Privacy Policy
Effective date: June 20, 2026
This Privacy Policy describes how GarbageCake ("FollowUpFlare," "we," "us," or "our") collects, uses, discloses, and protects information about you when you use the FollowUpFlare platform. It also describes your rights and choices regarding your information. By using the Service, you agree to the practices described in this Policy.
1. Who We Are
FollowUpFlare is a lead notification platform operated by GarbageCake, a sole proprietorship. Our platform connects your Meta Lead Ads account to your team via real-time SMS and email alerts when new leads are submitted through your connected ad forms. We are reachable at jake@garbagecake.com.
2. The Two Types of Data We Handle
FollowUpFlare handles two distinct categories of data with different privacy implications:
A. Account and operational data — information about you as our customer: your name, email, business name, billing details, and usage of our platform. We are the data controller for this information.
B. Lead data — contact information (name, phone, email, and any other fields) submitted by third parties (your prospective customers) through your Meta Lead Ad forms, which we retrieve and route to your designated recipients. For lead data, you are the data controller. We act solely as a data processor on your behalf. We process lead data only as necessary to deliver notifications and do not use it for our own analytics, advertising, or any purpose other than fulfilling the Service.
This distinction matters because your legal obligations as a business collecting lead data through Meta are separate from our obligations as your service provider.
3. Information We Collect
Information you provide directly:
- Account registration: your full name, email address, business name, physical business address, phone number, and password when you create an account.
- Payment information: billing name, card details, and billing address when you purchase credits. Full card numbers are processed and stored by Stripe; we store only a payment method token and the last four digits of your card for display purposes.
- Recipient information: names, email addresses, and phone numbers of team members you add as alert Recipients.
- Support communications: content of messages you send us through our support form or by email.
- Marketing preferences: whether you opt in to product updates and marketing communications during signup.
- Terms acceptance: a timestamp recording when you accepted these Terms during signup.
Information collected automatically:
- Log data: IP addresses, browser type and version, operating system, referring URLs, pages visited, and timestamps of access.
- Device information: device type and identifiers accessed via standard web browser APIs.
- Session data: authentication tokens stored in secure, httpOnly cookies to maintain your logged-in session.
- Consent records: IP address and timestamp recorded when a Recipient is added to your account and opts in to SMS notifications.
Lead data retrieved from Meta:
- We retrieve lead contact information from the Meta Leads API solely for the purpose of notifying your designated Recipients. This data is limited to what your Meta lead form is configured to collect. We have no ability to access Meta data beyond what is returned by the API for your authorized account. Lead data is stored in our database temporarily, subject to the 1,000-lead rolling retention limit described below.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: authenticating your account, retrieving lead data from Meta, routing notifications to Recipients, and managing your credit balance.
- Payment processing: charging your payment method for credit purchases and auto-refill transactions.
- Transactional communications: sending receipts, low-credit warnings, security alerts, and other account-related notifications. These are sent regardless of your marketing preferences.
- Marketing communications (opt-in only): if you checked the opt-in box during signup, sending you product updates, new features, tips, and occasional promotional offers. You may opt out at any time.
- Customer support: responding to your inquiries and resolving issues.
- Security and fraud prevention: monitoring for unauthorized access, abuse, and violations of our Terms.
- Legal compliance: fulfilling our obligations under applicable laws and responding to lawful requests from government authorities.
- Platform improvement: analyzing aggregated, de-identified usage patterns to improve the Service. We do not use individual lead data for this purpose.
We do not use lead data for advertising, profiling, product development, or any purpose other than delivering the notification Service on your behalf.
5. SMS Messaging and Mobile Numbers
We do not sell, share, rent, trade, or license mobile phone numbers or SMS consent records to any third party for marketing or advertising purposes. This is an absolute prohibition with no exceptions.
Mobile numbers collected through our platform are used solely for the following operational purposes:
- Sending the one-time opt-in confirmation SMS to Recipients when they are added to an account.
- Delivering transactional lead alert SMS messages to opted-in Recipients on behalf of the account holder.
- Processing opt-out (STOP) and help (HELP) requests from Recipients.
Message frequency: Recipients may receive multiple SMS messages per day depending on lead volume. During slow periods, no messages may be sent. Frequency is determined entirely by your incoming Meta lead volume.
Message and data rates: Standard message and data rates from the Recipient's mobile carrier may apply to all messages sent and received.
Opt-out: Recipients may reply STOP at any time to permanently unsubscribe from SMS alerts. They will receive one final confirmation message. They may also be removed by the account holder at any time.
See our full SMS Terms for complete details.
6. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
- Sub-processors / service providers: We share data with the following third-party providers who process data on our behalf, each subject to data processing agreements:
- Twilio, Inc. — SMS delivery. Recipient phone numbers and message content are transmitted to Twilio to send lead alert and opt-in SMS messages.
- Resend, Inc. — Email delivery. Recipient email addresses and message content are transmitted to Resend to send lead alert and account emails.
- Stripe, Inc. — Payment processing. Billing information is transmitted to Stripe to process credit purchases.
- Neon, Inc. — Cloud database hosting. All platform data is stored in Neon-hosted PostgreSQL databases located in the United States.
