Privacy Policy
Last updated: 17 September 2026 · English
1. Who we are
FrostDesk is operated by ARMOFLOW LTD, registered in England and Wales under company number 17081481. Our registered office is 167–169 Great Portland Street, London, England, W1W 5PF, United Kingdom. Contact us at hello@armoflow.com or write to that address, marked “Privacy — FrostDesk”.
This policy covers our website, business accounts, enquiries, and the customer information processed through FrostDesk’s communication and booking services.
ARMOFLOW LTD determines how information is used to run its website, administer its business relationships and subscriptions, provide support, and protect its service. For customer conversations and bookings managed on an instructor’s or business’s instructions, that instructor or business determines the purpose of the processing and FrostDesk provides the processing service. The instructor’s own privacy information also applies.
If you are an instructor’s customer, contact the instructor about your lesson, booking or conversation records. You may also contact us, and we will help identify the responsible business.
2. Information we process
| Information | Examples and sources |
|---|---|
| Accounts and business profiles | Name, email, phone number, account identifiers, authentication information, professional profile, photograph, languages, locations, services, prices and availability supplied by the user or an authorised sign-in provider. |
| Customers and bookings | Contact details, dates, times, party size, skill level, preferences, meeting points, booking status, payment status and notes supplied by customers or instructors. |
| Messages and integrations | Messages, replies, subjects, timestamps, sender and recipient identifiers, calendar information and authorisation tokens from connected services. Messages may contain information about other people. |
| Payments and subscriptions | Stripe account and transaction identifiers, billing details, amounts and subscription status. Payment card entry and connected-account verification are handled through the payment provider’s interfaces. |
| Technical information | IP address, browser and device information, requests, errors, security records, feature events and browser storage. Optional website analytics is governed by the consent choices described in our Cookie Policy. |
| Derived information | Conversation summaries, proposed replies, extracted booking details, operational history and customer priority indicators generated from the records above. |
Information comes from you, the instructor or business serving you, connected providers, and your use of the service. Public instructor profiles contain information the instructor chooses to publish and may be viewed or indexed by others.
Some information is needed to create an account, answer a request, process a payment or arrange a booking. Without it, the corresponding service may not be available. Optional integrations and analytics are not required for every feature.
3. Purposes and legal bases
For processing where ARMOFLOW LTD is the controller, we use the following purposes and bases:
| Purpose | Basis |
|---|---|
| Provide accounts, requested features and support; administer subscriptions and payments | Performance of a contract with you or steps you request before entering one. For contacts acting for a business, our legitimate interest in administering that business relationship. |
| Keep required financial records and respond to lawful regulatory requests | Compliance with applicable legal obligations. |
| Protect accounts, prevent abuse, diagnose faults and keep the service reliable | Our legitimate interests in operating and securing the service, taking account of the rights and interests of the individuals concerned. |
| Respond to business enquiries and publish instructor profiles at their request | Requested pre-contractual steps, performance of the requested service, or our legitimate interest in managing business enquiries, depending on the activity. |
| Optional website analytics | Consent, as described in the Cookie Policy. |
| Handle privacy requests and legal claims | Applicable legal obligations and our legitimate interest in establishing, exercising or defending legal claims. |
For customer information handled on an instructor’s instructions, the instructor determines the applicable legal basis. Enabling an integration does not by itself establish a legal basis for every use of another person’s information.
4. Connected services
Google sign-in: Google supplies the account information needed to authenticate through Supabase. Signing in does not itself connect Gmail or Google Calendar.
Gmail: When connected, the requested permissions allow reading email and sending replies on the connected account’s behalf. FrostDesk imports messages according to its channel rules and can use their content in the inbox and AI-assisted workflows. The read permission is broader than access to a single selected message.
Google Calendar: The connected service reads calendar information to establish availability and can create or update booking events using the permissions granted.
Google API information is used for the connected communication, availability and booking features described here. Its use and transfer are subject to the Google API Services User Data Policy, including the Limited Use requirements. Only connect an account if you are authorised to use its contents for these purposes, including the AI processing described below.
Connections can be disconnected in FrostDesk and permissions revoked through the provider’s account settings. Disconnecting an integration does not automatically erase records already imported.
WhatsApp: Meta delivers messages and identifiers for connected business messaging and carries outgoing replies. This does not provide general access to the contents of a person’s phone.
Stripe: Hosted payment and connected-account interfaces collect payment or verification information directly. Stripe also processes information for its own payment, security, fraud-prevention and legal responsibilities.
5. AI assistance and automated workflows
When the business enables AI features, FrostDesk sends relevant message content and business context to OpenAI’s API. This supports interpretation of requests, replies, summaries and booking workflows. Context may include names, conversation history, service details, availability, booking information and the instructor’s preferences. It can include information imported from Gmail or WhatsApp.
