Legal

Privacy Policy

How we collect, use, share and protect personal information across the Drawtab website, workspace and API — and the choices you have.

Effective September 16, 2026Last updated September 18, 2026
On this page

At a glance

We never sell your data

Not your account details, not your templates, and not the records you render.

Your records stay yours

Data from your spreadsheets, forms and events is used only to produce the graphics you ask for.

No AI training, no ads

We don’t use your content or connected-service data to train AI models or target advertising.

You stay in control

Disconnect services, clear render logs, delete workspaces, or ask us to access, correct or erase your data.

This summary is provided for convenience only. The full text below is what legally applies.

01

Who we are

Drawtab is operated by Digisept LTD, a company incorporated in Nigeria (“Drawtab”, “we”, “us” or “our”).

This Privacy Policy explains how we handle personal information when you visit drawtab.app, use the Drawtab workspace at workspace.drawtab.app, call the Drawtab API, read our documentation, or otherwise interact with us (together, the “Service”). It should be read together with our Terms of Service.

We process personal information in line with the Nigeria Data Protection Act 2023 (NDPA) and, where they apply to you, the EU and UK General Data Protection Regulations (GDPR) and applicable U.S. state privacy laws, including the California Consumer Privacy Act (CCPA).

02

Our role: controller and processor

Drawtab plays two different roles depending on whose data is involved:

  • Controller of account data. For information about our customers and website visitors — such as your account, workspace, billing and usage information — we decide how and why it is processed, and this policy applies in full.
  • Processor of Customer Data. When our customers use Drawtab to render graphics from their own records (for example, attendee names from Eventbrite, rows in a Google Sheet, Typeform responses or API payloads) and to deliver those graphics, we process that information on the customer’s behalf and under their instructions. The customer is the controller and is responsible for having a lawful basis and giving any required notices.

Received a graphic from an organisation using Drawtab?

If your name or details appear in a graphic or email sent through Drawtab, the organisation that sent it controls that information. Please contact them first about your data. If you contact us, we will direct your request to them and assist them as required by law.

03

Information we collect

Information you give us

  • Account details: name, username, email address, password (stored only as a secure hash), and optional profile details such as a profile photo and phone number.
  • Workspace and team details: workspace name, the members you invite (their email addresses and roles), and workspace settings such as sender display name and reply-to address.
  • Templates and uploads: the artwork you upload and the layers you design, including sample text, image URLs, fonts, colours and QR code content.
  • Pipeline configuration: how you map fields from a connected service to template layers, delivery settings, and batch files (CSV or spreadsheets) you upload.
  • Communications: messages you send to our support team and your feedback.

Information from the services you connect

When you connect a service or send us data through our API or webhooks, we receive the records you choose to render — which may include names, email addresses, ticket or order details, form answers, photos and other fields defined by you. We also receive the account identifier and email address of the connected account, and OAuth access tokens that let us act on your behalf. Section 5 explains this in detail.

Information created as you use the Service

  • Rendered outputs: the images Drawtab generates for you.
  • Render logs: the time, template, pipeline, status, credits used and delivery result of each render.
  • API keys: key names, scopes and usage. We store only a one-way hash of each secret key.
  • Billing records: your plan, billing cycle, credit balance and transaction history.
  • Security events: sign-ins, verification and password-change codes, and account deactivation or reactivation.

Information collected automatically

  • Log and device data: IP address, browser and operating system, device type, referring page, and the date and time of requests.
  • Product analytics (with your consent): pages viewed, features used, clicks, and session replays in which form inputs are masked. See Section 8.

Information from third parties

Our payment processing partners, Polar and Flutterwave, securely handle payment transactions on our behalf. Depending on the payment method and checkout flow used, they provide us with transaction confirmation (such as whether a payment succeeded, the plan or credit pack purchased, billing identifiers, and the associated customer email or reference). You may also receive direct transactional communications, such as payment confirmations, receipts, invoices, or authorization notices, directly from Polar or Flutterwave. We never receive, process, or store your full payment card details or bank account credentials on Drawtab servers.

04

How we use information

We use personal information only for the purposes below. Where the NDPA or GDPR applies, we rely on the legal basis shown.

