What happens to the data a flower business runs on.
This policy covers the stock, order and customer information handled by the platform, and the details submitted through the sign-up and contact forms on this site.
Scope of this policy
Two different kinds of information are described here, and they are treated differently. The first is business data: inventory batches, intake records, orders, delivery windows and the operational settings a florist or gifting studio configures. The second is personal data: the details of the people who sign up, and the customer and recipient records a subscribing business chooses to store in the platform.
For business data and for the customer records loaded by a subscribing business, that business is the owner and decision-maker. The platform processes it on their instructions in order to provide freshness tracking, demand forecasting, bundling suggestions and delivery scheduling.
Business data you load
Inventory and operational records are processed solely to run the features the subscribing business has enabled. In practice that means:
- Intake records, batch quantities, grades, supplier identity and received dates are used to calculate freshness windows per batch.
- Order history is used to produce demand forecasts and to measure delivery-window performance.
- Operational settings such as margin floors, protected varieties, window capacities and cut-off times are used to constrain what the platform suggests.
Business data is not used to benchmark one subscriber against another in a way that identifies either, is not sold, and is not supplied to suppliers, wholesalers or delivery partners except where the subscribing business sets up that connection themselves.
Customer and recipient records
Gifting means the buyer and the recipient are usually different people, and both may appear in a subscriber's records. Where a subscribing business stores customer names, contact details, delivery addresses, stated preferences, allergy notes or recurring occasion dates, those records belong to that business.
- They are used to present order history, apply preferences to a build and raise occasion reminders to the subscriber's own team.
- Occasion reminders are raised internally to the subscriber. No marketing message is sent to a subscriber's customer or gift recipient from this platform.
- A subscriber's customer list is never used to market this platform, and is never shared with another subscriber.
Subscribing businesses are responsible for having a lawful basis to store the recipient details they enter, and for responding to requests from their own customers about those records. Export and deletion tools are available to support that.
Information submitted through forms
The sign-up and contact forms on this site collect a name, a business name, a work email address, a city, a role, an indication of order volume, how stock is currently tracked, and any message that is typed in. These are used to create and configure an account, to reply to an enquiry, and to prepare a walkthrough.
Form submissions are delivered by email to the operating team through a transactional email provider. They are not added to a marketing mailing list, and no newsletter is sent on the basis of a form submission.
The forms include an arithmetic verification step and a hidden field that genuine visitors never fill in. These exist to reduce automated submissions, and neither creates a profile of the visitor or tracks them across sites.
How forecasts and suggestions are derived
Freshness positions are arithmetic: a received date measured against a vase-life profile, adjusted by the handling conditions recorded at intake. Demand forecasts are built from a subscriber's own order history, weighted toward recent months, with a regional occasion calendar and seasonal shape layered on top. Bundle suggestions are composed from stock currently in the watch zone, the formats already sold by that business, and the margin floor it has set.
No automated decision is taken that affects a subscriber's customers without a person approving it. Price changes, promotions and bundle releases all require an explicit release by an authorised account, and that release is recorded.
Who the data is shared with
Data reaches third parties only in these situations:
- Infrastructure and hosting providers that run the platform and store its data under contract.
- A transactional email provider used to deliver account emails, enquiry notifications and operational alerts.
- Suppliers or delivery partners that a subscribing business explicitly connects, and only the fields needed for that connection.
- Where disclosure is required by law or to respond to a valid legal process.
There is no sale of data, and no sharing for advertising purposes.
Retention, export and deletion
Inventory, order and customer records are retained for as long as an account is active, because historical records are what make freshness accuracy and demand forecasting work. A full export in a standard, readable format is available at any time while the account is live, and remains available through the end of a paid term after cancellation.
Deletion of an account and its records can be requested at any point. Once deletion is carried out, forecasts and reports that depended on that history cannot be reconstructed. Enquiry correspondence is kept only as long as it is useful to the conversation it belongs to.
Security measures
Traffic between a browser and the platform is encrypted in transit. Stored data, including backups, is encrypted at rest. Access inside the platform is role-based, so bench and delivery staff do not automatically see commercial figures such as margins and supplier pricing. Price approvals, bundle releases, stock adjustments and capacity overrides are written to an audit trail with the account and the time.
No system is beyond compromise. Where an incident affects a subscriber's data, that subscriber is informed with what is known, what is affected and what is being done, rather than after the fact.
Cookies and site measurement
This marketing site does not set advertising or cross-site tracking cookies, and does not embed social network tracking. The signed-in platform uses cookies that are necessary for authentication and for keeping a session active, which cannot be switched off without preventing sign-in.
Web fonts on this site are requested from a third-party font service, which means that service receives the request. No cookie is set by the site for that purpose.
Your choices
Anyone who has submitted a form or holds an account can ask what is held about them, ask for it to be corrected, ask for a copy, or ask for it to be deleted. Where a request concerns records stored by a subscribing business about its own customers, the request is passed to that business, since the records are theirs to act on.
Requests can be made through the contact form on this site.