Privacy Policy
Last updated: July 18, 2026
This policy explains what information Cobbleflow collects, why, and how it's handled — for both the businesses who use Cobbleflow to run their onboarding, and the clients those businesses onboard.
Who this policy covers
Cobbleflow is a two-sided product, and this policy talks about both sides of it. To keep things clear, we use two terms throughout:
- Provider — a business or individual (a coach, freelancer, agency, or similar) who signs up for a Cobbleflow account to build onboarding flows for their own clients.
- Client— someone a Provider is onboarding. Clients don't create a Cobbleflow account or log in — they access their onboarding through a private link a Provider sends them.
If you're a Client, the Provider you're working with is the one who decided what information to collect from you as part of their onboarding process (a contract, a payment, a form, a file, and so on) — Cobbleflow is the platform that runs it, not the business relationship itself. Questions about why a specific piece of information was asked for are usually best directed to the Provider you're onboarding with.
Information we collect
From Providers
When you sign up for and use a Cobbleflow account, we collect:
- Account information — name and email address, via our authentication provider (Clerk).
- Business information you add yourself — business name, logo, support/contact email.
- Content you create — flows, steps, contract text, form questions, and any personal notes you write to your clients.
- Payment setup information — if you connect Stripe to accept client payments, we store your Stripe account identifier and connection status. We do not receive or store your bank details; that relationship is directly between you and Stripe.
- Usage information — like when flows and clients were created, and basic activity timestamps used to power your dashboard.
From Clients
When a Provider onboards you as their Client, depending on what steps are in that specific flow, we may process:
- Your name and email address, which you provide to start the onboarding.
- Files you upload (e.g. brand assets, documents the Provider asked for).
- Your signature and the content of any contract you sign.
- Answers to any intake form questions the Provider included.
- Payment information, handled entirely by Stripe (see Payments below).
- Access credentials, if a Provider's flow includes a step asking you to hand off logins — see The credentials step below for how those are specifically protected.
- Whether and when you opened your onboarding link and completed each step — used to show the Provider your progress and to know when a gentle reminder might be useful.
How we use information
We use the information above to:
- Run the onboarding flows Providers build — displaying steps, saving your answers, and tracking completion.
- Let a Provider resume, review, and manage their own clients' progress.
- Send transactional email — a link to pick up where you left off, a reminder if an onboarding has stalled, a confirmation once a step is done.
- Process payments through our payment partner, Stripe.
- Keep the service secure, diagnose problems, and prevent abuse.
- Communicate with Providers about their account, and respond to support requests.
We do not sell personal information, and we do not use Client information to advertise to Clients or build a profile of them outside the context of the Provider's own onboarding.
Payments
Payment steps are powered by Stripe, using Stripe Connect. When a Client pays a Provider through Cobbleflow, that payment is processed by Stripe and routed directly to the Provider's own connected Stripe account — Cobbleflow is the technology that displays the payment step, but is not the recipient of the funds and does not store full card numbers or bank account details. Stripe's own privacy policy governs the payment data it processes directly.
E-signatures
Contract steps are powered by DocuSeal. When a Client signs a document, the signature, the signed document itself, and a record of when/how it was signed are stored by DocuSeal and referenced by Cobbleflow so both the Client and the Provider can access the signed copy afterward.
The credentials step
Some flows include a step where a Client hands off access to an account (a login, an API key, or similar) so the Provider can do their work. Because this is unusually sensitive:
- Values are encrypted before they're ever written to our database, and stay encrypted at rest.
- Only the Provider who owns that flow can ever view the decrypted values — through their authenticated dashboard.
- The Client-facing onboarding hub never displays these values back, even to the Client who submitted them — it only confirms that access was provided.
Data retention
We retain Provider account and workspace information for as long as the account is active, and Client onboarding data for as long as the associated Provider account exists, since it's part of that Provider's business records (e.g. a signed contract or payment history they may need later). If a Provider account is closed, we retain records for a reasonable period afterward to meet legal, accounting, and dispute-resolution obligations, then delete or anonymize them.
Security
We use industry-standard safeguards — encrypted connections in transit, encryption at rest for particularly sensitive data (see The credentials step), and access controls that scope every Provider strictly to their own workspace's data. No system is perfectly secure, and we can't guarantee absolute security, but we take it seriously and work to improve it on an ongoing basis.
Your rights & choices
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold about you. Providers can update most of their own account and workspace information directly from their settings. For anything else — including a Client's request about their own information — contact us at the email below and we'll work with you (and, where the request concerns Client data collected on a Provider's behalf, the relevant Provider) to resolve it.
Children's privacy
Cobbleflow is a business tool and is not directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we'll remove it.
International users
Cobbleflow and the service providers we rely on may process and store information in countries other than your own. Where required, we rely on appropriate safeguards for these transfers as provided under applicable law.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the “Last updated” date above and, where appropriate, let Providers know directly. Continued use of Cobbleflow after a change means you accept the updated policy.
Contact us
Questions about this policy or how your information is handled? Reach us at privacy@cobbleflow.com.