Privacy Policy
Last updated: August 21, 2026
This Privacy Policy explains how Anchor ("Anchor," "we," "us," or "our") collects, uses, and shares information when you use our sponsorship management service at anchor-crm.me and related app surfaces (the "Service").
This summary is written for clarity. It is not a substitute for advice from your own counsel for your jurisdiction.
1. Who this applies to
This policy applies to visitors, account holders, and organization members who use Anchor to manage sponsors, contacts, campaigns, events, documents, and related workflows.
2. Information we collect
We may collect the following categories of information:
- Account information: email address and profile photo URL from Google Sign-In, an optional display name you set in Anchor, and a record of when you accepted our Terms of Service.
- Organization and workspace data: organization names, membership and role information, campaign details, sponsorship goals, tiers, sponsors, contacts, events, and email templates you create or import.
- Files you upload: logos, agreements, receipts, invoices, CSVs, and similar documents you add to the Service, including files imported from Google Drive when you choose that option.
- Support messages: notes you send through the in-app help control, along with account and workspace context needed to respond.
- Usage and diagnostics (optional analytics): if you accept analytics cookies/preferences, we use Vercel Web Analytics and Vercel Speed Insights to collect page-view and performance signals (for example, which routes are visited and Core Web Vitals). These tools are designed to be privacy-preserving and cookieless on the client, but they still process technical data that may be considered personal data under some laws (such as IP-derived signals processed by Vercel). Analytics load only after you accept them in our consent banner or Settings.
- Essential technical data: authentication session data and workspace selection needed to operate and secure the Service.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service
- Authenticate users and manage organization access
- Store and display sponsorship records and uploaded files
- Send transactional notices related to your account or workspace (for example, security, invites, and support replies)
- Send product update / marketing emails only if you opt in (see Email preferences below)
- Measure product usage and performance when you consent to analytics
- Protect against abuse, fraud, and security incidents
- Comply with legal obligations
We do not sell personal information. We do not use Google user data for advertising.
4. Cookies and similar technologies
We use the following categories:
- Strictly necessary: authentication/session cookies from our auth provider (Supabase) so you stay signed in; and first-party cookies that store your selected organization and campaign (`selectedOrgId`, `selectedCampaignId`) so the app can load the correct workspace. These are required for the Service to function.
- Preferences: local browser storage for UI settings such as theme, cookie/analytics choice, and optional product-tour progress. These are not used for cross-site advertising.
- Analytics (optional): Vercel Web Analytics and Speed Insights. They are only enabled after you choose "Accept analytics." You can change this anytime in Settings or clear site data in your browser.
Where consent is required for non-essential analytics, we ask before enabling those tools. Essential cookies do not require the same consent because they are needed to provide the Service you request.
5. Email preferences (product / marketing)
When you create an account we may store your email with our email provider (Resend) so we can deliver transactional mail and, if you consent, product updates.
- Transactional email (account, security, invites, support) may be sent as needed to operate the Service.
- Product update / marketing email is sent only if you opt in via the in-app prompt or Settings. Opting in adds you to our product audience/segment in Resend; opting out unsubscribes you and removes you from that segment.
- You can change your choice anytime in Settings or by contacting us.
6. Google API Services and Limited Use
Anchor uses Google Sign-In for authentication and may use the Google Picker / Google Drive APIs so you can import a file you select into Anchor.
- Google Sign-In is used to create and access your Anchor account. We may store and display your Google account profile picture inside the Service.
- Google Drive access is optional and limited to files you explicitly select through the picker. We do not browse or sync your entire Drive.
- Selected files are downloaded into Anchor so they can be stored with your organization's sponsorship records (for example, a logo, agreement, receipt, or CSV import).
- Google user data is used only to provide or improve user-facing features of the Service, and not for any other purpose.
- Anchor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Anchor's access to your Google Account at any time in your Google Account permissions.
7. How we share information
We share information only as needed to operate the Service:
- Within your organization: members of your Anchor organization may see workspace data according to their roles.
- Service providers (processors): infrastructure that helps us host, authenticate, store, email, and measure the Service, including Supabase (auth/database/storage), Vercel (hosting, optional Web Analytics and Speed Insights), Resend (email delivery and contact audience sync), and Google (Sign-In and optional Drive import).
- Legal and safety: if required by law, or to protect the rights, safety, and integrity of users and the Service.
We do not sell or rent personal information to third parties.
8. Data storage and retention
We store Service data with our infrastructure providers. We retain account and organization data for as long as your organization uses Anchor, or as needed to provide the Service, resolve disputes, and meet legal requirements. You may request deletion of your account or specific records by contacting us.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your choices and rights
Depending on your location, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your account or personal data
- Export certain workspace data available in the product
- Withdraw Google authorization for Drive or Sign-In
- Opt in or out of product/marketing emails
- Accept or reject optional analytics
To make a request, email jasiri.w@gmail.com, or use Settings for email and analytics preferences.
11. Children
Anchor is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
12. International users
If you access the Service from outside the country where our infrastructure is hosted, your information may be processed in another country with different data-protection rules (including processing by providers such as Vercel and Resend that may operate in the United States).
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Continued use of the Service after changes become effective constitutes acceptance of the updated policy where permitted by law.
14. Contact
For privacy questions or requests, contact jasiri.w@gmail.com. Related terms are available in our Terms of Service.