Privacy Policy — plain-language summary
This page summarizes how Onflow Ads handles personal data — what is collected, why, who sees it, where it goes, how long it is kept, and what control you have over it.
This is a summary, not the policy itself. The full Privacy Policy is at onflowads.com/privacy. If this summary and the full policy ever differ, the full policy controls. The legal page shows its "Last updated" date at the top.
The short version
- Onflow Ads collects only what a feature actually needs to run, to keep the marketplace honest, and to give you analytics.
- Your personal data is never sold — not for money, not for "valuable consideration", not to a data broker, and not for behavioural advertising.
- A trading partner never sees your email address, your wallet balance, your ledger, your payout details or your other campaigns.
- Closing your account is not a full erase. Financial records, security logs and a few other things survive, for stated reasons — see What survives closure.
- One address does everything: privacy@onflowads.com.
How to read this page
The full policy has 28 numbered sections in eight parts. This summary follows the same order, and each heading below links to the section that binds.
| Part | Sections | Covered below |
|---|---|---|
| The basics | 1–3 | Who is responsible |
| What we collect | 4–9 | What is collected, People who are not users, What is never collected |
| Why we use it | 10–12 | How it's used, Automated decisions, AI |
| Who else sees it | 13–17 | What others see, Who data is shared with, Leaving the country |
| Your device | 18–19 | Cookies and tracking, Messages |
| Keeping and protecting | 20–21 | How long data is kept, Security |
| Your control | 22–24 | Your rights, Children, Complaints |
| The rest | 25–28 | Breaches, changes and contact |
Who is responsible
For your account, orders, payments, support and security logs, Onflow Ads decides what happens to the data. It is the Data Fiduciary under India's DPDP Act and the controller under the GDPR.
For personal data you put into the platform — a face or a name inside your creative, your own channel's members, data you collect on a landing page you send traffic to — you are responsible. You need a lawful basis for it and you must honour the rights of the people it belongs to. See §3 of the full policy.
Two features put you squarely in the controller's seat, and §3.2 names them: a white-label storefront (the enquiries strangers submit on your branded domain are your prospects — you must tell them who you are; Onflow does not market to them) and outbound webhooks (order records go to a host you nominate, and what happens there is yours to answer for).
Telegram is a third platform. What Telegram does with your data is governed by Telegram's privacy policy, not this one.
What is collected
You provide:
| Data | Examples |
|---|---|
| Account | Name, email address, password (stored only as an argon2id hash — never the password itself), 2FA secret if you enable it |
| Channels | Telegram id, username or invite link, title, description, category, language, subscriber and engagement figures, your pricing |
| Campaigns | Ad copy, images, buttons, destination links, budgets, schedules, targeting |
| Money | Top-up and payout amounts, provider references, and your payout destination (UPI ID, bank details or crypto address) |
| Verification | Legal name and country only. No ID document, no selfie, no biometric |
| Support | Contact-form name/email/message; a support ticket also stores a phone number if you give one, plus the page, IP and browser it was raised from |
Collected automatically: IP address, browser User-Agent, country inferred from IP, referring page, and what you did and when. There is a request-level activity record that keeps the email address or name carried by a request — which is why it outlives the account.
Computed about you: your reliability score and standing, performance and delivery metrics, risk and abuse signals, and commercial signals like tier and lifetime spend.
From Telegram sign-in: only your numeric Telegram user id and display name. Not your phone number, photo, contacts or messages.
From your channel: counts only — subscribers, views, reactions, timing. Never the member list, and never who viewed or reacted. The one identity read is the administrator list, which is how ownership is proved — the bot's presence in it is the proof, which is why no screenshots are asked for.
It never messages your subscribers privately, never posts anything outside the campaigns and slots you accept or book, and is never given your subscriber list — Telegram does not hand one to a bot. The same three limits are contractual, in Terms §4.2. Remove the bot as an administrator, or disconnect the channel, and its access ends immediately.
People who are not users
The audience of a channel never signed up for anything, so the full policy gives them their own section (§8).
- Paid Promotion clicks — links in creative are rewritten through a redirect so clicks can be counted honestly. What the click record stores is a one-way salted hash of IP + User-Agent plus country, referrer and device type — no IP address, no cookie, no profile, and the advertiser gets a number rather than an audience list. The redirect is also excluded from the general activity record that logs the IP of ordinary requests, so clicking an ad leaves a salted hash and nothing else.
- Subscriber Exchange taps — this is the one exception, and the policy says so plainly. When someone taps an exchange ad inside the bot, Telegram identifies them, and the numeric Telegram user id is recorded against the delivery so a channel owner is paid for genuine taps rather than one person tapping ten times. The id and the timestamp are all that is stored — no name, no username, no phone. The advertiser sees counts.
