Legal

Privacy Policy

How TumiFlow collects, uses, shares, protects, and retains personal and business information, including data received from Google when you connect Gmail.

Effective date: September 30, 2026Last updated: October 1, 2026

1. Who we are and what this policy covers

This Privacy Policy explains how TumiFlow handles information when people visit https://tumiflow.com, create or use an account, join a workspace, contact us, or use TumiFlow features and integrations. TumiFlow is a cloud-hosted business platform for customer relationship management (CRM), contacts, sales opportunities, a shared Inbox for customer email, appointments, tasks, funnels and lead forms, workflow automation, AI-assisted features, and subscription billing.

Service
TumiFlow
Operator
Kazumi Nagata / 永田 一美
Location
Osaka, Japan
Website
https://tumiflow.com
Privacy contact
tumiflow.support@gmail.com

For business data that customers put into their workspace (for example their contacts and customer conversations), the customer decides why and how it is used, and TumiFlow processes it to provide the service. For account administration, security, subscription billing and running TumiFlow itself, TumiFlow decides the purposes of processing.

2. Information you provide to us

Account information
Your name, email address, password (stored only in hashed form by our authentication system) or Google sign-in identity, interface language, and account and security settings.
Workspace and business information
Business name, workspace settings, team members you invite, their roles and permissions.
Contacts and CRM data
Contacts, companies, leads, sales opportunities, notes, tags, stages and other records you create or import.
Messages and conversations
Customer conversations, email messages, drafts, internal notes, sender and recipient details and timestamps stored in the TumiFlow Inbox.
Appointments, tasks, funnels and automation data
Appointments, tasks, funnel and lead-form content, form submissions received from your visitors, workflow definitions and workflow run history.
Support and feedback
Information you include when you contact us, submit a support request or send product feedback.
Payment and billing information
Plan, billing interval, payment status, Stripe customer and subscription references, GCash or GoTyme payment references, optional payment-proof images you upload, and billing history. Card numbers are entered with and handled by Stripe; TumiFlow does not store full card numbers.

3. Information collected automatically

When you use TumiFlow we process technical information needed to run and protect the service: authentication and session events, IP address and browser or device information where available, application error reports, and security and audit logs of important actions in a workspace.

4. Google user data and Gmail

Connecting Gmail is optional. It happens only when an authorized workspace user chooses to connect a Gmail mailbox and approves Google's consent screen. Signing in to TumiFlow with Google is separate and gives TumiFlow only your basic Google profile identity (name and email address) for login; it does not give access to Gmail.

When you connect Gmail, TumiFlow requests these Google OAuth scopes, and only these:

userinfo.email
To read the email address of the connected Google account, so TumiFlow can confirm which mailbox was connected, show it to your team and prevent the same mailbox being connected twice.
gmail.readonly
To read Gmail message content and metadata (sender, recipients, subject, date, message and thread identifiers, labels) and Gmail history, so incoming mail can be synchronized into the TumiFlow Inbox, grouped into the correct conversation thread and kept up to date. This scope cannot change or delete anything in your mailbox.
gmail.send
To send emails and replies that a workspace user writes and chooses to send from TumiFlow, from the connected mailbox, in the correct thread.

Using these scopes, TumiFlow may access: the connected Google account email address; Gmail message content and metadata required for Inbox synchronization; Gmail thread and conversation information required to keep replies threaded correctly; and the information necessary to send emails and replies on the user's behalf. To learn about new mail promptly, TumiFlow asks Gmail to send a notification when the mailbox changes; that notification contains only the mailbox address and a change marker, and TumiFlow then fetches the relevant messages through the authorized connection.

TumiFlow does not request or access Google Drive, Google Contacts, Google Calendar or any other Google service through this connection.

