Springso privacy policy
Last updated: 10 September 2026
This is a plain-language policy, written to be read rather than skimmed past. It is not a substitute for legal advice.
Springso builds and hosts websites for local businesses. That means we hold two kinds of information: what you tell us about your business so we can build and run your site, and what your customers type into that site when they ask you for a quote or book a job. This policy is about being straight with you about both: what we take, why, who else sees it, how long we keep it, and how to have it deleted.
Who we are
Springso is owned and operated by Nuu Labs LLC, a limited liability company registered in Wyoming, United States. In this policy, Springso, we, and us all mean the same thing. You means the business owner or team member using Springso, and your customers means the people who visit or use the website we host for you.
You can reach a person at hello at springso dot com. That inbox is read by a human, and it is the address for every request described under "Your rights" below.
Our registered office is 312 W 2nd St, Unit #A2299, Casper, Natrona County, WY 82601, United States. Email is much faster than post.
What this policy covers
The marketing site at springso.com, the sign-up flow, your account and dashboard, and the websites we host for you on springso.site or on your own domain.
The short version
- To build your site we ask for your business name, your existing website or Google listing if you have one, and a sentence or two about what you do. We use that, and nothing else, to write and design the site.
- Your customers' leads, bookings and contact details belong to you. We store them so you can see and answer them, and we do not use them for anything of our own.
- We use artificial-intelligence model providers to write copy and generate images. What we send them is about your business, not about your customers, and it is not used to train their models.
- We do not sell personal information, yours or your customers', and we never have.
- You can delete your site, your account and everything in it from the dashboard, or by emailing us.
What we collect
What you give us
- Your account. Your email address, and your name and profile picture if you sign in with Google. There are no passwords: you sign in with Google or with a code we email you.
- Your business. Name, category, phone number, email, address and service area, opening hours, the services you offer, your logo and photos, links to your Google Business Profile and social pages, and anything you type into the site editor or ask SpringAI to change.
- Your existing website or listing. If you give us a web address or pick your business from a search, we read what is publicly published there (your services, photos, reviews, hours) to build the first version of your site.
- Billing details. Your plan, your billing email, and the record of what you have paid. Card details go directly to our payment processor; we never see or store your full card number.
- Team members. The email addresses of people you invite, and the role you give them.
- Anything you send us. Messages to support.
What your customers give your site
When somebody fills in a form, asks for a quote or books a time on a site we host for you, we store what they entered: typically a name, a phone number or email address, a message, the service they want and a preferred time. We store it so you can see it in your dashboard, reply to it, and so the automations you switch on can send them a confirmation or a follow-up.
We process this information on your behalf. You decide what your forms ask for, you answer the leads, and you are responsible for how you treat your customers' details under the law where you operate. We do not contact your customers for our own purposes, build profiles of them, or share them with anyone except the providers listed below who deliver your emails and host your data.
What we collect automatically
- Standard technical information about you and about visitors to the sites we host: IP address, browser and device type, pages viewed, and the approximate city or region an IP address suggests. We use this to keep the service secure and to show you simple visit counts.
- The campaign link you arrived from, if you came from an advertisement.
- Cookies and similar technology, described under "Cookies and analytics".
What we never collect
We do not ask for government identification numbers, bank account numbers or financial statements, and you should not send them to us. Please do not put them in the site editor either.
Why we use it, and on what basis
- To build and host your site: because you asked us to, and to perform our agreement with you.
- To write copy and generate images: we send a description of your business to an artificial-intelligence model provider and receive text and images back. The provider is contractually bound not to use what we send to train its models.
- To run your dashboard: showing you leads, bookings and contacts, and sending the notifications you have switched on.
- To run automations you set up: a thank-you email to a customer, a reminder to you. They only run because you switched them on, and you can switch them off.
- To take payment and run your account: to perform our contract with you.
- To tell you what is happening: service email about your site, your leads and your account.
- To keep the service working and safe: security, abuse prevention, debugging, and rate limits.
- To measure our advertising: described under "Cookies and analytics".
We do not use your information, or your customers' information, to train any artificial-intelligence model, ours or anybody else's.
Who we give it to, and why
Our service providers. They handle data to do a job for us and nothing else:
- Hosting, database and infrastructure providers: where the website runs and where your account, your site and your customers' leads are stored.
- Our payment processor: taking payment and managing your subscription.
- Our email provider: sending the sign-in codes, your notifications, and the emails your automations send to your customers.
- Artificial-intelligence model providers: writing the copy and generating the images for your site, and powering SpringAI.
- Business data providers: the lookups behind "find my business" and the reading of your existing website.
- Domain and certificate providers: connecting your own domain and issuing its security certificate.
We will tell you which companies these are if you ask. We pick providers who are contractually bound to handle your information only to do that job, and who may not reuse it for their own purposes.
Your team. People you invite see what their role allows: an editor sees the site and the leads, a viewer only looks, an owner can change billing. You control who is in.
When the law requires it. If we are legally compelled, or to establish or defend a legal claim, or to protect somebody from harm.
If the business changes hands. If Nuu Labs LLC is ever sold or merged, your information may transfer with it. Any buyer would be bound by this policy, and we would tell you before anything changed.
We do not sell personal information, and we do not share it for cross-context behavioral advertising in the sense California uses those words, with one qualification you should read, in the next section.
Your website is public
The site we build for you is, by design, published on the internet. Whatever you put on it, your business name, phone number, address, hours, photos, and the reviews you choose to show, is visible to anyone, indexed by search engines, and may be read by AI assistants. Do not publish anything on your site that you would not want public. A draft that has not been published is reachable only by people who have its link, and is not submitted to search engines.
