Privacy Policy
Effective date · July 28, 2026
Florii is an all-in-one platform that helps flower shops run their business — managing inventory, products, orders, a public storefront, AI assistants, and social media — all in one place. This Privacy Policy explains what personal information we handle, why, and the choices and rights you have. We've written it in plain English because we want you to actually understand it.
A note on our two roles. Florii serves two different groups of people, and our privacy responsibilities differ for each. For the florists and their staff who hold a Florii account, we are the data controller. For a florist's own customers and shoppers — the people whose details a florist enters into Florii or who interact with a florist's storefront and AI receptionists — the florist is the data controller and we act only as a processor on the florist's behalf. This distinction runs through the whole policy, so we explain it carefully in Section 2 and again where it matters.
1. Introduction & Who We Are
Florii is a software-as-a-service platform for running a flower shop. Through the Florii web application at florii.app and the Florii mobile app for iOS and Android, florists, shop owners, and their staff can manage inventory and supplies, build product arrangements and recipes, take and track orders, run a public online storefront, use AI assistants (a dashboard co-pilot and storefront text and voice receptionists), generate product imagery, and publish to connected social media accounts. Florii is a multi-tenant platform: each flower-shop business is a shop, and a person can belong to one or more shops with a role of owner, admin, or staff. The service and this policy are provided in English only.
Florii is operated by Braintu Inc., located at 251 Little Falls Drive, Wilmington, Delaware 19808, USA ("Florii", "we", "us", or "our"). Throughout this policy we refer to the florists and staff who hold a Florii account as "you".
Scope. This policy primarily governs the personal information we handle as a controller — chiefly the account and business information of the florists and staff who use Florii. It also explains, for transparency, the categories of personal information we process on a florist's behalf when a florist uses Florii to manage their own customers and storefront. For that processor activity, the florist's own privacy policy governs how the data is used, and an individual end customer's rights run through the florist. We say more about this in Sections 2, 6, and 13.
2. Who This Policy Covers
Florii touches the personal information of two distinct groups of people, and our responsibilities are different for each. Please find the group that applies to you.
Account Users (florists, owners, and staff)
Account Users are the people who register for and use the Florii dashboard — shop owners, admins, and staff. For the personal information that relates to your Florii account and your use of the service, Florii is the data controller: we decide how and why that information is processed, and the rights described in Section 12 apply directly between you and us.
End Customers and Shoppers (a florist's own customers)
End Customers and Shoppers are the florist's own customers — the people whose details a florist enters into Florii (for example, order and delivery information) and the people who interact with a florist's public storefront, AI text receptionist, or AI voice receptionist. For this information, the florist is the data controller and Florii acts only as a processor, handling the data on the florist's behalf and under the florist's documented instructions.
If you are an End Customer or Shopper and want to exercise your privacy rights — to access, correct, or delete information held about you, for example — please contact the florist (the flower shop) you dealt with. For End Customers and Shoppers, the florist is the controller and must respond to data-subject requests; Florii will support the florist but will not respond to the individual directly without the florist's instruction, because the data belongs to the florist's business and is isolated to their shop. See Section 13 for more.
3. Information We Collect
The information below reflects what Florii actually collects and stores. Most of it lives in our primary backend (Supabase). We do not collect more than we describe here — in particular, we use no advertising trackers. We do run first-party product analytics for Account Users (never for a florist's own customers or shoppers), described under Technical & Usage Data below.
Account Information
When you create or use a Florii account, we collect your full name, email address, your phone number (if you sign in by phone), your role within each shop you belong to, and (optionally) an avatar. You can sign in with email and password (with email confirmation), a magic link / one-time email code, a phone number and one-time SMS code (the code is delivered by SMS through Twilio Verify), Google sign-in, or Microsoft sign-in. If you sign in with Google or Microsoft, we receive basic OAuth profile data from that provider (such as your name, email address, and profile image). If you register with a password, that password is hashed and managed by Supabase Auth — Florii never stores plaintext passwords and never sees your password in readable form.
