Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains how LitosFlow collects, uses, and protects information when you use our ticketing service. We aim to collect only what we need to run the Service and to be clear about how that information is handled.

1. Information we collect

We collect the following categories of information:

  • Account information — the name, email address, and organization details you provide when you register or are invited to a workspace.
  • Workspace content — the tickets, comments, boards, tags, and other data you and your members create while using the Service.
  • Billing information — plan and subscription details. Payment card data is handled directly by our payment processor and is never stored on our servers.
  • Usage and technical data — log data such as IP address, browser type, and actions taken in the Service, used to keep it secure and reliable.

2. How we use information

We use the information we collect to:

  • Provide, maintain, and improve the Service and its features;
  • Authenticate users, resolve the correct organization workspace, and enforce access controls;
  • Process subscriptions and payments for paid plans;
  • Communicate with you about your account, security, and service updates;
  • Detect, prevent, and address fraud, abuse, and security incidents.

3. Multi-tenant data separation

LitosFlow is a multi-tenant service. Every organization's data is scoped to that organization and is not accessible to other tenants. Access to workspace content is determined by the roles and permissions configured within each organization.

4. How we share information

We do not sell your personal information. We share information only in limited circumstances: with service providers who process data on our behalf (such as hosting and payment providers) under appropriate confidentiality obligations, when required by law or valid legal process, or to protect the rights, safety, and security of our users and the Service.

5. Data retention

We retain your information for as long as your account is active and as needed to provide the Service. When you close your organization, we delete or anonymize associated data in accordance with our retention practices, except where we are required to retain it to comply with legal obligations or resolve disputes.

6. Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit, scoped access controls, and session-based authentication. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.

7. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information. Organization administrators can manage much of this directly within the Service. For requests we cannot fulfill through the product, contact us through your organization's support channel.

8. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "last updated" date above and, where appropriate, provide additional notice.

9. Contact

If you have questions about this Privacy Policy or our data practices, please review our Terms of Service or contact us through your organization's support channel.