Outputs and operational records may be stored in FrostDesk. Depending on the business’s settings, a reply or booking action may require review or run automatically. Booking workflows use extracted request details together with configured services, availability and business rules; their output can affect the proposed booking or response. Customer priority indicators can reflect booking history, value and manual choices made by the instructor.
AI output can be inaccurate. Contact the instructor to request human review, correct the information used, or discuss a booking or response. Contact ARMOFLOW LTD for questions about its own processing.
OpenAI describes its standard API service as not using submitted data for model training unless the customer opts into sharing, and generally retaining abuse-monitoring content for up to 30 days, with exceptions such as legal requirements. These are provider terms, not a claim that FrostDesk has a special zero-retention arrangement. See OpenAI’s data controls.
6. Who receives information
Information is available to the responsible instructor or business and authorised people providing the service or support. Providers involved in the features used include:
- Supabase: database, authentication and application file storage.
- Vercel and Railway: frontend and backend hosting, request handling and operational records.
- OpenAI: the AI processing described above.
- Google and Meta/WhatsApp: connected sign-in, email, calendar, maps and messaging services; Google also provides optional Analytics.
- Stripe: payments, subscriptions and connected-account services.
- iubenda: cookie preferences, consent management and associated technical information.
- Sentry and internal notification providers, when configured: diagnostics, performance information, operational alerts and service notifications. Slack may receive information included in internal account or operational notifications.
Relevant information may also be shared with professional advisers, authorities where required, or parties to a business reorganisation under applicable legal requirements. Providers publish their own privacy information. Information intentionally published in an instructor profile is available to visitors.
7. Locations and international processing
Our primary Supabase database is hosted in Ireland, in AWS region eu-west-1. Other providers and connected services may process information in the United Kingdom, the United States and other countries in which they operate. The database’s location does not mean that every processing activity takes place in Ireland.
The transfer arrangements depend on the recipient and service. Applicable safeguards may include an adequacy decision or contractual safeguards such as the European Commission’s Standard Contractual Clauses with the relevant UK provisions. You can ask hello@armoflow.com for the arrangements applicable to a particular service and copies of relevant safeguards.
8. How long information is kept
Retention depends on the purpose and type of record. The criteria used are whether the information remains necessary to provide an active service, resolve an enquiry or dispute, follow the responsible instructor’s instructions, or meet an applicable legal obligation.
- Account and service records: the period needed to operate the account and then deal with closure, outstanding obligations and justified claims.
- Customer messages, bookings and notes: the purpose of the instructor’s service, their documented instructions, open bookings and relevant legal requirements.
- Support and operational records: the time needed to resolve the matter, investigate faults or security issues, and retain a proportionate record of the outcome.
- Financial records: the applicable accounting and tax requirements. These requirements do not automatically justify keeping unrelated messages or notes.
- Browser storage: the periods described in our Cookie Policy.
Supabase provides daily physical database backups with approximately seven days of recovery history under the current setup. Point-in-time recovery is not enabled. These database backups contain metadata about uploaded files, but not the files stored through Supabase Storage.
Removing a customer from the CRM currently marks the profile as deleted; it does not itself permanently erase the underlying profile, bookings or notes. Disconnecting an integration or expiring a booking link also does not necessarily delete the associated records. For a request to erase or return information, contact the instructor or our privacy address. Required records and justified legal holds can affect what may be erased; retained backup copies are distinct from the records in active use.
9. Your rights and requests
Depending on the applicable law and processing, you may request access, correction, erasure, restriction and a portable copy of your information. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Right to object: You may object to processing based on legitimate interests for reasons relating to your situation. You may object at any time to use of your information for direct marketing, if such processing takes place.
Send requests to hello@armoflow.com, identifying the service and information concerned. We may need proportionate information to verify identity. For records controlled by an instructor, we may refer the request to that instructor and assist them.
You may complain to the UK Information Commissioner’s Office or, where applicable, the data protection authority where you live, work or consider an infringement to have occurred.
10. Security, children and sensitive information
FrostDesk uses authentication and access controls, protects integration tokens and keeps operational records intended to support security. Account permissions, provider settings and the information users choose to share also affect security.
Instructor accounts are intended for business use. Bookings can involve children where arranged by a parent or instructor. The responsible business must provide appropriate information and establish the conditions for processing those records.
Avoid including health or other sensitive information in free-text messages or notes unless it is necessary and the responsible business has established the relevant legal conditions and safeguards. Content supplied to enabled AI workflows may be processed as described in section 5.
11. Cookies and policy updates
Our Cookie Policy explains device storage and tracking choices. We update the date of this policy when it changes and provide further information where needed for material changes in processing.