Privacy Policy
How we collect, use, share and protect personal information across the Drawtab website, workspace and API — and the choices you have.
On this page
At a glance
We never sell your data
Not your account details, not your templates, and not the records you render.
Your records stay yours
Data from your spreadsheets, forms and events is used only to produce the graphics you ask for.
No AI training, no ads
We don’t use your content or connected-service data to train AI models or target advertising.
You stay in control
Disconnect services, clear render logs, delete workspaces, or ask us to access, correct or erase your data.
This summary is provided for convenience only. The full text below is what legally applies.
Drawtab is operated by Digisept LTD, a company incorporated in Nigeria (“Drawtab”, “we”, “us” or “our”).
This Privacy Policy explains how we handle personal information when you visit drawtab.app, use the Drawtab workspace at workspace.drawtab.app, call the Drawtab API, read our documentation, or otherwise interact with us (together, the “Service”). It should be read together with our Terms of Service.
We process personal information in line with the Nigeria Data Protection Act 2023 (NDPA) and, where they apply to you, the EU and UK General Data Protection Regulations (GDPR) and applicable U.S. state privacy laws, including the California Consumer Privacy Act (CCPA).
Drawtab plays two different roles depending on whose data is involved:
- Controller of account data. For information about our customers and website visitors — such as your account, workspace, billing and usage information — we decide how and why it is processed, and this policy applies in full.
- Processor of Customer Data. When our customers use Drawtab to render graphics from their own records (for example, attendee names from Eventbrite, rows in a Google Sheet, Typeform responses or API payloads) and to deliver those graphics, we process that information on the customer’s behalf and under their instructions. The customer is the controller and is responsible for having a lawful basis and giving any required notices.
Received a graphic from an organisation using Drawtab?
If your name or details appear in a graphic or email sent through Drawtab, the organisation that sent it controls that information. Please contact them first about your data. If you contact us, we will direct your request to them and assist them as required by law.
Information you give us
- Account details: name, username, email address, password (stored only as a secure hash), and optional profile details such as a profile photo and phone number.
- Workspace and team details: workspace name, the members you invite (their email addresses and roles), and workspace settings such as sender display name and reply-to address.
- Templates and uploads: the artwork you upload and the layers you design, including sample text, image URLs, fonts, colours and QR code content.
- Pipeline configuration: how you map fields from a connected service to template layers, delivery settings, and batch files (CSV or spreadsheets) you upload.
- Communications: messages you send to our support team and your feedback.
Information from the services you connect
When you connect a service or send us data through our API or webhooks, we receive the records you choose to render — which may include names, email addresses, ticket or order details, form answers, photos and other fields defined by you. We also receive the account identifier and email address of the connected account, and OAuth access tokens that let us act on your behalf. Section 5 explains this in detail.
Information created as you use the Service
- Rendered outputs: the images Drawtab generates for you.
- Render logs: the time, template, pipeline, status, credits used and delivery result of each render.
- API keys: key names, scopes and usage. We store only a one-way hash of each secret key.
- Billing records: your plan, billing cycle, credit balance and transaction history.
- Security events: sign-ins, verification and password-change codes, and account deactivation or reactivation.
Information collected automatically
- Log and device data: IP address, browser and operating system, device type, referring page, and the date and time of requests.
- Product analytics (with your consent): pages viewed, features used, clicks, and session replays in which form inputs are masked. See Section 8.
Information from third parties
Our payment processing partners, Polar and Flutterwave, securely handle payment transactions on our behalf. Depending on the payment method and checkout flow used, they provide us with transaction confirmation (such as whether a payment succeeded, the plan or credit pack purchased, billing identifiers, and the associated customer email or reference). You may also receive direct transactional communications, such as payment confirmations, receipts, invoices, or authorization notices, directly from Polar or Flutterwave. We never receive, process, or store your full payment card details or bank account credentials on Drawtab servers.
We use personal information only for the purposes below. Where the NDPA or GDPR applies, we rely on the legal basis shown.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Create your account and workspace, store templates, run pipelines, render and deliver graphics, process API requests | Performance of a contract |
| Billing | Manage subscriptions, credit balances, top-ups and invoices | Performance of a contract; legal obligation (tax and accounting) |
| Security and abuse prevention | Authenticate users, rate-limit APIs, detect fraud, investigate misuse of our Acceptable Use rules | Legitimate interests; legal obligation |
| Service communications | Verification codes, security alerts, workspace invites, billing notices, changes to our terms | Performance of a contract; legitimate interests |
| Support | Respond to your questions and troubleshoot problems | Performance of a contract; legitimate interests |
| Improve the product | Understand which features are used and where people get stuck | Consent (analytics); legitimate interests (aggregated service metrics) |
| Product updates and marketing | Occasional emails about new features — you can opt out at any time | Consent or legitimate interests, as permitted by law |
| Legal compliance | Respond to lawful requests, enforce our terms, keep required records | Legal obligation; legitimate interests |
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
Drawtab connects to third-party services only when you ask it to, and requests the narrowest access available for the feature you use.