Business & Shop Data
For each shop, we store business configuration such as the shop name, its slug/URL, timezone, branding colors, and currency. This also includes the settings that drive your AI features: your AI operating instructions (the "brief"), and your receptionist's greeting, instructions, and language preference.
Your Customers' & Order Data
Florii lets you keep a light CRM and manage orders, which means you may enter personal information about other people — your own customers and the recipients of flowers. This includes customer records (name, phone, email, notes) and orders, which can contain: the buyer's contact details (name, email, phone, notes); the recipient's details (name, phone, delivery address, notes); the occasion; the fulfillment type (delivery or pickup); the delivery date; the card message; line items; subtotal; delivery fee; total; currency; status; and channel (online, point of sale, or phone).
Important: this is third-party personal data that you, the florist, choose to input. For this data the florist is the controller and Florii is the processor. You are responsible for having a lawful basis to enter and store this information (for example, your relationship with the customer) and for giving any notices your customers are owed. Please don't enter more than you need to fulfill the order.
Storefront & Receptionist Interactions
When a shopper interacts with a florist's public storefront and its AI text or voice receptionist, Florii may capture a reception lead on the florist's behalf. A lead can include the shopper's name, contact details (email and/or phone), a message or summary of what they wanted, the kind of request (order, callback, or question), the channel (text or voice), and a status. These leads are stored for the florist and surfaced in the florist's dashboard, and a notification email may be sent to the florist (see Section 6).
Voice Interactions
The AI voice receptionist answers phone/voice calls on the florist's public storefront. To do this, live call audio is processed in real time by our voice provider (ElevenLabs) for speech-to-text and text-to-speech. Calls are recorded and transcribed end to end — including any portion where the call is transferred to a member of the florist's team — and Florii stores, on the florist's behalf: the call recording (audio), a full transcript of the conversation, and a summary in the florist's dashboard inbox. Callers hear a recording notice in the call greeting. Call audio and a person's voice are sensitive, and call recording is regulated differently across jurisdictions — including "two-party" and "all-party" consent rules. Because the florist operates the storefront and its phone line, the florist is responsible for any additional call-recording and consent notices required for their callers in their jurisdiction. Florii operates a shared voice agent configured per shop and processes this audio only to provide the receptionist service.
Social Media Connections
If you connect a Facebook Page or Instagram Business account, we store the connection details so Florii can publish on your behalf: the provider (Instagram or Facebook), the external account id, the username, the page id and name, the profile picture URL, the connection status, and who connected it. We also store a long-lived access token, which is kept server-side only and is never exposed to the browser.
Images & Media
You can upload product and supply images (stored in Supabase Storage), and Florii can generate AI draft images, which are held only temporarily. Uploads are limited to 10MB and to JPEG, PNG, WebP, and GIF formats. Please note that images you upload may contain personal information (for example, people's faces); you are responsible for having the right to upload and use such images.
Technical & Usage Data
Like any web service, your device's IP address and similar connection information are necessarily handled by our hosting and backend providers (Vercel and Supabase) to deliver and secure the application. Florii itself does not run geolocation or build advertising profiles. We also process your authentication and session information via the essential cookies described in Section 8. We do not use advertising pixels or cross-site tracking.
Mobile App Permissions
If you use the Florii mobile app, it asks for access to your camera, photo library, and microphone only when you choose to attach a photo or record a voice note in a conversation. The app does not access these in the background, and declining a permission only disables that attachment feature.
Product Analytics, Session Replay & Error Reports (PostHog)
To understand where Account Users get stuck and what errors they hit, we run product analytics through PostHog (one analytics project per product, hosted in PostHog's US cloud). For Account Users only, this collects: usage events (screens opened and actions taken in the dashboard and the mobile app), device and connection metadata, client-side error reports (including native crash reports from the mobile app), and session replays — recordings of what your screen showed during a dashboard or mobile session. Replays capture screen content as you saw it, including text you type and images you view; passwords are always masked. Once you sign in, this data is linked to your account id and email so we can see a real session behind a real problem.
