#Flow PHP Work-Shop - Privacy Policy
Last updated: 31 July 2026
#1. What this policy covers
This policy covers the Flow PHP Work-Shop: the shop pages, buying digital content, and booking consulting. It describes the data involved in becoming and being a customer, and nothing else.
The controller of that data is:
Norbert Orzechowicz, sole proprietorship registered in Poland, NIP 6852282788 (EU VAT ID PL6852282788), Gołyszyn 100, 32-046 Skała, Poland, contact: support@flow-php.com
Payments are handled by Polar (Polar Software, Inc.) as Merchant of Record. For payment data, Polar acts as its own controller under Polar's privacy policy. We are the controller for the data we use to deliver access and provide support.
#2. How the shop works
The shop pages are statically generated. There is no application server and no database behind them: the pages you are reading are plain files. We do not run accounts, and there is nothing here to log in to.
Everything described below therefore sits with the providers listed in section 6, in accounts that belong to us. We remain the controller for it, because we chose those providers and decide what they collect and why.
#3. Analytics
We use PostHog (PostHog Cloud EU, hosted in the European Union) to see which
pages get visited. It is served through d.flow-php.com, a proxy on our own
domain.
PostHog runs in cookieless mode. It stores nothing in your browser: no cookie, no local storage, no session storage. Rather than giving you a persistent identifier, visits are grouped using a hash computed on PostHog's servers that rotates daily. We cannot recognise you across days, and we cannot link a visit to a person.
PostHog receives your IP address, browser and device type, and the pages you visit. The IP address is used to compute that daily hash and is then stripped, so it is not stored against the events. We use the result in aggregate. We run no advertising, we do not sell this data, and we do not combine it with purchase data to identify individuals.
Legal basis: our legitimate interest in understanding and maintaining the shop (art. 6(1)(f) GDPR).
#4. What we collect when you buy something, why, and on what legal basis
- Email address. To deliver access, send purchase-related messages, and provide support. This is collected by Polar at checkout and visible to us in the Polar dashboard. Legal basis: performance of a contract (art. 6(1)(b) GDPR).
- GitHub account or username. Where what you bought is delivered through GitHub, to grant you access as a collaborator. You connect this yourself in the Polar customer portal. Legal basis: performance of a contract (art. 6(1)(b) GDPR).
- Support correspondence. To handle your questions and complaints. Legal basis: performance of a contract and our legitimate interest in supporting customers (art. 6(1)(b) and (f) GDPR).
- Billing details and transaction records, including the billing address you give at checkout and any VAT ID you enter. Collected by Polar to issue your invoice and to meet accounting and tax obligations. These are primarily handled by Polar as Merchant of Record; where we keep records (for example for consultations), the legal basis is our legal obligation (art. 6(1)(c) GDPR).
- Sponsor listing (optional). If you opt in, the GitHub profile you choose to display, shown publicly on a sponsors list. Legal basis: your consent (art. 6(1)(a) GDPR), which you can withdraw at any time.
- Security and abuse prevention. Limited data to protect our repositories and detect misuse. Legal basis: our legitimate interest (art. 6(1)(f) GDPR).
We do not make any automated decisions about you, and we do not profile you.
#5. Payment data
We do not collect or store your card or payment details, and we never see them. Payment is processed by Polar as Merchant of Record, which issues your invoice or receipt and handles applicable taxes. Polar processes payment data under its own privacy policy.
#6. Service providers we use
We rely on the following providers. They process personal data on our behalf or as independent controllers, as applicable:
- Polar (payment, invoicing, tax as Merchant of Record) - United States
- GitHub (hosting repositories and managing access) - United States
- PostHog (shop analytics) - European Union
- Discord (optional community access, if you join) - United States
#7. International transfers
Our analytics provider stores data in the European Union. Polar, GitHub, and Discord are based in the United States. Where your data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, as provided by the respective provider. You can request more information about these safeguards using the contact details below.
#8. How long we keep your data
We keep your data only as long as necessary for the purposes above. Access and support data are kept for as long as you have access and for a reasonable period afterwards. Records needed for accounting or tax are kept for the period required by law. Analytics data is retained according to the retention settings of the provider in section 3. Consent-based data, such as the sponsor listing, is kept until you withdraw consent.
#9. Your rights
Under the GDPR you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interests, including the analytics described in section 3. Where processing is based on consent, you can withdraw it at any time without affecting processing carried out before withdrawal. To exercise any of these rights, contact us at support@flow-php.com.
You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO).
#10. Sponsors list
If you opt in at checkout, we display the GitHub profile you choose on a public sponsors list. This is entirely optional and based on your consent. You can ask us to remove your listing at any time by contacting support@flow-php.com, and we will remove it. Withdrawing consent is as easy as giving it.
#11. Cookies and local storage
We set no cookies on the shop pages. Our analytics sets none either, and there is no advertising or cross-site tracking. That is why you see no cookie banner.
The only things kept in your browser are there because you used a feature that needs them:
themein local storage. Remembers whether you chose light or dark mode. It never leaves your browser.
One third party sets its own storage, and only when you act:
- Polar's checkout, when you click to buy, under Polar's privacy policy.
You can block or delete any of this through your browser settings without losing any feature of the shop.
#12. Changes to this policy
We may update this policy. The current version is always available at this address, and material changes are reflected by updating the date above.
#13. Contact
For any privacy question or request, contact us at support@flow-php.com.
Our Terms of Sale are available at Terms of Sale.