Privacy Policy

Privacy Policy

Version 2.0. Effective 30 July 2026.

1. Who we are

StableFlow (“we”, “us”) is operated by Stableflow ltd, a company registered in England and Wales. We provide a software platform for equestrian businesses. For the purposes of UK GDPR and the EU GDPR, we are the data controller for our marketing website and account administration, and a data processor for personal data processed on behalf of our customers within the platform.

Contact: privacy@stableflowequine.io.

2. What we collect

We collect different categories of data depending on how you interact with us.

Marketing website visitors

  • IP address and approximate location (country) for pricing localisation and security.
  • Cookie data necessary for site function and, with consent, analytics.
  • Contact form submissions: name, email, phone, message.

Account holders (stable owners, instructors, professionals)

  • Account details: name, email, role, hashed password, two-factor settings.
  • Billing details processed by our payment partners (Stripe, GoCardless).
  • Activity logs for security and audit purposes.
  • Legal acceptance records: which Terms and Privacy Policy version you accepted, the date and time, your IP address, and your browser user-agent.

End users (riders, families, students)

Where the platform stores data about end users on behalf of our customers (riding schools, livery stables, and similar), we act as a processor. The customer is the data controller. Categories may include name, contact details, emergency contacts, medical notes, lesson attendance, billing history, media (photos and video) where a customer uses those features, and signed documents.

3. Lawful basis

  • Contract: processing necessary to provide the platform to account holders.
  • Legitimate interests: service security, fraud prevention, product analytics.
  • Consent: marketing communications and non-essential cookies.
  • Legal obligation: retention of financial records, response to lawful requests.

4. How we use data

  • To operate, secure, and improve the platform.
  • To process subscription and transaction payments.
  • To provide Sage, our assistant, which drafts messages and documents and performs supporting tasks you request.
  • To send transactional emails and messages (account, billing, security).
  • To respond to support and contact form enquiries.
  • To send marketing emails, only with consent and with an unsubscribe link.

We do not use your Customer Data to train third-party foundation models, and we do not sell your personal data.

5. Sharing data (sub-processors)

We share personal data with sub-processors that help us run the service:

  • Hosting: Vercel (United States, EU region for EU data).
  • Database: Neon (United States, EU region for EU data).
  • Payments: Stripe, GoCardless.
  • Email: SendGrid or an equivalent transactional email provider.
  • SMS, voice, and messaging: Twilio (including WhatsApp messaging).
  • Error monitoring: Sentry.
  • Sage processing: Anthropic, which powers our intelligent assistant features.

Each sub-processor is bound by a data processing agreement, and we apply UK and EU approved transfer mechanisms (such as the UK International Data Transfer Addendum and Standard Contractual Clauses) where data is transferred outside the UK or EEA. A current sub-processor list is available on request.

6. Retention

We retain account data for as long as the account is active. After cancellation we retain data for 30 days to allow export and reactivation, then delete or anonymise it except where retention is legally required (for example, financial records kept for the statutory period for tax purposes). Legal acceptance records are retained for as long as needed to evidence the agreement.

7. Your rights

Under UK and EU data protection law you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request erasure (the “right to be forgotten”).
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time.
  • Complain to the Information Commissioner's Office or equivalent supervisory authority.

Where we act as processor for an end user’s data, please direct requests to the relevant customer (the controller); we will assist them in responding. Otherwise, email privacy@stableflowequine.io. We respond within one month.

8. Security

We use industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access controls, audit logging, login lockout, two-factor authentication for admin accounts, and regular security reviews.

9. Children

The StableFlow platform is sold to businesses and is not directed to children. Where our customers (such as riding schools) store data about minors, or use features intended for younger participants, the customer is the controller and is responsible for obtaining the appropriate parental or guardian consent and for meeting any children’s privacy requirements that apply in their region. We act as processor and support the customer’s obligations through the platform’s consent and safeguarding features.

10. Cookies

We use strictly necessary cookies for authentication and session management. We use analytics cookies only with your consent. You can manage your preferences via the cookie banner shown on first visit, or by clearing cookies in your browser.

11. Changes to this policy

We may update this policy. The version and effective date at the top will change. Material changes will be notified by email to account holders.

12. Contact

Questions: privacy@stableflowequine.io. Postal address available on request.