Who we are
VinesFlowis an independently operated software service based in Pakistan. We work remotely and do not maintain a public customer-facing office. In this policy, "we", "us" and "our" refer to the operator of VinesFlow.
This policy explains what we do with information when you visit vinesflow.com or use the VinesFlow application. If you use VinesFlow as a member of an organization created by your employer or client, that organization decides what business records go into the system and who may see them; we process those records on their instructions.
Information we collect
Account information. Your name, email address and a hashed version of your password. We never store your password in a form we can read.
Organization information. The name and settings of each organization you create or join, your role within it, and your membership history.
Business records you enter. Everything you put into the system — customers, vendors, items, stock levels, sales orders, delivery challans, invoices, credit notes, purchase orders, goods receipts, bills, payments, tax rates and any files you attach. This is your data; we hold it so the product can work.
Technical information. The browser and device you signed in from, and the time you did. Our activity log records which user performed which action inside an organization.
Enquiries. If you contact us or request a demo, we keep what you send us and our correspondence with you.
How we use information
We use information to:
- provide the product, and keep your records available to the right people;
- authenticate you and maintain your sessions;
- submit invoices to the tax authorities where you have configured us to do so;
- provide support and respond to enquiries;
- monitor reliability, diagnose faults and prevent abuse;
- meet our own legal, accounting and tax obligations.
We do not sell your information, and we do not use the business records you enter to advertise to you.
Cookies and sessions
VinesFlow uses only the cookies it needs to work. Signing in sets a cookie that keeps you signed in, and it is not readable by scripts running in the page. We do not use advertising or tracking cookies.
Your browser may also store a preference such as your chosen colour theme. Blocking necessary cookies will stop you being able to sign in.
Sharing with tax authorities
If you enable digital invoicing, invoice data you create is transmitted to the Federal Board of Revenue (FBR), so that the invoice can be registered and returned to you with an invoice reference number and QR code.
What is transmitted is determined by the authority's published schema and typically includes your registration details, the buyer's details, line items, and the tax calculated. We transmit what you have entered. You remain responsible for its accuracy — see the terms for more on this.
We may also disclose information where we are required to by law, court order, or a lawful request from a public authority.
Service providers
We use third parties to run the service — hosting, database and file storage infrastructure. They may handle information on our behalf, only for the purpose of providing their service to us, and under contract.
We do not transfer your business records to anyone else for their own purposes, and we do not share them with other customers.
Where your data is stored
Your data is held on servers operated by our infrastructure providers. Where data is stored or processed outside Pakistan, we take steps to ensure it remains protected to the standard described in this policy. Tell us at [email protected] if you need to know the specific location for your organization.
How long we keep it
We keep your business records for as long as your organization is active. Accounting and tax records often have to be retained for a minimum period under Pakistani law, and where that applies we keep them for as long as required even if you would prefer them deleted.
When an organization is closed, we delete or anonymise its data within a reasonable period after any legal retention window has passed.
How we protect it
Passwords are stored in a form nobody here can read or reverse, and traffic between your browser and our servers is encrypted in transit.
Access to customer data by our own staff is restricted to the few people who need it to run the service or to answer a support request you have raised, and that access is logged. We do not read your books otherwise.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities where the law requires it.
Your rights
You may ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, or delete it. You can also object to particular uses, or ask us to restrict them.
If the information sits inside an organization you belong to but do not administer, we will usually direct your request to that organization's administrator, since they control those records.
Write to [email protected]. We will respond within a reasonable time, and may need to verify who you are first.
Changes to this policy
We may update this policy as the product changes or the law does. The date at the top shows when it was last revised. If a change materially affects how we handle your information, we will tell you before it takes effect.
Contact us
Questions about this policy, or about your information, go to [email protected].