Anyone, user or not, can exercise every right in §22 by writing to privacy@onflowads.com.
What is never collected
These are commitments in §9 of the policy, and narrowing one requires 30 days' notice:
- Sensitive data — health, biometrics, genetics, sexual orientation, religion, politics, union membership, caste or community.
- Full payment credentials — card numbers, CVVs, UPI PINs, banking passwords. Nobody at Onflow Ads will ever ask for one.
- Your channel's member list, or the identity of individual viewers or reactors.
- Precise device location — no GPS, no location permission. "Location" means country, inferred from IP.
- Data from children — see Children.
Onflow Ads also does not buy personal data from brokers, enrich your record from third-party datasets, or scrape personal data to build lists.
How it's used
Every purpose is paired with a lawful basis in §10. In short: running your account and delivering orders is contract; taking and moving money adds legal obligation; reliability scoring, fraud detection and security are legitimate interests; analytics tags and marketing email are consent, withdrawable at any time.
Data collected for one purpose is not silently reused for another.
Automated decisions
Reliability scores, eligibility floors, abuse and fraud signals, content-safety checks and rate limits are all decided by code first.
No automated decision permanently closes an account, confiscates a wallet balance or cancels a payout on its own — those need a person. An automated decision can suspend, hold or block pending that review. You can ask for a human to look again, put your side, and have the decision reconsidered.
AI
AI drafts copy, suggests targeting, describes channels, summarises analytics, checks creative for prohibited content and spots duplicates. §12 lists exactly what reaches a model provider — including the parts most policies leave out:
- Your brief, creative and channel profile when you use an AI feature.
- Support ticket threads, including your name, when AI drafts or triages a reply. Say so in the ticket and it will be handled manually instead.
- Both sides' history and money lines when AI assists on a dispute or fraud review.
- Your commercial figures when AI narrates your analytics.
Never sent: credentials, your 2FA secret, payment or payout details, or another user's account contents outside a dispute they are party to.
The engine is one of a small set of established commercial model providers; the full policy lists categories rather than brand names and will tell you which is in use if you ask (see below). Your data is not used to train AI models. Prompts and responses are not stored in the AI call log — with one deliberate exception: text that a safety check blocks is kept as the evidence for that decision, so an appeal can be judged on what was actually written.
What others see
A trading partner sees your channel's public profile and figures, the creative and order details for your deal with them, your public trust signals, and the delivery evidence.
Your email address, your wallet balance, your transaction ledger, your payout destination, your legal name from verification, your IP address, your other channels, or your other campaigns. One precision: where a channel owner needs to tell two advertisers apart they see a masked form — al****@g***.com — which is a label, not an address, and cannot be written to.
Delivery-proof and certificate pages are unlisted but reachable by anyone holding the link — treat the link as the secret.
Who data is shared with
Personal data is not sold, and not shared for cross-context behavioural advertising. What actually happens instead:
| Who | What they get |
|---|---|
| Hosting, database, cache | Everything, as the infrastructure that runs the platform |
| Network protection & edge | Request metadata (IP, User-Agent); bot-check tokens; uploaded media |
| Payment providers | Amount, currency, references. Card and UPI details are entered on their own checkout and never reach Onflow Ads. The crypto gateway gets no name, email or account id |
| Suppliers (Boost fulfilment) | The service, the target link and the quantity — never who you are |
| AI providers | The content an AI feature operates on (see AI) |
| Email, push, error monitoring | Your address and message content; your browser's push endpoint; technical error context |
| Analytics and support tools, where enabled and consented | Behaviour, and for two of them your identity — email, name, tier, role and credit balance |
The full policy describes each provider by what it does and what it receives rather than by brand. A published map of the infrastructure is a target list for anyone attacking it, and that risk lands on you as much as on Onflow Ads. You can have the names on request — email privacy@onflowads.com, no reason needed, answered on the §22.2 timetable. Anything that runs in your own browser — every cookie, every third-party tag — is still named in full, because withholding those would hide nothing from an attacker while stopping you giving informed consent.
Significant events are mirrored, as they happen, into a private operations channel only operators can read: the acting account's name and email, account id, IP, country, browser, the action and its outcome, and for money operations the amounts and references. A messaging provider therefore carries a copy of those operational records. §14.5 discloses this rather than calling it "internal logging".
What does not go into it: your payout destination (only its last four characters, so an operator can spot a changed destination without being able to use it), the legal name you gave for verification (dropped entirely), any phone number, and credentials of any kind.
Leaving the country
Onflow Ads is operated from India and its providers sit in several countries. Transfers rely on Standard Contractual Clauses or an adequacy decision where the EEA/UK is involved, and no data goes to a territory restricted under the DPDP Act.
