Legal

Privacy Policy

Effective date: August 1, 2026 · Last updated: August 2, 2026

Flowerlly™ does not sell your personal data. We do not share your account or order data with advertisers or data brokers except as described in this policy.

1. Who We Are

Flowerlly is operated by FLOWERLLY LLC. This Privacy Policy describes how we collect, use, and protect information when you use our floral-recipe and marketplace platform for the US & Canada — whether you join as a Shopper, Hobbyist, or Florist.

Contact: [email protected] (privacy requests: same address, subject “Privacy Request”).

2. Information We Collect

2.1 Information you provide

  • Account data: Name, email, password (hashed), role (shopper / hobbyist / florist_creator / admin), shop profile fields
  • Commerce data: Listings, carts, orders, delivery ZIP / local fulfillment details, claims messages
  • Payment method: Processed by our licensed payment provider (e.g. Stripe). We store payment references and status — not full card numbers
  • Content: Recipe steps, photos, and other materials you upload

2.2 Information collected automatically

  • Usage data: Pages and features used, recipe sessions, timestamps
  • Device data: IP address, browser/app type, OS, approximate locale
  • Log data: Server logs for security and troubleshooting (typically retained ~90 days)

2.3 AI-assist interactions

When you use AI features (stem scan, panic diagnosis, coaching), we process the inputs you submit (e.g. images or text) and model outputs needed to return a result. Processing follows our AI routing policy; we do not use your Customer Data to train third-party foundation models.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To process purchases, subscriptions, payouts, and claims
  • To deliver digital recipes and coordinate local fulfillment signals between buyers and sellers
  • To send service-related notifications and optional product updates
  • To detect fraud, abuse, and security incidents
  • To comply with legal obligations

We do not use your data to train third-party AI/ML foundation models. Models powering assistive features are used for inference under our control/routing. We may use aggregate, anonymized statistics to improve matching and product quality. See Section 15 of our Terms of Service.

4. Information Sharing

We share information only in these circumstances:

  • Service providers: Hosting, email, analytics, and similar processors bound by contract to use data only as instructed
  • Payment processors: Stripe (or successors) process cards and Connect payouts under their own privacy notices and PCI obligations
  • Counterparties to a transaction: Sellers receive buyer details needed to fulfill an order; buyers see seller/shop information disclosed on the listing
  • Legal requirements: If required by law, court order, or to protect rights and safety
  • Business transfers: In a merger or asset sale, data may transfer with notice before it becomes subject to a different policy

We do not sell, rent, or share personal data with advertisers or data brokers for cross-context behavioral advertising.

5. Data Retention

  • Account and profile data while the account is active; purged after a short post-cancellation window unless law requires longer retention
  • Order and tax-relevant records may be retained up to 7 years
  • Backup snapshots are purged on a rolling schedule (typically within 90 days of deletion)

6. Security

We use industry-standard measures including TLS for data in transit, encryption for sensitive data at rest where applicable, hashed passwords, and access controls. No method of transmission or storage is 100% secure.

7. Your Rights

All users

  • Access: Request a copy of personal data we hold about you
  • Correction: Correct inaccurate data
  • Deletion: Request deletion (subject to legal retention)
  • Portability: Export machine-readable data where available
  • Marketing opt-out: Unsubscribe links in marketing email

California residents (CCPA / CPRA)

You may request to know, delete, correct, and opt out of sale/sharing. We do not sell or share personal information for cross-context behavioral advertising. To submit a formal request, email [email protected] with subject “Privacy Request — CCPA”. We respond within 45 days. We will not discriminate against you for exercising CCPA rights.

Canadian residents (PIPEDA)

We process personal information in accordance with PIPEDA. You may access and challenge accuracy of your information via [email protected].

8. Cookies and Tracking

  • Essential cookies: Authentication and session management (required)
  • Analytics cookies: Optional anonymized product analytics; you may opt out where controls are offered

We do not use third-party advertising networks or ad-tracking cookies on the marketing site beyond essential operations (e.g. Cloudflare insights where enabled by infrastructure).

9. International Data Transfers

Flowerlly is operated for the US & Canada. Infrastructure may be located in the United States. If you access the Service from Canada or elsewhere, your data may be processed in the US with appropriate safeguards. AI inference for product features is routed under our LLM routing policy; we do not send bulk Customer Data to arbitrary third-party model vendors for training.

10. Children’s Privacy

The Service is not directed at individuals under 18. We do not knowingly collect personal information from children. If you believe we have, contact [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you via email or in-app notice at least 14 days before material changes take effect. The “last updated” date above reflects the latest revision.

12. Contact and Data Requests

Email: [email protected]

Operator: FLOWERLLY LLC

Response time: We aim to respond to privacy requests within 45 days.

See also our Terms of Service.