| Service | What we access | Why |
|---|---|---|
| Google Sheets & Drive | Only the specific spreadsheets you select with the Google file picker (the drive.file scope), plus your Google account email address | Read rows to render graphics and keep your pipeline in sync; show which account is connected |
| Airtable | Records and table structure in the bases you choose, webhooks, and your account email | Render graphics from new or updated records |
| Eventbrite | Your organisations, events and attendee or order details, and webhooks | Render tickets, badges or passes when people register |
| Typeform | Your forms, responses and webhooks, and basic account information | Render graphics from new form submissions |
| Webhooks & API | The payload you send to Drawtab | Render the graphic you requested |
Google API Services — Limited Use disclosure
Drawtab’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data from Google and every other connected service, we:
- use it only to provide and improve the user-facing features you enabled;
- do not sell it, or use or transfer it for advertising, retargeting, credit-worthiness or lending purposes;
- do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models;
- do not allow humans to read it unless you give us permission (for example, for support), it is necessary for security or to comply with law, or it has been aggregated and anonymised.
Tokens and disconnecting
OAuth tokens are encrypted with AES-256-GCM before they are stored. You can disconnect a service at any time from your pipeline or workspace settings. When you do, we remove the stored token from that pipeline, delete any webhooks we created, and revoke the grant once no other pipeline in your workspace uses that account. You can also revoke Drawtab’s access directly from your Google, Airtable, Eventbrite or Typeform account settings.
If a customer enables delivery, Drawtab emails the rendered graphic to the recipient address in their records, using the customer’s sender name and reply-to address. We process recipient information only to render and deliver that graphic, and to record whether delivery succeeded.
Customers are responsible for making sure they may lawfully send these emails — for example, because the recipient registered for their event or asked for the graphic. Drawtab must not be used to send unsolicited messages.
Rendered images are link-accessible
Rendered graphics are served from unguessable URLs so they can be shared and embedded. Anyone who has the link can view the image, so avoid rendering information you would not want shared with the person receiving it.
We keep personal information only as long as we need it for the purposes in this policy:
| Information | Retention |
|---|---|
| Account and profile | While your account is active. If you deactivate your account, you have 30 days to reactivate it; after that, we delete or anonymise it. |
| Templates, pipelines and rendered outputs | Until you delete them, delete the workspace, or your account is closed. |
| Render logs | Until you clear them from workspace settings or delete the workspace. |
| Connected-service tokens | Until you disconnect the service or delete the pipeline or workspace. |
| Customer Data received from connected services | Only as long as needed to render, deliver and show render history. |
| Billing and transaction records | As long as required by tax, accounting and other laws — typically up to 6 years. |
| Analytics data | Up to 12 months, then deleted or aggregated. |
| Support messages | Up to 3 years after the conversation ends. |
Residual copies may remain in encrypted backups for a limited period before they are overwritten. We may keep information longer where it is needed to resolve disputes, enforce our agreements or comply with the law.
We use administrative, technical and organisational safeguards appropriate to the risk, including:
- encryption of data in transit using TLS;
- AES-256-GCM encryption for stored third-party access tokens, and one-way hashing for passwords and API keys;
- workspace-level access controls, role-based permissions and least-privilege internal access;
- rate limiting, verified webhook signatures and monitoring for abuse;
- email verification codes for sensitive account changes.
No system is completely secure. If a personal data breach is likely to put your rights at risk, we will notify you and the relevant regulator — including the Nigeria Data Protection Commission — within the time limits required by law. Please keep your password and API keys confidential and tell us at once at hello@drawtab.app if you think your account has been compromised.
We are based in Nigeria, and some of our service providers operate in other countries, including the United States and the European Union. Your information may therefore be processed outside the country where you live.
When we transfer personal information across borders, we rely on a lawful transfer mechanism — such as an adequacy decision, standard contractual clauses or other safeguards recognised under the NDPA or GDPR — and require recipients to protect the information to the standard in this policy. Contact us to learn more about the safeguards we use.
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and get a copy;
- Correct information that is inaccurate or incomplete;
- Delete your information;
- Restrict or object to certain processing, including direct marketing;
- Port your information to another service in a structured, machine-readable format;
- Withdraw consent at any time, without affecting processing that happened before;
- not be subject to decisions based solely on automated processing;
- for California and other U.S. state residents, know what we collect, opt out of sale or sharing (we do neither), and not be discriminated against for using these rights.
How to use your rights
Many controls are built in: update your profile in account settings, disconnect services, clear render logs, delete a workspace, or deactivate your account. For anything else, email hello@drawtab.app. We may need to verify your identity before acting, and you may use an authorised agent. We respond within one month, or sooner where the law requires, and will tell you if we need more time.
Complaints
If you are unhappy with how we handle your information, please contact us first so we can try to help. You also have the right to complain to a data protection authority — in Nigeria, the Nigeria Data Protection Commission; in the EU or UK, your local supervisory authority.
Drawtab is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children through our own accounts. If you believe a child has created an account, contact us at hello@drawtab.app and we will delete it. Customers must not use Drawtab to process children’s personal information unless they have a lawful basis and any required parental consent.
We may update this policy as Drawtab evolves or the law changes. We will update the “Last updated” date above and, for material changes, notify you by email or in the app before they take effect. The version in force when you use the Service applies.
For questions about this policy or to exercise your rights, contact:
Questions about your privacy?
Reach our team at hello@drawtab.app. We aim to reply within 2 business days, and we answer formal privacy requests within the time limits set by applicable law.