YardFlow Privacy Policy
Last updated: 23 July 2026
This policy explains what information YardFlow collects, how it's used, and how it's protected. It covers the YardFlow product as a whole — not any single client's installation.
If you have questions about this policy, contact Futuristic Digital at nicolas@futuristicdigital.com.au.
1. Who this policy covers
YardFlow is a dispatch and billing system used by concrete supply businesses to manage deliveries, dockets, and invoicing. This policy applies to anyone whose information is processed by YardFlow — primarily the staff of a business using YardFlow (dispatchers, billing staff, administrators) and that business's own customers, whose details are recorded as part of normal billing and delivery operations.
Each business using YardFlow (a "client") controls its own data within the system. Futuristic Digital, as the developer and operator of YardFlow, processes that data on the client's behalf to provide the service.
2. Information we collect
Customer records
When a client sets up a customer account in YardFlow, it may store: the customer's business or billing name, a contact person's first and last name, an email address, and a business or postal address. YardFlow does not collect a phone number field.
User accounts
Staff who log in to YardFlow (dispatchers, billing staff, admins) have an account consisting of a username, an assigned role, and a securely hashed password. YardFlow does not require or collect an email address or legal name for staff user accounts — only a username.
Job and delivery records
Each delivery (job) recorded in YardFlow includes the customer it's for, the delivery site address, pricing and order details, and an optional free-text notes field. Because the notes field is free text entered by dispatch staff, it could occasionally contain other personal details a staff member chooses to record (for example, a site contact's name) — clients are responsible for what their staff enter here.
Signed delivery dockets
When a paper delivery docket is signed and returned, staff can scan and upload it (as a PDF, JPG, or PNG) to attach to the billing record. These files are stored securely in cloud object storage.
Activity records (audit log)
YardFlow keeps a permanent, tamper-resistant record of key actions taken in the system — for example, who created or edited a job, who reset a password, or who pushed an invoice to Xero, along with when it happened. This audit log is kept indefinitely and is not automatically deleted, including in cases where the underlying job record has itself been removed. This exists to maintain an accountable record of who did what, which is standard practice for a billing system.
3. How information is used
Information in YardFlow is used to operate the core service: creating and tracking deliveries, generating delivery dockets, calculating pricing, and producing invoices. It is not used for marketing, profiling, or any purpose beyond running the client's own dispatch and billing operations.
4. Sharing with third parties
Xero is the only third party YardFlow sends data to, and only when a client actively chooses to connect their Xero account and push an invoice. When an invoice is pushed to Xero, YardFlow sends: the billing contact's name, an order reference, a line-item description for each delivery (docket number, date, volume, and concrete strength), the invoice amount, and — if available — the scanned signed docket as an attached file.
YardFlow does not send a customer's email address, street address, contact person's name, or the free-text notes field to Xero. Only the specific invoice-relevant fields above are transmitted.
YardFlow does not sell, rent, or otherwise share personal information with any other third party.
5. Security
Passwords are never stored in plain text. YardFlow uses industry-standard salted password hashing (Werkzeug's PBKDF2-HMAC-SHA256 implementation) to store passwords securely. Login sessions use a signed browser cookie that expires when the browser is closed, unless a user chooses "Remember me," in which case the session may persist for a longer period (up to approximately 12 months) on that device.
Uploaded docket scans are stored in secure cloud object storage rather than on the application server itself.
6. Data retention
YardFlow does not currently apply an automatic time limit to most stored data — jobs, customer records, and audit log entries are retained indefinitely by default, as is standard for financial and billing records that may need to be referenced later (for example, during an audit or dispute).
Some records can be manually deleted by an authorised user within a client's account:
- A job can be deleted by an Admin only if it has not yet been billed or exported to Xero. Once a job has reached the billing stage, it is retained permanently and cannot be deleted, to preserve accurate financial history. Even where a job is deleted, a record of that deletion remains in the permanent audit log.
- A customer record can be deleted by Billing or Admin staff at any time.
- Staff user accounts cannot be permanently deleted, only deactivated. This is deliberate: a username is used to identify who performed an action throughout the audit log, so removing the account entirely would make historical records harder to interpret. A deactivated account can no longer log in.
7. Cookies and tracking
YardFlow does not use any analytics, advertising, or tracking scripts. The only external resource loaded by the application is Google Fonts, used purely to display text in the correct typeface. Loading a webfont from Google's servers means a user's device connects to Google to retrieve it, but no tracking or analytics data is collected through this.
8. Your rights
If you are a staff member or customer of a business using YardFlow and have questions about your information, please contact that business directly, as they control the data held in their own YardFlow account. If you need to contact Futuristic Digital directly about how YardFlow itself handles data, use the contact details at the top of this policy.
9. Changes to this policy
This policy may be updated from time to time as YardFlow's features change. The "Last updated" date at the top of this page will reflect the most recent revision.