Privacy Policy
Last updated 28 September 2026
Paperflower helps online shops answer the comments, direct messages and emails their customers send them. This policy explains what information we collect, why, who we share it with and how you can have it deleted. It covers the website at paperflower.io, the Paperflower web app and the Paperflower iPhone app. If you have a question, email hello@paperflower.io.
We are based in Australia and handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Who this is about
- Brands: the businesses and the team members who sign up and use Paperflower.
- Their customers: the people who comment, message or email those brands. Paperflower handles their messages on the brand's behalf and only to help the brand reply.
- Visitors to our website.
What we collect
- Account details: your name, email address, business name and password (stored only as a secure hash by our sign-in provider).
- Connected channels: when you connect Instagram, Facebook, TikTok, Gmail or another email inbox, we receive the comments, ad comments, direct messages and emails sent to your business on those channels, the names and profile pictures of the people who sent them, the posts they relate to, and the replies you send. We only request the access needed to show and answer these messages.
- Shopify: when you connect your store, we read products, stock, prices, shipping settings and, to answer order questions, the order and tracking details of a customer whose email matches the message.
- Brand knowledge: public pages of your website and anything you add, such as your tone of voice and house rules.
- Billing: your plan and payment status. Card details are handled by Stripe; we never see or store full card numbers.
- Usage and device information: basic logs such as the time of a request and error reports, used to keep the service working.
- Website visitors: our website uses the Meta and X advertising pixels to measure our own ads. You can block these with your browser's privacy settings.
How we use it
- To show your customer messages in one place, sort them (for example, buying questions, problems and spam) and write reply drafts for you to review.
- To send the replies you choose to send. Paperflower never posts public comment replies for you: you paste and post those yourself.
- To run your account, provide support, bill your plan and send service emails (for example, when you near your monthly allowance).
- To keep the service secure and fix problems.
We do not sell personal information, we do not use your customers' messages to advertise to them, and we do not use your data to train AI models for anyone else.
AI processing
To sort messages and draft replies, the text of a message and the relevant store and brand facts are sent to our AI provider, OpenAI, which processes it on our behalf under terms that do not allow it to use the data to train its models. On the Free plan no AI processing happens. On paid plans you can switch each AI feature off in Settings.
Who we share it with
We share information only with the services that run Paperflower for us, and only as much as each needs:
- Supabase (database and sign-in), Railway and Vercel (hosting)
- OpenAI (message sorting and reply drafts)
- Stripe (payments) and Resend (service emails)
- Meta, TikTok, Google and Shopify, when you connect them and to send the replies you choose
Some of these services store data outside Australia, including in the United States and Singapore. We also disclose information when the law requires it.
Data from Meta, Google and Shopify
Information we receive through Meta (Facebook and Instagram), Google (Gmail) and Shopify is used only to provide Paperflower's features to the brand that connected the account. We do not sell it, use it for advertising, or transfer it except as described above. Paperflower's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
We keep your information while your account is open. If you disconnect a channel, we stop receiving new messages from it. If you close your account, we delete your account and its messages within 30 days, except where we must keep records (such as invoices) by law.
Deleting your data
You can ask us to delete your account and all of its data at any time by emailing hello@paperflower.io from the address on your account. We will confirm by email once it is done, within 30 days.
If you removed Paperflower from your Facebook or Instagram settings and want the data we received through Meta deleted, email us with the name of your Facebook Page or Instagram account and we will delete it the same way. You can also disconnect any channel in Paperflower's Settings.
If you are a customer of a brand that uses Paperflower and want your messages deleted, contact that brand, or email us and we will help.
Security
Connections to Paperflower are encrypted, access to each brand's data is limited to that brand's account, and the access keys for connected channels are stored encrypted. No system is perfectly secure, but we work to protect your information and will tell you if a breach affects you, as the law requires.
Your rights
You can ask to see or correct the personal information we hold about you, or complain about how we have handled it, by emailing hello@paperflower.io. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Children
Paperflower is a business tool and is not intended for anyone under 16.
Changes
If we change this policy, we will update the date at the top and, for significant changes, tell account holders by email.
Contact
Paperflower · hello@paperflower.io