PurposeExamplesLegal basis
Provide the ServiceCreate your account and workspace, store templates, run pipelines, render and deliver graphics, process API requestsPerformance of a contract
BillingManage subscriptions, credit balances, top-ups and invoicesPerformance of a contract; legal obligation (tax and accounting)
Security and abuse preventionAuthenticate users, rate-limit APIs, detect fraud, investigate misuse of our Acceptable Use rulesLegitimate interests; legal obligation
Service communicationsVerification codes, security alerts, workspace invites, billing notices, changes to our termsPerformance of a contract; legitimate interests
SupportRespond to your questions and troubleshoot problemsPerformance of a contract; legitimate interests
Improve the productUnderstand which features are used and where people get stuckConsent (analytics); legitimate interests (aggregated service metrics)
Product updates and marketingOccasional emails about new features — you can opt out at any timeConsent or legitimate interests, as permitted by law
Legal complianceRespond to lawful requests, enforce our terms, keep required recordsLegal obligation; legitimate interests

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

05

Google and other connected services

Drawtab connects to third-party services only when you ask it to, and requests the narrowest access available for the feature you use.

ServiceWhat we accessWhy
Google Sheets & DriveOnly the specific spreadsheets you select with the Google file picker (the drive.file scope), plus your Google account email addressRead rows to render graphics and keep your pipeline in sync; show which account is connected
AirtableRecords and table structure in the bases you choose, webhooks, and your account emailRender graphics from new or updated records
EventbriteYour organisations, events and attendee or order details, and webhooksRender tickets, badges or passes when people register
TypeformYour forms, responses and webhooks, and basic account informationRender graphics from new form submissions
Webhooks & APIThe payload you send to DrawtabRender the graphic you requested

Google API Services — Limited Use disclosure

Drawtab’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data from Google and every other connected service, we:

  • use it only to provide and improve the user-facing features you enabled;
  • do not sell it, or use or transfer it for advertising, retargeting, credit-worthiness or lending purposes;
  • do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models;
  • do not allow humans to read it unless you give us permission (for example, for support), it is necessary for security or to comply with law, or it has been aggregated and anonymised.

Tokens and disconnecting

OAuth tokens are encrypted with AES-256-GCM before they are stored. You can disconnect a service at any time from your pipeline or workspace settings. When you do, we remove the stored token from that pipeline, delete any webhooks we created, and revoke the grant once no other pipeline in your workspace uses that account. You can also revoke Drawtab’s access directly from your Google, Airtable, Eventbrite or Typeform account settings.

06

Delivery emails and shared graphics

If a customer enables delivery, Drawtab emails the rendered graphic to the recipient address in their records, using the customer’s sender name and reply-to address. We process recipient information only to render and deliver that graphic, and to record whether delivery succeeded.

Customers are responsible for making sure they may lawfully send these emails — for example, because the recipient registered for their event or asked for the graphic. Drawtab must not be used to send unsolicited messages.

Rendered images are link-accessible

Rendered graphics are served from unguessable URLs so they can be shared and embedded. Anyone who has the link can view the image, so avoid rendering information you would not want shared with the person receiving it.

07

How we share information

We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as those terms are defined under the CCPA. We disclose information only as follows:

Service providers

We use trusted providers who process information on our instructions and under contracts that require them to protect it:

ProviderPurposeData involved
Cloud infrastructure providersHosting our website, application, authentication, database, file storage and rendering engineAll Service data, in transit and at rest
Polar and FlutterwaveCheckout, subscriptions, payment processing, tax calculation and billing receiptsName, email, billing details, transaction references, purchase history
Resend and email delivery providersAccount emails and graphic delivery emailsEmail address, name, email content
PostHogProduct analytics and session replay (only with consent)Usage events, device data, masked replays
WispHosting our blog contentNo customer data

Other disclosures

  • Your workspace: members of a workspace can see the templates, pipelines, renders and member list of that workspace, according to their role.
  • Services you connect: when you connect a third-party service, we exchange data with it as needed to run your pipeline — for example, registering a webhook.
  • Legal reasons: when we believe in good faith that disclosure is required by law, court order or a lawful request from authorities, or is needed to protect the rights, safety or property of Drawtab, our users or the public.
  • Business transfers: in a merger, acquisition, financing or sale of assets, information may transfer to the new owner, who must continue to protect it in line with this policy. We will notify you of any change in ownership that affects your information.
  • With your consent: in any other case where you ask us to share it.
08

Cookies and analytics

We use a small number of cookies and similar browser storage technologies:

CategoryUsed forCan I turn it off?
NecessaryKeeping you signed in, security and fraud prevention, remembering your cookie choice, saving unsent draftsNo — the Service cannot work without them. You can block them in your browser, but sign-in will fail.
AnalyticsPostHog product analytics and session replay, with form inputs maskedYes — off until you accept, and you can withdraw consent at any time.

