Last updated 27 September 2026
Privacy Policy
This policy explains what personal data Studioflow collects when you use the website and app at campaign-sync-up.lovable.app, why we collect it, who we share it with and the rights you have. We collect only what we need to run Studioflow.
1.Who we are
Studioflow is operated by VEKHAT Ltd., a company registered in Bulgaria. We are the controller of the personal data described in this policy, within the meaning of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Bulgarian Personal Data Protection Act.
- Company
- VEKHAT Ltd.
- UIC (ЕИК)
- 207661725
- Registered address
- 255, entr. A, fl. 1, apt. 1, Triaditsa District, Sofia 1404, Bulgaria
- tanchev@mywebcore.com
- Phone
- +359 888 868 617
We have not appointed a Data Protection Officer. For any privacy question, write to tanchev@mywebcore.com.
2.Data we collect
Account data
- Your email address, name and whether you use Studioflow as a creator or an editor.
- Your password, if you sign up with email. It is stored only in hashed form; we never see it in plain text.
- If you choose “Continue with Google”, Google shares your name, email address and profile picture with us. We do not get access to your Google account, Gmail or Drive.
Workspace content
Everything you add to Studioflow: campaigns and brand names, brand kits, videos and their deadlines and statuses, links to drafts and live posts, review notes and private notes, and the payment amounts and payment status you record for editors.
Payments you record for editors are only records: Studioflow does not move that money.
Billing, if you subscribe to a paid plan
- Stripe takes your payment. We never see or store your card number, security code or bank details.
- From Stripe we receive and keep your subscription details: plan, price, billing period, status, renewal and trial dates, any discount, and whether a payment failed or was refunded.
- A card fingerprint: a code Stripe generates that shows whether two payments used the same card, without revealing the card. We use it only to stop people rewarding themselves through the referral program.
- Promo codes you redeem, and whether you joined through someone’s referral link (and who).
Data about people you invite
When a creator invites an editor, we store the editor’s email address so the invitation can be matched to their account when they sign up. If you invite someone, please make sure they are happy to be contacted.
Technical data
- Your IP address, browser and device type, and the pages and requests you make, which our hosting provider records in server logs.
- Error reports. When something breaks, the error message, the page it happened on and basic browser details are sent to our hosting provider so we can fix it.
Messages to us
If you email or call us, we keep the conversation so we can help you.
Plan and billing activity
We keep a simple log of plan-related steps — for example viewing the pricing page, reaching a Free plan limit, starting checkout, starting a trial or cancelling — with your account ID when you’re signed in. It holds no names or email addresses and stays in our own database; we use it to understand which plans work.
We do not use advertising or third-party analytics trackers, and we do not ask for special categories of data (such as health or political opinions). Please don’t put them in notes.
3.How we use data and our legal bases
- To provide Studioflow: create and secure your account, show your workspace to you and to the people you work with, play drafts in the reviewer and send service emails such as password resets. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To keep Studioflow safe and working: prevent abuse and unauthorised access, investigate errors and improve reliability. Legal basis: our legitimate interest in running a secure, working service (Art. 6(1)(f) GDPR).
- To bill paid plans: take payments through Stripe, apply discounts and referral rewards, and switch features on or off with your plan. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To prevent referral and promo abuse and to understand our plans, using card fingerprints and the plan activity log described above. Legal basis: our legitimate interest in fair rewards and a sustainable service (Art. 6(1)(f) GDPR).
- To answer you when you contact us. Legal basis: contract, or our legitimate interest in responding to enquiries.
- To meet legal obligations, for example accounting rules or a lawful request from an authority. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
5.Transfers outside the EU
Some of our providers are based in, or store data in, the United States or other countries outside the European Economic Area. Where that happens, we rely on an adequacy decision (such as the EU–US Data Privacy Framework) or on the European Commission’s Standard Contractual Clauses, together with any additional safeguards they require. You can ask us for a copy of the relevant safeguards at tanchev@mywebcore.com.
6.How long we keep data
- Account data and workspace content: for as long as your account is open.
- After you ask us to delete your account: we delete it within 30 days. Copies in backups are overwritten within a further 90 days.
- Server logs and error reports: up to 90 days.
- Plan and billing activity log: up to 2 years.
- Subscription and invoice records: for as long as accounting and tax law requires, even after your account is closed.
- Messages to us: up to 2 years after the conversation ends.
- Data we must keep by law, such as accounting records: for the period the law requires.
8.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use your data;
- receive your data in a portable format, or have it sent to another service;
- object to processing based on our legitimate interests;
- withdraw any consent you have given, at any time.
To use any of these rights, including deleting your account, email tanchev@mywebcore.com from the address on your account. We will reply within one month. We may need to confirm your identity first.
You can also complain to a supervisory authority. In Bulgaria that is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg. You can also contact the authority in the EU country where you live or work.
9.Security
All traffic to Studioflow is encrypted with HTTPS. Passwords are hashed. Database access rules make sure each person can see only their own workspace and the work shared with them. No system is perfectly secure, so if you think your account has been compromised, change your password and tell us at tanchev@mywebcore.com. If a breach puts your rights at risk, we will notify you and the supervisory authority as the law requires.
10.Children
Studioflow is not meant for anyone under 16. We don’t knowingly collect data from children under 16. If you believe a child has created an account, tell us and we will delete it.
11.Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change is significant, we will also tell you by email or in the app before it takes effect. This policy should be read together with our Terms and Conditions.
12.Contact
For any question about this policy or your data, contact us:
- Company
- VEKHAT Ltd.
- UIC (ЕИК)
- 207661725
- Registered address
- 255, entr. A, fl. 1, apt. 1, Triaditsa District, Sofia 1404, Bulgaria
- tanchev@mywebcore.com
- Phone
- +359 888 868 617