- Vercel, Inc. — Application hosting and deployment infrastructure.
- Meta Platforms, Inc.: We connect to the Meta Graph API using your authorization token to retrieve lead data. We do not share your data back to Meta beyond what is inherent in using the API.
- Legal requirements: We may disclose your information to law enforcement, government agencies, or courts when required by applicable law, subpoena, court order, or when we believe in good faith that disclosure is necessary to protect our rights, protect the safety of any person, or investigate fraud.
- Business transfers: If GarbageCake is acquired, merged, or sells substantially all of its assets, your information may be transferred as part of that transaction. We will provide notice of such a transfer and your choices regarding your data.
- With your consent: We may share your information in other ways if you have given us explicit consent to do so.
7. Data Retention
Account data: We retain your account information for as long as your account is active. If you close your account, we will delete your personal information within 30 days, except where we are required to retain it by law (e.g., financial records for tax purposes).
Lead data: FollowUpFlare retains a maximum of 1,000 lead records per account on a rolling basis. When this limit is reached, the oldest leads are automatically and permanently deleted without notice. Lead data is also automatically deleted within 30 days of account closure. FollowUpFlare is not a compliant long-term data archive. You must maintain your own authoritative records of customer lead data in a system you control.
Payment records: Transaction records are retained for 7 years to comply with financial and tax recordkeeping requirements.
SMS consent records: Opt-in records, timestamps, and IP addresses are retained for the life of the account and for 4 years after the associated Recipient's relationship ends, to support compliance with TCPA recordkeeping requirements.
Support communications: Support tickets and correspondence are retained for 3 years after resolution.
Log data: Server logs are retained for 90 days.
8. Data Security
We implement commercially reasonable technical and organizational measures to protect your information, including:
- Encrypted data transmission using TLS 1.2+ for all data in transit.
- Hashed and salted password storage using bcrypt. We never store passwords in plaintext.
- Session tokens stored in secure, httpOnly cookies that are not accessible to client-side JavaScript.
- Email-based two-factor authentication required at login.
- Database access restricted to application-layer connections only.
However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your information. In the event of a data breach that is likely to result in risk to your rights, we will notify affected users as required by applicable law.
Note regarding Meta access tokens: Your Meta user access token is stored in our database to enable continuous lead retrieval. While stored in a secured environment, this is an acknowledged risk. You can revoke our access at any time through your Meta Business settings.
9. Sensitive Data — Important Warning
FollowUpFlare is a notification tool designed for standard lead generation use cases. We are not designed, audited, or certified to handle sensitive categories of personal data, including:
- Protected Health Information (PHI) as defined under HIPAA
- Financial account information governed by GLBA or PCI-DSS
- Social Security numbers or government identification numbers
- Biometric data
- Data about minors under age 13
- Data subject to state-specific sensitive data regulations (e.g., California's CPRA sensitive data categories)
If your Meta Lead Ad forms collect any of the above categories of data, you should not use FollowUpFlare to process those forms. You are solely responsible for ensuring that your use of our platform complies with all applicable laws governing the data types your forms collect. We will not enter into Business Associate Agreements (BAAs), Data Processing Agreements (DPAs) containing HIPAA obligations, or similar regulated data agreements.
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may update or correct inaccurate information through your account settings or by contacting us.
- Deletion: You may request deletion of your personal information. Note that some information may be retained for legal compliance reasons.
- Portability: You may request your data in a portable format.
- Opt-out of marketing: You may unsubscribe from marketing communications at any time using the unsubscribe link in any email or by contacting us.
- California residents (CCPA/CPRA): California residents have additional rights, including the right to know what personal information is collected and shared, the right to opt out of sale (we do not sell personal information), and the right to non-discrimination for exercising privacy rights. To exercise your CCPA rights, contact us at jake@garbagecake.com.
To exercise any of these rights, contact us at jake@garbagecake.com. We will respond to verifiable requests within 30 days.
11. Cookies and Tracking
FollowUpFlare uses the following types of cookies and local storage:
- Session cookies: A secure, httpOnly authentication cookie (
ff_session) that keeps you logged in. This is strictly necessary for the platform to function. - No third-party advertising cookies: We do not use tracking pixels, advertising cookies, or behavioral targeting technologies from third parties.
We do not currently use analytics platforms such as Google Analytics. We rely on server-side log analysis for operational monitoring.
12. Children's Privacy
FollowUpFlare is intended solely for use by business owners and professionals aged 18 and over. We do not knowingly collect, process, or store personal information from individuals under the age of 18. If you believe a minor has provided information through our platform, please contact us immediately at jake@garbagecake.com and we will promptly delete the relevant data.
13. International Users
FollowUpFlare is operated from the United States and is intended for use by U.S.-based businesses only. By using the Service, you acknowledge that your information will be processed and stored in the United States, which may have different data protection standards than your country of residence. We do not actively solicit or serve users outside the United States at this time.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will update the effective date at the top of this page and notify you by email. Your continued use of the Service after changes are posted constitutes acceptance of the updated Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
GarbageCake / FollowUpFlare
Email: jake@garbagecake.com
Web: followupflare.com