Privacy Policy
Last updated: August 6, 2026
Overview
ZoomFlow is operated by Connex Social LLC, doing business as Connex Digital ("Connex," "we," "our," or "us"), a Michigan limited liability company. This policy explains what we collect when you use ZoomFlow at zoomflowhub.com, why we collect it, who we share it with, and what you can ask us to do with it.
It also covers how we handle data in the course of our automation and integration services generally, since a ZoomFlow session is one of those services. Questions go to contact@connex.digital.
1. What ZoomFlow is
ZoomFlow sells scheduled one-hour Zoom consultations with automation consultants. You can book and pay without creating an account. If you create an account, you get a portal showing your session history, recordings, notes, receipts, remaining prepaid hours, and the action items your consultant noted.
2. Our service model
Connex provides automation and integration services hourly, working directly within client software platforms. Our approach aims to minimize data access while ensuring client control over systems and information.
No local data storage. We maintain a strict policy against downloading or storing client data locally. All work occurs directly within client platforms, with no local storage of client information.
Access management. Client platform access uses client-provided credentials or platform-specific roles. Temporary credentials are secured in our enterprise password management system. Clients maintain full control and may revoke access anytime.
Service delivery. Services are delivered through scheduled video conferences. Sessions may be recorded with client permission, though sensitive operations can be conducted unrecorded. Post-session access is not maintained unless specifically arranged.
3. Information you give us
When you book a session: your name, email address, and the description of the problem you want help with. If you tell us your company name or phone number, we keep that too.
When you pay: we collect billing name and email. Card details are entered directly with our payment processor and are never transmitted to or stored on our systems. We receive a confirmation, the last four digits, and the card brand.
When you create an account: your email address, and a password if you set one. Passwords are stored only as a salted hash by our authentication provider — we cannot read yours, and neither can anyone at Connex. You can instead sign in with a Google account (see Section 5) or with a single-use link we email you.
During a session: whatever you show or tell us. This regularly includes screen shares of your automation tools, and sometimes credentials or access to your systems (see Section 9).
4. Information we collect automatically
- Standard server and application logs: IP address, browser and device type, pages visited, timestamps
- Cookies and similar storage needed to keep you signed in and to remember basic preferences
- Basic analytics about how the site is used
We do not use advertising cookies and we do not sell or share your information for cross-context behavioral advertising.
5. Google Sign-In and Google user data
If you choose to sign in with Google, Google sends us a limited set of information based on the scopes we request:
| Scope | What we receive | Why |
|---|---|---|
| openid | A stable identifier for your Google account | To recognize you as the same user across sign-ins |
| .../auth/userinfo.email | Your primary Google account email address | To identify your account and match it to your booking history |
| .../auth/userinfo.profile | Your name and profile photo | To display who is signed in |
We do not request access to your Gmail, Google Drive, Google Contacts, or Google Calendar.
We store the identifier, email address, name, and profile photo on your ZoomFlow account record. We store OAuth tokens only as long as needed to maintain your session. We do not use Google Sign-In data to build advertising profiles, and we do not sell it.
You can revoke ZoomFlow’s access to your Google account at any time at myaccount.google.com/permissions. Revoking access removes your ability to sign in with Google; it does not by itself delete your ZoomFlow account or session history. To delete those, contact us (Section 12).
6. Limited Use disclosure
ZoomFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described in this policy
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition
- We do not use Google user data for advertising, and we do not sell it
- We do not allow humans to read Google user data unless we have your explicit consent, it is necessary for security or to comply with law, or the data has been aggregated and anonymized
7. Session recordings and notes
Sessions are recorded, and the consultant writes a summary afterwards. Both are saved to your portal.
- Why: so you can re-watch what was built, and so a consultant on a future session has context on your setup
- Who can see them: you, the other contacts linked to your organization in the portal, and Connex personnel who need access to deliver or support your work
- Consent: you are notified that recording is occurring when the session begins. If you do not want a session recorded, tell your consultant at the start and we will turn it off
- Retention: recordings and notes stay in your portal for as long as your account is active, so that your history remains available to you. We do not delete them on a schedule
- Deletion: email us and we will delete any specific recording or note
8. Confidentiality and NDAs
We maintain strict confidentiality of all client information and do not share information between clients or discuss client systems with third parties.
