PRFlow

Privacy Policy

Last updated: September 3, 2026

1. Introduction

PRFlow is operated by PRFLOW LABS LIMITED ("we", "our", or "us"), an Irish private company limited by shares registered in Ireland under company number 824206. Our registered office is Venture Hub, 136 Capel Street, Dublin 1, Dublin, D01 T2C9, Ireland.

This Privacy Policy explains how we collect, use, and safeguard your information when you use PRFlow ("the Service"), which delivers GitLab merge request and GitHub pull request notifications to Slack. PRFLOW LABS LIMITED is the controller of the personal data described in this policy, except where we process personal data on behalf of a customer under a data processing agreement.

2. Information We Collect

We collect the following types of information:

Account Information

  • GitLab username and email address
  • GitLab OAuth tokens (encrypted)
  • GitHub organization or account name and GitHub App installation identifiers
  • Slack workspace and channel information
  • Slack OAuth tokens (encrypted)

GitLab Project and Merge Request Data

Received from your GitLab instance via webhooks, and retrieved from the GitLab API on your behalf:

  • Merge request metadata (title, author, status, URL, branch names, approval and discussion counts)
  • Project names and identifiers
  • Pipeline status information
  • Comment content (for notification delivery only — see Section 5)

GitHub Repository and Pull Request Data

Received from GitHub via webhooks when you install the PRFlow GitHub App, and retrieved from the GitHub API on your behalf. The App's permissions are read-only (pull requests, checks, issues, and repository metadata); it has no access to repository contents, so PRFlow cannot read your source code:

  • Pull request metadata (title, author, status, URL, branch names, review and check status)
  • Repository names and identifiers
  • Check run and CI status information
  • Comment content (for notification delivery only — see Section 5)

Usage Data

  • Website page paths, interactions with page controls, performance metrics, referral source, and campaign parameters
  • Application page paths, interactions with page controls, visible text on interacted elements, and performance metrics
  • Browser, device, and approximate location information derived from the connection IP address
  • For signed-in application users, the Clerk user identifier, organization identifier, and organization role
  • Error diagnostics and sampled application session replays for troubleshooting; form inputs and media are masked in replays

3. How We Use Your Information

We use the collected information to:

  • Deliver merge request and pull request notifications to your Slack channels
  • Display pipeline, check, and CI status in notifications
  • Sync comments from GitLab and GitHub to Slack threads
  • Authenticate and authorize your account
  • Improve and maintain the Service
  • Respond to support requests

We do not sell your data. We use the GitLab and GitHub data we receive solely to provide the notification features you have configured. We do not modify its content, disclose it to third parties (beyond delivering it to the Slack workspace you configure), or use it for any other purpose without your consent.

4. Data Storage and Security

We take the security of your data seriously:

  • OAuth tokens are encrypted at rest using industry-standard encryption
  • All data is transmitted over HTTPS
  • Raw webhook payloads are processed in real time and not permanently stored
  • We use secure cloud infrastructure with regular security updates

We handle personal data in accordance with applicable privacy and data-protection laws and regulations.

5. Data Retention

What we store, and for how long:

  • Account information and encrypted OAuth tokens — retained while your account is active. Disconnecting an integration deletes its stored tokens.
  • Merge request and pull request metadata (title, author, status, URL, branch names, pipeline and check status) and references to the Slack messages we post — retained while your account is active so we can keep existing Slack messages up to date as merge requests and pull requests change.
  • Comment content — passed through to Slack for delivery and not stored. We keep only a reference (comment ID and Slack message ID) so that edits update the right Slack message.
  • Raw webhook payloads — processed in real time and not retained.

You may request deletion of your account and associated data at any time.

6. Third-Party Services

PRFlow integrates with the following third-party services:

  • GitLab - For authentication, receiving webhook events, and retrieving merge request data via the GitLab API
  • GitHub - For receiving webhook events from the PRFlow GitHub App and retrieving pull request data via the GitHub API
  • Slack - For delivering notifications to your workspace

We also rely on the following sub-processors to operate the Service: Railway (hosting and database), Clerk (authentication), Polar (billing), Sentry (error monitoring and masked application session replay), PostHog (website and product analytics), Umami (cookieless website analytics), Google (website analytics and advertising), and Crisp (optional website support chat). PRFlow's application servers and database are hosted on Railway in the European Union (Netherlands). Clerk, Polar, Sentry, PostHog, Umami, and Google may process data in other countries under their respective data-processing terms. PRFlow uses PostHog's European Union ingestion service. Google Analytics and Google Ads are operated by Google Ireland Limited and may transfer data to the United States under Google's data-processing terms and the EU-U.S. Data Privacy Framework.

When you connect PRFlow, merge request and project data is retrieved from your GitLab instance and transmitted to the Slack workspace and channels you configure. This means this data is transmitted to systems outside the GitLab platform. GitLab is not responsible for the privacy, security, or integrity of data once it has left the GitLab platform.

Likewise, when you install the PRFlow GitHub App, pull request and repository data received from GitHub is transmitted to the Slack workspace and channels you configure.

Your use of these services is governed by their respective privacy policies.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to processing of your personal data in certain circumstances
  • Disconnect your GitLab, GitHub, or Slack integrations at any time
  • Export your configuration data

8. Cookies

The PRFlow application uses cookies and similar storage for authentication, session management, and product analytics. Product analytics starts when a signed-in user uses the application; PRFlow does not use this application data for advertising or tracking across unrelated websites.

On prflow.dev, Umami, PostHog, and Google Analytics collect limited analytics without cookies until you make a choice. PostHog's cookieless mode uses a server-generated identifier that does not persist across days, and Google Analytics runs in consent mode with storage denied. If you accept analytics cookies, PostHog may store an identifier shared between prflow.dev and app.prflow.dev so visits can be recognized over time and connected to application usage, and Google Analytics stores its _ga cookies to recognize repeat visits for up to two years. If you reject analytics cookies, marketing-site events remain cookieless.

Advertising cookies are separate and off unless you accept them. If you accept them, Google may store identifiers such as _gcl cookies so PRFlow can measure which ads led to a visit or a signup, and so PRFlow ads can be shown to you on other websites. Accepting analytics cookies alone never enables this: advertising is its own choice in, and while it is off PRFlow's measurement stays non-personalized. PRFlow does not advertise inside the signed-in application and does not sell personal data.

The Crisp support chat is disabled until you accept live chat cookies. If enabled, Crisp stores a session cookie so it can keep your conversation available while you browse.

A necessary cookie stores your preference for 180 days. You can change or withdraw your choice at any time through.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of any material changes by posting the new policy on this page and updating the "Last updated" date.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact PRFLOW LABS LIMITED at hello@prflow.dev. You can also write to us at our registered office: Venture Hub, 136 Capel Street, Dublin 1, Dublin, D01 T2C9, Ireland.