Privacy Policy
This policy covers the SprintPad website, web app, iOS app, client portal, and related APIs.
1. Who we are
SprintPad (“SprintPad,” “we,” “us”) is a cloud workspace for client-service teams. This policy applies to https://sprintpad.io, the application at https://dev.sprintpad.io, the iOS app, the client portal, AI/MCP endpoints, and emails we send about the service.
If your organization (a “Workspace”) invites you, that Workspace’s administrators decide what work data is stored and who can see it. For that customer content, the Workspace is typically the controller and SprintPad processes it to provide the service.
2. Information we collect
Demo requests. If you request a walkthrough on this website, we store your name, work email, company, team size, plan interest, how you reached the form (including a plan you selected and any referral tag), and the notes you send as a prospect record, and we email you to arrange a demo.
Account and security. Email address, display name, password (stored by Firebase Authentication, not in recoverable form on our servers), Google account identifiers if you use Google sign-in, phone number if you enable SMS two-step verification, and authentication session data.
Workspace and work content. Data you or your teammates put in SprintPad, including tasks, projects, workstreams, milestones, comments, attachments, proofs, time logs, schedules, clients, contacts, contracts, invoices, templates, categories, roles, and settings. Client-portal contacts may have their own login and see only what the Workspace shares with them.
Payments. If a Workspace connects Stripe, we store configuration needed to create invoices and record payment status. Card and bank details are handled by Stripe on that Workspace’s Stripe account. SprintPad does not hold client funds.
AI agents. If you connect an MCP client, we store OAuth client metadata, the workspaces you approved, and tokens needed to keep that connection. Agents act with your SprintPad permissions until you revoke access.
Communications. Transactional email (invites, password setup, notifications) sent through our email provider. Support messages you send to us.
Technical logs. IP address, device/browser type, timestamps, and diagnostic logs generated by Google Cloud / Firebase while you use the service. We do not run a separate advertising analytics pixel on this marketing site or in the app as of the effective date.
Local device data. Preferences such as theme may be stored in your browser. The iOS app may use device services required for authentication (for example push or reCAPTCHA fallback for phone verification).
3. How we use information
- Respond to demo requests and communicate about a possible workspace.
- Provide, maintain, secure, and improve SprintPad, including syncing work across web and mobile.
- Authenticate users, enforce roles and workspace membership, and operate two-step verification.
- Send service emails (invites, access, security, product notices).
- Process portal invoices through a Workspace’s connected Stripe account when enabled.
- Honor AI-agent connections you authorize, and stop them when you revoke access.
- Detect abuse, debug outages, and meet legal obligations.
4. Legal bases (where applicable)
Where GDPR or similar laws apply, we process data to perform our contract with you or the Workspace, to pursue legitimate interests such as securing the service, with consent where we ask for it (for example Google sign-in or SMS MFA), and to comply with law.
5. Who we share information with
We do not sell personal information. We share data with:
- Google Cloud / Firebase — hosting, authentication, database, storage, and functions.
- SendGrid (Twilio) — transactional email delivery.
- Stripe — payment processing for Workspaces that connect their own Stripe account.
- Google — if you choose Google sign-in.
- AI clients you authorize — tools such as Claude or Cursor receive only what those tools request under the access you granted.
- Workspace members and portal contacts — according to roles and sharing settings.
- Authorities — when required by law or to protect SprintPad, users, or the public.
Service providers may process data in the United States and other countries where they operate. If we transfer personal data from the EEA/UK/Switzerland, we use appropriate safeguards such as the providers’ standard contractual clauses where applicable.
6. Retention
Account and workspace data is kept while the Workspace is active and for a reasonable period afterward so we can restore service, resolve disputes, or meet legal duties. You or a Workspace admin may delete records inside the product. Authentication logs and backups follow Google Cloud retention. You can request account deletion using the contact below.
7. Security
We use HTTPS, Firebase Authentication, workspace-scoped access rules, optional two-step verification, and Google Cloud security controls. No method of transmission or storage is completely secure. You are responsible for account credentials and for the sharing settings in your Workspace.
8. Children
SprintPad is a business tool. It is not directed at children under 13 (or the age required in your country), and we do not knowingly collect personal information from them.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of personal data, and to opt out of certain sharing. Workspace customer content is usually handled by your organization — start with your admin. For SprintPad-held account data, email privacy@sprintpad.io. California residents may request the categories of personal information we collected and the business purposes for which we used it; we do not sell or share personal information for cross-context behavioral advertising as those terms are used in the CCPA.
10. Cookies and similar technologies
The application uses cookies and local storage that are necessary to keep you signed in and remember preferences. This marketing site does not set advertising cookies. You can control cookies in your browser; disabling them may prevent sign-in.
11. Changes
We may update this policy. We will change the effective date at the top and, when changes are material, provide additional notice (for example in the app or by email). Continued use after the effective date means you accept the updated policy.
12. Contact
Privacy questions and requests: privacy@sprintpad.io
Product home: Home
Application: Open the app
Related: Terms of Service