5. How Gmail data is used

Gmail data is used only to provide visible, user-facing TumiFlow features that the user requested:

  • synchronizing the connected mailbox with the TumiFlow Inbox;
  • displaying messages to authorized users of the workspace that connected the mailbox;
  • keeping conversation and thread context so replies stay in the right thread;
  • sending replies and emails that a user writes and chooses to send through Gmail;
  • monitoring connection and synchronization health so users can see if the mailbox needs attention;
  • otherwise providing the connected Gmail functionality the user asked for.

Gmail data is not used for advertising, is not used to build advertising or marketing profiles, and is not shown to other workspaces.

6. Google API Services and Limited Use

TumiFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy.

In particular, Google Workspace data received by TumiFlow (including Gmail data):

  • is used only to provide and improve the user-facing features described above;
  • is not sold;
  • is not used or transferred for advertising, including retargeting, personalized or interest-based advertising;
  • is not transferred to data brokers or information resellers;
  • is not used to determine creditworthiness or for lending purposes;
  • is not used to train general-purpose or foundation AI models, whether TumiFlow's or anyone else's.

Google Workspace data is transferred to others only as necessary to provide the features above (for example to our hosting provider, or to an AI provider the workspace connected, when a user asks for an AI action as described in section 7), to comply with applicable law, or as part of a merger or acquisition with equivalent protections. Humans do not read this data except as described in section 10.

7. AI features (Bring Your Own Provider)

AI features in TumiFlow use a Bring Your Own Provider model. A workspace owner may connect the workspace's own OpenAI, Google Gemini or Anthropic account with an API key. TumiFlow does not provide its own AI model and does not include AI usage in the TumiFlow subscription; the provider bills the customer directly under the customer's own agreement with that provider.

Content is sent to the connected AI provider only when an authorized user starts an AI action, and only the content needed for that action. For example, if a user clicks to draft an AI reply in an Inbox conversation, the messages of that conversation (which may include email received through Gmail) are sent to the workspace's provider to create a draft. The draft appears in the reply box for the user to review; nothing is sent automatically. Gmail data is not sent to AI providers automatically, in the background, or in bulk.

If no AI provider is connected, no content is sent to any AI provider. The connected provider processes submitted content under its own terms and privacy policy. TumiFlow keeps only operational information about AI requests, such as provider, model, feature, time and success or failure.

8. How we use information

  • Provide, operate, maintain and troubleshoot TumiFlow and the integrations you connect.
  • Authenticate users and administer accounts, workspaces, memberships, roles and language preferences.
  • Run CRM, sales, Inbox, appointments, tasks, funnels, forms, collaboration and workflow automation features.
  • Perform AI actions a user specifically requests, using the workspace's own AI provider.
  • Create and manage subscriptions, verify payments and keep billing records.
  • Protect accounts and the service and investigate fraud, abuse, unauthorized access and security incidents.
  • Respond to support, privacy and legal requests and send important service notices.
  • Meet legal obligations and enforce our agreements.

We do not use customer business data or Google user data for advertising, and we do not sell personal information.

9. Storage and security

  • Data is stored on servers of our cloud hosting provider, not on users' devices, apart from the sign-in session kept in your browser.
  • Google OAuth access and refresh tokens and AI provider API keys are stored only on the server, encrypted, and are never sent to the browser or shown to workspace users after they are saved.
  • Gmail access tokens are refreshed on the server when they expire; if Google reports that access was revoked or expired, the mailbox is marked as needing attention instead of retrying indefinitely.
  • Every workspace is isolated: database access rules ensure users can only read records of workspaces they belong to, and role-based permissions control what each member can do.
  • Connections to TumiFlow use encrypted HTTPS.
  • Important administrative and platform actions are recorded in audit logs.

We use reasonable technical and organizational measures to protect information, but no system is completely secure and we cannot guarantee that unauthorized access will never occur. TumiFlow does not hold SOC 2, ISO 27001 or similar certifications.

