Privacy Policy

FLOWSTATE LLC  ·  Effective Date: May 1, 2026  ·  Last Updated: September 21 2026

1. Who We Are

FLOWSTATE LLC is a limited liability company registered in Washington, DC. We build and operate the Revenue Engine, a white-label system that works the existing leads and customers of home services contractors in the United States, under each contractor's own brand.

Our registered address is: FLOWSTATE LLC, 1717 M Street NW, Ste 1, Washington DC, 20036, USA.

You can reach us at: [email protected]

2. What This Policy Covers

This policy explains how FLOWSTATE LLC handles personal data in two distinct contexts.

The first context is our own relationships. Our clients are home services contractors. When they sign up, communicate with us, or use their client account, we process data about them and their staff. We also process data about people who visit FlowstateRevenue.com or contact us. In this context we decide how the data is used. We are the controller.

The second context is our role as a data processor on behalf of those clients. When we operate the Revenue Engine, we process personal data belonging to our clients' leads and customers, and to people referred to them. In that context, our clients are the data controllers. We act on their instructions, and their own privacy policies apply to that data. This distinction matters legally, and we address it explicitly in Section 8 and Section 12.

We aim to apply a uniform privacy standard across all U.S. residents. Where a state law provides rights or protections beyond this baseline, we honor those rights for residents of that state and, where operationally feasible, extend similar controls to all users.

3. Data We Collect

From Clients (Home Services Contractors)

When a company engages FLOWSTATE, we collect:

  • Business name, address, and contact details
  • Name and contact information of the primary point of contact
  • Names, work contact details, availability, and service areas of the client's consultants and staff
  • Billing information (processed via a third-party payment processor, we do not store payment card data ourselves)
  • The record of acceptance of our Terms & Conditions, including date, time, and version
  • Communications and correspondence
  • Account activity and usage data within our systems

From Website Visitors

When someone visits FlowstateRevenue.com, we may collect the following categories of data.

Identifiers and device information. IP address, browser type, device type, operating system, and unique device or browser identifiers.

Internet and network activity. Pages visited, time spent on each page, navigation behavior, and referral source.

Geolocation data. General location derived from IP address. We do not collect precise geolocation.

Contact and business information. Name, email address, phone number, and company name, where submitted through a form or voice interaction.

Audio and electronic data. Recordings and transcripts of interactions with our voice AI assistant.

Inferences. Where we link website activity to an existing contact record, we may draw inferences about interest and intent for follow-up purposes.

Website activity linked to known contacts. If you are an existing contact in our systems, we may use cookies or similar technologies to link your website activity to your contact record. This allows us to personalize your experience, such as pre-filling form fields, and to log pages visited and time spent for internal follow-up purposes. This only occurs where a prior relationship or inquiry exists.

Voice AI interactions. Our website includes a voice-based AI assistant. At the start of the conversation it tells you that it is an AI assistant and that the conversation is recorded and transcribed. If you do not want to be recorded, end the conversation and contact us through another available channel.

Lead and Customer Data (Processed on Behalf of Clients)

When we operate the Revenue Engine for a client, we process personal data belonging to that client's leads and customers. This data typically includes:

  • Full name
  • Phone number
  • Email address
  • Physical address or service area
  • Property and project information relevant to the client's service, such as property type, ownership status, and the work the person is interested in
  • Answers to the client's qualification questions
  • Self-reported budget range or payment preference, where the client has made this part of qualification
  • Lead source and status history
  • Consent records the client supplies, and opt-out records
  • Communication logs, call recordings, and transcripts generated by our systems
  • Appointment records, including the consultant's confirmation of whether an appointment took place
  • Referral form submissions, including the consent given on the form
  • For review requests: the request log and the public details of a published review (reviewer name, platform, date, and rating), used to match the review to the request

We do not collect this data for our own purposes. We process it solely to perform the services our clients have contracted us to deliver, and to keep the records that show what was done.

FLOWSTATE does not obtain consumer credit reports, act as a lender, mortgage broker, or consumer reporting agency, or make credit eligibility or financing decisions. Any budget or payment information collected during qualification reflects what the individual voluntarily disclosed and is used only to determine whether they meet the client's criteria for a consultation.

4. Why We Collect Data

Client Data

We use client data to deliver our services, process billing, keep records of billable outcomes and of acceptance of our terms, communicate about the account, comply with legal obligations, and improve our systems based on aggregate non-identifiable usage patterns.

Website Visitor Data

We use visitor data to operate and improve the website, respond to inquiries, personalize the experience for known contacts where applicable, understand how people find and use our site, serve relevant advertising to business visitors, and comply with applicable law.

Text Messages From FLOWSTATE

If you give us your mobile number and agree to receive texts from FLOWSTATE, we use it only to send the messages you agreed to. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help. We do not share mobile numbers or text messaging consent with third parties or affiliates for their marketing purposes.

