Privacy Policy
App: ZumFlo
Publisher: Sub37 Labs
Contact: privacy [at] zumflo.app
Last updated: 30 September 2026
Your privacy is essential. ZumFlo is built on the principle of Privacy by Design: your financial records belong to you. Sub37 Labs does not collect, sell, share, or view your data. This policy describes exactly what data the App processes, where it is stored, and what control you have.
1. Data We Collect and How It Is Stored
ZumFlo functions primarily as a local application on your iOS device. Your records live on your device and in your own iCloud. Sub37 Labs does not operate a central database with your records. Only for a few features that you start yourself - the AI features and searching online for your price list - does ZumFlo use its own processing service (see 3.5 and 3.6).
| Category | Examples | Storage |
| Identity & Contact | Name, email, phone number, profile photo | On device |
| Business Details | Company name, address, KvK number, VAT number, IBAN | On device |
| Financial Records | Daily logs, revenue, expenses, settlements, hours, kilometres | On device |
| Services & Products | Categories, prices, financial rules, cost agreements | On device |
| Calendar appointments (optional, Pro) | Treatment, client name, staff member, start and end time from your linked calendar link | On device |
| Calendar link (optional, Pro) | The address (URL) of your read-only calendar feed | iOS Keychain |
| Documents | Your host’s specifications, receipts, purchase invoices and price cards that you add or scan | On device |
| Authentication Tokens | OAuth access and refresh tokens for SumUp, PayPal POS and Moneybird | iOS Keychain |
| PIN Provider Identity | Merchant code and account name from your SumUp or PayPal POS account | On device |
| Accounting integration | Moneybird administration ID, ledger account mapping and contact links per location | On device |
| App Settings | Preferences, notification settings, lock timeout | On device |
| Biometric Reference | Face ID / Touch ID (used for App Lock) | iOS Secure Enclave |
No central database. Sub37 Labs has no access to the records on your device or in your iCloud and cannot open, read or analyse them. Data only reaches our processing service when you start an AI feature or the price list search yourself, and then only what that feature needs (see 3.5 and 3.6).
2. iCloud Sync
Your data is automatically synchronised via your personal iCloud account using Apple’s CloudKit framework. This is enabled by default and ensures your data is available across all your devices.
- Data is encrypted by Apple in transit (TLS) and at rest.
- Sub37 Labs has no access to your iCloud container — only your Apple ID can access it.
- You can disable iCloud sync for ZumFlo via iOS Settings → Apple ID → iCloud → Apps Using iCloud → ZumFlo.
- Apple’s handling is governed by Apple’s Privacy Policy.
3. Third-Party Integrations
ZumFlo offers optional integrations with external services. Data is only shared when you explicitly activate a connection.
3.1 SumUp (PIN Payments)
- Requested permissions: When connecting, ZumFlo requests two permissions (scopes):
transactions.history — access to your transaction history
user.profile_readonly — read-only access to your merchant profile
- What ZumFlo reads: Transaction amounts, timestamps, payment methods, transaction fees and tips. Additionally your merchant code and account name to retrieve transaction details and to reference the source of PIN transactions in reports. ZumFlo does not read email addresses, address details or account settings — even though they technically fall within the requested scope.
- Storage: Your merchant code and account name are stored locally on your device and included in generated reports as a source reference.
- Direction: From SumUp to the App. ZumFlo does not transmit financial data to SumUp.
- Tokens: OAuth tokens stored in the iOS Keychain (hardware-encrypted).
- Disconnect: My Business → Settings → Integrations → Payment integration → Disconnect. Tokens are immediately deleted.
- Their policy: SumUp Privacy Policy
3.2 PayPal POS (PIN Payments)
- Requested permissions: When connecting, ZumFlo requests two permissions (scopes):
READ:PURCHASE — read-only access to your transaction data
READ:FINANCE — read-only access to your financial data (transaction fees, payouts)
- What ZumFlo reads: Transaction amounts, timestamps, payment methods and tips via the Purchase API. Via the Finance API, the actual transaction fees per payment are retrieved. Additionally your account name to reference the source of PIN transactions in reports. ZumFlo does not read product catalogues, inventory data or account settings.
