Privacy Policy

Last updated: 25th March 2026

1. Who we are

Spinal ("Spinal", "we", "us") provides a collections and accounts-receivable platform that helps businesses manage invoices, payments, and customer communication. This policy explains what data we collect, why, and how you can control it.

Data controller: Spinal, registered at 439 Metal Box Factory, 30 Great Guildford Street, London, SE192GA, United Kingdom.
Contact: andrew@withspinal.com

This policy applies to withspinal.com and the Spinal dashboard application.

2. Who this applies to

Customers - businesses that sign up for Spinal and their team members using the dashboard.
Debtors / end customers - people and businesses our customers are collecting payment from, who we contact by email, SMS, or WhatsApp on our customers' behalf.
Website visitors - people browsing withspinal.com before signing up.

3. Data we collect

Account data - name, work email, password (hashed), role, login activity.

Business data - company name, entity details, and the invoices, payments, credit memos, and customer records your business gives us or syncs from your accounting/ERP system (e.g. QuickBooks, Chargebee, and other providers connected via our sync integrations).

Communication data - emails, SMS, and WhatsApp messages sent to your customers on your behalf, including content, delivery, and read status. If you connect a Gmail or Microsoft 365 (Outlook) account, see Section 5 below - those have their own rules.

Payment/bank data - where you connect a bank account for payment reconciliation (via Plaid), we receive transaction and account data needed to match payments to invoices. We do not store full bank credentials — those are handled directly by Plaid.

Enrichment data - publicly available company and contact information (e.g. from LinkedIn or company websites) we use to find the right finance contact for a customer.

Technical data - IP address, browser/device type, and cookies (see our [Cookie Policy]).

4. How we use your data

- Provide the core service: tracking invoices, running collections workflows, sending reminders and communications
- Reconcile payments against invoices
- Find and enrich contact details so reminders reach the right person
- Improve and secure the product (debugging, fraud prevention, analytics)
- Comply with legal obligations

We do not sell personal data, and we do not use it for third-party advertising.

5. Gmail / Microsoft 365 integration

If you connect a Gmail or Microsoft 365 (Outlook) account to Spinal, we access it only to send and read the specific emails needed for invoice communication and reply handling — for example, sending a payment reminder and matching a customer's reply back to the right invoice thread.

Gmail - Spinal's use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements:

- We do not use Gmail data to serve ads.
- We do not allow humans to read Gmail data except: with your explicit consent, for security purposes (e.g. investigating abuse), to comply with the law, or where the data has been aggregated and anonymized.
- We only request the Gmail scopes necessary for the features you use, and you can disconnect your Gmail account at any time from account settings, which revokes our access.

Microsoft 365 / Outlook - We access your mailbox via the Microsoft Graph API under the same principles: only the scopes needed to send reminders and read replies, no use for advertising, no human access except for consent, security, or legal reasons, and you can disconnect at any time from account settings, which revokes our access token. Our use of Microsoft Graph data complies with the [Microsoft APIs Terms of Use](https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use).

6. Legal basis for processing (UK/EU users)

Contract - processing customer, invoice, and communication data is necessary to provide the service you signed up for.
Legitimate interest - product improvement, security, and fraud prevention.
Consent - where required, e.g. WhatsApp opt-in messaging to a debtor.

7. Who we share data with

We share data with sub-processors who help us run the service, under contracts requiring them to protect it:

Google - Gmail integration (Section 5)
Microsoft - Microsoft 365 / Outlook integration (Section 5)
Twilio - SMS and WhatsApp delivery
Plaid — bank connection and payment reconciliation
ERP/accounting connector provider - syncing invoices and customers from your accounting system

We do not share personal data with these providers for their own marketing purposes.

8. International transfers

Some sub-processors above are based outside the UK/EU. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.

9. Data retention

We retain data for as long as your account is active, and for andrew@withspinal.com afterward to meet legal, accounting, or dispute-resolution obligations, after which it is deleted or anonymized.

10. Security

We use industry-standard measures - encryption in transit and at rest, access controls, and multi-tenant isolation - to protect your data. No system is 100% secure, and we encourage reporting any concerns to andrew@withspinal.com.

11. Your rights

Subject to your location, you may have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. To exercise these rights, contact andrew@withspinal.com. If you're in the UK/EU, you also have the right to complain to your local data protection authority.

12. Children's privacy

Spinal is a business product and is not directed at, or intended for use by, children.

13. Changes to this policy

We'll update the date at the top of this page when we make changes, and notify you of material changes.

14. Contact us

Questions about this policy: andrew@withspinal.com