through the WhatsApp Business API.

Studio and drafts

Images, sketches, prompts, and generated stills or films, plus credit usage against the firm wallet.

Billing

Plan, interval, seat count, payment status, and identifiers our payments provider needs. We do not store full card numbers on ArchFlow servers. Card data is handled by Dodo Payments as merchant of record.

Technical logs

IP address, browser, pages requested, and error logs needed to run and secure the service. We do not sell advertising profiles.

4. How we use it

  • Provide the workspace, portal, Archie, Render Studio, and Technical Drafts.
  • Authenticate you, keep seats and permissions accurate, and send system mail (invites, password reset, invoices from us).
  • Process subscription payments and credit the firm wallet.
  • Update firm records when you ask Archie to change an email, phone, address, or other field.
  • Send email as you after you confirm a draft, when a mailbox is connected.
  • Prevent abuse, debug failures, and meet legal duties.

Legal bases (GDPR / UK GDPR) include contract (providing the service you bought), legitimate interests (security, product operation, answering support), consent (optional mailbox connect, WhatsApp link, cookies that are not strictly necessary), and legal obligation. Under POPIA we process for the same purposes with the grounds that apply to those purposes.

5. Archie and other AI

Archie is ArchFlow’s assistant on the web and on WhatsApp. It reads and can update the same firm data you can, within your team permissions. It may send the text of your prompt and the tool results it needs to a large-language-model provider (currently Anthropic) so it can answer. Render Studio and Technical Drafts send images and prompts to image-generation providers to produce the still, film, or plan you requested.

Do not paste secrets you would not store in the firm file. Archie can be wrong. Confirm emails before send. You stay responsible for what is written to the CRM and what is sent to a client.

6. Google user data

If you sign in with Google or connect Gmail so Archie can send and read mail as you, ArchFlow accesses Google user data only with your consent, and only for the features you turn on. We request these Google API scopes:

  • openid, email, and profile — to create or sign in to your ArchFlow account and show the Google account you used.
  • gmail.send — to send an email from your Gmail address after you review a draft and confirm send. We do not send mail in the background without that confirmation.
  • gmail.readonly — to read incoming messages so we can show mail that matches a client or contractor already stored on your firm. We do not store your whole inbox.

How we use Google user data: account authentication, sending confirmed mail from your mailbox, matching inbound mail to known firm contacts, and refreshing the connection with the tokens Google returns. We do not use Google user data for advertising, credit scoring, or selling access to other parties. We do not allow humans to read Google user data unless you ask us to for support, we must do so for security or law, or the data is already public.

ArchFlow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide and improve the mailbox features you requested. We do not transfer Gmail content to other parties except the processors that deliver this product (for example our EU database host), and then only to provide those features.

OAuth tokens are stored encrypted. You can disconnect Gmail in Settings → Account, or revoke ArchFlow in your Google Account permissions. After disconnect we stop using those tokens and delete them from the firm record.

7. Connected email (Gmail and Outlook)

Connecting Gmail or Outlook is optional. Tokens are stored so Archie can send as you and, where configured, read inbound mail that matches known firm contacts. Sending requires an explicit confirmation in the product. You can disconnect the mailbox in Settings → Account. Revoking access in Google or Microsoft also stops new use of those tokens. Google and Microsoft are independent controllers of their own account data; their policies apply as well.

8. WhatsApp

Archie on WhatsApp is optional reach into the same firm dataset. Meta processes messages under its WhatsApp Business terms. We use the content to carry out your instructions (create or update records, send a drawing, quote a render). Unlink the number in Settings if you want that channel off.

9. Client portal

Clients do not need an ArchFlow account. A firm shares a token link. Anyone with the link can see the progress, fees, invoices, approved drawings, and council status the firm chose to publish. The firm can revoke the link. Treat the URL like a document you would email a client.

10. Payments

Subscriptions and eligible purchases are charged by Dodo Payments as merchant of record. Dodo receives the billing details needed to take payment and handle tax where it is the seller of record. See Dodo’s own privacy notice as well. Plan prices on the site are in US dollars unless we say otherwise.

11. Processors we rely on

We use specialist providers to run ArchFlow. The main ones today are:

  • Supabase — authentication, database, file storage, and edge functions (hosted in the EU, eu-west-1).
  • Vercel — hosting the web application.
  • Dodo Payments — checkout and subscription billing.
  • Anthropic — Archie language responses.
  • Image-generation providers — Render Studio and Technical Drafts outputs.
  • Google and Microsoft — optional sign-in and mailbox OAuth.
  • Meta — WhatsApp Business delivery.
  • Resend — some system email (invites, notifications) when a personal mailbox is not used.

Providers only get what they need to perform that job. We will update this list if the stack that holds personal information changes in a material way.

12. Cookies and device storage

We use cookies and similar storage to keep you signed in, remember a plan you picked before signup, store theme preference, and keep the last day’s Archie conversation on the device you used. These are needed to run the product, not to advertise across the web. You can clear site data in the browser; you will need to sign in again.

13. How long we keep it

Account and firm records stay until the firm deletes them or the account is closed and any legal retention period ends (for example tax records for invoices). Archie chat history on the server is a short rolling window; the browser copy expires after one day. Mailbox tokens stay until you disconnect. Backups exist for a limited period for disaster recovery. Support mail to sales@archflowsolutions.com is kept as long as the thread is still needed.

14. When we share it

We do not sell personal information. We share it with the processors above, with the firm’s own members according to permissions, with a client who has a portal link the firm created, and if the law or a binding request requires it. If ArchFlow is sold or merged, information may move with the business under this policy or a successor notice.

15. International transfers

You may access ArchFlow from outside the country where the data is stored. Infrastructure listed above may process data in the EU, the United States, or other regions those providers operate in. Where a transfer needs a safeguard (for example standard contractual clauses), we rely on the provider’s terms and those clauses.

16. Security

Access to the workspace is authenticated. Firm data is scoped so one firm cannot read another. Mailbox tokens are stored encrypted. No internet service is perfectly secure. Use a unique password, limit team permissions, and revoke portal links and mailboxes you no longer need.

17. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port personal information, to object to some processing, and to withdraw consent (for example disconnect Gmail). Firm users can edit most practice records in the app or ask Archie to update them. For account deletion or a copy of what we hold, email sales@archflowsolutions.com from the address on the account. We may need to verify who is asking.

If we process your details only because a firm stored them (you are a client of that firm), contact that firm first. We will help the firm respond.

You can complain to your data protection authority. In South Africa that is the Information Regulator. In the EEA or UK, complain to your local authority.

18. Children

ArchFlow is built for architecture practices, not for children. We do not knowingly collect information from anyone under 16. If you believe a child created an account, write to sales@archflowsolutions.com and we will close it.

19. Changes

We will update this page when the product or the law requires it. The date at the top is the current version. Material changes will be noted here; if a change needs consent, we will ask for it.

ArchFlow

Questions about this page: sales@archflowsolutions.com

Product

PracticeStudioPlans

Account

Sign InRegister

Legal

PrivacyTerms

© 2026 ArchFlow. All rights reserved.