Contractual safeguards bind the company data is sent to. They do not bind a foreign government. What Onflow Ads controls is how little crosses a border — a supplier gets a link, a crypto gateway gets an amount, an AI provider gets the text you are editing.
Cookies and tracking
Every cookie Onflow Ads sets itself is strictly necessary, first-party, HttpOnly and Secure, and none is used for advertising:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Sign-in session | Keeps you signed in (a random token only) | 48 hours, or 30 days with "remember me" |
| Verification flow | One verification flow — sign-up, email change, password reset, 2FA step | 30 minutes |
| Telegram sign-in binding | Binds a Telegram sign-in to the browser that started it | 10 minutes |
| Google / Apple sign-in state | Anti-forgery state tying the round trip to the browser that began it | 10 minutes |
Preferences kept in your browser and never sent: your cookie choice, your currency preference, your basket and saved channels, and a per-tab welcome flag.
Third-party tags — Google Analytics 4, Google Tag Manager, PostHog, Microsoft Clarity, and Meta/TikTok/Snap/Pinterest/LinkedIn/Reddit/X pixels — are all optional, ship off, and load only after you accept. Reject, and none of them ever loads. Turning the consent requirement off is treated as a material change needing 30 days' notice.
Since nothing loads without an affirmative "Accept", a browser that never accepts is already opted out — the outcome GPC is designed to produce. The GPC header is not detected automatically today; the full policy says so in §18.4 rather than claiming a control that has not been built. Declining the banner achieves the same thing immediately.
Where the live-chat widget is enabled it is placed in the page itself, so it loads before you answer the banner. So do the fonts, Telegram's Mini App script, the payment provider's checkout on the top-up page, and the library CDNs behind a few interactive pages. Loading a script from another host discloses your IP and browser to that host.
Messages
- Service messages — codes, receipts, order and payout notices, expiry reminders — cannot be switched off while you hold an account.
- Marketing is consent-based, carries a one-click unsubscribe that works without signing in, and consent is re-checked at the moment a campaign is sent. Segments are built from tier, role and signup recency — never from your message content, creative or tickets.
- Telegram messages stop if you turn the category off or block the bot. Browser push needs your browser's permission and stores only the endpoint, keys and User-Agent.
- WhatsApp codes are entirely opt-in, use your own number, and carry only the same six-digit code — never marketing, links or media.
How long data is kept
| Data | Retention |
|---|---|
| Account, profile, channels, listings | While the account is open; deleted or anonymised on closure |
| Orders, deals, delivery evidence | Up to 8 years from completion |
| Payments, wallet ledger, payouts, invoices | Up to 8 years (Indian company and tax law) |
| Support tickets | Up to 3 years after the matter closes |
| Verification codes and sessions | Minutes to hours — they expire by design |
| Security and activity records | See below — the honest answer is longer |
| Aggregate statistics | Indefinitely (not personal data) |
There is no automatic expiry over security and activity records today. They are kept while useful for security, fraud investigation and defending claims, and reviewed periodically. The policy says so rather than quoting a period the system does not yet enforce. You can ask for them to be dealt with sooner under §22.
Backups: encrypted copies of the database are taken on a regular cycle and held off-site for a limited period, so deleted data can persist in a backup for a short time afterwards. Backups are never used to restore a record that was deliberately deleted. The schedule, the retention window and where they live are deliberately not published — that detail would help an attacker and tells you nothing about your own data.
What survives closure
- Financial and order records, for the periods above.
- Security and activity records — including the email address and name carried by the request, the IP, country and browser — with the link to the account severed but the entries kept.
- Support tickets, and copies of emails already sent to you.
- Referral and affiliate attribution, and the identifiers inside a completed cross-promotion pairing — both describe a relationship with another user.
- Creative you published. Delivered images are cached to be fast and can stay retrievable by direct URL; creative sent to Telegram to be posted lives on Telegram's servers under their retention.
- An anti-evasion marker, but only if you leave with standing below baseline: a one-way hash of your email address plus the standing you would resume at. The restriction lifts after 90 days (upheld fraud) or 45 days (anything else). Leave in good standing and nothing is written at all. See Account standing.
- What another user legitimately holds about a deal you did with them, and content already published.
Security
Encryption in transit; passwords stored only as argon2id hashes and re-hashed as parameters improve; optional 2FA; session tokens that rotate and can be revoked everywhere at once; forced sign-out from every device on a password reset or email change; rate limits and lockouts keyed on hashed identifiers; bot-checks on public forms; role-limited staff access with the most damaging actions reserved to the platform owner.
No system is perfectly secure, and the policy does not pretend otherwise. What it commits to is taking those measures, reviewing them, telling you when something goes wrong, and not quietly weakening a protection the document describes.
Onflow Ads will never ask you for your password, a verification code, a card number, a UPI PIN or your Telegram login code. Anyone who does is not Onflow Ads. Report a security flaw to security@onflowads.com; good-faith researchers will not be pursued.