Scope and limits. Analytics covers Account Users only: the public storefront, receipts, and every end-customer surface are never instrumented, so your customers and shoppers are not tracked by us. On the web, analytics events are sent through our own domain (first-party); marketing pages set no analytics identifiers until you sign in. In the mobile app, analytics runs only in production builds and reports directly to PostHog. We use analytics to improve the product — never for advertising, and we never sell it.
4. How We Use Information
We use personal information only for the purposes below. For users in the EEA, UK, and similar regimes, we also note the lawful basis we rely on under Article 6 of the GDPR/UK GDPR.
- Provide and operate the service — to set up and run your shop, store your inventory, products, orders, and customers, and deliver the features you use. Lawful basis: performance of our contract with you.
- Authenticate you and secure accounts — to sign you in, keep your session active, remember your active shop, and protect against unauthorized access. Lawful basis: performance of contract and our legitimate interests in security.
- Run AI features — to power the dashboard co-pilot and the storefront text and voice receptionists, and to generate and edit images. Lawful basis: performance of contract; and, where an AI feature is optional, your consent.
- Send transactional email — to deliver team-invitation emails and lead/handoff notifications to florists. Lawful basis: performance of contract and our legitimate interests in operating the service.
- Publish to social media on your instruction — to post images and captions to the Facebook Page or Instagram account you have connected. Lawful basis: your consent (you connect the account and can disconnect it at any time).
- Maintain security and prevent abuse — to detect, investigate, and prevent fraud, abuse, and security incidents, and to keep the platform reliable. Lawful basis: our legitimate interests and, where applicable, legal obligation.
- Comply with law — to meet our legal and regulatory obligations and to establish, exercise, or defend legal claims. Lawful basis: legal obligation and legitimate interests.
Where we process a florist's customer/order/storefront data, we do so only on the florist's instructions as their processor, for the purpose of providing the service — not for our own purposes.
5. Artificial Intelligence
Florii uses AI to help you work faster. We are transparent about which providers power these features and what data is sent to them. All text AI requests are routed through the Vercel AI Gateway to the model providers below.
Dashboard AI co-pilot and storefront text receptionist — Anthropic (Claude)
The dashboard co-pilot and the storefront text receptionist are powered by Anthropic's Claude (default model Claude Sonnet, currently claude-sonnet-5, and configurable), reached via the Vercel AI Gateway. For the co-pilot (authenticated dashboard), Claude may receive your shop and business data, inventory, product information, account-user names, and the conversation messages, and — at your direction — can read and write inventory, products, and orders, generate or edit images, and publish to your connected social accounts. For the storefront text receptionist, Claude sees only your public catalog (no costs and no stock levels), answers shopper questions, and can capture a lead.
Image generation and editing — Google (Gemini)
Product photos, storefront banners, and social post images are generated and edited using Google's Gemini (model gemini-2.5-flash-image), reached via the Vercel AI Gateway. Gemini receives product descriptions, your styling instructions, and any images you provide.
Voice receptionist — ElevenLabs
The storefront voice receptionist is powered by ElevenLabs voice agents ("Convai"), which handle speech-to-text and text-to-speech for phone/voice calls, over telephony provided by Twilio (which provisions the shop's phone number, carries its calls, and produces the call recordings we store on the shop's behalf). ElevenLabs processes the live call audio and conversation content and receives the shop name, currency, public catalog, and the conversation in order to answer the call and capture a lead; it also performs speech-to-text on call recordings. Please also see the Voice Interactions note in Section 3.
Model training
Data sent to these AI providers is used to generate responses for you and to provide the relevant feature. Where a provider offers the option, we configure our integration to opt out of using your data to train that provider's models. We keep this statement aligned with the terms actually in force with Anthropic, Google, and ElevenLabs.
Accuracy and human oversight
AI output can be incomplete or inaccurate. AI suggestions are tools to assist you, not a substitute for your judgment — please review AI-generated content, prices, and customer responses before relying on or publishing them.
6. How We Share Information & Our Sub-processors
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California law (the CCPA/CPRA). We do not rent or trade personal information. We disclose personal information only to the service providers ("sub-processors") that help us run Florii, and in the limited other circumstances described below.