Lead and Customer Data (Processed on Behalf of Clients)

We process this data only as instructed by our clients and only to deliver the contracted services. This includes qualifying leads, booking appointments, following up on proposals, requesting reviews, collecting referrals, and reactivating dormant leads on behalf of the client. It also includes keeping the records that prove what happened, for billing and for legal compliance.

5. Cookies and Tracking Technologies

Our website uses cookies and similar technologies. Here is what that means in practice.

Strictly necessary cookies keep the site functioning. These cannot be turned off.

Analytics cookies help us understand how visitors use the site. These may include online identifiers such as IP address and device information, depending on configuration.

Personalization cookies may be used to link a returning visitor to an existing contact record in our systems, enabling features such as pre-filled forms and logged browsing activity. This only applies where a prior relationship or inquiry exists.

Marketing and advertising cookies may be placed to serve relevant advertising to business visitors and to measure the effectiveness of our campaigns. These technologies may share limited identifiers and activity data with advertising partners for cross-context behavioral advertising directed at business prospects visiting our website. We do not use marketing cookies or retargeting in connection with lead or consumer data processed on behalf of our clients.

We do not sell personal data for money. Some state laws define "sale" or "sharing" broadly enough to cover the advertising cookies described above. That is why we offer the opt-outs below. Apart from those cookies, we do not share personal data of website visitors with third parties for those third parties' own marketing purposes.

You can control cookie preferences through our cookie preference center when you first visit the site. You can also adjust your browser settings to block or delete cookies at any time. Note that disabling certain cookies may affect how the site works.

We honor browser-based opt-out preference signals, including Global Privacy Control, as an opt-out of advertising cookies for that browser.

All visitors have the right to opt out of the use of cookies for cross-site tracking, advertising, or behavioral personalization. A "Do Not Sell or Share My Personal Information" link is available on our website for this purpose.

We do not use marketing cookies or share data for advertising purposes in connection with individuals who interact with our systems as leads or customers of our clients.

6. How We Store and Protect Data

We use a set of third-party platforms to store and process data. These fall into the following categories:

  • A CRM and automation platform used for contact management, workflow automation, and system logic
  • A payment processing platform that handles all billing transactions
  • An automation integration platform that connects our internal systems
  • A communications platform used to send and receive SMS messages, emails, voice calls, and chat messages, including WhatsApp
  • AI model providers used to conduct conversations and support automated steps within our workflows
  • A separate secured database where we keep billing and compliance records, outside our clients' accounts

All platforms we use are contractually bound to process data only on our instructions and to maintain appropriate security standards. We do not transfer personal data outside of these systems without a legitimate reason. Members of our team work from outside the United States, including from the European Union, and may access data from there. The same access controls apply wherever they work.

Security. We implement reasonable technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure. Access is limited to personnel and systems that require it to deliver our services. No system is completely secure. If we become aware of a data breach affecting your personal data, we will notify affected parties without unreasonable delay and in accordance with applicable law. Where we act as a processor on behalf of a client, we notify that client without unreasonable delay and no later than 72 hours after we become aware, so they can fulfill their own notification obligations.

Data retention. We apply the following retention periods:

  • Client data: for the duration of the service relationship and five years afterward
  • Billing and compliance records: five years from the date each record was created. These are the minimum records we need for billing, audit, legal compliance, and the defense of legal claims. They include consent records, call and message logs, recordings and transcripts tied to a billable outcome or an opt-out, form submissions, and consultant responses. Federal telemarketing rules require records of this kind to be kept for five years.
  • Opt-out and do not call records: at least five years, and longer where a state law requires it
  • Website visitor data: up to 12 months
  • All other lead and customer data processed on behalf of clients: no longer than 90 days after the end of the service relationship, unless the client requests earlier deletion or applicable law requires otherwise. Clients can request an export of their data during the first 30 days of that period.

7. Deletion Requests and Legal Hold

You have the right to request deletion of your personal data. When we receive a verified deletion request, we act on it as quickly as possible and no later than 45 days from receipt.

If your data reached us through one of our clients, that client decides what happens to it. We pass your request to the client, or tell you how to reach them, and we then act on their instructions.

Some data cannot be deleted immediately because federal or state law requires us to retain it for a defined period, or because we need it to establish or defend legal claims. Examples include consent records, opt-out logs, and the communication records described as billing and compliance records in Section 6, which relate to the TCPA, the CAN-SPAM Act, and the FTC Telemarketing Sales Rule.

When a retention obligation applies, we do the following:

  • We delete everything we are not required to keep
  • We place the remaining data in a restricted state, removed from all active systems, workflows, and reporting
  • We use it for no purpose other than the specific legal purpose for which it is retained
  • We delete it as soon as the applicable retention period expires

We do not use legal retention as a reason to keep data we do not need. If your deletion request cannot be fully fulfilled because of a legal hold, we will tell you which data we are retaining, why, and when it will be deleted.

