Legal
Privacy Policy
Your privacy matters to us. This policy explains what information we collect, how we use it, and the choices you have.
Effective date: 30 May 2026
1. Information We Collect
We collect information you provide directly to us, as well as data generated automatically when you use our services.
Personal Information
When you request a website, contact us, or create an account, we may collect:
- Your name and business name
- Email address
- Phone number or WhatsApp contact
- Website preferences and project requirements
- Brand assets you provide (logos, photographs, copy)
- Payment information (processed securely by our third-party payment processor, Flutterwave — we do not store your card details)
Usage Data
When you visit our website, we automatically collect certain information, including your IP address, browser type, operating system, referring URLs, pages viewed, and the dates and times of your visits.
Cookies & Similar Technologies
We use cookies and similar tracking technologies for analytics purposes to understand how visitors interact with our website. You can control cookie preferences through your browser settings. Disabling cookies may affect certain features of our site.
2. How We Use Your Information
- Deliver our services — design, develop, and host your custom website
- Communicate with you — respond to inquiries, send project updates, and provide support
- Process payments — facilitate transactions through Flutterwave
- Improve our services — analyse usage patterns to enhance our website and offerings
- Legal compliance — meet our legal obligations and protect our rights
- Marketing — send occasional updates about our services (only with your consent; you can opt out at any time)
3. Information Sharing & Third-Party Services
We do not sell, rent, or trade your personal information. We share data only with trusted third-party service providers who assist us in operating our business:
- Flutterwave — payment processing. Your payment data is handled directly by Flutterwave under their own privacy policy. We do not store card numbers or bank account details on our servers.
- Clerk — authentication and user account management (email, session tokens).
- Resend — transactional email delivery (welcome emails, project updates, invoices).
- Cloudflare — website hosting, static asset storage (R2), and DDoS protection.
- Railway — database hosting. All data is encrypted at rest and in transit.
- Sanity — content management system. A dedicated Sanity project is provisioned for each client.
- GitHub — version control for your website source code.
- Anthropic— AI-assisted website generation. Your project brief may be sent to Anthropic’s API; it is not used to train their models under their API terms of service.
We may also disclose your information when required by law, to protect our rights, or to prevent fraud or security threats.
4. Data Security
We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Your data is stored in secure, cloud-hosted databases with encryption in transit and at rest. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
5. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes described in this policy, provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. When your data is no longer required, we will securely delete or anonymise it. Brand assets provided for website projects are retained for the duration of your hosting relationship with us and deleted upon request after service termination.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate or incomplete data
- Deletion — request that we delete your personal data, subject to legal retention requirements
- Objection — object to certain processing of your data
- Data portability — request your data in a structured, commonly used format
To exercise any of these rights, please contact us at info@florishonline.com. We will respond to your request within a reasonable timeframe.
7. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at info@florishonline.com.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Effective Date” at the top of this page and notify you via email or a prominent notice on our website. We encourage you to review this policy periodically.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
- Company: FlorishOnline Ltd.
- Location: Kigali, Rwanda
- Email: info@florishonline.com
- Website: florishonline.com
See also our Terms of Service · Have questions? Contact us