Privacy Policy

Effective date: 9 September 2026 Operator: Sharkflow Private Limited (Singapore)
Data-protection contact: [email protected] (reaches the person responsible for data-protection requests)

This policy explains how Sharkflow Private Limited ("Sharkflow", "we", "us") handles personal data when it provides the Sharkflow multi-tenant business operations platform, ThePlatform by Sharkflow mobile application, its websites, and related support (together, the "Service").

INARA ORGANICS PTE. LTD. publishes the iOS app with Sharkflow’s authorization. This distribution role does not grant Inara access to other organizations’ data. Sharkflow remains the service operator described in this policy.

Our role

We determine how account, billing, security, and service-administration data is handled. For business records that a customer organization puts into the Service, that organization determines the purpose of processing and Sharkflow generally processes the data on its instructions. If you are an employee, customer, supplier, or other person whose data was provided by a customer organization, contact that organization first; we will support it in responding to your request.

Personal data we handle

  • Account and identity data, such as name, work email, phone number, login and consent records, organization membership, and role.
  • Organization and business data, including company profiles, contacts, documents, finance records, HR and payroll records, schedules, and statutory or compliance records.
  • Communications and commerce data from connected services, including email, support conversations, store customers and orders, shipping details, and integration identifiers.
  • Files and content submitted for storage, OCR, search, automation, or AI-assisted work, including prompts and generated output.
  • Billing data, subscription status, usage records, and payment tokens handled by our payment provider. Sharkflow does not store full payment card numbers.
  • Technical and security data, such as session information, hashed IP addresses, audit events, device information, and service logs.

Mobile app data and permissions

The mobile app receives account and workspace records from our servers and collects information you submit, including personal phone numbers and residential addresses, attendance actions, expense claims, leave requests and reasons, and workplace messages. Leave requests may include medical, hospitalization, maternity or paternity information. Authorized staff can access records according to their organization’s permissions.

  • Camera: used with your device permission to scan workplace QR codes. The scanner processes camera frames on the device; this feature does not upload photographs or video to Sharkflow.
  • Notifications: when enabled, Apple Push Notification service processes a device token so we can deliver notifications. You can disable notifications in iOS Settings without losing access to the app.
  • Screenshot events: when you take a screenshot while viewing a workplace conversation, the app records that an event occurred in that group. It does not upload the screenshot image. The event is associated with your account and group for accountability.
  • Device storage: the app stores a sign-in token using platform-protected storage. Signing out removes the locally stored token.
  • Location and advertising: the app does not request GPS location or an advertising identifier. A workplace QR code or attendance record can identify your work location. We do not use this information for advertising.

The current mobile interface does not offer AI prompt submission or document OCR. Separately configured platform automations may process workspace records; the AI section below describes those services. Installing the mobile app is not permission to use your data for model training.

How we use personal data

  • Provide, secure, administer, and support the Service.
  • Authenticate users and enforce organization access controls.
  • Process customer instructions, including storage, bookkeeping, HR, communications, commerce, automation, OCR, and AI-assisted tasks.
  • Measure usage, bill subscriptions, and prevent fraud or abuse.
  • Diagnose incidents, maintain audit evidence, and comply with legal obligations or enforce our agreements.
  • Improve the Service using operational and product feedback. We do not sell personal data or use customer content for third-party advertising.

AI-assisted processing

When an organization enables AI or OCR features, relevant content may be sent to the provider selected for that task. The provider and model can vary by configuration. We use authenticated commercial API access and available provider privacy controls, and limit the data sent to what the feature needs. However, provider terms, service tiers, features, and settings determine how submitted content is retained and used. Where those terms or settings permit it, a provider may retain content, have authorized reviewers inspect it, or use it to improve or train models. Sharkflow does not control those provider practices and does not promise zero retention or no training. The current providers are identified below. Acceptance of this policy is not a substitute for explicit permission where required for a particular disclosure. Before using a feature with personal data, contact your organization administrator for the provider, purpose and applicable controls; do not submit restricted data unless its processing is authorized and protected. Sharkflow remains responsible for selecting subprocessors with appropriate contractual protections; a provider’s separate terms do not remove our own obligations.