8. Lead and Customer Data: Our Role as a Processor

When a home services contractor engages FLOWSTATE, it gives us access to its leads and customer database. We contact those individuals on the client's behalf and under the client's brand, by AI voice call, SMS, email, and chat (including WhatsApp where the client has activated it), depending on the contracted services.

Client responsibility for consent. The client is responsible for ensuring that all required consents were obtained before providing that data to us. We require clients to represent and warrant that all submitted leads were collected lawfully and that proof of consent can be demonstrated. We reserve the right to request proof of consent and to reject or suspend campaigns where consent is incomplete, outdated, limited to other channels, or otherwise insufficient.

How we use the data. FLOWSTATE processes lead and customer data strictly to deliver the contracted services. We do not use it for our own marketing. We do not sell it. We do not share it with other clients. We do not combine it across client accounts except for internal security and aggregate analytics purposes. We do not keep it after the service relationship ends, other than the billing and compliance records described in Section 6 and Section 7.

Outreach model and consent basis. FLOWSTATE does not conduct cold outreach. We only contact people our clients supply, and people who come in through a client's own forms. Our clients are required to confirm that each person has given the consent the law requires for the channels we use, including prior express written consent for AI voice calls and marketing texts, and that they have honored all opt-outs and do not call requests. We rely on that confirmation. We may ask for proof, and we may refuse or remove any contact.

Before initiating outreach, we apply the opt-outs, do not call requests, and suppression records the client gives us, together with the ones already recorded in our systems for that client.

For lead reactivation campaigns involving older contact records, clients are required to confirm that consent remains valid, unrevoked, and applicable to the intended outreach channels before we begin.

Referrals. When a customer or lead refers someone to a client, the referred person fills in the referral form themselves, including the consent language. We never contact a referred person who has not submitted that form. Clients cannot upload referral names or numbers for us to contact.

Review requests. We ask every eligible customer a client gives us for a review. We do not select people by how positive we expect them to be. We do not offer incentives. We do not write, edit, or post reviews. To confirm that a review was published, we compare public reviews on the platform (such as Google or Trustpilot) with our request log, using the reviewer's public name and the date.

Opt-out mechanisms. Every outreach channel includes a clear opt-out mechanism:

  • SMS: reply STOP to any message. SMS opt-outs are processed automatically.
  • Email: use the unsubscribe link in any email. Email opt-outs are honored within 10 business days as required by the CAN-SPAM Act. The unsubscribe mechanism remains functional for at least 30 days after each message is sent.
  • Phone: ask to be removed during any call. The request is added to the suppression list before any further outreach.
  • WhatsApp: reply STOP or request removal in any message.

An opt-out you give by call or text stops both marketing calls and marketing texts from that client. An email unsubscribe stops email. You can ask to be removed from all channels at any time. Opt-out records are retained for at least five years.

AI voice and call recording. Where AI is used to conduct voice calls on behalf of a client, the call identifies the business being represented, states that the caller is an automated AI assistant, states that the call is recorded, and offers a way to opt out. If you do not want to be recorded, you may end the call and contact the business through another available channel.

If you are a lead or customer of one of our clients and want to stop receiving messages or learn more about how your data is used, contact the client directly or reach us at [email protected].

9. Your Rights

The following rights apply to all individuals. Where a specific state law grants additional rights, we honor those rights for residents of that state.

If your data reached us through one of our clients, that client is the controller. We pass your request to them or tell you how to reach them, and we help them respond. Opt-outs from calls, texts, and emails are different. We apply those directly, as described in Section 8.

Right to know. You can ask what personal data we hold about you, where it came from, why we use it, and with whom it is shared.

Right to correct. You can ask us to fix inaccurate or incomplete data.

Right to delete. You can ask us to delete your personal data. We will do so as described in Section 7, subject only to the retention obligations described there.

Right to data portability. You can ask us to provide your personal data in a structured, commonly used format where technically feasible.

Right to opt out of sale or sharing. We do not sell personal data for money. We do not share personal data from leads or consumers for advertising purposes. We may share limited business visitor data with advertising partners through marketing cookies on our website. You may opt out through our cookie preference center or via the "Do Not Sell or Share My Personal Information" link on our website.

Right to opt out of targeted advertising and profiling. You may opt out of the use of your data for targeted advertising or automated profiling through our cookie preference center or by contacting us directly.

Right to limit use of sensitive personal information. You may direct us to limit the use of your sensitive personal information to what is strictly necessary to deliver the service you requested. Contact us at [email protected].

Right to human review. Where an automated system has been used to make a qualification decision affecting you, you may request that a human review that decision. To make this request, contact us at [email protected].