- Storage: Your account name is stored locally on your device and included in generated reports as a source reference.
- Direction: From PayPal POS to the App. ZumFlo does not transmit financial data to PayPal POS.
- Tokens: OAuth tokens stored in the iOS Keychain (hardware-encrypted).
- Disconnect: My Business → Settings → Integrations → Payment integration → Disconnect. Tokens are immediately deleted.
- Their policy: PayPal POS Privacy Policy
3.3 Moneybird (Bookkeeping)
- Requested permissions: When connecting, ZumFlo requests the following permissions:
sales_invoices — create and manage sales invoices
documents — read documents
estimates — read estimates
bank — manage financial accounts and journal entries
settings — read administration settings (ledger accounts, VAT rates)
- What ZumFlo writes: Sales invoices, journal entries, accrual bookings and payment registrations based on your settlements. It may update the customer ID field on existing contacts to establish a link with your work locations, and finalises its own draft invoices for sending. ZumFlo does not delete any records, does not modify invoices or entries created by other sources, and does not change administration settings such as ledger accounts or VAT rates.
- Direction: Bidirectional — the App reads and writes in your Moneybird account.
- Tokens: OAuth tokens stored in the iOS Keychain.
- Disconnect: Via My Business → Settings → Integrations → Accounting, or via your Moneybird account settings.
- Their policy: Moneybird Privacy Statement
3.4 Calendar link (optional, Pro)
- How it works: You paste a read-only calendar link (iCal/ICS, for example from Salonized) into ZumFlo yourself. The App fetches that calendar directly over a secure connection (HTTPS) from your device. No Sub37 Labs server is involved.
- No access to your iPhone calendar: ZumFlo does not ask for access to your iPhone’s calendar. Only the link you add yourself is read.
- What ZumFlo reads and stores: For each appointment the treatment, the client name, the staff member and the start and end time. These are stored in your ZumFlo data (on your device and in your iCloud) to pre-fill your daily log, link payments to appointments and show your forecast. Notes from an appointment stay on your device only.
- The link itself: Stored in the iOS Keychain of this device and not synced via iCloud. On a new device you link your calendar again.
- Client names: Never go to Sub37 Labs, to TelemetryDeck or to an AI service. Your clients’ data is your business’s data; ZumFlo only processes it on your own device and in your own iCloud.
- Unlink: My Business → your location → Calendar → Unlink.
3.5 AI features: settlement check and document scanning
A few features use a language model (AI). They run only when you start them yourself, never automatically or in the background.
- Settlement check (Pro): You add your host’s specification (PDF, scan, CSV or Excel). Text recognition happens on your device. Before anything is sent, ZumFlo removes personal data on your device: client names are replaced by codes that only your device can translate back, and times are removed. If the App then still finds an email address, phone number, postcode, street name or citizen service number (BSN), the upload is blocked. What is sent: per day the amounts from your own daily logs (revenue, payment methods, vouchers, tips, BTW breakdown, hours and kilometres), the names of your service and cost categories, your cost agreements with that host, and the dates and amounts from your host’s specification. Notes are never sent. The comparison report with names is put together on your device.
- Scanning receipts, purchase invoices and price cards: The document or photo you choose (PDF, photo, Excel or CSV) is sent in full, so that supplier, date, amounts and BTW (or, for a price card, your services and prices) can be read. Such a document may contain your data or the supplier’s. Do not send documents containing your clients’ data. The result goes back to your device; the document itself is not stored after processing.
- Where it is processed: In a Sub37 Labs processing service on Microsoft Azure, West Europe region (the Netherlands). The text analysis is done by the Claude language model from Anthropic PBC (United States) as a sub-processor. Anthropic does not use this data to train models.
- Notification when the check is ready: The settlement check can take a few minutes. To notify you, the service stores your device’s push token (a technical address for notifications, without a name or email address).
- Retention: Verification jobs, their result and push tokens are kept for at most 90 days, so the App can fetch the result, and are then deleted automatically. Scanned documents are not stored.