10. Human access to your data

TumiFlow staff, including platform administrators, do not have automatic access to customers' mailboxes, Gmail messages or workspace content, and do not read them as part of normal operations. Authorized personnel may view specific user data only:

  • with the explicit permission of the customer, for example to resolve a support request the customer raised;
  • when necessary for security purposes, such as investigating abuse, fraud or a security incident;
  • when required to comply with applicable law or a valid legal request;
  • when the data has been aggregated and anonymized for internal operations, such as counting how many mailboxes are connected.

11. Sharing and service providers

TumiFlow does not sell personal information or Google Workspace data. We share information only with service providers that process it on our behalf to operate TumiFlow, under appropriate confidentiality and security obligations. These categories include cloud hosting and database, authentication, application hosting and delivery, payment processing (Stripe), and services the customer chooses to connect (for example Google for Gmail, or the customer's own AI provider). The current list is on our Subprocessors page at https://tumiflow.com/legal/subprocessors.

We may also disclose information when required by law, to protect users, TumiFlow or others from fraud, abuse or security threats, as part of a business reorganization with equivalent protections, or when the customer directs us to.

12. Retention and deletion

Account and workspace data
Kept while the account or workspace is active and needed to provide the service. Customers can delete individual records (such as contacts and conversations) in the app at any time.
Disconnecting Gmail
When a user disconnects Gmail in TumiFlow, TumiFlow stops mailbox notifications, revokes its access at Google, and deletes the stored Gmail access and refresh tokens and synchronization data for that connection. No new mail is read or sent after that. Messages already imported into the Inbox remain part of the workspace until a user deletes them or the workspace is deleted.
Revoking at Google
You can also remove TumiFlow's access at any time at https://myaccount.google.com/permissions. TumiFlow then marks the mailbox as needing attention and can no longer access it.
Deleting an account or workspace
Send a deletion request to tumiflow.support@gmail.com from the account email. Verified deletion requests are processed within a reasonable period, subject to legal, security, billing, fraud-prevention, backup, and audit retention requirements. Deletion covers the workspace's data, including imported Gmail messages and any stored tokens.
Limited longer retention
Billing and tax records, security logs and audit records may be kept longer where reasonably necessary or required by law. Deleted data may remain in encrypted backups for a limited time until those backups expire.

13. Your rights and choices

  • Access and correction: you can view and edit most of your information in the app, or ask us for a copy or a correction.
  • Deletion: you can delete records in the app or ask us to delete your account or workspace.
  • Withdrawing access: you can disconnect Gmail or an AI provider in TumiFlow settings at any time, and revoke TumiFlow's Google access in your Google Account.
  • Questions or requests: contact tumiflow.support@gmail.com. We may need to verify your identity and authority before acting.

If your data is held in a workspace controlled by another business (for example a company you are a customer of), we may need to refer your request to that business.

14. International processing

TumiFlow is operated from Japan, and our hosting and other service providers may process and store information in other countries, including the United States and countries where those providers operate. Those countries may have data-protection laws different from yours. Where required, we rely on appropriate contractual protections. AI providers a workspace connects process data in the locations they choose under their own terms.

15. Cookies and analytics

TumiFlow uses only essential browser storage: a sign-in session so you stay logged in, security protections, and preferences such as language and light or dark theme. TumiFlow does not use advertising cookies or third-party advertising trackers. Our hosting provider may collect basic, aggregated traffic statistics needed to run the website. See the Cookie Policy for details.

16. Children

TumiFlow is a business service and is not directed to children. Users must be at least 18 years old. We do not knowingly collect personal information from children; if you believe a child has provided personal information, contact tumiflow.support@gmail.com and we will delete it.

17. Changes to this policy

We may update this Policy when the service, our providers or legal requirements change. The "Last updated" date at the top of this page shows when it was last changed. If we make material changes, especially to how Google user data is used, we will notify users through the service or by email before the changes take effect.

18. Contact

For privacy questions or requests, contact Kazumi Nagata / 永田 一美, TumiFlow, Osaka, Japan, at tumiflow.support@gmail.com.

Questions about this document?

Email TumiFlow: tumiflow.support@gmail.com