Privacy Policy
Last updated: April 17, 2026
1. Introduction
Fast Flow Management, trading as Data Form Solution ("we", "us", "our"), operates the Data Form Solution platform (dataformsolution.com). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it.
This policy applies to all users of our platform, including Brand Partners and their customers, regardless of location. We have designed this policy to comply with applicable data protection laws including the General Data Protection Regulation (GDPR) in the European Union, the California Consumer Privacy Act (CCPA) in the United States, the Act on the Protection of Personal Information (APPI) in Japan, and the Australian Privacy Principles (APPs).
2. Information We Collect
2.1 Information You Provide
- Account information: First name, last name, email address, mobile phone number, and username when you register as a Brand Partner.
- Order information: Name, email, phone number, date of birth, shipping address, product selections, and subscription preferences submitted through order forms.
- Payment information: Subscription payments are processed by Stripe, our third-party payment processor. For product orders, billing details (card number, card holder name, expiry date, and CVV) submitted via order forms are stored using strong encryption (AES-256) and are held for a maximum of 24 hours only. After that period, all sensitive billing information is permanently and irreversibly deleted from our database. We do not retain payment card details beyond this 24-hour window under any circumstances.
- Communication preferences: Your separate opt-in choices for email notifications and SMS notifications. Email and SMS consent are captured independently — opting in to one never enrolls you in the other. Standard message and data rates may apply to SMS, and you may reply STOP at any time to opt out.
2.2 Information Collected Automatically
- Session data: We use essential session cookies to maintain your login state and remember your display preferences (e.g., light/dark mode).
- Usage data: Basic server logs including IP address, browser type, and pages visited, used solely for security monitoring and service improvement.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your Brand Partner account
- Process and manage orders placed through the platform
- Share customer order data (including personal information, billing address, and payment details) with the Brand Partner associated with the order, so they can create a LifeWave account on the customer's behalf and process the product purchase
- Process subscription payments via Stripe
- Send order notifications via email and/or SMS based on your preferences
- Provide one-time login codes for passwordless authentication
- Provide customer support and respond to inquiries
- Maintain the security and integrity of the platform
- Monitor usage patterns (such as invite frequency and notification volume) to enforce our fair usage policy and prevent abuse
- Comply with legal obligations
4. Third-Party Service Providers
We share your information with the following trusted parties, solely for the purposes described:
4.1 Brand Partners (Order Data Sharing)
When you submit an order through the Data Form Solution order form, your personal information (name, email, phone number, address), billing details (billing address, card type, card number, cardholder name, expiry date, and CVV), and product selections are shared with the independent LifeWave Brand Partner associated with your order. The Brand Partner uses this information to create a LifeWave account on your behalf and to process the purchase of the products you selected. Data Form Solution does not process any payment directly — the Brand Partner handles the transaction through LifeWave.
By submitting the order form you explicitly consent to this data sharing. The Brand Partner is an independent third party and is responsible for their own handling of your data once received.
4.2 Third-Party Service Providers
- Stripe (stripe.com) — Payment processing for subscription fees. Stripe collects and processes payment card information in accordance with PCI-DSS standards. See Stripe's Privacy Policy.
- Twilio (twilio.com) — Delivery of SMS notifications. Phone numbers are shared with Twilio solely for message delivery. See Twilio's Privacy Policy.
- Postmark (postmarkapp.com) — Transactional email delivery for login codes and notifications.
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
5. Data Retention
We retain personal data only for as long as it is necessary to provide the service or to comply with a legal obligation. Specific retention periods:
- Account data: Retained for as long as your account is active. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
- Completed order data: Retained for the duration of the Brand Partner's account for operational, accounting, and tax-record purposes.
- Abandoned order data: If an order form is started but never submitted, the personal information you entered is automatically anonymized 90 days after the form was abandoned. After anonymization only non-identifying aggregate fields (currency, product selections, totals, brand-partner attribution) are kept for analytics; your name, email, phone, address, and date of birth are permanently and irreversibly removed.
- Sensitive billing details: Payment card information (card number, card holder name, expiry date, and CVV) is encrypted at rest and stored for no longer than 24 hours from the time of order submission. An automated process permanently deletes all billing details after this retention period. This data cannot be recovered once deleted.
- One-time login codes (OTP): Expire within 5 minutes and are invalidated after use or on a new code request.
- API session tokens (mobile app): Expire 60 days after issue. Tokens that have not been used for 30 days are also automatically revoked. You can review and revoke active sessions at any time from within the mobile application.
- Server logs: Standard request logs (IP address, user agent, request path) are retained for up to 30 days for security monitoring and abuse prevention, then rotated and discarded.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including encrypted connections (HTTPS/TLS), hashed authentication tokens, encryption of sensitive data at rest (AES-256), and strict access controls. Billing information is encrypted the moment it is submitted and is automatically purged from our systems within 24 hours — it is never stored in plain text. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Objection: Object to processing of your data in certain circumstances.
European Union Residents (GDPR)
You additionally have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local data protection authority. Our legal basis for processing is contractual necessity (to provide the service) and legitimate interest (to maintain platform security).
California Residents (CCPA)
You have the right to know what personal information is collected, the right to request deletion, and the right to non-discrimination for exercising your privacy rights. We do not sell personal information as defined under the CCPA.
Japan Residents (APPI)
You have the right to request disclosure, correction, or cessation of use of your personal information. We handle personal information in accordance with the Act on the Protection of Personal Information.
Australia & New Zealand Residents (APPs)
You have the right to access and correct your personal information under the Australian Privacy Principles and the New Zealand Privacy Act. You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or the New Zealand Privacy Commissioner.
8. Cookies
We use only essential cookies required for the functioning of the platform. These include session cookies for authentication and a preference cookie for your display theme (light/dark mode). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
9. International Data Transfers
Your data may be processed in countries other than your own, including the United States (where Stripe and Twilio are headquartered). Where data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent mechanisms, in compliance with applicable data protection laws.
10. Children's Privacy
Our platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of any material changes via email or through a notice on the platform. Your continued use of the service after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a complaint, please contact us at:
Business name: Fast Flow Management (trading as Data Form Solution)
Email: [email protected]
Website: dataformsolution.com