Your rights
Every right below is extended to every user, wherever you live:
| Right | What it means |
|---|---|
| Access | What is held, what is done with it, and who it went to |
| Correction and completion | Fix, complete or update anything wrong or stale |
| Erasure | Delete what is no longer needed — with the honest limits above |
| Portability | A structured, machine-readable copy |
| Withdraw consent | Analytics, marketing, WhatsApp codes — as easy to withdraw as to give |
| Object and restrict | Object to legitimate-interests processing, or pause it while a dispute is resolved |
| Human review | A person looks again at an automated decision |
| Nominate | Name someone to exercise your rights if you cannot (DPDP Act) |
| Opt out of sale/sharing | US state law — honoured regardless, since neither happens |
| Non-discrimination | Exercising a right costs you nothing in service, price or standing |
How to use them
- Write from the account's email address to privacy@onflowads.com, or use the contact form.
- Name the right you are exercising.
- Include enough to find the record — account email or OFA ID, and for anything order-related the reference and dates.
- For a correction, say what the correct value is. For a deletion, say whether you want the whole account gone or only specific data.
Acknowledged within 72 hours, answered within 30 days. It's free, unless a request is manifestly unfounded or repetitive — and you'd be told before, not after.
Some things need no request at all: disconnect a channel, update your own details from the dashboard, or control cookies in your browser.
A request can be declined where the law requires keeping the data, where it is needed for a legal claim or a live dispute, where complying would expose someone else's data, where the data is held on your instructions as controller, where identity cannot be verified, or where erasure would defeat the anti-evasion marker while it is still in force. You are told which reason applies, the rest of the request is honoured, and you can escalate.
Children
Onflow Ads is for adults: you must be at least 18, or the age of majority where you live if higher. No data is knowingly collected from anyone under 18, no advertising is directed at children, and no child is tracked or profiled. If a child has provided personal data, write to privacy@onflowads.com and it will be dealt with promptly.
If your own channel's audience includes children, you must not use the Services to advertise to them anything you could not lawfully advertise to a child.
Complaints
Raise it first with privacy@onflowads.com with "Grievance" in the subject. Acknowledged within 24 hours, disposed of within 15 days.
If that does not resolve it: the Data Protection Board of India; your national supervisory authority in the EEA, UK or Switzerland; or your local authority elsewhere. You are never required to arbitrate or waive a statutory complaint route.
Breaches, changes and contact
- Breaches — you are notified without undue delay, in plain language: what happened, what data, likely consequences, what has been done and what you should do. Regulators are notified within their deadlines, including 72 hours where the GDPR applies. Notification will not be delayed to protect reputation.
- Changes — a material change gets 30 days' notice and applies prospectively only. Corrections and changes that reduce collection take effect on publication. Ask and you will be told what the policy said on any past date.
- Additional Privacy Terms — §27 anchors disclosures published between deploys (a new processor, a new purpose, a new country). Each shows the date it was added, and each forms part of the notice.
Contact: privacy and data rights → privacy@onflowads.com · everything else → support@onflowads.com or onflowads.com/contact · security → security@onflowads.com
Frequently asked questions
Does Onflow Ads sell my data?
No — not for money, not for other valuable consideration, not to a data broker, and not for behavioural advertising. It is shared only with a counterparty to run your deal, and with providers who run part of the platform.
Can my trading partner see my email address?
No. They see your channel profile and figures, the creative, your public trust signals and the delivery evidence for your deal — never your contact details, balance, ledger or other campaigns.
Does Onflow Ads store my card number?
No. Payment instruments are entered on the provider's own checkout. What comes back is an amount, a status and a reference.
Does the AI train on my content?
No. Your data is not used to train AI models and your content is not licensed to anyone for training.
Does my support ticket go to an AI?
It can, where AI drafts or triages the reply — including your name and what you wrote. Say so in the ticket and it will be handled manually.
Do you know who clicks my ads?
Not for Paid Promotions: only a salted, non-reversible hash plus country, referrer and device. The Subscriber Exchange is the exception — a tap inside the bot records the tapper's numeric Telegram user id, so genuine taps can be paid for. Nothing else about that person is stored.
If I close my account, is everything gone?
No, and the policy is explicit about it. Financial records, security and activity records, support tickets, sent-email copies and — if you leave below baseline — a one-way anti-evasion hash all survive. Everything else is deleted or anonymised.
What ID documents do you need for payouts?
None through the platform. Verification collects your legal name and country. If a payment provider or the law ever requires more for a specific payout, you will be told what, who it goes to, and why, before you send it.
Next: the last of the three legal summaries — Refund Policy (summary), covering top-ups, Boost orders and cancelling a placement.