Privacy policy
Last updated 10 October 2026
Vexa Flow (flow.vexalabs.io) is agency management software made by Vexa Labs (vexalabs.io). This policy explains what information we collect when agencies and their teams use Vexa Flow, why we collect it, and the choices you have.
Who is responsible
Each agency that signs up is responsible for the information about its own clients and team that it puts into Vexa Flow. Vexa Labs runs the software and looks after that information on the agency's behalf. Questions about this policy can be sent to hello@vexalabs.io.
What we collect
- Account details: names, work email addresses, mobile numbers and positions of agency owners and team members, and a securely hashed password and optional PIN.
- Agency details: company name, logo, address, GST number, website and contact details that the owner adds.
- Work information: clients, monthly plans, tasks, due dates, review notes, chat messages and client payment records that the team enters.
- Technical information: IP address, browser type and sign-in times, used to keep accounts secure and to stop misuse.
- Trial requests: the details sent through the sign-up form on our website.
Google Drive and Google user data
An agency owner can choose to connect the agency's own Google Drive. When they do, Vexa Flow asks Google for these permissions only:
drive.file: to create folders and save, show and delete only the files that people upload through Vexa Flow. We cannot see or open any other file in the Drive.emailandopenid: to show which Google account is connected.
Videos, graphics, voice notes and client documents uploaded in Vexa Flow are stored in the agency's own Google Drive, not on our servers. We keep only the file name, size and Drive file ID so the team can find and preview the file. We store the connection token securely so uploads keep working, and we delete it when the owner disconnects Google Drive.
Vexa Flow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and no person reads it except when the agency asks us for help or the law requires it.
The owner can disconnect Google Drive at any time from the Google Drive page in Vexa Flow, or remove access from their Google account at myaccount.google.com/permissions.
How we use information
- To run Vexa Flow: sign people in, show tasks, route work, send in-app reminders and show performance reports.
- To keep accounts safe: detect wrong-password attempts and misuse.
- To manage the agency's trial and subscription, and to reply to support requests.
We do not sell personal information and we do not use agency or client data to advertise.
Who can see what
Each agency works in its own separate space. Inside an agency, people see only what their role allows: owners see everything in their agency, managers see their own team, and other team members see the clients they work on. Client approval links show one piece of work to whoever holds the link, until it expires.
Service providers
We use a hosting provider to run our servers and database, and Google to store files when an agency connects Google Drive. These providers process data only to provide their service to us.
Cookies
We use essential cookies only: one to keep you signed in, one to remember your device until you log out, and a security token that protects forms. We do not use advertising or tracking cookies.
How long we keep data
We keep an agency's data while its account is active. If a trial or plan ends, the data is kept so the agency can continue later. An agency owner can ask us to delete the agency's account and data by writing to hello@vexalabs.io; files in the agency's own Google Drive stay under the agency's control.
Security
Data is sent over encrypted HTTPS connections. Passwords and PINs are stored as one-way hashes, sign-in attempts are limited, and access inside each agency follows its roles.
Your choices
Team members can update their password and PIN in My account. To see, correct or delete personal information, contact your agency owner or write to us at hello@vexalabs.io.
Changes
We will update this page when our practices change and show the new date at the top.