- Usage limits: The AI features have usage limits per subscription. How much you have used is tracked by the App in your own data, not on our server.
- Legal basis: Performance of the contract (Art. 6(1)(b) GDPR): you ask for the check or the scan yourself.
3.6 Searching online for your price list (optional)
- During setup you can let ZumFlo look up your price list online. The App then sends your business name, town, country and sector to our processing service.
- It searches for your salon’s public web page via the Brave Search API (Brave Software, United States), reads the price list with the language model (see 3.5) and fetches that website’s logo via Google’s favicon service.
- The search result is reused for a day if you search again, and deleted automatically within 90 days.
- You can also enter your services manually or scan a photo of your price card (see 3.5); then nothing is searched online.
Sub37 Labs requires that any third party with which the App exchanges data provides protection equal to or greater than this policy.
4. Device Permissions
| Permission | Purpose | Required? |
| Notifications | Reminders to complete your daily log, and a notification when a settlement check is ready | Optional |
| Camera | Scan documents (specifications, receipts, invoices, price cards) and take a profile photo | Optional |
| Photos | Choosing a photo goes through the iOS photo picker: ZumFlo only receives the photo you pick, with no access to your library | No permission needed |
| Face ID / Touch ID | App Lock via biometric authentication | Optional |
ZumFlo does not access your location, microphone, contacts, your iPhone’s calendar, health data, or any sensor not listed above. The calendar link works through a link you add yourself (see 3.4). If you look up an address, your search term goes to Apple Maps; no location permission is needed for that.
5. Subscriptions and Payments
All payments are processed via your Apple ID account through Apple’s in-app purchase system. Sub37 Labs does not collect, store, or have access to your payment details, credit card information, or billing address. Apple’s handling is governed by Apple’s Privacy Policy.
6. Analytics and Telemetry
ZumFlo collects minimal, privacy-first usage analytics to improve the App. These analytics record only that an action occurred (e.g. “a daily log was created”), never the content of that action (no amounts, names, or financial data).
- Analytics events contain no personally identifiable information (PII)
- No financial data (amounts, revenue, costs) is ever included in analytics
- No advertising identifiers (IDFA) or cross-app tracking frameworks are used
- No third-party advertising or advertising SDKs are present
- No device fingerprinting is performed
- No data is shared with data brokers or marketing platforms
- ZumFlo does not use cookies, neither in the app nor on the website
Examples of events that may be recorded: app launched, onboarding completed, daily log created, subscription started. Examples of data that is never recorded: revenue amounts, cost details, personal names, location data.
These analytics are processed by TelemetryDeck GmbH (Germany), a privacy-first analytics provider. TelemetryDeck does not receive any personally identifiable information and cannot identify individual users. See TelemetryDeck’s Privacy Policy.
Specifically, ZumFlo only collects categorical usage data: which features are used (e.g. daily log created, report exported), subscription status (Standard or Pro) and technical diagnostics (iOS version, app version). When you take out a subscription, the type of subscription, the price, the country and the currency of that purchase are recorded. If you import a price list, the original names of your services may be sent so we can improve service recognition. No revenue amounts, names of people, financial data or personally identifiable information is ever sent.
These statistics are on by default. ZumFlo provides an in-app setting that lets you disable them: Settings → Privacy → Share anonymous usage statistics. When disabled, no events are sent.
For our website (zumflo.app) we use Plausible Analytics, a privacy-friendly analytics service. Plausible does not use cookies, does not collect personal data and does not store IP addresses. Data is hosted in the European Union (Germany). No consent is required as no personal information is processed. More information: plausible.io/data-policy.
7. Future: Sector Benchmarking (Opt-In)
In a future version, ZumFlo may offer an optional benchmarking feature. If introduced:
- Participation is entirely voluntary and requires explicit consent
- Only aggregated, quantised metrics would be shared — never raw financial data
- Data is anonymised using k-anonymity (minimum group size of 10)
- You can withdraw consent at any time
- This Privacy Policy will be updated before activation
8. Data We Do Not Collect
ZumFlo does not:
- Use advertising identifiers (IDFA) or cross-app tracking
- Contain third-party advertising or advertising SDKs
- Perform device fingerprinting
- Include financial amounts or personal data in analytics
- Share data with data brokers or marketing platforms
9. Data Retention and Deletion
9.1 Retention
Your data remains on your device and in your iCloud account for as long as you choose to keep it. There is no automatic expiration.
