Privacy Policy

Effective [EFFECTIVE_DATE]. This explains what Settlr collects, why, and who it is shared with.

1. Who this applies to

This policy covers two kinds of person:

  • You, the freelancer or agency who creates a Settlr account.
  • Your client, who never creates an account, but whose name, email, phone number, and payment information are processed by Settlr on your behalf when you invoice them, and when they approve a proposal, sign a contract, or pay through a link you send them.

If you are a client and have a question about how your data is handled, you can contact the freelancer who invoiced you directly, or reach Settlr at [SUPPORT_EMAIL].

2. What Settlr collects

About you, the account holder: your name, email, phone number, business name, bank account details (used to set up your Paystack subaccount so payments reach you directly), a preferred brand colour and logo if you set one, and the content you create — clients, projects, proposals, contracts, and invoices.

About your client, entered by you or by them: name, email, phone number, and — only for the specific invoice they are paying — payment details processed directly by Paystack (Settlr does not receive or store your client's card number). If your client signs a contract, Settlr records the signature, the IP address and browser information used to sign it, and a hash of the exact document text they signed, so the signature can later be shown to correspond to that specific version of the contract.

Automatically: standard technical information (IP address, browser type, pages visited) needed to keep the service secure and working, and usage counts (like how many AI proposal drafts you have generated this month) used only to enforce your plan's limits.

3. Why Settlr processes this data

To provide the service you sign up for: generating and sending your proposals, contracts and invoices; processing payments through Paystack; sending you and your clients the notifications the product is built around (an invoice was sent, a proposal was approved, a payment was made); enforcing your plan's limits; and keeping the platform secure — including the automated checks described in the rate-limiting section below, which exist to stop abuse of login, AI, and payment endpoints, not to profile individual users.

If you use the AI proposal writer (Pro and Agency plans), the brief you type is sent to Anthropic, the company that provides the underlying AI model, solely to generate your draft. Anthropic does not receive your client's data unless you choose to include it in the brief yourself.

If you turn on your public portfolio (Pro and Agency plans), the information you choose to show there — your name, bio, brand colour, and reviews clients have left — is genuinely public on the open internet, with no login required to view it. Anything you keep off your portfolio, or any review a client marks private, stays private.

4. Who Settlr shares data with

Settlr shares data only with the service providers needed to run the product, and does not sell your data or your clients' data to anyone.

  • Paystack — processes every payment, bank transfer, and payout. Paystack's own privacy policy governs how they handle payment data; Settlr does not control Paystack's practices beyond what it is contractually entitled to.
  • Supabase — hosts Settlr's database, authentication, and file storage. This means data is stored and processed outside Nigeria (in the EU). Supabase is a well-established provider with its own security and privacy commitments; using it means Settlr does not need to run its own database infrastructure, which would be a materially larger security surface for a company this size to secure alone.
  • Resend — sends the transactional emails the product relies on (an invoice notice, a password reset). Only the minimum information needed to send that specific email is shared.
  • Anthropic — receives the brief you type when you use the AI proposal writer, described above.
  • Vercel — hosts the application itself.

Settlr may also disclose information if required by law, to protect the rights or safety of Settlr, its users, or the public, or in connection with a merger, sale, or transfer of the business (in which case you would be notified).

5. Data retention

Settlr keeps your account data for as long as your account is active. If you close your account, we keep the records needed for legitimate business and legal purposes (for example, transaction records that may be required for tax or dispute purposes) for 90 days afterward, then delete or anonymise them.

6. Your rights

Under Nigeria's Data Protection Act (NDPA) and comparable data protection law, you have the right to know what personal data Settlr holds about you, to correct inaccurate data, to ask for it to be deleted (subject to the retention needs above), and to object to certain processing. To exercise any of these rights, contact [SUPPORT_EMAIL].

If you are a client of a Settlr user rather than an account holder yourself, the same rights apply to the data processed about you — contact either the freelancer who invoiced you or Settlr directly.

7. Security

Settlr uses industry-standard practices to protect data, including encrypted connections (HTTPS) everywhere, database-level access controls that restrict every user's data to that user alone, and a security review of the client-portal and payment paths before they were launched. No system is completely secure, and Settlr cannot guarantee absolute security, but security is treated as a first-class requirement throughout the product, not an afterthought.

8. Children

Settlr is not directed at anyone under 18 and does not knowingly collect data from anyone under that age.

9. Changes to this policy

If this policy changes in a material way, we will make reasonable efforts to notify account holders (by email or an in-app notice) before the change takes effect.

10. Contact

Questions about this policy or your data: [SUPPORT_EMAIL].

[LEGAL_ENTITY_NAME]
[REGISTERED_ADDRESS]