Legal

Privacy Policy

Last updated: July 7, 2026

This policy explains what data Getflyt collects, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act. For a deeper dive into our controls, see the Security & GDPR page.

What we collect

  • Account: email, name, workspace name and profile settings.
  • Google Drive: access tokens you grant so we can generate signed download links on your behalf. We do not copy file contents to our servers.
  • Delivery events: access logs (timestamp, IP, city, country, device) for each transfer, retained up to 12 months.
  • Payments: Stripe handles all card data. We only store metadata (customer id, subscription status, connected account id).

What we don't do

We don't sell your data. We don't scan the contents of your files. We don't train AI models on your data. We don't share your clients' emails with third parties beyond what's required to deliver the transfer (Stripe for payment, Resend for email).

Subprocessors

Cloudflare (hosting), Supabase (database, EU region), Clerk (authentication), Google (Drive integration), Stripe (payments), Resend (transactional email). We sign a Data Processing Agreement with each subprocessor.

Cookies

We use strictly necessary cookies for authentication. No third-party marketing or ad cookies.

Your rights (GDPR)

You can request access, correction, export, restriction or deletion of your personal data at any time. Email privacy@getflyt.co — we respond within 30 days.

Data controller

Interfront Ltd., 120 High Road, London N2 9ED, United Kingdom.
Contact: privacy@getflyt.co

← Back to home