9.2 Deletion
You are in full control. You can delete data at any time:
- Individual records: Delete daily logs, categories, or financial rules from within the App.
- Full reset: My Business → Settings → Data Management → Erase all data. This also removes the SumUp, PayPal POS and Moneybird tokens from the Keychain; your iCloud data is removed through sync. The counters of your AI usage are deliberately kept.
- iCloud data: Disable sync via iOS Settings → Apple ID → iCloud → Apps Using iCloud → ZumFlo. Delete the container via iOS Settings → Apple ID → iCloud → Manage Storage.
- Third-party tokens: Disconnect SumUp, PayPal POS or Moneybird via My Business → Settings → Integrations. Tokens are immediately removed from the iOS Keychain.
- Uninstall: Removing the App deletes all locally stored data.
Deletion on your device is immediate and permanent.
9.3 Data at our processing service
Data from a settlement check (job, result and push token) and price list search results are kept for at most 90 days and then deleted automatically (see 3.5 and 3.6). Erasing data in the App does not immediately remove this copy. If you want it removed sooner, email ; we will then delete it within 30 days.
10. Revoking Consent
- Device permissions — iOS Settings → ZumFlo → toggle individual permissions off.
- iCloud sync — iOS Settings → Apple ID → iCloud → Apps Using iCloud → ZumFlo.
- SumUp / PayPal POS / Moneybird — My Business → Settings → Integrations → Disconnect, or via the third party’s own account settings.
- Calendar link — My Business → your location → Calendar → Unlink.
- AI features — If you do not use the settlement check or scanning, no data is processed for them.
- Notifications — iOS Settings → Notifications → ZumFlo.
11. Children’s Privacy
ZumFlo is a business administration tool for self-employed professionals and is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has used the App, please contact .
12. Security
- All data is stored in the iOS-encrypted application sandbox.
- OAuth tokens are stored in the iOS Keychain with hardware-backed encryption (Secure Enclave).
- Optional App Lock via Face ID or Touch ID.
- iCloud data is encrypted by Apple in transit and at rest.
- Backups (.zumflo) are always encrypted (AES-256) with a password you choose.
- Only for the AI features and the price list search is data sent over an encrypted connection (HTTPS) to our processing service on Microsoft Azure in West Europe.
13. International Transfers
Because iCloud sync is enabled by default, Apple may store data in data centres outside your country of residence, subject to Apple’s data processing agreements. If you connect SumUp, PayPal POS or Moneybird, data may be processed in those services’ jurisdictions. Anonymous usage analytics are processed by TelemetryDeck GmbH in Germany. Our processing service runs on Microsoft Azure in West Europe (the Netherlands). For the AI features (3.5) and the price list search (3.6), data is transferred to Anthropic PBC and Brave Software in the United States. These transfers are based on the European Commission’s Standard Contractual Clauses.
14. Your Rights Under GDPR
Within the European Economic Area, you have the following rights under the General Data Protection Regulation:
- Access: View all your data directly in the App.
- Rectification: Edit any record in the App.
- Erasure: Delete individual records or all data (see Section 9).
- Data portability: Export your complete records as an encrypted .zumflo backup, and your figures as PDF and CSV reports.
- Restriction & objection: You exercise these rights by managing integrations and permissions directly.
Because your records reside on your device, you exercise most of these rights directly. For data at our processing service (9.3) you can send a request. Need help? Email .
15. Governing Law
This Privacy Policy is governed by the laws of the Netherlands. Any disputes shall be submitted to the competent court in the Netherlands.
16. Changes to This Policy
- The “Last updated” date at the top will be revised.
- Material changes will be communicated via a notice in the App.
- Continued use after the update constitutes acceptance.
17. Contact