PRIVACY NOTICE — GREENFLAGS
Last updated: July 10, 2026
1. Data controller
The controller of your personal data is the owner of the GreenFlags platform (https://greenflags.dev and https://app.greenflags.dev), a natural person conducting business activities, registered with the Mexican tax authorities under RFC BAMJ910403F20 (the "Controller").
For personal safety reasons, the Controller's full name and tax address are not published in this notice; they will be provided immediately to anyone who requests them at the contact email indicated in section 9.
This notice is issued in compliance with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (the "Law").
2. Personal data we collect
When you create an account and use the Service we collect only:
- Identification and contact data: name and email address, provided by you when registering or when invited to a workspace.
- Credentials: your password, stored only in irreversibly encrypted form (hash); no one, not even the Controller, can read it.
- Technical data: IP address, request identifiers and technical logs generated by use of the Service, for security, audit and diagnostic purposes.
- Service usage data: the configuration you create (workspaces, projects, environments, flags, tokens) and the audit logs of actions performed in your workspace.
Payment data: payments are processed directly by Stripe; the Controller does not collect, store or have access to your card data. Stripe processes that data under its own privacy policies.
We do not collect sensitive personal data (health, ethnic origin, beliefs, etc.) and the Service is not designed to store it. Under the Terms and Conditions, entering third parties' personal data in flag content is prohibited.
Geolocation: if you use the geofencing feature, the coordinates of your applications' end users are evaluated locally in your own systems through the SDKs and are never sent to GreenFlags' servers. The Controller does not collect end-user locations.
3. Purposes of processing
Primary purposes (necessary for the service):
- a) Creating and managing your account and workspace.
- b) Providing the Service: managing and reading feature flags, API tokens and team.
- c) Processing billing and charges for your plan (through Stripe).
- d) Sending you essential transactional emails (account verification, password reset, invitations, billing notices), through Brevo.
- e) Service security: fraud and abuse prevention, audit logs, incident response.
- f) Handling your support and contact requests.
Secondary purposes (not necessary for the service):
- g) Sending you product news and informational communications about GreenFlags.
You may object to the secondary purposes at any time by writing to the contact email in section 9, without affecting the provision of the Service.
4. International transfers and processors
We do not sell, rent or share your personal data with third parties for commercial purposes. To operate, the Service uses providers acting as processors that may process data outside Mexico:
| Provider | Country | Role |
|---|---|---|
| Cloudflare, Inc. | United States | Compute, network and storage infrastructure |
| Stripe, Inc. | United States | Payment processing |
| Brevo (Sendinblue SAS) | France / European Union | Transactional email delivery |
These transfers are necessary to provide the Service you contract and are carried out under the Law. By accepting this notice and using the Service, you consent to those transfers. Additionally, your data may be shared when required by a competent authority through a duly founded and motivated order.
5. Cookies and similar technologies
- The public site (greenflags.dev) uses Cloudflare analytics without tracking cookies.
- The application (app.greenflags.dev) uses only strictly functional cookies and local storage: keeping your session active and remembering your language. We do not use advertising or third-party tracking cookies.
6. Retention period
We keep your data while your account is active. Upon account closure, workspace content is deleted as set out in the Terms and Conditions (reference period: 30 calendar days), except for information we must retain by legal obligation (for example, billing records).
7. ARCO rights and withdrawal of consent
You have the right to Access your data, Rectify it, Cancel it and Object to its processing (ARCO rights), as well as to withdraw your consent and to limit the use or disclosure of your data.
To exercise them, send a request to the email in section 9 including: (a) your name and the email associated with the account; (b) a clear description of the right you wish to exercise; and (c) any element that helps locate your data. We will respond within the timeframes set by the Law (up to 20 business days to inform you of the determination and 15 additional business days to make it effective, where applicable).
You can also rectify your information and delete content directly from the Service dashboard.
8. Competent authority
If you believe your data protection rights have been violated, you may turn to Mexico's Secretaría Anticorrupción y Buen Gobierno (SABG), the competent authority for personal data protection in Mexico.
9. Contact
For privacy matters, exercising ARCO rights, or to request the Controller's name and tax address: [email protected].
10. Changes to this notice
This notice may be updated to reflect legal or Service changes. Changes will be published on this same page, updating the "last updated" date; relevant changes will additionally be notified by email or in the dashboard.
11. Minors
The Service is intended for people over 18 for professional or business purposes. We do not knowingly collect data from minors; if we detect an account belonging to a minor, it will be cancelled.
Note on this translation
This is a courtesy English translation. The legally binding version is the Spanish one, available at https://greenflags.dev/es/privacy/.