We honor client NDAs, with employee obligations extending beyond service delivery.
9. Credentials and access to your systems
Consulting sessions frequently involve your live systems. Two rules govern how we handle that:
- We ask you to grant access through your own tools’ invitation and permission features wherever possible, rather than sharing a password
- Where a credential is unavoidable, we ask that you rotate or revoke it after the engagement. We do not store client credentials in our systems as a matter of practice
If we hold anything on your behalf that you want removed, tell us and we will remove it.
10. Who we share information with
We use third-party providers to run ZoomFlow. Each receives only what it needs:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing, receipts, and refunds |
| Zoom | Hosting and recording sessions |
| Supabase | Application database, file storage, authentication, and sign-in emails |
| Google Cloud and Google Workspace | Google Sign-In, session calendar invitations, and our business email |
| Airtable | Client and booking records used by our internal team |
| Harvest | Invoicing and time tracking for clients billed after their sessions |
| Fillout | Booking and post-session feedback forms |
| Resend | Transactional email delivery |
| Zapier | Routing booking and session-summary email between our systems and our mail provider |
| Pipedrive | Sales and lead records — your contact details and the deals associated with them |
| Slack | Internal notifications to your consultant about your booking and feedback |
| Vercel | Website hosting and traffic analytics |
| Axiom | Application logging and error monitoring |
| Anthropic | An AI assistant our team uses internally to query booking and session records. Your data is not used to train models |
We also disclose information when required by law, to enforce our Terms & Conditions, to protect our rights or someone’s safety, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy.
We do not sell your personal information.
11. How long we keep things
| Data | Retention |
|---|---|
| Account records | While your account is active, then deleted within 30 days of your request to close it |
| Session recordings and notes | While your account is active, or until you ask us to delete them |
| Booking and payment records | As required for tax and accounting purposes, at least 7 years |
| Server logs | 90 days |
| Google Sign-In profile data | While your account is active |
12. Your choices and rights
You can:
- Access or correct your information — sign in to your portal, or email us
- Delete your account, recordings, or notes — email us. We will complete deletion within 30 days, except where we must retain records for legal or accounting reasons
- Revoke Google access — at myaccount.google.com/permissions
- Opt out of non-essential email — unsubscribe link in any marketing email. Transactional email about your bookings and payments continues while your account is active
Depending on where you live, you may have additional rights — including to a copy of your data in portable form, to object to certain processing, or to appeal a denial. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws, and residents of the EU/UK, can exercise these by emailing us. We will not discriminate against you for exercising any of them.
13. Security measures
We use encryption in transit, access controls limiting client data to personnel who need it, and providers who maintain their own security programs. Client access credentials are stored in an enterprise password manager, and access is revoked when an engagement ends.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you as required by applicable law.
14. Service communications
We send email about your bookings, payments, session summaries and portal access for as long as your account is active. These are transactional rather than marketing, and continue regardless of any marketing preferences.
15. International users
We operate from the United States and store data in the United States. If you use ZoomFlow from outside the US, you are transferring your information to the US, where privacy laws may differ from those in your jurisdiction.
16. Children
ZoomFlow is a business service and is not directed at children under 16. We do not knowingly collect information from children under 16. If you believe a child has given us information, contact us and we will delete it.
17. Changes to this policy
We will post any change here and update the "Last updated" date. If a change materially affects how we handle your information, we will notify account holders by email before it takes effect.
18. Contact
Connex Social LLC (dba Connex Digital), 4370 Chicago Dr. SW, Suite 524, Grandville, MI 49418, United States — contact@connex.digital
Connex Social LLC DBA Connex Digital · 4370 Chicago Dr. SW, Suite 524, Grandville, MI 49418 · contact@connex.digital