Our sub-processors
We rely on the following sub-processors, each engaged for a specific purpose and bound by terms that require them to protect personal information and process it only as needed to provide their service to us:
- Supabase — our primary backend: the PostgreSQL database, authentication (Supabase Auth), and file storage for images. Row-Level Security enforces strict per-shop data isolation. Supabase runs on Amazon Web Services (AWS).
- Vercel — application hosting and deployment, and the Vercel AI Gateway that routes all of our AI model requests.
- Anthropic — the Claude models that power the dashboard co-pilot and the storefront text receptionist (reached via the Vercel AI Gateway).
- Google (Gemini) — the Gemini model used for AI image generation and editing, reached via the Vercel AI Gateway.
- Google (OAuth) — Google OAuth for "Sign in with Google," used to authenticate Account Users who choose that method.
- Microsoft (Azure OAuth) — Microsoft OAuth for "Sign in with Microsoft," used to authenticate Account Users who choose that method.
- ElevenLabs — the AI voice receptionist that handles storefront phone/voice calls (speech-to-text and text-to-speech), and speech-to-text for call recordings.
- Twilio — telephony: provisions each shop's phone number, carries its calls, and produces the call recordings we store on the shop's behalf; also delivers the one-time SMS sign-in codes (Twilio Verify).
- Resend — transactional email delivery (team-invitation emails and lead/handoff notification emails sent to florists).
- PostHog — product analytics, session replay, and error/crash reporting for Account Users of the dashboard and mobile app (one analytics project per product, hosted in PostHog's US cloud). See Technical & Usage Data in Section 3.
- Meta Platforms, Inc. — social media publishing via the Facebook Graph API and Instagram, when you connect a Facebook Page or Instagram Business account.
- logo.dev — fetches a public business logo by website domain to display storefront logos. We send it only the public website domain you provide for your shop — we do not send it any customer or order data. Because logo images are requested from the visitor's browser, logo.dev may incidentally see the visitor's IP address, as with any web request.
Sub-processor changes
We maintain an up-to-date list of sub-processors and will provide florists with reasonable advance notice of any new or replacement sub-processor, so that florists can object where they have grounds to do so.
Other disclosures
We may also disclose personal information: (a) to comply with law or a valid legal request, or to protect the rights, safety, and security of Florii, our users, and the public; (b) in connection with a business transfer such as a merger, acquisition, financing, or sale of assets (with continued protection of the information under this policy); and (c) with your consent or at your direction. Where we act as a processor, any disclosure of a florist's customer data follows the florist's instructions.
7. Third-Party Platform Integrations
Sign in with Google or Microsoft
You can sign in to Florii using your Google or Microsoft account. When you do, we receive basic profile information from that provider (such as your name, email address, and profile image) to create and authenticate your account.
Google API Services User Data Policy (Limited Use). Florii's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide and improve the sign-in feature you requested and do not use it for advertising or sell it.
Likewise, when you use "Sign in with Microsoft," we use the Microsoft profile data we receive only to provide the sign-in feature you requested, and we do not use it for advertising or sell it.
Other sign-in methods
In addition to Google and Microsoft sign-in, you can authenticate with email and password (with email confirmation) or with a magic link / one-time email code. These methods are handled by Supabase Auth; see Section 3 (Account Information) for the data involved.
Meta (Facebook and Instagram)
If you connect a Facebook Page or Instagram Business account, you authorize the connection through Facebook Login (OAuth). We request least-privilege scopes — only what is needed to publish images and captions on your behalf — and we store the resulting long-lived access token server-side only, never exposing it to the browser. We use the access and data obtained through Facebook Login only to provide the publishing feature you connected, and we do not use it for advertising or sell it. You can revoke this access at any time by disconnecting the account in Florii or through your Facebook/Instagram settings. Our use of these platforms complies with the applicable Meta Platform Terms and Developer Policies.
