This Privacy Policy explains how [COMPANY LEGAL NAME, e.g. Sprex LLC] (“Sprex,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Sprex website and application (the “Service”).
Sprex is currently offered to a small, invite-only early-access group of software resellers. This policy is a draft for review before a public launch.
1. Information we collect
Account and sign-in information
We collect information used to create and manage your account, including your name or display name, email address, account identifier, and sign-in method. If you use Google sign-in, Google helps authenticate you and provides the account information needed to sign you in. Sprex does not receive your Google password.
Workspace and team information
We collect workspace names, workspace membership, administrator or representative roles, teammate invitation email addresses, who sent an invitation, whether an invitation was accepted, and related timestamps.
Partner, deal, and settings information
We store the information that you and your teammates enter into Sprex, including:
- partner or software-vendor profiles, categories, pricing models, margin terms, rebates, MDF, distributor details, and program-year information;
- customer account names, product or deal names, deal stages, dates, terms, prices, costs, quantities, usage assumptions, and other deal details;
- workspace settings, such as margin thresholds, stage probabilities, commercial assumptions, and monthly document-extraction limits; and
- sample data if a user chooses to load it.
This information may include confidential business information belonging to you, your customers, vendors, distributors, or other third parties.
Uploaded documents and extraction information
When you upload a partner agreement, order form, quote, invoice, image, or similar file, we collect and store:
- the uploaded file and its original file name, file type, size, storage identifier, page count, uploader, upload time, and attachment status;
- document-extraction status, error information, processing duration, file and page counts, and the AI model identifier used;
- extracted values, source quotations, source file and page references, confidence levels, validation issues, and notes; and
- matching suggestions and the partner or deal to which a document is attached after confirmation.
For confirmed order-form changes, Sprex also keeps a change log showing the deal field changed, its prior and new values, the supporting document and extraction, who confirmed the change, and when it was confirmed.
Usage and technical information
We record monthly document-extraction usage and reservation status so we can enforce workspace allowances and track successful or failed processing.
The Service also reports application errors through Lovable’s platform diagnostics. Those reports can include the error, the page path where it occurred, and related technical context.
[CONFIRM: the complete technical-log fields collected by Lovable, including whether IP address, device, browser, request metadata, or identifiers are retained, and for how long.]
Information stored in your browser
Sprex stores the identifier of your last-selected workspace in your browser’s local storage under sprex.workspace. A legacy marginiq.workspace value may be read once, moved to the new key, and removed. Authentication technology may also store session information needed to keep you signed in.
[CONFIRM: the exact cookies or browser-storage items used by Lovable Cloud authentication, their purposes, and their durations.]
Sprex does not currently use advertising cookies, behavioral advertising, or a consent-tracking platform. Google Fonts are loaded from Google when the app is displayed, which may cause your browser to send standard request information to Google.
[CONFIRM: whether self-hosted fonts will replace Google Fonts before launch.]
2. How we use information
We use information to:
- create and secure accounts and workspaces;
- accept workspace invitations and manage team roles;
- save, organize, calculate, and display partner and deal information;
- calculate estimated revenue, costs, margin, pipeline, renewals, and related planning figures;
- upload, store, read, and attach documents;
- send uploaded documents to an AI service to extract proposed partner or deal details for user review;
- match order forms to possible partners and deals within the same workspace;
- keep a record of confirmed document-based deal changes;
- enforce monthly extraction allowances and other workspace settings;
- operate, troubleshoot, secure, and improve the Service; and
- communicate with users about the Service, support, security, or policy updates.
We do not sell personal information. We do not display third-party advertising in Sprex.
Sprex does not use your Customer Data (including uploaded documents and extracted details) to train artificial intelligence models.
[CONFIRM: the legal basis or bases for each processing purpose where privacy law requires one, including contract, legitimate interests, consent, and legal obligations.]
3. How document extraction works
Uploaded documents are kept in private storage organized by workspace. Access rules are designed so that only members of the relevant workspace can view its documents. Short-lived download links are used when an authorized user opens a document.
When a user asks Sprex to extract information, the Service sends the selected document contents to OpenAI models accessed through Lovable’s AI Gateway. The extraction requests instruct the model to treat document contents as data, ignore instructions contained inside documents, avoid guessing, and return source quotations and confidence levels. The Service validates extracted values for issues such as impossible percentages, negative prices, and invalid dates.
AI output can be incomplete or wrong. Users must review extracted information before creating a partner or confirming deal changes. Sprex does not save a reviewed partner or deal from an extraction until the user confirms it.
