Legal
Privacy Policy
Last updated: September 9, 2026
Florra ("Florra", "we", "us") provides a web application for cannabis production operations. This Privacy Policy explains what information we collect when you use florra.app and app.florra.app, how we use that information, and the choices available to you.
Scope
This policy applies to visitors to our marketing site, company admins, invited users, and other users of the Florra web application.
Information we collect
- Account information. Email address, display name, company name, and login credentials (passwords are handled by our authentication provider).
- Company and production data. Rooms, stations, task categories, tags, labour rates (admin-only), invite details, active/completed tasks, breaks, product/lot/ quantity details, notes, exports, and other workspace settings.
- Support and communications. Messages and information you send to support (for example via email).
- Technical and security data. Service logs and diagnostics needed to operate, maintain, and secure Florra (for example authentication events and error logs).
How we use information
- Provide, operate, maintain, and secure Florra
- Authenticate users and manage account, roles, and company membership
- Power product features (for example Live Floor, replay views, labour metrics, and exports)
- Respond to support requests and service communications
- Prevent abuse, fraud, unauthorized access, and security incidents
- Comply with legal obligations and enforce our Terms of Use
We do not sell personal information.
Roles and control of workplace data
Company admins control their workspace configuration, user access, and much of the company data entered in Florra. If you are a worker or invited user, requests about company data (including corrections or deletion requests tied to workplace records) may need to be handled by your company admin first.
How data is stored and processed
Florra uses third-party cloud infrastructure, including Google Firebase (such as Authentication and Cloud Firestore) and related Google Cloud / Hosting services. Data is stored and processed through those providers under their terms and security controls, in addition to this policy.
When we share information
We may share information only as reasonably necessary to:
- Operate Florra with trusted service providers and subprocessors
- Comply with legal process or regulatory requirements
- Protect Florra, our users, and the public from fraud, abuse, or security threats
- Support a merger, acquisition, financing, or asset transaction (with appropriate safeguards)
We do not share personal information with advertisers for their independent marketing.
Data retention
We retain information for as long as needed to provide the service, maintain security and records, and satisfy legal obligations. Retention periods vary by data type and business need. Admins may be able to delete or reset some company data in-product. You can request account deletion by contacting hello@florra.app.
Security
We use reasonable administrative, technical, and organizational safeguards, including encrypted transport, authenticated access controls, and provider security tooling. No system is perfectly secure, so you are responsible for using strong credentials and protecting invite links and account access.
International transfers
Depending on where you access Florra, information may be processed in jurisdictions other than your own through our service providers.
Children
Florra is intended for workplace use and is not directed to children. We do not knowingly collect personal information from children.
Policy updates
We may update this policy from time to time. We will update the "Last updated" date at the top of this page when changes are made. Continued use of Florra after an update means you accept the revised policy.
Contact
Questions about this Privacy Policy or privacy requests: hello@florra.app