Primue
Primue
Legal

Privacy Policy

Last updated August 3, 2026
Draft — not yet reviewed by a lawyer. Everything in [square brackets] must be completed before this is published, and the whole document should be checked by a qualified lawyer in your jurisdiction. It is written to describe accurately what this software does, but that is not the same thing as legal advice.

[Legal entity name] (“Primue,” “we,” “us”) provides a white-label business operating system covering business wallets, AI-assisted documents, e-signature, certificates, invoicing, HR & payroll, CRM and analytics (the “Service”). This policy explains what we collect, why, and who else sees it. It applies to visitors to primue.com and to organisations and individuals using the Service (“you”).

Registered address: [Registered business address]. Privacy contact: [privacy@primue.com].

1. What we collect

Account data — name, email, business name, and a password stored only as a salted hash. If you sign in with Google we receive your name, email and profile picture from Google.

Content you create — documents, contracts, certificates, invoices, payroll records, client records, uploaded logos and images, and the signatures drawn or typed into documents.

Signature evidence— when a document is signed we record the signer’s name, the time, their IP address and browser user-agent, and a cryptographic hash chain of the document and signature. This exists so a signature can be shown to be genuine and untampered later. It is retained with the document.

Payment records — amounts, currency, payment status, and the email address a payer gives at checkout. We never receive or store card numbers; those go directly to Stripe.

Usage data — pages visited, features used, browser and device type, IP address and timestamps.

2. How the AI features handle your content

The AI Assistant, document drafting and certificate wording generate text using a specialist third-party AI provider. To do that, the request you make and the document being worked on are processed by that provider on our behalf, under a contract that requires them to keep it confidential, use it only to return your result, and not use it to train their models.

Content sent to the AI features is transmitted encrypted and is not retained by the provider for their own purposes. As with any cloud service, use your judgement about what you put into it.

The rest of the Service does not involve AI at all — your wallet, payment links, stored documents, signing and certificates are processed only by us and the providers listed below.

AI output is a draft, not advice. Anything with legal or financial effect should be reviewed by a qualified professional before you rely on it or send it to anyone.

3. Who else processes your data

We do not sell personal information. These sub-processors handle it on our behalf:

  • Supabase — database, authentication and file storage. Holds essentially all Service data.
  • Stripe — payment processing, checkout and payouts. Receives payer card details directly; we never see them.
  • Our AI provider — text generation for the AI features, as described in section 2. Named on request.
  • Vercel — application hosting and delivery. Processes request metadata including IP addresses.
  • Google — only if you choose to sign in with Google.

We also disclose information where legally required, and to other users inside your own organisation according to the permissions your administrator sets.

These providers operate in [list countries/regions], so your data may be processed outside [your country].

4. Links you share are public

Signing links, invoice links and certificate verification links are deliberately reachable by anyone who has the link, without signing in — that is how the person you send them to can open them. The link’s random identifier is the only thing protecting it. Treat these links as you would an unlisted document: anyone you forward one to can see its contents.

5. How long we keep it

Account and business data is kept while your account is active. Signed documents and their signature evidence are kept for [retention period] because their value depends on being able to prove later that a signature was genuine. Payment records are kept as long as tax and accounting law requires — see [applicable requirement].

On deletion request we remove your data within [number] days, except where we are legally required to keep records.

6. Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to processing, and to complain to a data protection authority. To exercise any of these, contact [privacy@primue.com]. We respond within [number] days.

If you are in Nigeria, the Nigeria Data Protection Act 2023 applies and your supervisory authority is the Nigeria Data Protection Commission. If you are in the EU/UK, GDPR rights apply. [Confirm which regimes apply to your business with a lawyer.]

7. Security

Data is encrypted in transit. Passwords are salted and hashed and never stored in readable form. Access between customer accounts is isolated at the database level. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as required by law.

8. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.

9. Changes

We will post any change here and update the date above. For changes that materially affect your rights we will notify you by email before they take effect.

© 2026 Primue Inc.SecurityAPIPricingContactPrivacyTermsCookies