Privacy Policy

Last updated: July 6, 2026

This Privacy Policy explains how Sprigline ("Sprigline", "we", "us") collects, uses, and protects personal information when you visit sprigline.com, create a workspace, or use the Sprigline field service management platform (the "Service").

Sprigline is operated from Mexico, and the Service is hosted on infrastructure located in the United States. Sprigline is a multi-tenant platform: each business ("Workspace Owner") operates its own isolated workspace and invites its own staff and clients.

By accepting this Privacy Policy when you create an account, you acknowledge the practices described here. We record the version of this policy you accepted, together with a timestamp, as evidence of your consent.

1. Who is responsible for your data

Our responsibilities depend on whose data is involved:

  • Workspace Owners, staff, and website visitors — Sprigline is the data controller (responsable, under Mexican law) for your account information, billing records, and usage data.
  • Clients of a business that uses Sprigline — the Workspace Owner is the data controller for client records, property details, job history, and photos stored in their workspace. Sprigline processes that data on the Workspace Owner's behalf as a processor (encargado), acting only on their instructions.

If you are a client of an outdoor services business that uses Sprigline, direct privacy requests about your records to that business first — they control the data, and we will support them in responding.

2. If you are a client of a business using Sprigline

When you create a client portal account on a business's workspace (for example, yourprovider.sprigline.com), your data is split between two controllers:

  • Sprigline controls your login credentials (email and hashed password), your legal acceptance records, and the technical data needed to keep your account secure. Registration is on Sprigline's platform, which is why you accept Sprigline's Terms and this Privacy Policy when signing up.
  • The business controls everything about your service relationship — your contact details, property addresses, job history, photos of work performed, quotes, and invoices. Sprigline processes this data only on the business's instructions.
  • Payments you make through the portal go directly to the business's Stripe account; Stripe processes your payment data under its own privacy policy, and Sprigline never sees your card details.
  • Emails and notifications you receive through the portal (job updates, quotes, invoices) are sent by Sprigline on the business's behalf.

To access, correct, or delete your service records, contact the business first — they control that data. For anything about your login account or these acceptance records, contact us directly at privacy@sprigline.com.

3. Information we collect

We collect the following categories of information:

  • Account information — name, email address, phone number, password (stored only as a cryptographic hash), and role when you register or are invited to a workspace.
  • Business and workspace data — company name, workspace subdomain, logo, client and property records, job details, schedules, quotes, invoices, and photos uploaded to document work.
  • Payment information — subscription billing and client payments are processed by Stripe. Sprigline never stores full card numbers; we receive only payment status and limited metadata from Stripe.
  • Legal acceptance records — the version of the Terms of Service and Privacy Policy you accepted, your email, and the acceptance timestamp.
  • Communications — messages you send through our contact form or support channels, and notification emails delivered on your behalf.
  • Technical data — IP address, browser type, device information, and usage logs collected automatically to keep the Service secure and reliable.

4. How we use information and our legal bases

We use personal information for the purposes below. Where the GDPR or similar laws apply, the legal basis for each purpose is noted:

  • Providing and operating the Service — scheduling, invoicing, notifications, and the client portal (performance of a contract).
  • Authenticating users and enforcing role-based access within each workspace (performance of a contract).
  • Processing subscription and client payments through Stripe (performance of a contract; legal obligation for tax records).
  • Sending transactional emails — job notifications, quotes, invoices, password resets (performance of a contract).
  • Recording your acceptance of our legal terms (legal obligation and legitimate interest in evidencing consent).
  • Securing the Service — monitoring for abuse, fraud, and incidents (legitimate interest).
  • Improving the Service using aggregated, de-identified usage patterns (legitimate interest).
  • Complying with applicable law, court orders, and lawful requests from authorities (legal obligation).

We do not sell personal information, we do not "share" it for cross-context behavioral advertising as defined by the CPRA, and we do not use workspace data (including client records and job photos) for advertising or to train advertising models.

5. Service providers (subprocessors)

We rely on a small number of infrastructure providers, all processing data in the United States, to run the Service:

  • Supabase — database, authentication, and file storage.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional email delivery.
  • Vercel — application hosting and content delivery.

Each provider processes data only as needed to deliver their service to us and is bound by contractual confidentiality and data protection commitments. We will update this list when subprocessors change.

6. International data transfers

The Service is hosted in the United States: your data is stored and processed on US servers operated by the subprocessors listed above. Sprigline personnel access the Service from Mexico for operation and support.

If you use the Service from outside the United States, you understand that your information is transferred to and processed in the United States, and may be accessed from Mexico. Where required, we rely on our subprocessors' standard contractual protections and equivalent safeguards for these transfers.

7. Cookies

Sprigline uses cookies that are strictly necessary to operate the Service — primarily secure authentication cookies that keep you signed in to your workspace. We do not use third-party advertising or cross-site tracking cookies, which is why the Service does not show a cookie consent banner.

Because we do not track users across sites, the Service treats all traffic the same regardless of "Do Not Track" or Global Privacy Control signals — there is no tracking to opt out of.

8. Data isolation and security

Every workspace is logically isolated: data belonging to one business is not accessible to another. Access within a workspace is controlled by roles (owner, admin, staff, client), enforced both in the application and at the database layer with row-level security.

Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Passwords are hashed, payment credentials never touch our servers, and access to production systems is restricted and logged.

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify affected users and, where required, competent authorities without undue delay and in accordance with applicable law.

9. Data retention

  • Workspace data — retained for as long as the workspace remains active; deleted or anonymized within 90 days of workspace closure, except as noted below.
  • Billing and tax records — retained for the period required by applicable tax and accounting law.
  • Legal acceptance records — retained even after account deletion, as evidence of the agreement that governed the relationship.
  • Security logs — retained for a limited period consistent with their purpose, then deleted or aggregated.

10. Your rights — European Economic Area and United Kingdom (GDPR)

If the GDPR or UK GDPR applies to you, you have the right to access, rectify, erase, and receive a portable copy of your personal data; to restrict or object to certain processing; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

11. Your rights — California (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to access and receive a copy of it; to correct inaccurate information; to delete it (subject to legal exceptions); and to not be discriminated against for exercising these rights.

We do not sell personal information and have not done so in the preceding 12 months; there is therefore no need for a "Do Not Sell or Share My Personal Information" opt-out.

12. Your rights — Mexico (LFPDPPP)

If Mexican data protection law (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) applies to you, you may exercise your ARCO rights — Access (Acceso), Rectification (Rectificación), Cancellation (Cancelación), and Objection (Oposición) — as well as revoke consent, by contacting us at privacy@sprigline.com. We will respond within the timeframes established by the LFPDPPP.

13. Exercising your rights

To exercise any of the rights above, email privacy@sprigline.com from the address associated with your account, or use the contact form on our website. We may need to verify your identity before acting on a request. If your request concerns records held in a business's workspace, we will refer it to that Workspace Owner and assist them in responding.

14. Children

The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the Service or by email before they take effect, and the "Last updated" date above will always reflect the current version. Each version is identified so that your acceptance record refers to the exact text you agreed to.

16. Contact

Questions about privacy at Sprigline? Email privacy@sprigline.com or use the contact form on our website.