Privacy Policy

Effective date: August 12, 2026 · Last updated: August 12, 2026

This page explains what NetOrderFlow collects, why, and who else handles it. It describes what the product actually does today. If something here is unclear, email us and we'll answer plainly.

Who we are

NetOrderFlow ("we", "us") provides mobile order entry and NetSuite-ready CSV export for sales teams. You can reach us at support@netorderflow.com or through the contact form on netorderflow.com.

What we collect

  • Account information. Your name and email address. If you sign in with Google, we receive basic Google profile details (name, email, and profile image) — nothing else from your Google account.
  • Business data you enter or import. Customers, items, prices, orders, templates, and the files produced by exports. This is your organization's data; we store and process it so the service works.
  • Billing. Subscriptions are handled by Stripe. Card numbers are entered on Stripe's pages. We never see or store card numbers — we keep only a Stripe customer and subscription reference, your plan, and its status.
  • Support requests. When you contact support we attach a small context snapshot: the screen you were on, your role, whether you're an admin, your plan and subscription status, your organization name and id, your user id and email, the record you were looking at if you started from one, your browser and window size, timezone, language, the app build, and the most recent client-side error if one happened. This list is shown to you in the form before you send, and it never includes the contents of the page, your customer or pricing data, or your export files.

How we use it

To run the service, bill subscriptions, answer support requests, and send transactional email such as trial and account notices and support replies. We don't sell your data, and there are no advertising trackers in the app.

Service providers

  • Supabase — database, authentication, and file storage.
  • Stripe — payments and subscription billing.
  • Resend — transactional email.
  • Google — optional sign-in, only if you choose it.

How data is separated

Every record carries the organization it belongs to, and access is enforced at the database row level rather than only in the screens. Users see their own organization's data and nothing from any other organization. Within an organization, access is further narrowed by role, and by sales rep and territory assignment if an admin turns that restriction on.

Retention and deletion

We keep your data while the account is active. Your organization owns what it enters and imports. Admins can clear organization data from inside the app, and you can ask us to delete an organization's data by emailing support. Deactivating a user removes their access but keeps their past orders with the organization, so history stays intact.

Cookies and local storage

We use browser storage for session authentication and for interface preferences such as dismissed banners and saved drafts. No advertising or cross-site tracking cookies.

Security

Traffic is encrypted in transit. Access is controlled by authentication, role-based permissions, and row-level isolation per organization. Accounts are created by invitation from an admin rather than open sign-up into an existing organization.

Children

NetOrderFlow is a business product and is not directed at anyone under 18.

Changes

If this policy changes, we'll update this page and revise the date at the top.