Privacy Policy

Effective: April 8, 2026 Β· FlexServe is a product of Nexint Technology Solutions

This privacy policy describes how FlexServe collects, uses, and protects your information. FlexServe is built and operated by Nexint Technology Solutions. References to "we", "us", or "FlexServe" in this policy mean Nexint Technology Solutions in its capacity as the operator of the FlexServe product.

1. Information We Collect

1.1 Account information

When you sign up, we collect your business name, email address, and phone number. We do not collect or store your payment card details β€” all payments are processed directly by Stripe (a PCI-compliant processor); we only keep a Stripe customer reference to manage your billing.

1.2 Business content

Our guided setup form captures information about your business: services, pricing, hours, location, and visual preferences. This is used to generate your website.

1.3 Connected social profiles (OAuth) β€” coming soon

Social-media account connection is a feature we are rolling out and it is not yet enabled for accounts. As we roll it out, when you choose to connect your Google Business Profile, Instagram, Facebook Page, TikTok, YouTube, or WhatsApp Business via OAuth, we will receive read-only access to profile information, recent posts, reviews, ratings, hours, address, phone, and categories. We will not request or use any "write" or "publish" permissions. We will never post on your behalf, send messages on your behalf, or modify your profiles.

1.4 Booking and customer data

When customers book through your FlexServe site, we store the records you and your clients create in your CRM: client name and contact details, booking details (service, staff, date, time), intake-form answers and booking metadata, and any optional client notes, tags, or birthday you choose to add. This data belongs to you and is scoped to your tenant account.

1.5 AI processing of your content

To build your site, the answers you give during onboarding and the image prompts derived from your business description are sent to third-party AI providers to generate your website copy and images. These providers act as sub-processors and, under their terms, do not use this content to train their models.

1.6 Technical, security, and analytics data

We collect IP addresses in our security and audit logs to protect the service and investigate abuse. We use essential session cookies (HttpOnly authentication and refresh tokens) that are required to keep you signed in, and we collect basic product analytics such as page views. The service is built for businesses and is not directed to children; we do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies).

2. How We Use Your Information

To generate and maintain your website, booking system, and client portal; to send your onboarding answers and image prompts to third-party AI providers to generate your site; to pre-fill your business profile during onboarding; to deliver bookings, reminders, and notifications; to process payments via Stripe; and β€” as we roll out social-media connections, and only when you connect an account β€” to display your own social posts on your FlexServe site and surface profile-improvement recommendations.

3. How We Store Your Information

Your data is stored in encrypted databases hosted on secure cloud infrastructure. OAuth access and refresh tokens are encrypted at rest using strong, industry-standard encryption with securely managed encryption keys.

4. What We Don't Do

We do not sell your data to third parties. We do not use your business or customer data to train machine learning models. We do not share your data with advertisers. We do not post, message, or follow anyone on your behalf via your connected social accounts. We do not retain OAuth tokens for accounts you've disconnected.

5. Third-Party Sub-Processors

We share data with the sub-processors needed to run the service: a payment processor (Stripe), cloud hosting, storage, and email-delivery providers, and third-party AI providers for site generation. We share data with social platforms (such as Google, Meta, or TikTok) only if you choose to connect those accounts, a feature we are rolling out. Our AI providers act as sub-processors and, under their terms, do not use your data to train their models.

6. Your Rights

You can disconnect any OAuth-connected profile at any time. You can export or delete your data from Dashboard β†’ Settings, or by emailing privacy@flexserve.ai. EU/UK users have GDPR rights. California users have CCPA rights β€” we do not sell personal information.

7. Data Retention and Deletion

Deleting your account immediately and permanently removes your tenant's data from our systems. We do not keep it afterward, except for limited records the law specifically requires us to retain. Suspended accounts are retained until you delete them. Unpublished or dormant sites are purged after 90 days.

8. Security

We follow industry best practices: HTTPS everywhere, encryption at rest and in transit, role-based access control, regular security audits.

9. Changes to This Policy

We may update this policy from time to time. For material changes, we will provide reasonable advance notice by email or in-app notification. Continued use of the service after the effective date constitutes acceptance.

10. Contact Us

Questions about this policy or your data: privacy@flexserve.ai

Β© 2026 Nexint Technology Solutions Β· FlexServe is a product of Nexint Technology Solutions