YOUR INFORMATION

Clear about your data.

What FlyerRun stores, who can access it, and how tracking works.

Connected preview · Updated 23 September 2026This notice describes the current preview. This app is hosted at app.flyerrun.com. Verification email delivery and the final retention policy still need to be completed.

Campaign updates and device alerts

Your Updates inbox stores campaign alerts, read status and the categories of new alerts you choose to receive. You can change these preferences in Updates. These are service updates, not marketing subscriptions.

Device notifications are optional. If you enable them, FlyerRun stores a private browser delivery address and the device name you choose. Your browser’s notification provider processes that address, sender details and connection information to deliver an alert. Lock-screen alerts contain a generic prompt to open FlyerRun; customer and campaign details stay inside your signed-in account. You can remove a device in Updates or turn off permission in browser settings.

Adding FlyerRun to your Home Screen creates an installable web app. Its offline page and brand icons can be saved on your device. The app does not cache private campaign pages, files or API responses for offline use. Account data and changes require an internet connection. Device-alert delivery requires completed server setup and depends on browser and phone settings.

Campaigns and booking drafts

FlyerRun stores the campaign details, files, quotes, messages and enquiry outcomes you provide to coordinate your mailing and show your results. While you fill out a booking, an unsent draft is saved in this browser tab so it can survive sign-in. It is sent to FlyerRun when you submit the request while signed in. Clear draft removes it; a successful submission also removes it.

Your account and access

On app.flyerrun.com, Supabase manages account authentication and passwords. FlyerRun uses secure, HttpOnly session cookies. Customer signup requires email verification and remains unavailable until the email sender is configured. Demo accounts work only in the local preview.

Customers can access their own campaigns. Authorized FlyerRun operators can access campaigns to prepare quotes, coordinate mailing and support customers. Customer registration cannot grant admin access.

The contact form stores your name, email, optional business and phone, topic, message and permission to respond in a private FlyerRun admin inbox. It does not subscribe you to marketing. Email notifications are not connected; staff review messages in the inbox.

Your public enquiry page shows the campaign business, offer, service area and explicitly saved business phone number. Pickup addresses, private booking contacts and account identifiers are not published there. Only save a public business number you are authorized to use.

Online and offline marketing reports

Your marketing workspace stores campaign names, channels, offers, monthly figures, report references and follow-up notes. An enabled marketing enquiry page publishes only the business name and offer. Submitted contact details stay in the campaign owner’s account. Repeated submissions using the same email in the same marketing campaign keep the original enquiry.

Monthly advertising figures are entered by the customer and labelled accordingly. Google and Meta are not automatically connected. FlyerRun stores your tracking business name, business number, selected phone service and QR website. Incoming-call records contain a reference, called business number, time, result and duration, with any outcome and source you confirm. Records are labelled manual, imported or connected. We do not retain caller numbers, audio or transcripts in these call logs. A private connection key is displayed once; only its hash is stored. You can replace or disable it in Calls & QR.

Marketing observations are calculated from recorded figures. They are not proof that a campaign caused a sale. Enquiry totals are not deduplicated across different channels, and ad-platform conversions are kept separate.

Enquiries and follow-up

Enquiry forms ask for consent to share contact details and a message with the campaign business and FlyerRun for follow-up. These details appear in the campaign workspace. Do not enter sensitive personal information in messages or artwork. An enquiry is not consent to unrelated marketing.

Website attribution and customer setup

Customers and authorized FlyerRun admins can configure tracking for a business. Setup and confirmed-sales changes record the account that made them. Our website snippet stays off until the website grants analytics consent. After consent, it saves a random visitor identifier in that website’s local storage and creates a 30-minute tracking session. Withdrawing consent stops new collection and removes that local identifier; it does not erase records already received.

Consented website records may include campaign tags, Google or Meta click identifiers, the page path and events such as page views, call-button clicks and successful form activity. The snippet does not read form contents, names, email addresses or payment fields. A QR opening can carry a single-use reference lasting 15 minutes to connect a consented website session. First and last recorded sources support attribution; missing sources remain unknown. Website events are not verified sales or completed calls.

Business owners confirm their own leads and received revenue separately. Administrators can help with setup and authorized call-record imports. Call forwarding, recording, ad-account synchronization and automated conversion exports are not enabled by entering business details. Existing data remains available after a campaign is paused or archived.

Tracking links and cookies

A real tracking-link visit records a campaign or business link, any flyer batch and time. A first-party, HttpOnly cookie lasts 30 minutes, reduces repeated counts for the same link or campaign and connects an enquiry to the most recently opened batch in that browser. Known preview bots are filtered, but counts can still include unrecognized automated traffic. Visits are not unique-person counts or proof of delivery.

FlyerRun does not store IP addresses or browser fingerprints in these visit records. Hosting and infrastructure providers may process request information for their own security and operations. External destinations have their own privacy practices.

Authenticated Preview destination opens a link without recording a visit. For the FlyerRun enquiry page, a separate HttpOnly preview cookie lasts 10 minutes. A test submission is checked but is not saved as a lead. An expired test form asks you to reopen preview. Opening a real QR link exits preview mode; genuine activity can then be recorded. External websites may count their own visits even during a FlyerRun preview.

Phone numbers, reports and changes

Your saved business number is used on the FlyerRun enquiry page. It does not automatically measure calls to your existing line. Incoming calls need records from your phone service. The FlyerRun receiver accepts authenticated events from a compatible phone system; Rogers, Bell and Telus connections are not automatically activated by saving your number. A dedicated number or forwarding requires separate setup.

Reports use the events and outcomes stored for your campaigns. Revenue reflects the paid outcomes you enter, grouped by the enquiry's creation month, not verified payment transactions. Saving a phone number or QR destination changes future interactions and preserves existing campaign history. We keep account and campaign change records to support access control and resolve conflicting edits.

Storage, correction and deletion

In this connected preview, newly submitted campaigns, uploaded files, messages and enquiry outcomes are stored in FlyerRun's Supabase project in Canada. Production sign-in is managed by Supabase; secure session cookies are stored in your browser. Earlier local campaign records stay local unless their transfer is approved. Files are available through authenticated downloads.

Use your campaign's Messages to request a correction, a copy of your information or a deletion review. We will consider any records needed for an active order or applicable legal obligations. No automatic retention or deletion schedule is configured in this preview. For privacy questions, email contact@flyerrun.com or call +1 (416) 725-8792. A retention policy must be confirmed before paid launch.

Current service limits

The public app is hosted on Cloudflare, with private application records in Supabase. Verification email delivery still needs configuration. Interac payments are verified manually; there is no automatic bank connection. Carrier call feeds and advertising-account sync require separate setup. Choosing a paid plan saves a request; it does not take a payment. See the draft service terms for mailing and tracking responsibilities.

Bookings and payment references

We keep your requested service, approved quote, billing province, contact details and the bank transfer reference you provide. A FlyerRun admin checks receipt and records the payment status. We do not collect banking passwords, card details or security answers, and this app has no automatic bank connection.