Effective Date: September 13, 2026
This policy covers Flipp accounts, the web service and the iOS and Android apps operated by pier creative.
pier creative operates Flipp, including its website and mobile apps. Your employer or organization controls the work records it asks you to create and the access it grants to colleagues and managers. We process those records to provide Flipp to that organization. Contact us about your account or the service, and contact your organization about its employment records and retention obligations.
We process your name, email, account and sign-in identifiers, organization memberships, assigned roles and profile information. Existing profiles may include a phone number, biography, birth date or profile image. Work features process time entries, project and tag allocations, expense amounts, currencies, payment methods, descriptions, approval decisions and reimbursement status. Enabled web modules may also contain recruiting, goals, feedback and other employment records supplied by you or your organization.
When you choose Google sign-in, we receive your Google account identifier, email address, verification status and basic profile information, such as your name and profile picture. We use this information to create or link your Flipp account, authenticate you and display your profile. Google sign-in does not request access to your Gmail, Drive or Calendar. Sign-in credentials are processed on the server and are not shared with colleagues. Microsoft and Apple sign-in provide equivalent account information according to the permissions you grant. You can disconnect Flipp from your provider's account settings or request deletion of your Flipp account. Removing provider access does not by itself delete existing Flipp work records; our retention and deletion policy applies to those records.
Files you choose to upload, their filenames and their contents are stored with the relevant account and organization. A receipt can include names, addresses, tax or bank details beyond its total and merchant. Company posts, images, comments and reactions are visible to authorized colleagues. Reports, blocks and moderation records support community safety and have more restricted access. Upload only material that you are entitled to share.
When your organization enables AI and you request a receipt scan, the document and its contents are sent to OpenAI to extract expense details. Review the extracted information before submitting it. You can enter expenses manually without requesting AI extraction. Whether your employer requires a receipt for a particular claim is a separate policy decision.
If you allow push notifications, we register a device token linked to your account, store your category preferences, and process notification content and delivery results. Expo, Apple Push Notification service and Firebase Cloud Messaging deliver these messages. Notification previews may appear on your lock screen according to your device settings. You can change notification permissions in system settings and category preferences in Flipp. In-app updates remain available without push permission.
Authentication uses password hashes and revocable session credentials. Native credentials are kept in the device's secure storage. The web service uses cookies for sessions and preferences. Network addresses, request timings, response status, account or error identifiers and technical logs may be processed to operate, protect and diagnose the service. These records can relate to an identifiable person; an IP address or hashed identifier is not automatically anonymous. The app also contacts Expo for application updates.
We use information to provide accounts and organization workspaces, record and review work, deliver updates, answer support requests, prevent abuse and meet applicable legal obligations. Depending on the context and applicable law, processing is necessary to provide the service, meet an obligation, pursue a legitimate operational or security interest, or act on your consent. Your organization's employment-related processing has its own purposes and legal basis. We do not sell or rent personal information.
Vercel and Neon provide application hosting and database services; Vercel Blob stores uploaded files. Microsoft Azure Communication Services delivers application email. Microsoft, Google and Apple process information for their sign-in services when you choose them. OpenAI handles requested receipt extraction. Expo, Apple and Google support updates and push delivery, and Axiom and hosting logs support diagnostics. Providers receive information needed for their respective functions. We may also disclose information where legally required or necessary to protect users and the service. An external link you open is governed by that site's own privacy practices.
Flipp's infrastructure and service providers can process information outside your country. Applicable data-transfer requirements and the arrangements for your organization's workspace apply to those transfers. Contact us for information about the providers, processing locations and safeguards relevant to your account.
We retain information for the purpose for which it is needed, subject to applicable legal obligations. Ordinary account-deletion requests have a completion target of 30 days, capped at one calendar month. We aim to review requests within two working days and explain any permitted extension before the initial deadline. We remove eligible account and personal content; employer records with a documented retention requirement are handled separately. For Swiss organizations, required working-time records generally have a five-year period, and accounting records and supporting receipts a ten-year period. These periods do not apply automatically to all data or every country. Other employment records require a specific basis and expiry. We keep a minimal deletion-case record for 24 months. Provider, live-copy and backup handling forms part of fulfilment; we explain any applicable retained categories, reasons and expiry when completing a request.
You can update profile details, choose whether to upload optional information, use manual expense entry and manage notification preferences. Depending on applicable law, you may request access, correction, deletion, restriction or portability, object to processing, withdraw consent, or complain to the competent data-protection authority. Withdrawing consent does not undo earlier lawful processing. We may need proportionate identity verification before acting, and will explain any applicable exception.
For privacy questions or requests, email support@flippapp.ai. You can also visit the account-deletion page. If you cannot sign in, contact support from your account email where possible.
We update this page when our practices change and show the effective date above. Material changes will be communicated through the service or another appropriate channel.