BalloonFloPrivacy

Privacy Policy

Last updated 25 August 2026

Who we are

BalloonFlo is an iPhone app for balloon decorators and event stylists. It is operated by BalloonFlo, a sole proprietorship based in Florida, United States.

For anything in this policy, including a request to delete your data, write to balloonflo@gmail.com.

This policy covers three different people

The stylist — the person who installs BalloonFlo and uses it to price and send proposals. We handle that data as described below.

The stylist’s clients — the people who receive a proposal link. They never installed anything and never agreed to anything with us. For their data, the stylist decides what is collected and why, so the stylist is the controller and BalloonFlo is the processor acting on those instructions. If you received a proposal and want your details removed, the fastest route is to ask the stylist who sent it; you can also write to us at the address above and we will act on it.

Someone who joins the waitlist — a decorator who left their details on our website to be told when BalloonFlo opens up. They have not installed anything and may never do so. We are the controller for that, and it has its own section below.

What stays on the phone

There are no accounts and no sign-in. The following is stored only in the app on the stylist’s device and is not sent to us:

  • The product catalog, labour rates and pricing settings
  • Draft proposals and proposal history
  • Expense receipts and the figures read from them
  • Payments a stylist records by hand — the amount, the date and whether it was cash, a transfer or a card
  • The base address a stylist works from, used to measure delivery distance

The rest of the business profile — the business name, email address, phone number and logo — is stored on the device too, but a copy travels with every proposal that is sent, because those are printed on the document the client reads.

    If the app is deleted, or the phone is lost or reset, this information is gone. It is not backed up to us and we cannot recover it.

    What we store on our servers

    Nothing about a job reaches our servers until a proposal is sent to a client. At that point we store:

    • The proposal itself — the client’s name, email address and phone number; the venue and venue address; the event date; the inspiration photos; and every line item and price. This is what the client’s link displays, so it has to be stored to be served.
    • The client’s response, if they respond — whether they accepted or declined, the name they typed, the time, and their IP address and browser user-agent. The last two are kept as evidence of who agreed and when, in case the agreement is later disputed.
    • Whether the proposal was opened — the first and last time the link was opened, and how many times. This is so the stylist can tell a quote that was read from one that never arrived. No IP address, no device or browser details, and no record of individual visits — three timestamps and a count, nothing that could identify who did the opening.
    • Service usage — a device identifier, daily request counts, and the processing cost of those requests. This is used to enforce daily limits and to control costs. It contains no proposal content.

    A sent proposal is stored as a permanent, unchangeable record of what a client was shown. That is a deliberate design decision: editing a document after someone has agreed to it would rewrite what they agreed to.

    If you join the waitlist

    Our website has a form for decorators who want an invite when BalloonFlo opens up. Joining it is the only thing on that page that stores anything about you.

    What we keep: your email address, and — only if you choose to type them — your name and the area you work in. We also record which link brought you to the form, so we can tell whether a printed flyer or the website itself is doing the work. Nothing else. There is no account, no password, and no tracking of what you read on the page.

    What we use it for: sending you an invite when there is a place, and nothing else. We do not sell the list, share it, rent it, or use it for advertising, and BalloonFlo sends no marketing to it.

    Anti-abuse: the form is open to anyone, so our server briefly holds the IP address a submission came from in order to refuse an obvious flood of them. It is held in memory for one minute, it is never written to the database, and it is not linked to your email address.

    Getting off the list: reply to any email from us, or write to balloonflo@gmail.com and say so. We delete the row rather than marking it unsubscribed, and we will confirm.

    Proposal links

    • Each link contains a secret token. We store only a SHA-256 hash of it, never the token itself, so a copy of our database gives nobody access to any proposal.
    • Links stop working 14 days after they are sent.
    • Proposal pages are marked no-index, so search engines do not list them.
    • Anyone holding the link can open the proposal. Treat it like a document sent by email, because that is what it is.

    Photos, voice and location

    Photos. When a stylist photographs an installation for a quote, that image is sent to Anthropic’s API to identify the components in it. A photographed receipt is sent the same way, to read the figures off it — the receipt itself is then kept only on the phone, but the picture of it does leave the device to be read. Under Anthropic’s API terms that content is not used to train their models. Photos attached to a proposal are also stored with the proposal, because they appear in the document the client reads.

    Voice. Spoken job details are captured on the device and transcribed using Apple’s speech recognition. The resulting text is sent to Anthropic’s API to pull out the job details. We do not store the audio recording on our servers.

    Location. Location is used to work out the driving distance from the stylist’s base address to a venue so that a delivery fee can be calculated. That base address stays on the device, and so do the coordinates — the distance is worked out on the phone. Turning an address into coordinates is done by Apple, so a base address or a venue address is sent to Apple’s address-lookup service to be located. A venue address also appears in the stored proposal, because it is printed on the proposal.

    Companies that process data for us

    • Anthropic — analyses photos, receipts and spoken job details
    • Resend — delivers the email carrying a proposal link to a client
    • Railway — runs our server and database, in the United States
    • Vercel — serves our website and the web page a client opens
    • Google Fonts — serves the two typefaces used on our public website, including this page and the support page. Loading them tells Google the IP address of the browser that asked. It is not used inside the app or on a proposal page, and we intend to serve those files ourselves instead
    • Sentry — receives crash reports so we can fix what breaks
    • Apple — provides the speech recognition used for voice capture, and the address lookup used to measure delivery distance

    We do not sell data, we do not share it for advertising, and BalloonFlo contains no advertising. We do not collect or process payment card details.

    How long we keep things

    • Proposal links — expire after 14 days
    • Sent proposals and client responses — kept as the record of what was shown and agreed, until deletion is requested
    • Open counts — deleted with the proposal they belong to
    • Usage and quota counts — kept to enforce limits and manage costs
    • Crash reports — kept for as long as Sentry retains them under our plan
    • Waitlist entries — kept until BalloonFlo opens up or you ask us to remove yours, whichever comes first

    Deleting your data

    On the phone: deleting the app removes everything stored on the device.

    On our servers: email balloonflo@gmail.com and say which proposals or which device you mean. We will delete the data and confirm, normally within 30 days. There is no account to close, so no sign-in is needed to ask.

    You can also ask what we hold about you, or ask us to correct it, at the same address.

    Children

    BalloonFlo is a business tool for professional decorators. It is not directed at children and we do not knowingly collect information from anyone under 13.

    Security

    All traffic between the app, our server and the client’s browser uses HTTPS. Link tokens are stored only as hashes. No API keys or secrets are shipped inside the app. No system is perfectly secure, and we will not pretend otherwise — if something goes wrong that affects you, we will tell you.

    Changes to this policy

    If this policy changes we will update the date at the top. If a change materially affects what we collect or who we share it with, we will say so rather than quietly revising the page.

    Contact

    BalloonFlo · Florida, United States
    balloonflo@gmail.com