SMARTER WORKFLOW FOR
NEXT-LEVEL DESIGNERS
Last updated August 2026
FloHaus is software that window treatment design and installation businesses (each, a "Business") use to manage their own clients, projects, and communications. Understanding who is responsible for what starts with one distinction:
Each Business decides what client information to collect, why, and how it's used — FloHaus is the software they use to do it. In privacy-law terms, the Business is the controller (or, under California law, the business) for its own clients' information, and FloHaus is the processor (or service provider) acting on that Business's instructions. FloHaus does not decide what a Business collects about its clients, and does not use that information for its own purposes — see Section 5.
If you are a client of a Business that uses FloHaus — for example, someone getting window treatments designed and installed — and you have a question about your own information, the fastest path is to contact that Business directly; they hold the answers about what was collected and why. This policy explains what FloHaus itself does with data as the software provider, including the protections in place around a Business's client information.
When a Business signs up and its staff use FloHaus, we collect account information: business name, staff names, emails, phone numbers, roles, and optional profile details (photo, bio, tool links). Billing details are handled by our payment processor, Stripe — FloHaus does not store full card numbers.
A Business enters information about its own clients into FloHaus to run its projects: name, phone, email, address, appointment and project details, room and product photos, design preferences, and notes staff record about the relationship. This information belongs to the Business, not to FloHaus — see Section 4 for how strictly that's enforced.
Room photos a Business uploads are used to generate design renderings, mood imagery, and written design descriptions through our AI provider (currently Google's Gemini models) — see Section 3. These images and photos are stored on the Business's behalf and remain part of that Business's data.
When a Business sends a text or email through FloHaus to one of its own clients — appointment reminders, order updates, and similar — the message content and delivery status are stored so the Business can see its own communication history. See our SMS Messaging Policy for how consent to text a client is collected.
Like most web applications, we automatically log standard technical information (IP address, browser, pages visited, timestamps) to operate the service securely and diagnose problems.
FloHaus relies on a small number of specialized providers to operate. Each receives only the data it needs to perform its specific function, under its own data-processing terms:
We do not sell personal information to these providers or anyone else, and we do not permit them to use Business or client data for their own advertising purposes.
FloHaus is used by many independent Businesses. Every client, project, and team record is tied to the specific Business that created it, and the application enforces that a Business's staff can only ever see their own Business's data — never another Business's clients, projects, or team. There is no shared or cross-Business view anywhere in the product.
As the software provider, FloHaus needs limited visibility to run the business — but that access is deliberately narrow and split into two tiers:
Account-level information— a Business's name, signup date, subscription status, admin contact, and team and client counts — is visible to authorized FloHaus staff on an ongoing basis, the way any software provider needs to see who its customers are and whether their accounts are in good standing. This never includes the Business's actual client names, contact details, or project content.
A Business's actual client and project data is not visible to FloHaus staff by default. Viewing it — for example, to investigate a support request — requires deliberately entering a logged support session: the staff member must record in writing why they're accessing that specific Business's data before anything is shown. That record is permanent, cannot be deleted, and is visible to the affected Business itself, in its own account settings, so a Business can always see exactly when and why FloHaus staff looked at its data.
This is sometimes called a "break-glass" access model — the same pattern used by hospitals and other software providers entrusted with sensitive third-party data, where standing access is deliberately avoided in favor of logged, justified, one-time entry.
We use the information described above to: operate and maintain the FloHaus application; generate the AI design renderings and descriptions a Business requests; deliver the SMS and email messages a Business sends to its own clients; process billing; provide customer support (including the logged access described in Section 5); secure accounts and detect abuse; and understand aggregate, de-identified usage patterns to improve the product. We do not use a Business's client data to advertise to that Business's clients, and we do not sell personal information.
Information is retained for as long as a Business's account is active. A Business can permanently delete an individual client or project at any time from within FloHaus; deletion is immediate and permanent, not a soft-delete or trash folder. If a Business cancels its account, its data is retained for a limited period to allow for reactivation or export, after which it is deleted, except where we're required to keep certain records longer (for example, billing records) for legal or accounting reasons.
If you are a Business's staff member with a FloHaus account, you can access and correct most of your own information directly in Settings, or by contacting us.
If you are a Business's client, the Business you worked with is responsible for your information and is the right first contact for access, correction, or deletion requests, since they control what was collected. Depending on where you live, you may also have rights you can exercise directly against FloHaus as the processor of that data — for example, under the EU/UK GDPR (rights to access, correct, delete, restrict, or port your data) or the California Consumer Privacy Act (rights to know, delete, correct, and opt out of the sale or sharing of personal information — which we don't do). You can reach us at privacy@flohaus.ai and we'll route your request appropriately, including to the relevant Business where required.
We use encryption in transit, per-Business data isolation (Section 4), and the logged access-control model described in Section 5 to limit who can see what. No system is perfectly secure, but these controls are designed so that access to sensitive client information is the exception, not the default — and always accountable.
FloHaus is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16.
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify Business admins directly.
Questions about this policy can be sent to privacy@flohaus.ai. See also our Terms of Service & SMS Messaging Policy.