We're a small studio, so there's no privacy department here to hide behind. This page says exactly what we collect, where it sits, who else can see it, and how long it stays. It is written to be read.
We keep what we need to answer you and to run the software we built for you. We don't sell it, we don't track you around the internet, and you can ask us to delete it by writing one email.
This site, the live demo, and the client portal we run at this address. Not the businesses we build software for — their data is theirs.
This site and the portal. Everything below is about flexvivid.com: the homepage, the live demo, and the client portal where our clients report issues and preview changes to their own systems.
Not the systems we build. When we build software for a business, that system holds the business's own records — their customers, their orders, their invoices. The business owns that data and decides how it is used. We operate the system on their instructions. If you are a customer of one of our clients and want to know what they hold about you, ask them; we will help them answer.
Who you are actually writing to. FlexVivid is a small independent software studio working out of Lakewood, New Jersey. Nothing here is routed through a support desk. Write to hello@flexvivid.com and the person who built the thing will answer you.
This is the whole list. There is no hidden category, and there is no field on this site that quietly does something other than what its label says.
Every use on the left has a reason we can say out loud. Everything on the right is a thing we could technically do and have chosen not to build.
Five uses, all of them obvious
No exceptions, no small print
There's no data broker, no ad network and no reseller behind any of this
Which is also the reason this site has no cookie banner. There is nothing here to consent to.
The sign-in cookie. Signing in to the client portal sets a cookie called sw_session. It holds a signed token with your user id and your role on the project, and nothing else. JavaScript can't read it, it is only ever sent back to this site, and it expires after thirty days or when you sign out.
The marketing pages set no cookies at all. The homepage, the demo and these two documents store nothing on your device and report nothing about your visit to anyone. No pixels, no session recording, no consent management platform quietly loading fourteen vendors behind a button that says "accept".
Fonts are the one outside request. These pages load three typefaces from Google Fonts, so your browser asks Google's servers for them and Google can see your IP address while it answers. That is the only external request the page makes. Everything else — every style, every script, the whole drawing — is served from this domain.
Do Not Track. There's nothing for us to honour, because nothing here is tracking you in the first place.
We run on other companies' infrastructure, which means naming them. Each one is here for a specific job, and none of them is paid in data.
We don't use your business records to train models of our own
We operate software that runs real businesses. That deserves a plainer statement than most privacy pages manage.
You own the code and the data. From the first phase, not at the end of some earn-out. We hold your data as the operator of your system, on your instructions, and you can have a full export of it whenever you ask.
We access it to build, run and fix it, and for nothing else. No mining it for our own purposes, no bundling it into a product, no showing it to another client. When a fix needs real data to reproduce, we work with the smallest amount that will do the job.
Attachments are not public. Screenshots, recordings and voice notes attached to an issue are stored privately and served only to a signed-in user with access to that project. There's no shareable public link.
Passwords are hashed, traffic is encrypted. Portal passwords are stored as bcrypt hashes, so nobody here, including us, can read them. Everything runs over HTTPS, and the pages ship with a content security policy that refuses any script we did not put there ourselves.
If something ever goes wrong, you will hear it from us. No system is beyond reach and we're not going to pretend otherwise. If data we hold is ever exposed, we will tell you what happened, what was affected and what we did about it, in plain language, as soon as we know — not after a comms review.
A schedule rather than a sentence, because "as long as necessary" tells you nothing.
| No. | Record | How long we keep it | Where it lives |
|---|---|---|---|
| 01 | Enquiry from the form | While the conversation is live, and afterwards as a record of who asked and what they needed. Deleted on request, whether or not we ever worked together. | CLOUDFLARE · DATABASE |
| 02 | Portal account | For as long as we run your system. Closed and removed when the work ends, on your instruction. | CLOUDFLARE · DATABASE |
| 03 | Issue reports and attachments | With the project history, because a fix only makes sense next to the report that caused it. Removed with the project, or earlier if you ask us to drop a particular recording. | CLOUDFLARE · FILE STORAGE |
| 04 | Email we have sent you | Delivery records sit with the email provider on their own retention schedule. Our copy stays with the project it belongs to. | BREVO · RESEND |
| 05 | Server logs | A short window on the host's own schedule. We do not copy them anywhere or keep our own archive of them. | CLOUDFLARE |
| 06 | Outreach contact details | Until you tell us to stop. Then we remove you and keep a note that you asked, so nobody writes to you again by accident. | CLOUDFLARE · DATABASE |
One email. No form, no fee, and no requirement to explain yourself.
See it, correct it, take it, or delete it. Write to hello@flexvivid.com and we will tell you what we hold about you, fix it if it is wrong, send you a copy, or delete it. We aim to answer within a few working days. If a request needs longer, we will say so and tell you why.
Stopping our email. Reply to any message and say so, or write to the address above. We remove you and record that you asked, which is what stops it happening twice. You never have to prove you asked.
Where the law gives you more. Depending on where you live you may have rights under laws such as the GDPR or the CCPA. We're not going to claim a certification we don't hold. What we will do is honour the substance of those requests — access, correction, deletion, a copy of your data, and no worse treatment for having asked — whoever you are and wherever you are writing from.
Requests about a client's system. If your request is about data held inside software we operate for one of our clients, the client decides. We will pass it straight to them and help them answer it properly.
Children. This is business software. The site isn't aimed at children and we don't knowingly collect anything about them.
Last updated 30 July 2026. If it changes in a way that matters, the date changes with it and clients hear about it directly rather than through a quiet edit.
Privacy questions, in writing
Or just call
Leave a message and we will call you back