Cross Platform Flow

Privacy Notice

CrossFlow plans to process only the data needed to operate the website, fulfill future orders, provide support, and protect product security.

Data-controller brand: Muiao / CrossFlow
Effective: 2026-08-25
Client analytics SDK: None
Paddle checkout: Disabled

01 / CURRENT WEBSITE

What the current site handles

  • Hosting logsCloudflare and other hosting infrastructure may generate standard request logs such as IP address, time, path, User-Agent, response status, and security events to deliver, protect, and troubleshoot the site.
  • Language preferenceThe home page stores the selected language in browser localStorage. It stays in the browser and can be removed by clearing site data.
  • Campaign parametersMarketing links may contain UTM parameters. There is no client analytics SDK today, although a requested URL can still appear in standard server logs.
  • Technologies not usedThe current site does not load Paddle.js, accept payment, set advertising trackers, build behavioral profiles, or require registration.

02 / PADDLE

Future checkout data

When sales open, Paddle will act as the planned Merchant of Record and independently process name, email, address, payment method, tax, and transaction data. Paddle Checkout collects payment fields; CrossFlow should not receive full card numbers. Read the Paddle Privacy Notice.

CrossFlow receives only order and customer fields needed for fulfillment, license management, order support, fraud prevention, refund coordination, and legal duties—for example Paddle customer/transaction IDs, purchased product, status, time, email, and necessary region data. Checkout data is not automatically used for marketing; marketing subscription requires separate consent.

03 / FEEDBACK AND SUPPORT

GitHub feedback may be public

Ordinary issues go to a public GitHub repository, where content, usernames, and attachments are public by default. Do not submit secrets, LAN addresses, private clipboard contents, payment details, or unrelated personal data. GitHub processes account and platform data under its own privacy terms.

Security, privacy, or abuse-enabling matters must use GitHub private vulnerability reporting, never a public issue.

04 / DESKTOP APP

Application data boundary

There is no public downloadable application today, so there is no public-Beta app telemetry. Future releases will enumerate local configuration, paired identity, support bundles, crash reporting, update checks, or optional telemetry before download. App behavior not listed in the release privacy notice will not upload by default.

Input events or future clipboard content transmitted by CrossFlow must not become marketing analytics data. Any diagnostic export must be user-initiated and reviewable before sending.

05 / PURPOSE, RETENTION, SHARING

Purpose, retention, and sharing

We process data to provide the site and product, fulfill orders, answer requests, pursue legitimate security interests, meet contracts, and comply with law. Hosting security logs follow provider security/troubleshooting periods; order and financial records follow contract, tax, refund, and legal periods; support and security records remain until resolution and reasonable recurrence prevention.

Data is shared only with necessary hosting, payment, source/issue tracking, security, or legal providers, or where law and protection of users or product security require it. Personal data is not sold.

06 / YOUR CHOICES

Access, correction, and deletion

Applicable law may grant rights to access, correct, delete, restrict, object, or export personal data. Use Paddle Buyer Support first for payment and receipt data. For CrossFlow product or privacy requests, use the private reporting route with “Privacy request” in the title; never put a privacy request in a public issue.

Until a dedicated privacy mailbox is configured, private GitHub reporting is the current confidential contact route. This limitation will be reviewed before live checkout opens.