Privacy Policy

App: ZumFlo
Publisher: Sub37 Labs
Contact: support [at] zumflo.app
Last updated: March 12, 2026

Your privacy is essential. ZumFlo is built on the principle of Privacy by Design: your financial records belong to you. Sub37 Labs does not collect, sell, share, or view your data. This policy describes exactly what data the App processes, where it is stored, and what control you have.

1. Data We Collect and How It Is Stored

ZumFlo functions primarily as a local application on your iOS device. Sub37 Labs does not operate servers that store your data.

CategoryExamplesStorage
Identity & ContactName, email, phone number, profile photoOn device
Business DetailsCompany name, address, KvK number, VAT number, IBANOn device
Financial RecordsDaily logs, revenue, expenses, settlements, hours, kilometresOn device
Services & ProductsCategories, prices, financial rules, cost agreementsOn device
Authentication TokensOAuth access and refresh tokens for SumUp and MoneybirdiOS Keychain
App SettingsPreferences, notification settings, lock timeoutOn device
Biometric ReferenceFace ID / Touch ID (used for App Lock)iOS Secure Enclave

No external server. Sub37 Labs does not operate a central database. We have no technical means to access, read, or analyse your data.

2. iCloud Sync

If you enable iCloud synchronisation, your data is stored in your personal iCloud account via Apple’s CloudKit framework.

3. Third-Party Integrations

ZumFlo offers optional integrations with external services. Data is only shared when you explicitly activate a connection.

3.1 SumUp (Payment Processing)

3.2 Zettle by PayPal (Payment Processing)

3.3 Moneybird (Bookkeeping)

Sub37 Labs requires that any third party with which the App exchanges data provides protection equal to or greater than this policy.

4. Device Permissions

PermissionPurposeRequired?
NotificationsDaily reminders to complete your daily logOptional
CameraCapture a profile photo (stored locally only)Optional
Photo LibrarySelect a profile photo from your libraryOptional
Face ID / Touch IDApp Lock via biometric authenticationOptional

ZumFlo does not access your location, microphone, contacts, calendar, health data, or any sensor not listed above.

5. Subscriptions and Payments

All payments are processed via your Apple ID account through Apple’s in-app purchase system. Sub37 Labs does not collect, store, or have access to your payment details, credit card information, or billing address. Apple’s handling is governed by Apple’s Privacy Policy.

6. Analytics and Telemetry

ZumFlo collects minimal, privacy-first usage analytics to improve the App. These analytics record only that an action occurred (e.g. “a daily log was created”), never the content of that action (no amounts, names, or financial data).

Examples of events that may be recorded: app launched, onboarding completed, daily log created, subscription started. Examples of data that is never recorded: revenue amounts, cost details, personal names, location data.

These analytics are processed by TelemetryDeck GmbH (Germany), a privacy-first analytics provider. TelemetryDeck does not receive any personally identifiable information and cannot identify individual users. See TelemetryDeck’s Privacy Policy.

7. Future: Sector Benchmarking (Opt-In)

In a future version, ZumFlo may offer an optional benchmarking feature. If introduced:

8. Data We Do Not Collect

ZumFlo does not:

9. Data Retention and Deletion

9.1 Retention

Your data remains on your device (and in your iCloud account, if enabled) for as long as you choose to keep it. There is no automatic expiration.

9.2 Deletion

You are in full control. You can delete data at any time:

Because Sub37 Labs does not store data on external servers, deletion is immediate and permanent.

10. Revoking Consent

11. Children’s Privacy

ZumFlo is a business administration tool for self-employed professionals and is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has used the App, please contact .

12. Security

13. International Transfers

If you enable iCloud sync, Apple may store data in data centres outside your country of residence, subject to Apple’s data processing agreements. If you connect SumUp or Moneybird, data may be processed in those services’ jurisdictions. Anonymous usage analytics are processed by TelemetryDeck GmbH in Germany. Sub37 Labs itself does not transfer your data internationally.

14. Your Rights Under GDPR

Within the European Economic Area, you have the following rights under the General Data Protection Regulation:

Because all data resides on your device, you exercise these rights directly — no request to Sub37 Labs is necessary. Need help? Email .

15. Governing Law

This Privacy Policy is governed by the laws of the Netherlands. Any disputes shall be submitted to the competent court in the Netherlands.

16. Changes to This Policy

17. Contact

Sub37 Labs
The Netherlands

For privacy-related questions, data requests, or to exercise your rights under GDPR:

We aim to respond to all requests within 30 days, as required by GDPR.