Right to appeal. If we decline your privacy request, you may appeal that decision by contacting us at [email protected] and indicating that you are submitting an appeal. We will respond to appeals within 45 days. If your appeal is denied, we will provide an explanation and, where required by applicable law, information about how to submit a complaint to your state attorney general.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will require written proof of authorization and may verify your identity directly before acting on the request.

Right to non-discrimination. Exercising any of these rights will not result in denial of service, a different price, or a lower quality of service.

How to submit a request. Contact us at [email protected] with a description of your request. To verify your identity, we will match the information you provide against data we already hold in our systems, such as confirming a verification link sent to your email address on file. We will not ask you to provide more personal information than is reasonably necessary to verify your identity. We will respond within 45 days. If we need more time, we will notify you before that deadline.

10. Sensitive Personal Information

Some data we process on behalf of clients falls into categories that require additional protection under applicable law.

Sensitive personal information under applicable privacy law may include precise geolocation, biometric data, account credentials, government identifiers, health data, racial or ethnic origin, religious beliefs, sexual orientation, children's data, and similar categories. We do not collect these categories in the ordinary course of our services, and our clients are not allowed to give them to us.

Qualification data that we do collect on behalf of clients can include a self-reported budget range or payment preference, and property-related information such as home ownership status. While not classified as sensitive personal information under most applicable laws, we treat this data with the same level of protection.

This qualification data is used solely to determine whether an individual meets the criteria established by our client for a consultation. It is used to support a single routing decision in that specific context. We do not use it to build profiles over time, combine it with external data sources, evaluate creditworthiness for any consumer lending or financial purpose, or use it for advertising, targeting, or any purpose beyond the qualification decision it was collected for.

We do not collect biometric identifiers. We do not extract or store voiceprints, facial geometry templates, or any other biometric identifier derived from voice or image data. Voice recordings made during AI-assisted interactions are transcribed for service delivery and record keeping only and are not processed to identify individuals by their voice or physical characteristics.

11. Automated Decision-Making and AI

Some of the conversations conducted on behalf of our clients, and some of the steps within our automated workflows, involve AI systems. This includes AI language models and AI voice agents.

These systems support routing, lead qualification, and appointment scheduling. They do not make decisions that produce legal effects or similarly significant consequences for individuals. The data processed within these systems is subject to the same handling rules described in this policy.

Where AI is used to conduct conversations, the individual is interacting with an automated system. No attempt is made to conceal this. A disclosure is provided at the start of each automated interaction, and the system confirms that it is automated whenever someone asks.

AI model providers used within our systems process data only as required to execute the requested task, under terms that restrict their use of the data.

Individuals may request human review of any automated qualification outcome as described in Section 9.

12. Our Role as a Service Provider

When we process personal data on behalf of a client, we act as a service provider, contractor, or processor under applicable law. In that capacity, we process personal information only under a written agreement with the client that restricts our use of the data to the contracted business purpose. Those terms are in Section 13 of our Terms & Conditions, available at https://www.flowstaterevenue.com/terms.

Under that agreement we do not sell or share client lead data. We do not use it for our own commercial purposes or outside our direct relationship with the client. We do not combine it with data from other sources, except where the law allows a service provider to do so, for example to detect security incidents and fraud. We bind our own service providers to the same restrictions by written contract. We help our clients respond to privacy requests, and we tell a client if we can no longer meet these obligations. We do not keep the data beyond the terms of that agreement, which includes the five-year billing and compliance records described in Section 6.

13. Children's Data

Our services are designed for business use. We do not knowingly collect personal data from individuals under the age of 18, and our clients are not allowed to give us such data. If we become aware that we have collected data from a minor, we will delete it promptly.

14. Do Not Track

There is currently no binding federal or state standard requiring websites to honor Do Not Track browser signals. We do not currently alter our data practices in response to Do Not Track signals. We honor Global Privacy Control, as described in Section 5.

15. Third-Party Links

Our website may contain links to external sites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before sharing any personal data with them.

16. Governing Law

This policy is governed by the laws of the District of Columbia, without regard to conflict of law principles. Nothing in this section limits any rights you may have under the laws of the state in which you reside.

17. Changes to This Policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. If we make material changes, we will notify active clients by email at least 30 days before the change takes effect. Continued use of our website or services after the updated policy becomes effective means the updated policy applies going forward. Client contractual obligations are governed by our Terms & Conditions. If this policy and Section 13 of the Terms & Conditions differ on how we handle a client's lead and customer data, the Terms & Conditions control.

18. Contact

If you have questions about this policy, want to exercise your rights, want to submit an appeal, or want to request information about our subprocessors, contact us at:

FLOWSTATE LLC

1717 M Street NW, Ste 1
Washington DC, 20036, USA

[email protected]

© Flowstate LLC . All rights reserved.