← Back to sign in

Privacy Notice

How Sriggle Fintech collects, uses, protects and deletes personal data. Written to meet GDPR Articles 13–14, the CCPA/CPRA notice requirements, and comparable laws (India DPDP Act, UAE PDPL).

1. Who does what with your data

For the account you register and the people you invite, Sriggle Technologies is the data controller. For the customer and vendor records your company keeps inside the application, your company is the controller and Sriggle Fintech processes that data on your instructions — the application ships the tools you need to answer your own data-subject requests (export and erasure on every customer/vendor page).

2. What we collect, and why

DataPurposeLegal basis
Your name, email, password hash, avatar, language Operating your sign-in and profileContract (GDPR Art. 6(1)(b))
Card references: gateway tokens, brand, last four digits, expiry Charging the monthly subscription. Full card numbers and security codes are never stored — the card lives with the payment gateway. Contract
Customer/vendor contacts, documents, payments you record Your bookkeeping — processed on your instructions Your company's basis (usually contract/legal obligation)
Audit trail: who did what, when, from which IP Financial-records integrity and securityLegal obligation / legitimate interest
WhatsApp/SMS message content and attachments Sending documents and receiving bills you choose to exchangeContract

3. Processors we use

4. Your rights

5. Retention

6. Security

7. Cookies

Only strictly necessary cookies: the sign-in session, CSRF protection, and your selected entity. No analytics, no advertising, no third-party cookies — which is why there is no cookie banner.

8. Contact

Data protection questions and data-subject requests: privacy@sriggle.tech. We answer within 30 days (GDPR) / 45 days (CCPA).

Version 1.0 · This notice ships with the application; review it with your counsel and replace the contact address before going live.