Sharing and disclosure

We disclose personal data to authorized members of the relevant customer organization, to the subprocessors needed to deliver the Service, and where required to protect the Service, enforce an agreement, complete a corporate transaction, or comply with law. We do not share personal data with third parties for their own advertising.

Subprocessors

The following providers may process customer personal data when their corresponding feature is used. Processing location describes the provider footprint recorded in our current register and is not a promise of exclusive data residency.

ProviderPurposeProcessing location
AppleiOS app distribution and push notification deliveryGlobal
HetznerCloud infrastructure and hostingGermany / Singapore
CloudflareDNS, edge security, and object storageGlobal
StripeSubscription billing and payment processingGlobal
HitPayEvent registration and store checkout paymentsSingapore
ResendTransactional email deliveryGlobal
TwilioTransactional SMS and WhatsApp deliveryGlobal
Meta PlatformsInstagram messaging integrationGlobal
TelegramOrganization-configured Store issue-intake botGlobal
ShopifyCommerce integrationGlobal
EasyParcelShipping and logistics integrationMalaysia / SEA
Fireworks AIAI inferenceUnited States
AnthropicAI inferenceUnited States
OpenAIAI inference and embeddingsUnited States
GoogleEmail integration, AI, embeddings, and document processingGlobal
Mistral AIDocument OCRFrance / EU

International transfers

Some providers process data outside Singapore. We use contractual and organizational safeguards intended to require protection comparable to applicable Singapore data-protection requirements. A customer may ask us for current transfer information relevant to its enabled providers.

Retention and deletion

We keep personal data while it is needed to provide the Service, satisfy the customer's documented instructions, secure and audit the platform, resolve disputes, or meet legal obligations. Retention varies by data category. For example, Singapore business and tax records may need to be retained for at least five years from the relevant year of assessment. When data is no longer needed for a business or legal purpose, it is deleted or anonymized under our retention schedule.

Deleting an individual login is different from deleting the customer organization’s records. Payroll, accounting, attendance and other employer-controlled records may remain where required by law or a documented lawful purpose, with access limited to authorized persons. We communicate applicable exceptions when responding to a request.

Account closure does not immediately remove every backup copy. Backup copies are access-restricted and expire under the applicable backup lifecycle; a recovery must respect previously completed deletion requests. Ask the privacy contact for the applicable retention and backup disposal periods for your request. We do not promise immediate or universal erasure of legally retained records.

Your choices and rights

Depending on the applicable law and our role, you may request access, correction, deletion, or a copy of personal data, or withdraw consent where processing relies on consent. Exceptions can apply, including legal retention and the rights of other people.

Registered users can request an export or deletion from the privacy section of their web profile page. Mobile users can open Data requests from the sign-in screen or account menu. Other individuals can follow our data request process or email [email protected]. We may verify identity and coordinate with the customer organization responsible for the data.

Cookies

The Service uses first-party cookies and similar browser storage that are necessary for sign-in, session security, organization selection, and user preferences. We do not currently use third-party advertising pixels or cross-site behavioral advertising cookies. If that changes, this policy and any required consent controls will be updated before the technology is enabled.

Security

We use access controls, tenant isolation, encryption for designated restricted fields, audit logging, secrets management, and operational monitoring. No system is completely secure, and customers remain responsible for their users, connected accounts, and access settings.

Children

The Service is for organizations and is not directed to children. Users must be at least 16. Users aged 16–17 may access the Service only as authorized staff of a customer organization, with any parent or guardian permission required by applicable law. Staff aged 16–17 may not purchase subscriptions or bind their employer under our service terms. Ordinary staff users do not need authority to enter a contract on behalf of their employer.

Changes and contact

We may update this policy and will publish the revised effective date. Material changes will be communicated through the Service or another appropriate channel. Questions, requests, or complaints may be sent to [email protected]. You may also contact the Personal Data Protection Commission of Singapore.