GanttFlow™
TemplatesGuidesPricing
Sign inStart free
On this page
  • Privacy Policy
    • The short version
    • What we collect
    • What we don't do
    • Why we use your data
    • Who we share it with
    • Where your data lives
    • Cookies
    • How long we keep things
    • Your rights
    • Security
    • Children
    • Changes to this policy
    • Contact
  • Terms of Service
  • Refund Policy
  • Accessibility

Privacy Policy

Last updated: 22 August 2026

1. The short version

GanttFlow is run by one person, Vishal Gungah, in Ontario, Canada. We collect the minimum we need to give you an account, take your payment, and sync your projects. We don't sell your data, we don't run advertising trackers, and we never see your card number. Questions or requests: support@ganttflow.ca.

2. What we collect

Account information. When you sign up, our authentication provider Clerk collects your email address, your name if you give one, and your password or the identity of the social login you used (for example Google). We see your email address and user ID so we know which account is yours.

Billing information. When you buy a plan, Stripe collects your payment details and billing address. We receive from Stripe only a customer ID, a subscription or payment ID, which plan you're on, its status, and when the current period ends. We never receive or store your full card number.

Your project data. On the Free plan, your project stays in your own browser's local storage and is never sent to us. On Pro and Lifetime plans, the projects you choose to sync — their names, tasks, lanes, dates, milestones, and settings — are stored in our database so they're available on your other devices.

Usage and performance data. We use Vercel Analytics and Vercel Speed Insights, which record anonymous, aggregated page views and page-load performance. These do not use cookies to follow you across other websites and don't build a profile of you.

Product usage events. When you're signed in, we record a small number of in-app interactions against your user ID — for example, opening an upgrade prompt, exporting a chart, importing a project file, or applying a template. These records note which feature you interacted with, never your project's content: no project, lane, or task names, and no dates or other project data. We use this to understand which parts of the product lead people to upgrade, so we know what to build and explain better — not to profile you individually or to advertise to you.

Technical logs. Our hosting, rate-limiting, and error-monitoring providers keep short-lived logs — including IP addresses, request details, and technical error reports — used to keep the service running, diagnose problems, and stop abuse. Error reports are configured to exclude request bodies and headers, and we don't record your screen.

3. What we don't do

We don't sell your personal information. We don't share it with advertisers. We don't run third-party advertising or cross-site tracking pixels. We don't read your project contents except when you specifically ask us to look at something to help with a support issue.

4. Why we use your data

  • To create and secure your account and let you log in.
  • To take payment and give you the features your plan includes.
  • To store and sync your projects when you're on a paid plan.
  • To understand which features lead people to upgrade, using the product usage events described above.
  • To email you about your account — receipts, billing problems, important changes to the service or these policies.
  • To keep the service working, diagnose faults, and prevent abuse.

Our legal basis, where that concept applies to you, is performing our contract with you for the first three, our legitimate interest in running a safe and working service for the last two, and consent where you've given it.

Marketing emails. We will not send you marketing or promotional email unless you've explicitly opted in, in line with Canada's Anti-Spam Legislation. Transactional email — receipts, billing problems, security notices, and required changes to these policies — is sent regardless, since it's necessary to run your account. Any marketing email includes an unsubscribe link, and you can also opt out from your account settings at any time.

5. Who we share it with

We use a small number of service providers, each of which handles only the data it needs:

  • Clerk — accounts, login, and session management.
  • Stripe — payment processing, subscriptions, invoices, and the billing portal.
  • Neon — the Postgres database that stores subscription records and synced projects.
  • Vercel — hosting, plus anonymous analytics and performance measurement.
  • Upstash — rate limiting, which briefly stores request counts keyed to your user ID.
  • Sentry — error monitoring, to help us find and fix bugs; configured not to receive your project's content or record your screen.
  • Resend — delivering account emails, like welcome messages and important notices.

We may also disclose information if we're legally required to, or if it's necessary to protect our rights or someone's safety. If GanttFlow were ever sold or transferred, your data would move with it and we'd tell you first.

6. Where your data lives

GanttFlow is operated from Canada, and our providers store and process data on servers in Canada, the United States, and the European Union. By using GanttFlow you understand that your data may be processed outside your own country. Where we transfer personal data out of the EU or UK, our providers do so under Standard Contractual Clauses or an equivalent recognized safeguard.

7. Cookies

We use cookies that are strictly necessary to run the product: a session cookie from Clerk to keep you logged in, and security cookies to protect against cross-site request forgery. We don't use advertising or cross-site tracking cookies. Your Free-plan project is kept in your browser's local storage, not in a cookie, and never leaves your device.

8. How long we keep things

We keep your account and project data for as long as your account is open. If you delete a project, it's removed from our database. If you close your account, we delete your account and project data within 30 days, except for billing records that Stripe and we are required to keep for tax and accounting purposes — normally seven years. Technical logs are kept for a short period, typically 30 days or less. If we ever have a security incident affecting your data, we keep records of it for up to two years, in line with our obligations under Canadian privacy law.

9. Your rights

You can ask us to show you what data we hold about you, correct anything wrong, export your data, or delete your account and everything in it. You can also object to certain processing or ask us to restrict it. Email support@ganttflow.ca and we'll respond within 30 days. Pro and Lifetime plans can also export projects themselves, any time, from inside the app using the JSON export button — this costs nothing extra as a data-rights request, so free-plan users can get the same export by emailing us. If you're in Canada you can also complain to the Office of the Privacy Commissioner of Canada; if you're in the UK or EU you can complain to your local data protection authority. If you're a California resident, you have the same rights to know what we collect and to request deletion under the CCPA — and, as stated above, we do not sell personal information.

10. Security

Traffic to GanttFlow is encrypted with HTTPS. Passwords are handled entirely by Clerk and are never stored by us. Card details are handled entirely by Stripe and are never stored by us. Every server route that reads or writes your projects checks your identity and your plan on the server, not just in your browser. No system is perfectly secure, but if there's ever a breach affecting your data, we'll tell you and the relevant regulator as quickly as we can.

11. Children

GanttFlow isn't intended for anyone under 16, and we don't knowingly collect data from children. If you believe a child has given us personal information, email support@ganttflow.ca and we'll delete it.

12. Changes to this policy

If we change this policy in a way that matters, we'll email account holders and update the "last updated" date at the top of the page.

13. Contact

Privacy questions or requests go to Vishal Gungah at support@ganttflow.ca.

© 2026 GanttFlow
TermsPrivacyRefundsAccessibilityContact