Cookies and analytics
On springso.com and in your dashboard we use a small number of analytics and advertising tools, and only in production:
- Product analytics providers: how people move through the site, so we can see where the sign-up flow confuses people.
- Advertising measurement providers: so we can tell which advertisement led somebody to subscribe.
To the advertising platforms we send an event (for example "signed up" or "purchased") together with your IP address, browser type and approximate location, so a conversion can be recognized. We do not send them your business details or your customers' details.
Some US state privacy laws treat this kind of advertising measurement as "sharing" or as a "sale", even though no money changes hands. Rather than argue about the definition, we let you switch it off:
- Turn on Global Privacy Control in your browser, or use a browser or extension that sends it. We treat that signal as a valid opt-out, on every page, without you having to find anything on our site.
- Or email us and ask, at the address above.
On the sites we host for you we set only what the site needs to work: a cookie to remember a booking in progress, for instance. If you add your own Google Analytics id in Settings, Google's tag runs on your site under your Google account and your responsibility. We do not run our own advertising tags on your customers' visits.
You can refuse cookies in your browser settings. Springso works without them; signing in needs a cookie to remember that it is you.
Do Not Track. Browsers can send a Do Not Track header. There has never been an agreed standard for what a website should do about it, so we do not respond to it. We do honor Global Privacy Control, which does have one, as described above.
Sensitive information
We do not ask for sensitive personal information as California defines it, and we do not need any. The one thing we hold that is close is the sign-in session that keeps you logged in, which exists only for security and fraud prevention, purposes the law permits without offering a separate right to limit.
If your customers send you sensitive information through your site's forms (health details for a treatment, for instance), that is information you have chosen to collect, and you are responsible for it. We store it for you and do nothing else with it.
How long we keep things
- A site you built but never published: thirty days after you built it. Then it is deleted automatically, along with its photos and any leads it received. Most people who try Springso do go live, but keeping abandoned drafts of other people's businesses indefinitely is not something we want to do.
- Your account, your site and your customers' leads: while you are a member. If your subscription ends, the site goes offline but stays editable for ninety days so you can pick a plan again or export what you need. After that we delete it, unless you ask us to keep it for longer.
- Billing records: as long as tax and accounting law requires, which in the US is generally seven years.
- Support email: up to two years.
- Server logs: thirty days.
When you delete a site from the dashboard, or ask us to delete your account, we do, including your customers' details held for that site. Backups roll off within thirty days.
Your rights
Wherever you live, you can ask us to:
- Know what we hold about you, where we got it, why we have it, and who we have given it to.
- Get a copy of it, in a portable format. Your leads and contacts can be exported from the dashboard at any time.
- Correct anything that is wrong. Most of it you can change yourself in Settings.
- Delete it. Your site can be deleted from Settings; your account by emailing us.
- Opt out of the advertising measurement described above.
Several of those rights come from state privacy laws, including California's CCPA, as amended by the CPRA, and the comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Maryland, Minnesota and a growing list of others, and from the GDPR and UK GDPR if you are in Europe. Some of those laws only bind companies above a size we have not reached.
We are not going to hide behind that. We give everybody the same rights, in every state and every country, whether or not the law currently obliges us to.
You will never be treated differently for exercising any of this. No worse price, no worse service.
How to ask: email hello at springso dot com and say what you want. We will verify it is really you, usually by confirming you control the email address on the account, and answer within 45 days, or tell you why we need longer. An authorized agent may ask on your behalf with your written permission; we will ask for proof of it, as the law allows.
If we say no, we will tell you why, and you can appeal simply by replying to that email. We will answer an appeal within 45 days, in writing, with our reasons. If you are still unhappy, you can complain to your state Attorney General or your local data protection authority, and we will tell you how.
Your customers' rights. If one of your customers asks us to see or delete what your site holds about them, we will pass the request to you, because it is your data and your decision, and we will help you carry it out. If we cannot reach you, we will act on the request ourselves.
Nevada. If you are a Nevada resident, that same address (hello at springso dot com) is our designated address for a request not to sell your information, and we will answer within 60 days.
California "Shine the Light". We do not disclose personal information to third parties for those third parties' own direct marketing. There is nothing to opt out of, but you may ask us to confirm it and we will.
Children
Springso is for businesses and the adults who run them. It is not directed at children, and you must be at least 18 to hold an account. We do not knowingly collect information from anyone under 18. If you believe a child's information has reached us, email us and we will delete it.
Where your information is held
We are based in the United States and our providers are principally in the United States, so that is where your information and your customers' information is stored and processed. If you or your customers are somewhere else, using Springso means that information is transferred there. Where the law requires it, we rely on standard contractual clauses with our providers for that transfer.
Security
Everything travels over encrypted connections and is stored encrypted at rest by our providers. There are no passwords to leak: sign-in is by Google or a single-use code. Access to member data is limited to the people who need it to run the service.
We will not pretend to be unbreakable, because nobody is. What we can do is hold as little as possible, for as short a time as possible, and be honest with you quickly if something goes wrong. If a breach affects you or your customers, we will tell you and the regulators that require telling, and give you what you need to tell your customers.
Changes to this policy
When we change it, we update the date at the top. If a change materially affects what we do with your information, we will email you before it takes effect.
Contact
hello at springso dot com, for questions, and for any of the requests above.
Nuu Labs LLC, 312 W 2nd St, Unit #A2299, Casper, Natrona County, WY 82601, United States.