We do not use advertising or cross-site tracking cookies. Analytics does not load until you opt in through our cookie banner. You can change your mind at any time:

Cookie choices are stored per site, so drawtab.app and workspace.drawtab.app each ask separately.

09

How long we keep information

We keep personal information only as long as we need it for the purposes in this policy:

InformationRetention
Account and profileWhile your account is active. If you deactivate your account, you have 30 days to reactivate it; after that, we delete or anonymise it.
Templates, pipelines and rendered outputsUntil you delete them, delete the workspace, or your account is closed.
Render logsUntil you clear them from workspace settings or delete the workspace.
Connected-service tokensUntil you disconnect the service or delete the pipeline or workspace.
Customer Data received from connected servicesOnly as long as needed to render, deliver and show render history.
Billing and transaction recordsAs long as required by tax, accounting and other laws — typically up to 6 years.
Analytics dataUp to 12 months, then deleted or aggregated.
Support messagesUp to 3 years after the conversation ends.

Residual copies may remain in encrypted backups for a limited period before they are overwritten. We may keep information longer where it is needed to resolve disputes, enforce our agreements or comply with the law.

10

How we protect information

We use administrative, technical and organisational safeguards appropriate to the risk, including:

  • encryption of data in transit using TLS;
  • AES-256-GCM encryption for stored third-party access tokens, and one-way hashing for passwords and API keys;
  • workspace-level access controls, role-based permissions and least-privilege internal access;
  • rate limiting, verified webhook signatures and monitoring for abuse;
  • email verification codes for sensitive account changes.

No system is completely secure. If a personal data breach is likely to put your rights at risk, we will notify you and the relevant regulator — including the Nigeria Data Protection Commission — within the time limits required by law. Please keep your password and API keys confidential and tell us at once at hello@drawtab.app if you think your account has been compromised.

11

International data transfers

We are based in Nigeria, and some of our service providers operate in other countries, including the United States and the European Union. Your information may therefore be processed outside the country where you live.

When we transfer personal information across borders, we rely on a lawful transfer mechanism — such as an adequacy decision, standard contractual clauses or other safeguards recognised under the NDPA or GDPR — and require recipients to protect the information to the standard in this policy. Contact us to learn more about the safeguards we use.

12

Your privacy rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and get a copy;
  • Correct information that is inaccurate or incomplete;
  • Delete your information;
  • Restrict or object to certain processing, including direct marketing;
  • Port your information to another service in a structured, machine-readable format;
  • Withdraw consent at any time, without affecting processing that happened before;
  • not be subject to decisions based solely on automated processing;
  • for California and other U.S. state residents, know what we collect, opt out of sale or sharing (we do neither), and not be discriminated against for using these rights.

How to use your rights

Many controls are built in: update your profile in account settings, disconnect services, clear render logs, delete a workspace, or deactivate your account. For anything else, email hello@drawtab.app. We may need to verify your identity before acting, and you may use an authorised agent. We respond within one month, or sooner where the law requires, and will tell you if we need more time.

Complaints

If you are unhappy with how we handle your information, please contact us first so we can try to help. You also have the right to complain to a data protection authority — in Nigeria, the Nigeria Data Protection Commission; in the EU or UK, your local supervisory authority.

13

Children

Drawtab is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children through our own accounts. If you believe a child has created an account, contact us at hello@drawtab.app and we will delete it. Customers must not use Drawtab to process children’s personal information unless they have a lawful basis and any required parental consent.

14

Changes to this policy

We may update this policy as Drawtab evolves or the law changes. We will update the “Last updated” date above and, for material changes, notify you by email or in the app before they take effect. The version in force when you use the Service applies.

15

Contact us

For questions about this policy or to exercise your rights, contact:

Digisept LTD

Nigeria

Email: hello@drawtab.app

Questions about your privacy?

Reach our team at hello@drawtab.app. We aim to reply within 2 business days, and we answer formal privacy requests within the time limits set by applicable law.