Privacy Policy
Flovisto ("we", "us", or the "Service") respects your privacy. This policy explains what personal information we collect when you use flovisto.com and the application at rs.flovisto.com, how we use and share it, and the rights available to you. We operate in accordance with applicable Israeli privacy and data-security law.
1. Who we are and how to contact us
The Service is operated by Flovisto. Privacy questions and requests may be sent to privacy@flovisto.com.
2. Information we collect
- Information you provide: full name, email address, password (stored only as a secure hash), and business details such as business name, tax or company number, address, phone number, and logo.
- Information created through use of the Service: documents you create or upload, which may contain personal information; vehicle-data queries against Israeli public sources; and activity and security logs, including IP address and sign-in timestamps.
- Minimal technical information: one essential authentication cookie and cookieless analytics on the marketing website. See our Cookie Policy.
3. Your customers' information — our role as processor
When you manage information about your customers, drivers, vehicles, or documents, you control that information and Flovisto processes it only on your instructions to provide the Service. We do not use it for independent purposes.
4. Why we use information
- To provide, operate, and maintain the Service and generate documents.
- To authenticate users and provide secure sign-in, including two-factor authentication.
- To provide technical support and customer service.
- To protect the Service and prevent abuse and fraud.
- To comply with legal obligations, including tax and bookkeeping requirements.
- To improve and maintain the Service.
5. Service providers and information sharing
We do not sell personal information. We use service providers that process information only for us and under our instructions:
- Microsoft Azure — application and database hosting, storage and backups, error reporting through Application Insights, and messages through Azure Communication Services.
- Azure AI Document Intelligence — automated recognition of supplier invoices, vehicle licences, and other documents a user chooses to submit for processing.
- Cloudflare Web Analytics — cookieless measurement of traffic on the marketing website, without cross-site tracking.
- Google Calendar API — optional, user-initiated, read-only synchronization of events from a connected calendar. See section 11.
- Israeli Ministry of Transport public data (data.gov.il) — retrieval of vehicle information based on a vehicle number entered by the user.
We may also disclose information where required by law, a court order, or to protect our legal rights.
6. Cookies
We use one essential cookie to maintain secure authentication. Cloudflare Web Analytics does not set cookies, and we do not use advertising or marketing cookies.
7. Information security
We use commonly accepted safeguards, including HTTPS encryption in transit, encryption at rest, two-factor authentication, tenant-data isolation, access controls, and audit logs. No system is completely secure, but we work continuously to protect information in a reasonable manner.
8. Retention
We retain information while your account is active and for a reasonable period afterwards. Accounting documents and records are retained as required by law, including up to seven years under applicable tax law. Authentication logs are retained for at least 12 months where required by Israeli Tax Authority guidance, and backups are retained for a limited period.
9. Your rights
Subject to applicable law, you may request access to or correction of your personal information and may request its deletion, subject to legal retention obligations. Contact privacy@flovisto.com. Requests concerning information controlled by one of our business customers should be directed to that business.
10. International data transfers
Microsoft Azure and other service providers may store or process information on servers outside Israel, including in the European Union, using commonly accepted safeguards.
11. Google Calendar data
Connecting Google Calendar is optional and occurs only after the user takes an explicit action and grants consent. Flovisto receives the connected Google Account email address and read-only access to events in its primary calendar in order to import and synchronize those events into the tenant's Flovisto environment. Flovisto does not create, modify, or delete Google Calendar events.
To maintain the connection, Flovisto stores encrypted Google access and refresh tokens, the connected account email address, and imported event data. Google user data is used only to provide the synchronization requested by the user. It is not sold, used for advertising, or used to train artificial-intelligence models. It is not transferred to third parties except infrastructure providers required to operate the Service or where required by law. Flovisto's use of Google user data complies with the Limited Use requirements of the Google API Services User Data Policy.
Selecting “Disconnect” revokes the Google authorization and removes the integration record and stored connection tokens from Flovisto. Business records created from previously imported events are not deleted automatically when the integration is disconnected. They can be deleted in the product or through a request to privacy@flovisto.com.
12. Changes to this policy
We may update this policy from time to time. The current version and its update date will be published on this page.
13. Contact
For any privacy question, contact privacy@flovisto.com.