Skip to content
Flywheel

Legal

Privacy Policy

Last updated 1 September 2026. An attorney has not yet blessed this page — treat it as the product’s honest description, not legal advice.

Flywheel (“we”, “us”) is the lead-response product at use-flywheel.com. This page covers that site, the subscriber dashboard, and the public API.

Two roles

  • You as a subscriber. When you create an account, we are the controller of that account data.
  • Your customers. When we text someone on your behalf, you are the controller of their data and we are your processor. You need a lawful basis to message them. We honour STOP immediately.

What we collect

  • Account details you type at signup or in Settings (name, login email, phone, timezone, Place ID).
  • Messages, contacts, appointments, and consent events needed to run the product.
  • Technical logs (IP, user agent) for security and delivery.

SMS

Outbound texts go through our messaging provider. Quiet hours are enforced in the recipient’s timezone. STOP/HELP are honoured at the carrier and in our records. We do not sell phone numbers.

Google reviews (opt-in)

If you save a Google Place ID, we may fetch reviews live from Google Places when you open Reviews in the dashboard. We store only the Place ID. We do not cache, copy, or remix review text, ratings, or author names (Google Places API terms). Display includes the attribution Google requires. Using that fetch also means you agree to Google’s Maps/Places terms and Google’s Privacy Policy.

Testimonials

A first-party quote is stored only after the person replies YES. We do not invent quotes or turn them into a star score.

Webhooks

A subscriber can register an HTTPS URL and we will POST signed event payloads there. Most events name ids and states, not message text. message.received is the exception: it includes the inbound body, because that is what an inbox integration needs. Subscribing to it is opt-in — you name the event. An empty event list means every other event, not this one. Partner API access is still required to register an endpoint; there is no extra permission beyond naming it.

Each delivery is a row we keep so we can retry a miss. After the subscriber accepts a payload we empty it: 24 hours for message.received, 7 days for everything else. A delivery we gave up on keeps its body so it can be inspected or replayed. The message itself stays in the conversation until the account is deleted.

Sharing

We use subprocessors to send SMS, host the app, and (if you opt in) read Places. We do not sell personal information. A subscriber’s API key can read that subscriber’s data; we do not give one subscriber another’s.

Retention and rights

We keep account data while the account is active and for a limited period after cancellation as needed for logs and disputes. You can ask us to access, correct, or delete subscriber account data at [email protected]. Requests about a customer of yours should go to you; we will help you fulfil them.

Children

A minor is never the SMS recipient. The guardian is the contact. serves_minors defaults on.

Contact

[email protected]