Sprig ← Back to home

Privacy policy

Last updated: September 22, 2026

Sprig ("we", "us", "our") provides a workspace for managing a business's Google Business Profile, connected social accounts, marketing campaigns, and customer support inbox. This policy describes, in detail, what personal data we collect, why we collect it, how long we keep it, who it is shared with, and the choices and rights you have over it.

By creating an account or using Sprig, you agree to the collection and use of information in accordance with this policy.

1. Who this policy covers

This policy applies to two kinds of people: the account holder who signs up for Sprig ("you", "the customer", "the controller" of their own workspace), and the individuals that customer interacts with through the product — the senders of the emails, reviews and messages that a customer's connected accounts receive. We act as a data processor on behalf of the customer for that second category.

2. Information we collect

Account and profile data — name, email address, password (stored hashed with bcrypt, never in plain text), company name, phone number, address, and any brand details (logo, colours, tone of voice) you enter.

Content you create — posts, captions, images and video you generate or upload, message templates, contact and lead records, scheduled campaigns, and support-ticket messages.

Connected-account data — data pulled from Google, Meta, Canva or another provider you explicitly connect, strictly limited to what each feature needs. The Google section below lists this precisely.

Usage and log data — like most web applications, our servers automatically record standard technical data on every request: IP address, browser type and version, device type, pages visited, and timestamps. This is used for security (detecting abuse and unauthorised access), diagnosing errors, and understanding aggregate product usage. It is not used to build an advertising profile of you.

Cookies and similar technologies — we use a small number of strictly necessary cookies to keep you signed in and remember your session (see §7). We do not use third-party advertising or cross-site tracking cookies.

3. Google user data we access, and why

We only request the following Google scopes, and only after you explicitly grant them on Google's own consent screen. Each is used for exactly one stated purpose, and for nothing else:

Sprig's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is never used to serve advertisements of any kind; it is never used to train generalised AI/ML models; it is never sold, rented, or transferred to data brokers or other third parties for their own purposes; humans read this data only when necessary for security purposes, to comply with law, or with your explicit consent for support.

4. Other connected accounts

If you connect Meta (Facebook, Instagram, WhatsApp), Canva, or an AI content provider, we access only what each feature needs — publishing the posts and messages you create, and sending your prompts and drafts to the AI provider you configured so it can generate text or images for you. The same rule applies as for Google: connect it in Settings, disconnect it there at any time, and each token is scoped to the feature it powers and to nothing else.

5. How we use information

6. Sharing and disclosure

We do not sell your personal data. It is shared only in these circumstances:

7. Cookies

We use only strictly-necessary, first-party cookies: a signed session cookie to keep you logged in, and a CSRF token to protect form submissions. Neither is used for advertising or shared with a third-party ad network. You can block cookies in your browser, but the product requires the session cookie to function while logged in.

8. Data security

Access and refresh tokens for every connected account are encrypted at rest and are never logged or displayed in plain text. Passwords are hashed, never stored in reversible form. Data is tenant-isolated at the database level: one customer's workspace cannot query or read another's. Access to production data is limited to the personnel who need it to operate the service. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.

9. International data transfers

Your data may be processed in a country other than the one you live in. Where that happens, we rely on the receiving provider's own compliance with applicable data-protection law (including, for Google's and Meta's own processing of the data covered by their APIs, their respective certifications and standard contractual clauses).

10. Data retention

We keep your workspace's data for as long as your account is active. Disconnecting a Google, Meta or other account revokes our access to it immediately and stops any further sync from that account. If you delete your account, we delete your workspace's data within 30 days, except where a longer period is required by law (for example, financial records) — see our data deletion page for the full process.

11. Your rights

Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data; export your data in a portable format; object to or restrict certain processing; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us using the details below — we will respond within the time required by applicable law.

12. Children's privacy

The service is intended for business use by adults and is not directed at, or knowingly used to collect data from, children under 16. If we learn we have collected data from a child under 16, we will delete it.

13. Third-party links

The product links out to third-party sites and services you choose to connect (Google, Meta, Canva, and others). Their own privacy policies govern their handling of your data once you leave our product to authorise them, and we encourage you to read them.

14. Changes to this policy

We will update the date at the top of this page whenever this policy changes, and will post material changes here — and, where the change is significant, notify account holders by email — before they take effect.

15. Contact us

Questions about this policy, or a data request under §11: smit.laravel@gmail.com