Floum
Back to home

Legal

Privacy policy

Provisional version, 9 October 2026

1. Who we are

Floum is an email marketing service for Shopify stores developed by VPDC Solutions (Ponticelli S.R.L.S.), Italy, VAT no. IT09743221211 ("we"). For any privacy question write to info@floum.app.

2. This website

The floum.app website uses no cookies, analytics or advertising and loads no third-party resources (fonts are hosted on our own server too). Our hosting provider automatically logs technical visit data (IP address, date and time, requested page, browser) for security and operation; we keep it for no more than 30 days.

If you email us, we process the data you send (name, email address, message content) only to reply to you, based on our legitimate interest or on the pre-contractual steps you request, and keep it for as long as needed to handle your request.

3. The Floum service for stores

When a store uses Floum, the store is the controller of its customers' data and we act as processor (Art. 28 GDPR), under a data processing agreement signed with the store. We process only the data needed for the service, received from Shopify: name, email address, address (country and city, for segmentation and time zone), marketing consent status, orders and email interactions (delivery, open, click, unsubscribe).

We use this data only to send the emails decided by the store and measure their results. We do not sell it or share it with other stores or third parties for their own purposes. We respect recipients' consent: anyone who unsubscribes no longer receives marketing emails, and the status is synced with Shopify. When a store uninstalls Floum or requests deletion, we delete the related data within the timeframes required by Shopify and the GDPR.

4. Where data is stored and who helps us

Data is stored in the European Union. We rely on providers acting as our sub-processors, including Amazon Web Services (email sending and hosting, EU Stockholm region) and our application hosting provider in the EU. The up-to-date list of sub-processors is available on request.

5. Security

Communications are encrypted (HTTPS/TLS), store access credentials are encrypted in the database, staff access is limited and protected by two-factor authentication, and data access is logged.

6. Your rights

You can request access, rectification, erasure, restriction or portability of your data and object to processing. If you are a customer of a store using Floum, please contact the store first, as it is the controller of your data; we will help it handle your request. You also have the right to lodge a complaint with your data protection authority (in Italy, the Garante per la protezione dei dati personali).