Privacy Policy

Last updated: July 28, 2026
Before you rely on this: this is a starting draft covering standard practice for a SaaS tool like this one, not finished legal advice. Have a lawyer review it against the specific privacy laws that apply to where your customers are based (for example NDPR in Nigeria, or GDPR if you ever serve users in the EU/UK) before treating it as your final policy.

1. What this policy covers

This Privacy Policy explains what information Sigil ("we", "us") collects when a company and its team members use the Service, how we use it, and the choices available to you.

2. Information we collect

CategoryExamples
Account informationName, email address, password (stored in hashed form by our authentication provider, never in plain text)
Company informationCompany name, join code, list of members and their roles
Request dataWhatever fields your company's approval templates collect — this can include names, monetary amounts, dates, and any other business information your team enters
File attachmentsDocuments or images your team uploads to a request (e.g. receipts, evidence of payment)
Usage dataBasic activity like sign-in times and which requests you've interacted with, used to make the product work (e.g. showing your pending approvals)

3. How we use this information

We do not sell your data, and we do not use your company's request data for advertising.

4. Where your data is stored and processed

Sigil is built on Google Firebase (authentication, database, file storage, and hosting infrastructure) and uses a third-party transactional email provider to deliver notification emails. These providers process data on our behalf under their own security and privacy commitments; we don't control their infrastructure directly, but we choose providers with strong industry-standard security practices.

5. Data separation between companies

Each company's data is logically separated in our database and protected by access rules so that one company's members cannot read another company's requests, templates, or team information.

6. Data retention

We retain your data for as long as your company's workspace remains active. If a company or account is deleted, we will remove the associated data within a reasonable period, except where we're required to retain it for legal or accounting reasons.

7. Your rights

Depending on where you're located, you may have rights to access, correct, or request deletion of your personal information. Company administrators can manage most of this directly (deactivating a member, editing team information); for anything else, contact us using the details below.

8. Cookies and local storage

The Service uses your browser's authentication session (managed by our sign-in provider) to keep you logged in. We do not use advertising or third-party tracking cookies.

9. Children's privacy

The Service is intended for business use by adults acting on behalf of a company and is not directed at children. We do not knowingly collect information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. We'll take reasonable steps to notify users of material changes.

11. Contact

Questions about this Privacy Policy, or requests relating to your personal data, can be sent to [insert contact email].