Customer messaging channels (rolling out)
Florii is introducing a conversations inbox that connects a shop's WhatsApp, Instagram, and Facebook Messenger accounts, so a florist can read and answer customer messages from the Florii dashboard and mobile app. This feature is currently rolling out to selected shops. When your shop connects a messaging channel, Florii stores — on your behalf, as your processor — the conversations and messages exchanged with your customers, including attachments (such as photos and voice notes, which may be transcribed so your team and the AI assistant can read them). Channel connections are authorized through the platform provider (Meta) and can be disconnected at any time. A Slack connection remains planned but is not live; we will update this policy before it becomes available.
8. Cookies & Tracking
Florii uses only essential, strictly-necessary cookies — the minimum required to make the service work and keep it secure. We do not use any non-essential cookies.
- Supabase Auth session cookie (essential, not httpOnly) — keeps you signed in and maintains your authenticated session; it is read by the app in your browser to keep your session fresh.
- Active-shop cookie (essential, not httpOnly, persists about 1 year) — remembers which shop you are currently viewing; it is readable by the app in your browser.
- OAuth-state cookie (httpOnly, essential, lasts about 10 minutes) — provides CSRF protection while you connect a social account.
The public storefront shopping cart is kept in your browser's localStorage (not a cookie) so the storefront can remember your selections on your device.
We use no advertising pixels and no cross-site tracking. Our marketing pages set no analytics identifiers: before you sign in, any analytics run without cookies or persistent storage. After you sign in, our first-party product analytics (see Section 3) keeps its identifier in your browser's storage on our own domain so your session can be associated with your account. Because we rely only on strictly-necessary cookies plus this signed-in, first-party product analytics — and use no advertising or cross-site tracking — no cookie-consent banner is required under the applicable rules.
9. Data Security
We take security seriously and apply safeguards appropriate to the sensitivity of the data we handle:
- Encryption in transit — data is protected with TLS as it travels between you and Florii.
- Encryption at rest — data is encrypted at rest by our backend provider, Supabase.
- Per-shop isolation — Row-Level Security (RLS) enforces strict multi-tenant separation, so one shop's data is not accessible to another.
- Server-side token storage — OAuth and social access tokens are stored server-side only and are never exposed to the browser.
- Least-privilege access — we request least-privilege OAuth scopes for third-party connections.
- CSRF protection — social-account connection flows are protected against cross-site request forgery.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. We do not currently claim formal certifications such as SOC 2 or ISO 27001. Where we act as a processor and become aware of a personal-data breach affecting a florist's data, we will notify the affected florist without undue delay so they can meet their own obligations, and we will support any legally required notifications.
10. Data Retention
We keep personal information only for as long as we need it for the purposes described in this policy.
- Account & shop data (controller) — retained while your account and shop are active, and for a reasonable period afterward to handle wind-down, legal, and security needs, after which it is deleted or anonymized (generally within 30 days).
- Florist customer, order, and reception-lead data (processor) — retained according to the florist's instructions for as long as the florist uses Florii, and deleted or returned on termination of the florist's account, subject to any short-term backup retention.
- Voice call recordings and transcripts — stored on the florist's behalf alongside the conversation they belong to, and they follow the florist-data retention above (retained per the florist's instructions, deleted or returned on termination).
- Social access tokens — retained while the connection is active; deleted when you disconnect the account or your shop is closed.
- AI draft images — held only temporarily and not retained as permanent records.
- Backups — residual copies may persist in routine encrypted backups for up to 90 days before being overwritten.
Where we cannot state an exact period, we determine retention based on the nature and sensitivity of the data, the purpose for which we hold it, applicable legal requirements, and the need to resolve disputes and enforce agreements.
11. International Data Transfers
Florii relies on infrastructure and sub-processors that are based in or operate from the United States, including our hosting and database providers (Supabase runs on AWS; Vercel), our AI and voice providers (Anthropic, Google, ElevenLabs, Twilio), and our product-analytics provider (PostHog, US cloud). If you or your customers are located outside the United States — for example, in Latin America, the EEA, or the UK — your personal information may be transferred to and processed in the United States and other countries whose data-protection laws may differ from those where you are located.
Where the data-protection law that applies to you requires a specific safeguard for that transfer, we will put an appropriate one in place. Our primary hosting region is in the United States.
