Skip to content

Privacy

Privacy

This policy describes the categories of data Gather Sprout processes for accounts and capture. It does not invent legal entities, processors, or certifications that are not configured for your deployment.

Last updated: 24 August 2026.

What we process

Depending on how you use Gather Sprout, the product may process account credentials, profile and OAuth identity details, and session metadata such as a keyed IP fingerprint and user agent; organisation, membership, invitation, API-key, and audit records; captured email addresses, subscription status, attributes, lists, tags, and attached provenance (source surface and any page, offer, referrer, UTM, path, device, or metadata context supplied by the capture); consent and suppression evidence; analytics, survey, referral, booking, membership, billing, campaign, and automation records where those modules are used; uploaded import files and generated exports; plus support messages sent by email or through the contact form. For paid plans, card details and payments are processed by Stripe; Gather Sprout stores only a Stripe customer reference, never card numbers.

Why we process it

To operate your workspace, capture and verify signups, honour consent and unsubscribe choices, send transactional account messages and any enabled campaign or automation messages you authorise, provide support, secure the service, and meet applicable legal obligations.

Your choices

Workspace owners can request an organisation export from Settings or the management API and can schedule organisation deletion through the management API. Settings also provides account export and deletion controls, and subscribers can use unsubscribe and confirmation links on messages. For access or erasure requests related to your account, email [email protected].

Operator identity

Registered legal entity name, company number, and postal address are not published on this page. Email [email protected] for deployment-specific operator details.

What this page does not claim

This page does not assert a DPA template, subprocessors list, retention schedule, cookie inventory, international transfer mechanism, or certification (for example SOC 2) unless those are separately published for your deployment.

Terms · Contact · Security