Skip to main content

Security

What we protect. Who can see it. What you control.

You are handing us client names, open requests, partner contacts, and the record of a season. This page is how that works. Privacy and Terms hold the legal detail. This is the operational one.

For the operator

The questions that actually matter.

This page does not block a signup. It is here so you can decide — before a winter is sitting in the system.

Your clients stay yours

Each workspace is isolated. Another operator cannot open your clients, your partners, or your requests. We do not sell that data. We do not use it to train public models.

Who can see what

You, and the people you invite. Partners see only what you send them — a brief, a date, a status — not the whole client record. Clients see the itinerary you publish, through a link you control. If a link leaks, you regenerate it and the old one dies.

Where it lives

The applications run on Vercel. Data sits in a managed PostgreSQL database, encrypted in transit and at rest. Card payments go through Stripe; we never store card numbers. FrostDesk talks to WhatsApp and Gmail through OAuth — we never ask for those passwords.

What we can see

Only what we need to keep the product running, and to help you when you ask. Access is limited, logged, and not a shared intern login.

If something goes wrong

We watch for failures. If client data is exposed, we tell you — and we tell the ICO when the law requires it. Write to hello@armoflow.com. That is the same address for a suspected issue.

How you leave

Cancel when you want. No lock-in. Ask and we export or delete what we hold, as set out in the Privacy Policy.

If you find a problem

Tell us. We will look.

If you discover a vulnerability, email hello@armoflow.com. Report it; do not go looking through data that is not yours. The legal pages are Privacy and Terms. This page is the one you read before you close.