FlowPay
On this page

FlowPay privacy policy

Last updated 2026-09-10

FlowPay is a SentiDawn product. The SentiDawn Privacy Policy and Terms of Service apply to it, and the terms below are additional terms specific to FlowPay. Read the SentiDawn Privacy Policy.

Who we are

FlowPay is a SentiDawn product for managing work assignments, timesheets, approvals, earnings calculations and payment records. This notice explains the information handled specifically in FlowPay. Read it with the SentiDawn Privacy Policy.

[Operator legal name][Operator address]

Information we collect

  • Sign-in and access information: Google account identity, name, email address and profile-picture URL; FlowPay identifiers, account status, Client membership, roles, module permissions and language preferences. The sign-in configuration requests openid email profile; it adds no Gmail or Google Drive access scopes. FlowPay stores your email address in its application database. Your Google name and profile-picture URL are retained in the sign-in session cookie and used in the account menu, not written to the application database as a Google profile. The picture is loaded from the Google-provided URL rather than copied into FlowPay file storage. Client-maintained profiles are separate records. Google sign-in does not give FlowPay your Google password.
  • Profile information entered by you or an authorized administrator: names, display names and telephone numbers. A Client can maintain its own profile of an Operator; that profile is distinct from another Client's profile of the same person.
  • Work records: assignments, dates, shift schedules, holidays, compensation rules, timesheet entries, time adjustments, leave, claims, quantities, notes and approval decisions, including the recorded actor and decision time where the workflow captures them.
  • Money records: calculated earnings, settlement runs, payment dates, amounts, descriptions and attached evidence. FlowPay records payments made outside the service.
  • Uploaded files: evidence provided for leave, claims or payment records, together with file type, size and record associations. Files may contain information about other people or financial or health details; provide only what the relevant process needs.
  • Service-operation information: errors, service events, request paths, the history of MCP permission changes, and the current state of other permissions. For MCP, FlowPay also stores account-linked credential records used to authenticate and verify requests, including their active or retired status. Diagnostic error details or paths can contain identifiers; these logs are not represented as anonymous.

Information may come from you, Google sign-in, the Client or personnel managing your work, and calculations performed from those records. Required fields and evidence depend on the action and configured scheme. Missing required information can prevent that action; an attachment is not optional in every claim workflow.

How we use information

FlowPay uses these records to identify the signed-in person, determine access, organize assigned work, generate and update timesheets, process requests and decisions, calculate earnings and settlements, and show payment records to the permitted viewers. Service events support operation and fault diagnosis. Names and contact details help authorized personnel identify the people involved in the work.

[Processing purposes and legal bases to be confirmed]

Who can see what

Client personnel see information within the Client and module access granted to them. Operators see the work and earnings information available to their own account. Not every internal Client record is shared: for example, non-wage payment entries are excluded from the Operator earnings view. Profiles maintained by different Clients are separate. Administrative access depends on the relevant role and function; signing in alone does not grant all access.

An authorized MCP connection can return FlowPay information to the connected client or AI assistant and can perform supported actions within its permissions. MCP permissions are managed separately for each person and server. Before connecting an assistant, consider who operates it and how it handles data returned to it.

Retention

Ending an assignment, removing a permission or signing out does not itself erase the work or payment history. Disabling a personnel record is also different from deleting it.

[Retention and deletion schedule][Backup retention]

Other services and disclosure

Google handles the Google sign-in step. FlowPay uses database, file-storage and service-monitoring infrastructure to operate the product, and an identity broker to manage MCP identity and credentials. If you connect an MCP client, information returned by authorized tools is also handled by that client and any AI service it uses. Their handling is separate from storage inside FlowPay.

[Infrastructure providers and locations][International-transfer details]

Security

FlowPay checks access by role and scope. Uploaded evidence is encrypted before it is stored in the configured file store; designated profile-name and telephone fields are also encrypted in storage. Authorized application functions can decrypt information they are permitted to display. Keep your sign-in account and connected clients secure. FlowPay retains service-managed MCP signing credentials to authenticate requests; rotating a credential retires the previous record rather than immediately deleting it.

Requests about your data

For questions about your personal data or to make a request, contact [email protected] and identify FlowPay and the records concerned. For a work-record correction, you can also contact the Client that manages the record. You do not need to send your password or MCP credentials. See the rights and request process in the SentiDawn Privacy Policy.

Cookies and browser storage

The sign-in system uses cookies for the session and sign-in security, including protecting the authorization flow and remembering its return destination. FlowPay also stores display preferences such as theme and sidebar state in your browser. Temporary browser state helps recover from an application-version mismatch. Your account language preference is stored on the server. Clearing browser storage can reset preferences or require you to sign in again; it does not delete your work records.

Contact

SentiDawn — [email protected]. Please identify FlowPay in your message.

[Operator legal name][Operator address]

Changes

The last-updated date identifies when this text was edited. This page remains a draft until the final policy and its effective date are published.

[Effective date]