SymoLink

Legal

Privacy Policy

Effective October 2026Applies to symolink.com, app.symolink.com, the SymoLink app and the SymoLink Box

The short version

1Who we are

SymoLink is a texting and calling gateway. Agencies and businesses connect their CRM, and real Android phones with their own SIM cards (plus, for calls, an optional SymoLink Box) send and receive the texts and calls.

SymoLink is run by:

Flowsier LLC, a Wyoming (United States) limited liability company

Postal address: 5830 East 2nd Street, Casper, WY 82609, United States

Privacy and legal questions: [email protected]

In this policy, “SymoLink”, “we” and “us” mean Flowsier LLC. “You” means anyone whose information we handle: a person who signs in to SymoLink, a visitor to our website, or a person who texts or calls a business that uses SymoLink.

2Our two roles

Privacy laws give different duties to the business that decides why and how personal information is used (a “controller”, or under California law a “business”) and to the service that handles it on that business’s behalf (a “processor” or “service provider”). We are each, for different data.

We are the processor for client data

Agencies and businesses (our “customers”) use SymoLink to text and call their own contacts. The contacts, messages, calls, recordings, call summaries and phone data that pass through SymoLink for them belong to them. We call this client data. For client data:

  • the customer is the controller (or, when an agency runs SymoLink for its own clients, the agency is the processor and we are its sub-processor);
  • we use it only to provide SymoLink to that customer, as our Data Processing Addendum sets out;
  • the customer’s own privacy notice tells their contacts how it is used. If you received a text or call from a business through SymoLink and want to see, correct or delete your information, please contact that business. If you contact us, we will pass your request to them.

Agencies may offer SymoLink to their clients under their own brand. If you use a texting or calling app from your agency, the agency is your first point of contact.

We are the controller for account data

We decide how we use the details of the people who sign in to SymoLink, our billing records, our website visitors and people who write to us. We call this account data. This policy is mainly about account data, and explains what we do as a processor so you can see the whole picture.

3What we collect

Account data (we are the controller)

  • Sign-up and login: your name, email address, company name, the countries you serve, your role, and your password (stored only as a one-way hash we cannot read back).
  • Agreements: the version of these legal pages and of any country texting rules you accepted, with your name, email, the time and your internet (IP) address.
  • Sign-in and security records: IP address, browser type, sign-in times, failed sign-in attempts, and an audit log of important actions in your account (who did what, and when).
  • Billing: your plan, seats in use, invoices and payment status. Card details are entered on Stripe’s page and stay with Stripe; we only receive the card brand, last four digits and expiry if Stripe shows them to us.
  • Support: what you write to us, and what we see while helping you (see “Support access” in section 5).
  • Website: symolink.com sets no cookies and runs no analytics. Our web server records the usual technical details of each request (IP address, page, time, browser) for security. If you book a demo, the form (hosted by us at forms.flowsier.com) collects what you type into it, such as your name, email, phone number and company.

Client data (we are the processor)

  • Contacts synced from the customer’s CRM: names, phone numbers and the CRM’s own contact and conversation IDs.
  • Messages: the text and any pictures or files of texts sent and received, with phone numbers, times and delivery status.
  • Calls: who called whom, when, for how long and the outcome. If the customer switches recording on, the call recording.
  • AI call summaries, only if the customer switches them on and connects its own AI accounts: a written transcript and a short summary of a recorded call (see section 5).
  • WhatsApp, where a customer uses it: the same kinds of message data, through a WhatsApp account the customer links.
  • Phone and Box data: for each gateway phone, its name, Android and app version, battery level and charging, signal strength, network type, carrier, the SIM cards’ phone numbers and SIM serial numbers (ICCID), and the SIM’s country (from the mobile network code, MCC). We store a scrambled ID derived from the app’s Android ID, not the phone’s IMEI. For a Box: its connection to the phone (including the phone’s Bluetooth name and address) and its software and security-chip state. We do not collect location (GPS), contacts stored on the phone, or the list of apps on it.

