Privacy notice
Last updated: 10 September 2026
This notice explains how personal information is handled when you browse the Maxim Flow website or get in touch. TwentySix OÜ operates Maxim Flow and is the data controller for personal information collected through this website. I’m Daniel Birch, the developer behind Maxim and your contact for privacy questions. Please use the contact form to get in touch. My email address is daniel@danielbirch.dev.
When you get in touch
The contact form asks for your name, email address, business name, team size and message. You can also provide a phone number and select a plan. If you arrive from a feature page, the form includes that feature so I know what you’re asking about. Your selected pricing region, currency and displayed prices are included with the enquiry, along with an enquiry reference.
I use this information to answer your questions, discuss your requirements and help you choose a plan. The form sends it through EmailJS to my email inbox. Your message is not saved in your browser’s local storage. Sending an enquiry does not subscribe you to a newsletter. Please avoid including sensitive personal information or your customers’ records.
Where an enquiry is about entering a contract with you, I process it to take the steps you request before that contract. For other business enquiries, TwentySix OÜ relies on its legitimate interest in responding to people who contact me about Maxim.
Regional pricing and browser storage
The website uses your browser’s language settings and a country lookup to suggest a pricing region. The lookup sends a request from your browser to api.country.is, with GeoJS as a fallback. These services receive your IP address to identify a country; the website does not request your device’s precise location. You can change the pricing region yourself.
A manual region selection is stored in local storage until you change it or clear your browser’s site data. An automatically detected region is reused for up to 30 days before another lookup. That 30-day period controls when the result is refreshed; it does not automatically delete the stored value. This storage is used to remember pricing preferences.
The website currently has no advertising trackers or visitor analytics scripts. Interactive product examples use sample data. Changes you make in those examples do not create a customer account or update a live business’s records.
Services used by the website
Loading the website and its external resources involves sharing connection information, including your IP address, with the services delivering them. The website is configured for Netlify hosting. Google Fonts supplies some of the typefaces. EmailJS delivers contact-form enquiries and my email provider receives the resulting messages. Country lookups use the services described above.
You can read more in the EmailJS privacy policy, Netlify privacy statement, Google Fonts FAQ and GeoJS privacy policy.
Some service providers process information outside the European Economic Area. EmailJS states that its processing facilities are in the United States and that it uses contractual safeguards for transfers from Europe. Contact me if you would like information about the providers handling your enquiry.
If you choose the WhatsApp link after submitting the form, WhatsApp receives the information needed to open the conversation, including your name in the prepared message. WhatsApp and other websites you choose to visit have their own privacy policies.
Payments through Stripe
Online payments are planned but are not yet enabled. Once available, Stripe will process subscription and setup-fee payments. Payment details will be entered through Stripe’s payment interface; the planned integration will not store full card numbers or card security codes on the Maxim website or its backend.
Stripe may process your contact and billing details, payment information, transaction history and device information to complete payments and prevent fraud. I will receive the billing, transaction and subscription information needed to manage your service, invoices, refunds and payment enquiries. Read the Stripe privacy policy for its processing purposes, international transfers and privacy rights.
TwentySix OÜ will use payment and subscription records to perform the contract, meet accounting and tax obligations and pursue its legitimate interest in preventing fraud and resolving disputes. Records will be retained for the applicable statutory periods and as needed to resolve outstanding payment matters.
Booking a call
An online booking calendar is planned but is not yet enabled. When available, it will use the contact details you provide, your selected appointment time, time zone and any booking notes to arrange a call. Booking information will be shared with the scheduling provider and my connected calendar to manage availability, confirmations, reminders and appointment changes. Please avoid including sensitive information or customer records in booking notes.
Booking information will be used to arrange the conversation you request or deliver your setup appointment. The legal basis will be steps you request before entering a contract, performance of the service contract or, for other business conversations, TwentySix OÜ’s legitimate interest in responding to enquiries. Booking a call will not subscribe you to marketing.
The scheduling provider has not yet been selected. Its identity, privacy policy and any relevant storage, retention and international-transfer details will be added before the calendar is enabled. Any cookie or consent requirements for the payment and booking integrations will also be addressed before they are enabled.
How long information is kept
Enquiry correspondence is needed while I answer your questions and deal with any follow-up. If you become a customer, relevant correspondence may also form part of the service record. Any further retention depends on outstanding matters and applicable record-keeping requirements. You can contact me to ask about the information held about you or request its deletion.
Copies held by service providers, including delivery records and backups, are subject to their retention arrangements. Browser storage follows the rules described above.
Your privacy rights
Depending on the circumstances, you can request access to your personal information, ask for corrections or deletion, request a restriction on its use and request a portable copy. You can also object to processing based on legitimate interests. If processing relies on your consent, you can withdraw that consent without affecting earlier processing.
To make a request, use the contact form or email daniel@danielbirch.dev. I may need to confirm your identity before sharing personal information. You can also raise a concern with your local data protection authority. The European Data Protection Board lists the authorities in the EEA.
Your business’s Maxim instance
The current setup provides each subscribed business with a separate Maxim instance, database, backend server and email sending setup. This describes how the service is currently delivered, rather than a commitment to a particular infrastructure or provider indefinitely.
I may reconfigure, replace or migrate the infrastructure, hosting providers, databases, email services and other technical components as I consider appropriate to operate, maintain and develop Maxim. Changes remain subject to the service agreement, applicable data protection requirements and the agreed safeguards for customer data, including separation between businesses’ data and access controls.
Where a change requires notice, authorisation or an update to the data-processing arrangements, TwentySix OÜ will follow those requirements before making the change. This notice does not override your service agreement or remove your privacy rights.
This notice covers website visits and enquiries, plus payments and bookings once enabled. The service agreement and data-processing arrangements govern records held in your instance, including information about your team and customers, and the process for changes to the service.
The payment and booking sections describe planned services. This notice will be reviewed against the completed integrations before they become available and updated when the website’s handling of personal information changes.