FLO Privacy Policy
BackOfficial English document
The published English version is the controlling legal document. FLO localizes the surrounding guidance only; the approved legal text below is unchanged.
Version 1.0.0 · Effective August 19, 2026
1. Scope
This Privacy Policy explains how Facilities Logistics and Operations, LLC ("FLO," "Company") collects, uses, shares, retains, and protects information through the FLO facilities-operations platform, flosystems.app, theflo.app, related subdomains, and associated services. FLO is a B2B service. Customer organizations usually decide which users are invited, which records are entered, and how workplace data is used.
For workplace records that a customer enters and controls, the customer organization acts as the business or controller, and FLO acts as a service provider or processor that handles those records on the customer's behalf. For account, billing, security, audit, and product-improvement information that FLO decides how to use, FLO acts as the business or controller. If the parties sign a Data Processing Addendum, it governs the service-provider processing.
2. Information FLO collects
Account information: name, work email, phone if provided, role, profile photo, account settings, authentication and access records.
Organization and store information: company details, regions, stores, addresses, operating status, contacts, role assignments, and administrative settings.
Facilities and work records: work orders, preventive maintenance, schedules, notes, messages, approvals, attachments, photos, videos, receipts, estimates, invoices, and completion records.
Time and labor records: clock-in/out, breaks if used, shift duration, travel and work-order labor, adjustments, approvals, and related audit records.
Location information: Continuous route or background work-location data while a user is actively clocked in, and limited point-in-time location when a clocked-out user deliberately activates a work-related feature that requires location.
Financial and operational information: budgets, estimates, actual costs, receipt amounts, vendor charges, invoice references, and allocations.
Vendor, inventory, and asset information: contacts, assignments, asset tags, serial numbers, quantities, conditions, locations, and related notes.
Device, usage, audit, and security information: IP address, browser/device details, login and access events, role and data changes, error logs, audit logs, and security events.
Support and feedback: support requests, bug reports, product suggestions, and communications with Company.
FLO is not designed to collect biometric identifiers, consumer advertising profiles, payment-card data, full bank credentials, medical records, Social Security numbers, or highly sensitive HR files. Customers should not upload unnecessary sensitive information.
3. Location tracking
Continuous route and background work-location collection occurs only while a user is actively clocked in and the applicable location feature is enabled. When a user is clocked out, FLO may collect a limited, point-in-time location only after the user deliberately activates a work-related feature that requires location and receives an on-screen prompt. A point-in-time location request while clocked out does not activate continuous or background route tracking. Certain route or work-verification features may require the user to clock in before they can be used.
Location may be used for route proof, work verification, time and travel records, operational accountability, troubleshooting, security, audit, and dispute resolution. Customer organizations are responsible for all employee notices, consents, policies, wage/hour compliance, personal-device reimbursement, labor and union obligations, and lawful workplace use. FLO does not use location information for advertising and does not track users outside of work-related use.
4. How FLO uses information
Provide, operate, maintain, configure, secure, and improve FLO.
Manage organizations, users, roles, stores, work orders, schedules, vendors, inventory, assets, time records, and related workflows.
Support location maps, route proof, work verification, address lookup, and travel records.
Provide onboarding, support, troubleshooting, billing administration, and customer communications.
Maintain audit, security, abuse-prevention, billing, and dispute records.
Analyze usage, identify bugs, prioritize improvements, and plan functionality.
Comply with law, enforce agreements, protect rights and safety, and respond to lawful requests.
5. Service providers and disclosures
FLO does not sell personal information and does not use personal information for cross-site behavioral advertising. FLO may disclose information to service providers that support authentication, databases, file storage, hosting, email, analytics, logging, error monitoring, mapping, geocoding, routing, security, billing, payment, e-signature, documentation, and support. FLO requires these providers to protect information consistent with this Policy, and may add or change providers as the platform develops.
FLO may disclose information when required by law, legal process, or government request, or when reasonably necessary to protect Company, customers, users, systems, rights, safety, or property. FLO may transfer information in connection with a merger, acquisition, financing, reorganization, or sale, subject to contractual and legal requirements.
6. Customer administration and access
Customer organizations manage their own Admins, users, roles, permissions, stores, and records. Customer Admins may add or remove users, manage access, block accounts, send reset links, force sign-outs, review records, and export data depending on permissions.
Company personnel may access underlying systems and customer records when reasonably necessary for support, security, billing, troubleshooting, legal obligations, operations, and product improvement. Administrative access may be logged.
7. Data isolation and security
FLO is designed as a multi-tenant service with role-based access controls and database access restrictions intended to separate customer organizations. Company uses commercially reasonable safeguards appropriate to the pilot stage. No internet service, software platform, transmission, storage system, or backup process can be guaranteed completely secure, continuously available, or error-free. If FLO confirms a security incident that affects Customer Data, FLO will notify the affected customer organization without undue delay, and in no event later than seventy-two (72) hours, or within any shorter period required by law, so the customer organization has time to meet its own legal notification deadlines, and will cooperate as the law requires. The customer organization is responsible for notifying its employees or other individuals when the law requires.
8. Retention, export, and deletion
FLO retains information while the customer account is active and as needed to provide the service, maintain records, support billing, preserve audit/security evidence, comply with law, resolve disputes, enforce agreements, and protect the platform.
During the pilot, automated deletion and export schedules may be incomplete. Location and time records may be retained as workplace, route-proof, operational, audit, or dispute records. After termination, a customer may request a reasonably available export during the period stated in the contract. Information may later be deleted or retained for backups, legal holds, security, billing, audit, compliance, or dispute purposes.
9. Cookies and local storage
FLO may use functional cookies and local storage to keep users signed in, protect accounts, remember preferences, and support pilot-code or security workflows. These technologies are not currently used for advertising or cross-site tracking.
10. User choices and privacy requests
Privacy requests may be sent to privacy@flosystems.app. Employees, contractors, technicians, managers, vendors, and other users may need to direct requests to their customer organization because the organization controls the workspace and many workplace records. Requests may be limited by law, contract, security, billing, recordkeeping, technical constraints, or the rights of others.
Depending on applicable law, individuals may have rights to know, access, correct, delete, or limit certain processing, including the right to limit the use of sensitive personal information such as precise location. FLO and the customer organization will cooperate to respond according to their respective legal roles. FLO does not deny service, charge different prices, or provide a different level of service because a person exercises a privacy right.
11. International use
The pilot is intended for United States organizations. If customers or users access FLO from another jurisdiction, additional transfer, notice, contract, or privacy requirements may apply. FLO does not offer the service outside the United States during the pilot, and a customer that reaches FLO from another country is responsible for its own local requirements.
12. Children
FLO is a business service and is not directed to children. FLO does not knowingly collect personal information from children under 13. If FLO learns that it has collected personal information from a child under 13, FLO will delete it. Because some workplace users may be minors of legal working age, the customer organization is responsible for confirming that each user it invites meets the minimum age to work and to use the service. Customers should not provide accounts to individuals who are not legally permitted to use the service for workplace purposes.
13. Changes
FLO may update this Privacy Policy as the service changes. Material updates will be communicated through email, in-app notice, the website, or another reasonable method. The effective date and version will be updated.
14. Contact
Privacy: privacy@flosystems.app
Legal: legal@flosystems.app
Support: support@flosystems.app