Privacy
Useful data, without building a profile of a person.
ENFLOW measures how its own pages and links are used so the service can improve. It does not use advertising cookies or a persistent visitor identifier. Payment information is handled only after an accepted scope is invoiced through PayPal.
ENFLOW receives contact submissions after Cloudflare checks and relays them to the relevant ENFLOW inbox. ENFLOW does not create a separate contact database. Separate, first-party site measurement records structured events without copying contact-form contents into analytics.
Information received through the contact desk
When someone submits the form, ENFLOW receives the sender's email address and the information they choose to include, such as name, organization, country, public website, question, deadline and project context. We use it to review and respond to the enquiry, define and deliver accepted work, maintain business and accounting records, prevent abuse, and comply with applicable obligations.
Do not send passport details, payment credentials, medical records, confidential trade secrets or other sensitive personal data unless an appropriate handling method has first been agreed in writing.
Hosting, form security and delivery
Cloudflare hosts and protects the website, validates form submissions with Turnstile, and relays accepted submissions by email. It may process the submitted fields and technical request information such as IP address, request time, browser details and requested URL to deliver and secure those services.
Analytics and cookies
ENFLOW records page views and transitions, active time, scroll depth, section reach, important link impressions and clicks, outbound and affiliate clicks, contact-form start and submission events, selected request category, page-performance measurements and anonymous error categories. It also records the page or content identifier, referring host, an allowlisted set of campaign values such as UTM parameters, language, viewport class and broad country-level delivery context.
The analytics event dataset does not contain a name, email address, contact message, payment information, IP address, raw browser user-agent, complete referring URL, complete query string or a persistent visitor ID. ENFLOW does not set an analytics cookie or use third-party advertising trackers. Browser Global Privacy Control and Do Not Track signals disable this first-party event collection.
Cloudflare provides the hosting and analytics infrastructure and may process IP address, browser and request information to deliver, protect and measure the service. Raw first-party event rows are retained in Cloudflare Analytics Engine for up to three months. Aggregated, non-person-level reports may be retained longer to compare content and service performance over time.
Payments
Accepted JAPAN DESK work is invoiced through PayPal. PayPal processes the payer's account, card and transaction data under its own privacy terms. ENFLOW receives the payment and invoice records needed to confirm and account for the transaction, but visitors should never email payment credentials.
Affiliate links
Clicking a clearly labeled affiliate link may take the reader to a third-party service. That provider applies its own privacy policy and may use link parameters to attribute a referral.
Retention and sharing
Enquiry and service records are kept only as long as reasonably needed for the purposes above and any applicable contractual, accounting, security or legal obligation. Information is not sold. It may be shared with a relevant Japan-side contact only where the requester asks for or approves external enquiry, and only to the extent reasonably needed for that enquiry.
Contact and data requests
To request access, correction, deletion or an explanation of personal information handled by ENFLOW, use the ENFLOW contact form and select “Correction, rights or privacy.” Some records may need to be retained where required for an ongoing contract, accounting, security or legal obligation.
Changes
Material changes to data collection require a new policy version before the relevant feature is enabled.
Public identity revision: Aug 17, 2026 JST