12. Your Privacy Rights
Depending on where you live, you may have rights over your personal information. This section describes the rights of Account Users, for whom Florii is the controller. If you are an End Customer or Shopper of a florist, please see Section 13 — your requests should go to the florist.
EEA / UK (GDPR and UK GDPR)
If you are in the EEA or the UK, you have the right to: access the personal information we hold about you; request rectification of inaccurate data; request erasure ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests; and withdraw consent at any time where we rely on consent (withdrawing consent does not affect processing already carried out).
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO), and in the EEA, your local data protection authority. We'd appreciate the chance to address your concerns first, but you can contact them at any time.
California (CCPA / CPRA)
If you are a California resident, you have the right to: know and access the personal information we collect, use, and disclose; delete personal information; correct inaccurate personal information; obtain a portable copy; and opt out of the sale or sharing of personal information — though, as noted in Section 6, we do not sell or share personal information. You may also limit the use of sensitive personal information. We will not discriminate against you for exercising your rights, and you may use an authorized agent to submit a request on your behalf.
The categories of personal information we collect, the categories of sources, the business and commercial purposes for which we use them, and the categories of sub-processors to whom we disclose them are described in Sections 3, 4, and 6. We disclose personal information to the sub-processors listed in Section 6 for the business purposes described there. In the preceding 12 months we have not sold or shared personal information for cross-context behavioral advertising.
How to exercise your rights
To make a request, email us at privacy@florii.app. To protect your information, we will take reasonable steps to verify your identity before acting, and we will respond within the timeframes required by applicable law (generally within one month under the GDPR/UK GDPR and within 45 days under the CCPA/CPRA, with extensions where permitted). For End Customers and Shoppers, the florist is the controller and must respond to data-subject requests; Florii will support the florist but will not respond to the individual directly without the florist's instruction. Requests that concern an End Customer's data held on a florist's behalf will therefore be routed to the relevant florist, who is the controller of that data.
13. For the Customers of Our Florists
If you are a customer or shopper of a flower shop that uses Florii — for example, you placed an order with a florist, or you interacted with a florist's storefront, AI text receptionist, or AI voice receptionist — please note that Florii processes your personal information on that florist's behalf, as their processor, and only under their instructions. The florist is the data controller for that information.
Because the florist controls this data and it is isolated to their shop, you should direct any privacy request — to access, correct, or delete your information, or to ask how it is used — to the florist (the flower shop) you dealt with. For End Customers and Shoppers, the florist is the controller and must respond to data-subject requests; Florii will support the florist and forward information as needed, but will not respond to the individual directly without the florist's instruction. The florist's own privacy policy, not this one, primarily governs how your information is used.
14. Children's Privacy
Florii is a business tool for flower shops and is not directed to or intended for children. The Florii service, and the storefronts and receptionists it powers, are not intended for use by children, and we do not knowingly collect personal information from anyone under 16 (or under 13 in the United States). If you believe a child has provided personal information through Florii, please contact us and we will take appropriate steps to delete it.
Florists should not enter the personal information of children into Florii without a valid lawful basis and any required parental consent.
15. Changes to This Policy
We may update this Privacy Policy from time to time as Florii evolves or as legal requirements change. When we make changes, we will revise the "Last updated" date shown near the top of this policy. If the changes are material, we will provide more prominent notice — for example, by email to Account Users or an in-app notice — before the changes take effect. The version identified by the most recent "Last updated" date governs. We encourage you to review this policy periodically.
16. Contact Us
If you have any questions, concerns, or requests about this Privacy Policy or your personal information, we're here to help.
- Privacy inquiries: privacy@florii.app
- General/support inquiries: support@florii.app
- Entity: Braintu Inc.
- Address: 251 Little Falls Drive, Wilmington, Delaware 19808, USA
This Privacy Policy is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules.
We're committed to handling your information carefully and transparently. If you have any questions about this policy, want to exercise a privacy right, or need help, please reach out to our privacy team — we read every message and aim to respond promptly. If you are a customer of a flower shop that uses Florii, please contact that shop directly for requests about your information; the florist is the controller of that data and Florii supports them as their processor.
privacy@florii.app