1. Scope and roles
Construct Labs operates this website and provides AgencyFlow and related services. This policy applies when you visit our website, contact us, join a pilot, install a product, or use a service that links to this page.
For website inquiries, product accounts, security records, and direct business contacts, Construct Labs generally decides why and how information is processed.
For information processed through a customer’s connected business account, the customer or agency may decide the purpose of processing and Construct Labs may act as a service provider or processor. Requests about that information may need to be handled by the customer that controls the account.
2. Information we collect
Website and contact information
- Your email address, name, company, and the contents of a message when you contact us.
- When you call support, your phone number, call time, routing metadata, and what you say to the automated voice assistant may be processed to answer the call. Call recording is not enabled.
- For a pilot application, the number range of client accounts you manage, your description of the repeated task, and your consent to be contacted about AgencyFlow.
- Basic request data such as IP address, browser type, device type, requested page, referring page, timestamps, and security signals.
AgencyFlow account and installation information
- User, agency, company, application, and client-account identifiers supplied by the connected platform.
- User role, account type, agency-owner status, and the active client-account identifier used to verify access.
- OAuth access and refresh tokens, granted permissions, token expiration, installation status, and reauthorization status.
- Application install and uninstall event identifiers, timestamps, and the minimum routing metadata needed to process those events.
Revenue Guard information
- Inbound or outbound direction, normalized communication channel, client-account identifier, event time, response deadline, response status, and response duration.
- One-way hashes of contact and conversation identifiers used to match inbound and outbound events without retaining the original identifiers in response records.
- Response-target settings and an optional estimated lead value entered by the agency.
AgencyFlow discards message bodies, names, email addresses, phone numbers, sender and recipient fields, attachments, and other webhook fields that Revenue Guard does not need. Full webhook payloads are not logged or stored.
3. Where information comes from
We receive information directly from you, from your browser or device, from the third-party platform where you install AgencyFlow, and from service providers that help us operate and secure the service.
We do not purchase marketing lists or obtain connected CRM customer records from data brokers.
4. How we use information
We use information to:
- provide installation, authentication, token refresh, portfolio status, response monitoring, attention queues, and limited alerts;
- respond to support, sales, security, and legal requests;
- protect accounts, investigate failures, prevent abuse, and maintain service reliability;
- measure product operation and improve features using limited technical and aggregate information;
- administer pilots, subscriptions, billing, and business records;
- comply with law and enforce our agreements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use connected account data to train general-purpose models.
5. Legal bases
Where a legal basis is required, we process information as needed to perform a contract, take steps requested before entering a contract, pursue legitimate interests in operating and securing the service, comply with legal obligations, or act with consent.
Our legitimate interests include preventing fraud, maintaining service reliability, answering business inquiries, improving product operation, and protecting customers. You may object to processing based on legitimate interests as described below.
7. Retention
We keep information only for as long as needed for the purposes described here, including service operation, security, dispute resolution, and legal obligations.
| Record | Typical period |
|---|---|
| OAuth state | 10 minutes, followed by automatic expiration. |
| Webhook deduplication record | 7 days. |
| Resolved Revenue Guard record | 30 days. |
| Unmatched outbound routing record | 24 hours. |
| Pilot-form email deduplication hash | 24 hours. The record contains a one-way email hash and expiration, not the submitted form fields. |
| Application logs | 7 days. Webhook bodies and pilot-form contents are not logged. |
| Failed queue messages | Up to 14 days. |
| OAuth tokens | While the installation is active. Tokens are removed when an uninstall is processed or reauthorization is required. |
| Installation, settings, and unresolved response metadata | While the service is active, then for a limited period needed for account closure, security, support, and legal records. |
| Pilot applications and business communications | For as long as needed to review the application, manage the inquiry or business relationship, and meet recordkeeping duties. |
Backups and provider-level recovery copies may persist briefly after deletion before normal rotation removes them.
8. Security
We use administrative, technical, and organizational safeguards appropriate to the information we process. Current controls include HTTPS, managed encryption at rest, narrowly scoped access permissions, separate secret storage, short log retention, redacted logs, one-time OAuth state, webhook signature checks, bounded retries, and short-lived embedded sessions kept in browser memory.
No system is completely secure. If you believe information or credentials have been exposed, contact us immediately. Do not send the credentials themselves.
9. International transfers
Construct Labs and its service providers may process information in the United States and other countries. Privacy laws in those locations may differ from the laws where you live. Where required, we use recognized transfer safeguards or another lawful transfer mechanism.
10. Your privacy rights
Depending on where you live, you may have the right to request access, correction, deletion, portability, restriction, or an objection to certain processing. You may also have the right to withdraw consent and appeal a denied request.
We do not discriminate against anyone for exercising a privacy right. We may need to verify your identity and authority before acting. If the request concerns data controlled by your agency or another customer, we may direct the request to that organization.
To submit a request, email hello@constructlabs.io with the subject “Privacy request.” You may also complain to the data protection authority in your jurisdiction.
United States state notices
During the preceding 12 months, we may have collected identifiers, internet or device activity, professional or business information, commercial or subscription records, and account credentials. We use and disclose these categories for the business purposes described in this policy. We do not sell them or share them for cross-context behavioral advertising.
11. Children
Our website and services are for businesses and adults. They are not directed to children under 18, and we do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy when our products, service providers, or legal duties change. The current version will remain at this URL with an updated effective date. We will provide additional notice when required by law or when a material change affects active customers.
13. Contact
Privacy and security questions can be sent to hello@constructlabs.io.
Construct Labs
United States