4Why we use it

What we doDataLegal basis (GDPR)
Create and run your account, sign you in, send sign-in and password emailsAccount dataContract
Bill agencies and businesses, collect payment, keep tax recordsBilling dataContract; legal obligation
Keep SymoLink secure: stop guessing of passwords, find abuse, keep audit logsSign-in and security recordsLegitimate interests (security); legal obligation
Answer support requests and fix problemsAccount data; client data when neededContract; legitimate interests
Enforce our Terms and the texting rules (for example, spam or unlawful messages)Account data; sending volumes and settingsLegitimate interests; legal obligation
Tell you about changes to SymoLink, these pages, or your billName, emailContract; legitimate interests
Answer a demo bookingWhat you typed in the formSteps before a contract; legitimate interests
Send and receive the customer’s texts and calls, sync them with the CRM, show phone healthClient dataOn the customer’s instructions (we are the processor)

We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use client data to train AI models, and we make no decisions about people based solely on automated processing that have legal or similarly significant effects on them.

5Who we share it with

Service providers we use (our sub-processors)

ProviderWhat they do for usWhere
HostingerOur servers: the database, the app, call recordingsMalaysia
CloudflareDomain names, secure network connection to our servers, email forwarding for our addresses, and storage of our encrypted backupsWorldwide network; backups in Asia Pacific
ResendSends our sign-in, password and billing emailsJapan (sending region); United States company
StripeTakes card payments and keeps card details for our subscriptionsUnited States and worldwide

The full list, with any changes, is in our Data Processing Addendum.

Services the customer chooses

Some data goes to services the customer connects, under the customer’s own account and agreement with them. These are not our sub-processors; we send data to them because the customer tells us to:

  • The customer’s CRM, which SymoLink reads contacts from and writes messages, calls and call notes to.
  • Mobile carriers: texts and calls travel over the mobile network of the SIM in the customer’s phone.
  • AI providers, if the customer switches on call summaries and adds its own keys: the recording goes to OpenAI to be written out, and the transcript (with the phone numbers, direction, length and outcome of the call) goes to Anthropic for the summary.
  • WhatsApp, if the customer links a WhatsApp account.
  • The agency’s own email or payment accounts, if an agency connects them to send emails or bill its own clients (for example Resend, Stripe, PayMongo, PayPal or Xendit).

Support access

Our support team can open an agency’s account to help only while that agency allows it (Agency Settings → SymoLink support; the agency can switch it off at any time). Every visit and every change is written in the agency’s audit log. While helping, we may see client data, and we use it only to solve the problem.

Other cases

  • The law: if a valid legal request (such as a court order) requires it. Where the law allows, we tell the customer first.
  • Safety and abuse: to stop fraud, spam or harm, or to protect our rights and users.
  • A business change: if Flowsier LLC is merged or sold, the new owner would continue this policy, and we would tell you.

6Where it is stored

Our servers and database are in Malaysia. Encrypted backups are stored with Cloudflare in Asia Pacific. Our providers, and our company, are also in other countries, including the United States and Japan. When personal information from the European Economic Area, the United Kingdom or Switzerland is moved to a country without an adequacy decision, we use the European Commission’s Standard Contractual Clauses (and the UK and Swiss equivalents) with our customers and providers, as our Data Processing Addendum explains.

7How long we keep it

DataHow long
Messages, contacts, call details and summariesUntil a user deletes them or the client account is deleted. Customers can delete messages and contacts at any time.
Call recordings and transcripts90 days by default, then deleted automatically (the customer can choose a different period). The short call summary stays with the call.
Phone health history (battery, signal)7 days by default (an agency can choose 1 to 30). The latest status is kept while the phone is linked.
A client account after its CRM removes the SymoLink app30 days, in case the client installs it again. Then its CRM connection and CRM links are deleted, and, if the account was created by that install and has no seats, phones or Boxes left, the whole client account with its messages, calls and contacts. An account still in use stays until its agency deletes it.
A client account its agency deletesDeleted at once, with its messages, calls, contacts, phones and its audit log. A short record that it was deleted stays in the agency’s audit log.
Your login, sign-in records and audit logWhile your login or the account exists. Sign-in sessions end after 30 days.
Agreement records (these pages, country rules)While the account exists, and afterwards as long as we may need them to show what was agreed.
Billing records and invoicesAs long as tax and accounting law requires.
BackupsEncrypted copies of the database roll off after 31 days. Deleted data leaves the backups within that time.
Demo bookings and support emailsAs long as we need them to answer and follow up, then deleted.

Deleting an account

  • An agency can delete any of its client accounts in the dashboard (Clients → Delete client account).
  • Users can delete messages and contacts in the dashboard.
  • To close your whole company account, or to delete your own login, email [email protected] from the address on the account. We confirm it is you, then delete it within 30 days, except records we must keep by law (such as invoices).

