Legal

Privacy Policy

How TumiFlow collects, uses, shares, protects, and retains personal and business information.

Effective date: September 30, 2026Last updated: September 30, 2026

1. Scope and who we are

This Privacy Policy explains how TumiFlow processes information when people visit tumiflow.com, create or use an account, join a workspace, contact us, or use TumiFlow features and integrations. TumiFlow is a multilingual cloud-hosted software service for customer relationship management, contacts, sales opportunities, inbox and customer communication, appointments, tasks, funnels and lead forms, workflow automation, AI-assisted business features, billing, subscriptions, and connected third-party providers.

TumiFlow is operated by Kazumi Nagata / 永田 一美 in Osaka, Japan. Privacy questions and eligible requests may be sent to tumiflow.support@gmail.com.

For customer business data, the customer generally decides why and how that data is used, and TumiFlow processes it to provide the service. For account administration, service security, subscription billing, and operation of TumiFlow, TumiFlow determines the relevant processing purposes.

2. Information we may process

Account data
Name, email, authentication information, workspace membership and roles, language preferences, and account or security settings.
Business and workspace data
Contacts, companies, leads, opportunities, tasks, appointments, funnels, form submissions, workflow definitions, internal notes, files, and workspace settings supplied or created by customers and their authorized users.
Communication data
Email messages, customer conversations, drafts, conversation metadata, sender and recipient information, message timestamps, attachments where used, and customer language information.
Billing data
Subscription plan, billing interval, payment status, Stripe references, GCash or GoTyme payment references, manual-payment review status, optional payment-proof images, and billing history. TumiFlow does not store raw card numbers; card details are handled by Stripe.
Technical and security data
IP or network information where available, browser and device information, authentication events, security logs, application errors, and audit events.
Support data
Information included in support, legal, privacy, or other communications with TumiFlow.

3. AI provider data and Bring Your Own Provider

TumiFlow uses a Bring Your Own Provider (BYOP) model for AI features. A workspace owner may connect the workspace's own OpenAI, Google Gemini, or Anthropic account and select a supported model. AI provider usage and charges are governed by the customer's agreement with that provider and are not included in the TumiFlow subscription.

Provider credentials are handled server-side and protected in storage. Full API keys are not returned to workspace users after storage. TumiFlow sends the content needed for an AI-assisted action to the provider selected by the workspace when an authorized user requests that action. TumiFlow may retain safe operational metadata such as provider, model, feature, timestamp, and success or failure status.

TumiFlow does not use customer business data to train its own general-purpose AI models. Connected AI providers may process submitted content under their own terms and privacy policies; customers should configure and use those providers appropriately for their data.

4. Google and Gmail integration

Customers may voluntarily connect a Google or Gmail account to use authorized Inbox and related communication features. TumiFlow uses Google access only to provide features the customer authorizes. Depending on the feature, TumiFlow may process email messages and attachments, sender and recipient details, timestamps, message identifiers, thread metadata, mailbox address, and other information required for Inbox functionality.

TumiFlow does not sell Google user data and does not use Google user data for advertising. Google credentials and connection tokens are handled server-side and cannot be retrieved by workspace users. Gmail notifications identify the connected mailbox; message content is fetched from Gmail through the authorized connection when needed for the Inbox.

Disconnecting Gmail stops new access through that connection. Records already created or synchronized in TumiFlow may remain under the account, retention, legal, and deletion rules described in this Policy. Users may also revoke TumiFlow's Google permissions through their Google Account. Google has not been represented here as having verified or endorsed TumiFlow.

5. How we use information

  • Provide, operate, maintain, and troubleshoot TumiFlow and requested integrations.
  • Authenticate users; administer accounts, workspaces, memberships, roles, and language preferences.
  • Support CRM, sales, appointments, tasks, funnels, forms, collaboration, customer communication, and workflow automation.
  • Perform AI-assisted actions specifically requested by an authorized user through the workspace's selected provider.
  • Create and manage subscriptions, verify payments, maintain billing history, and handle billing support.
  • Protect accounts and the service; investigate fraud, abuse, unauthorized access, and security incidents.
  • Respond to support, privacy, and legal requests and communicate operational notices.
  • Improve reliability, usability, accessibility, and performance using appropriate operational information.
  • Meet legal obligations and enforce applicable agreements.

6. Legal grounds and customer instructions

Depending on the applicable law and context, processing may be based on performance of a contract, steps requested before entering a contract, legitimate interests in operating and protecting the service, consent, or compliance with a legal obligation. When TumiFlow processes customer business data on the customer's behalf, the customer's configuration and use of the service provide the documented instructions, subject to the Terms of Service and any applicable Data Processing Addendum.

7. Sharing and service providers

TumiFlow does not sell personal information. TumiFlow may disclose information to service providers and subprocessors only as reasonably needed for hosting and infrastructure, authentication, security, payment processing, customer-authorized integrations, support, and service delivery. Current providers are described on the Subprocessors page.

Information may also be disclosed when required by law; to protect TumiFlow, customers, users, or others from fraud, abuse, or security threats; in connection with a business reorganization subject to appropriate safeguards; or when the customer or user directs or authorizes the disclosure. Connected third-party providers process information under their own terms.

8. International processing

TumiFlow and its service providers may process information in Japan and other countries where the relevant provider operates. Those countries may have different data-protection laws. Where required, TumiFlow will use an appropriate transfer mechanism or contractual protection. Customers are responsible for assessing transfers caused by providers they independently connect.

9. Retention and deletion

Active account and workspace information is retained while reasonably needed to provide the service. After cancellation or account closure, operational data may be retained for a limited period before deletion or anonymization, including to allow orderly closure, resolve disputes, maintain security, or comply with law. Billing, tax, security, fraud-prevention, audit, and legal records may be retained longer where reasonably necessary or legally required.

Deletion may not be immediate from every backup or disaster-recovery copy, and legally required billing records may not be deleted on request. Copies may remain until backup cycles complete, subject to access restrictions and ordinary retention controls. Eligible access, export, correction, or deletion requests may be sent to tumiflow.support@gmail.com.

10. Security

TumiFlow uses measures designed to protect information, including authenticated access, workspace isolation, role-based permissions, server-side handling of provider credentials, protected secret storage where implemented, payment handling by payment providers where applicable, and operational security controls. No system is completely secure, and TumiFlow does not guarantee that unauthorized access or loss can never occur.

TumiFlow does not claim SOC 2, ISO 27001, HIPAA, or other certification unless a current, specific certification is separately published by TumiFlow.

11. Your choices and rights

Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, or a portable copy of eligible personal information. Requests and privacy questions may be sent to tumiflow.support@gmail.com. TumiFlow may need to verify identity and authority before acting, and some information may be retained where permitted or required by law.

When TumiFlow processes data for a business customer, a request concerning that customer's data may need to be directed to or handled with that customer. Users can also manage authorized integrations through available service or provider controls.

12. Children

TumiFlow is a business service and is not directed to children. Users must be at least 18 years old, unless applicable law requires a higher age to enter a binding agreement. If you believe a child has provided personal information improperly, contact tumiflow.support@gmail.com.

13. Changes and contact

TumiFlow may update this Policy as the service, providers, or legal requirements change. The updated date will be revised, and material changes may be communicated through the service or another appropriate channel. Questions may be sent to tumiflow.support@gmail.com.

Questions about this document?

Email TumiFlow: tumiflow.support@gmail.com