Sprex does not use your Customer Data (including uploaded documents and extracted details) to train artificial intelligence models.
Lovable states that its contracts with third-party AI providers restrict their training on and retention of customer data.
[CONFIRM: whether Lovable uses AI Gateway requests from this app for its own model training.]
[CONFIRM: how long Lovable’s AI Gateway and OpenAI retain documents, prompts, outputs, and request logs.]
4. How we share information
We share information only as needed to operate the Service, comply with law, protect rights and safety, or complete a business transaction described below.
Service providers
Current service providers or technology platforms include:
- Lovable — hosting the app and its Lovable Cloud backend, which runs in part on infrastructure providers including Supabase, as well as authentication integration, file storage, server processing, platform diagnostics, and the Lovable AI Gateway used for document extraction;
- Google — optional Google sign-in and delivery of Google Fonts; and
- OpenAI — models used to process uploaded documents for extraction through Lovable’s AI Gateway.
These providers may process information on our behalf under their applicable agreements and privacy terms.
[CONFIRM: the complete and current list of Lovable’s subprocessors.]
Workspace members
Information entered into a workspace is visible to authorized members of that workspace. Workspace administrators can manage team access and roles, change workspace settings, delete partners and deals, and delete or detach documents. Representatives can create and edit partner and deal data and upload and view workspace documents, subject to the Service’s access rules.
Legal and safety reasons
We may disclose information if we reasonably believe disclosure is required by law, legal process, or a valid government request, or is necessary to protect the rights, safety, and security of Sprex, our users, or others.
Business transfers
If Sprex is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.
We do not sell personal information, and we do not share personal information for third-party behavioral advertising.
5. How long we keep information
Account, workspace, partner, deal, attached-document, extraction, usage, and change-log information is kept while it is needed to provide the Service or until it is deleted under the available controls or an approved deletion request, subject to legal, security, backup, and dispute-resolution needs.
Unattached draft uploads that are abandoned are scheduled for deletion after about 24 hours. This cleanup removes their database records and queues their stored files for erasure. Cleanup runs automatically and may also run when a user opens the upload screen, so deletion may not occur at exactly the 24-hour mark.
Documents attached to a partner or deal are kept until a workspace administrator deletes them or the workspace is deleted. Current database relationships are designed to remove workspace records when their parent workspace is deleted.
Deleted information may remain in our hosting provider's backups for a limited time before it is permanently removed.
[CONFIRM: the exact backup retention period.]
[CONFIRM: the final account- and workspace-deletion process, including identity verification, administrator approval, timing, exceptions, and whether self-service deletion will be added before launch.]
6. Security
Sprex uses measures currently implemented in the Service, including:
- authenticated access to private workspaces;
- access rules that limit data to members of the relevant workspace;
- administrator and representative roles;
- private document storage with short-lived download links; and
- server-side checks on document processing and confirmed changes.
Sprex is hosted on Lovable, whose platform is certified to SOC 2 Type II and ISO 27001.
No security method is perfect, and we cannot promise that information will never be accessed, altered, lost, or disclosed without authorization.
[CONFIRM: incident-response process, breach-notification contacts and timing, encryption details, backup controls, security testing, and any certifications before making further security claims.]
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, download, or delete personal information, object to or restrict certain processing, or receive a portable copy.
You can correct much of the workspace data directly in Sprex. Workspace administrators can manage members, settings, partners, deals, and attached documents under the controls provided in the app.
To request access, correction, account deletion, workspace deletion, or another privacy action, contact [CONTACT EMAIL]. We may need to verify your identity and authority over a workspace before acting. A workspace deletion request should be made by a workspace administrator. Deleting an account may not delete information that belongs to a shared workspace if other authorized members still need it.
[CONFIRM: response periods, appeal rights, authorized-agent procedures, and jurisdiction-specific rights required for the locations in which Sprex will be offered.]
8. International processing
The Service and its providers may process information outside the place where you live. Sprex's database and file storage are hosted in Lovable Cloud's Americas region.
[CONFIRM: where AI processing by Lovable’s AI Gateway and OpenAI takes place and any transfer mechanism used for international transfers.]
9. Children
Sprex is a business service and is not intended for children. You must be at least 18 years old and able to enter a binding agreement to use it. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy as Sprex changes. We will post the revised policy with a new “Last updated” date and provide any additional notice required by law. Material changes will apply prospectively unless the law permits otherwise.
11. Contact us
Questions or requests about privacy may be sent to:
[COMPANY LEGAL NAME, e.g. Sprex LLC][MAILING ADDRESS]
[CONTACT EMAIL]