8How we protect it

  • Every connection to SymoLink is encrypted (HTTPS, HSTS), and the SymoLink Box checks our server’s certificate before it connects.
  • Passwords are stored only as Argon2id hashes. Repeated wrong passwords pause sign-in, and sensitive actions ask for your password again.
  • CRM tokens, linked WhatsApp sessions, saved keys, call recordings and transcripts are encrypted with AES-256-GCM, each with its own key.
  • Each agency’s data is kept apart from every other agency’s, and we test that separation automatically.
  • Servers sit behind firewalls; the admin panel is reachable only through a protected Cloudflare login.
  • Backups are encrypted (AES-256) before they leave the server, and we test restoring them.
  • Logs leave out passwords, tokens and other secrets.
  • Important actions are written in audit logs that the agency can read.

No system is perfectly secure. If a breach affects your personal information, we will tell the affected customers without undue delay, as the law and our Data Processing Addendum require.

9Cookies and browser storage

  • symolink.com sets no cookies and runs no analytics or advertising. The page loads its fonts from Google Fonts, so your browser sends your IP address to Google when it fetches them. The demo form at forms.flowsier.com may use its own cookies to work.
  • app.symolink.com (the dashboard) uses two cookies that it needs to work: one keeps you signed in (up to 30 days) and one protects your forms against cross-site attacks. It also keeps your settings in your browser’s storage, such as the account you last opened, light or dark mode, your sound devices for calls and your recently dialled numbers. Nothing is used for tracking or advertising, so no consent banner is needed.
  • Help videos in the dashboard play from YouTube (privacy-enhanced mode), Vimeo or Loom only when you open them.

10Your rights

Depending on where you live, you may have the right to:

  • know what personal information we hold about you and get a copy;
  • correct it;
  • delete it;
  • get it in a portable format;
  • object to, or ask us to limit, some uses;
  • withdraw consent where we rely on it;
  • complain to a data protection authority.

To use them, email [email protected]. We answer within 30 days (45 days for California requests, which we may extend once as the law allows). We may ask you to confirm who you are, and you may use an authorised agent. We will never treat you differently for using your rights.

For client data (messages and calls with a business), we pass your request to the business that controls it and help it answer.

11California (CCPA)

This section adds to the rest of this policy for California residents, under the California Consumer Privacy Act as amended by the CPRA.

  • Categories we collected in the last 12 months (as a business, for account data): identifiers (name, email, IP address); commercial information (plan, seats, invoices); internet activity (sign-in and audit records); professional information (company and role); and account login details. Sources: you, your company, and our own systems. Purposes and recipients are in sections 4 and 5.
  • Sensitive personal information: only your account login (email and password), used only to sign you in. We do not use it to infer anything about you.
  • No selling or sharing: we do not sell personal information or share it for cross-context behavioural advertising, and have not in the last 12 months. We have no actual knowledge of selling or sharing information of anyone under 16.
  • Service provider: for client data, we act as our customers’ service provider and use it only for the business purposes in our Data Processing Addendum.
  • Your rights: to know, delete, correct, and not be discriminated against (section 10).

12Europe and the UK (GDPR)

If you are in the European Economic Area, the United Kingdom or Switzerland, the legal bases for each use are in section 4, and transfers are covered in section 6. Where we rely on legitimate interests, you can object, and we will stop unless we have compelling reasons. You can complain to the data protection authority where you live or work. We have not appointed a representative in the EU or the UK; write to us at [email protected].

13The Philippines

For people in the Philippines, we handle personal information in line with the Data Privacy Act of 2012 (Republic Act No. 10173). For client data we are a personal information processor for our customers. You have the rights in section 10, including the right to be informed, to object, to access, to correct, to erasure or blocking, to data portability and to damages, and you may complain to the National Privacy Commission.

14Children

SymoLink is a business service for adults. It is not meant for anyone under 18, and we do not knowingly collect personal information from children for our own purposes. If you think a child gave us their details, write to us and we will delete them.

15Changes to this policy

When we change this policy, we update the effective date at the top. If a change is important, we tell account Owners by email or in the dashboard before it takes effect.

16Contact us

Flowsier LLC, a Wyoming (United States) limited liability company

Postal address: 5830 East 2nd Street, Casper, WY 82609, United States

Privacy and legal: [email protected]

Agency support and billing: [email protected]