Privacy Policy

Sunday HQ, Corp.

Last updated: 31 August 2026

Introduction

This Privacy Policy ("Policy") describes how Sunday HQ, Corp., a Delaware corporation, operating the Sunday for Creators platform ("Sunday," "we," "our," or "us"), collects, uses, shares, and protects information about you when you use our platform and related services (collectively, the "Services"). Our Services include, but are not limited to, automated invoice generation, financial tracking, Gmail integration for in-app email management, deal organisation and task tracking, media kit generation, and an AI manager assistant.

We operate a global platform. This Policy is written to address the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the comprehensive privacy laws of other US states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others), Canada's PIPEDA and Quebec Law 25, Australia's Privacy Act and Australian Privacy Principles, Brazil's LGPD, Switzerland's revised FADP, and other applicable data protection laws. Where the law in your jurisdiction grants you additional rights, we honour those rights.

By using the Services, you confirm that you have read this Policy and understand how we handle your information. If you do not agree with this Policy, please do not use the Services.

1. Who We Are and How to Contact Us

Sunday is operated by Sunday HQ, Corp., a Delaware corporation, with its principal place of business at 1111B S Governors Ave # 93449, Dover, DE 19904. For most personal information collected through the Services, Sunday HQ, Corp. acts as the data controller (or "business" under CCPA/CPRA).

Where we provide the Services to a business customer (for example, a creator agency or production company) under a separate agreement, that customer may act as the controller of personal information about its team members, contractors, or talent, and we will act as a processor on its behalf in accordance with the data processing terms agreed with that customer.

For questions about this Policy, to exercise your privacy rights, or to contact our Privacy Team:

Email – privacy and rights requestsadmin@withsunday.io
Email – security and incident reportsadmin@withsunday.io
Email – general supportadmin@withsunday.io
Mailing address1111B S Governors Ave # 93449, Dover, DE 19904, United States
Privacy contact (named individual)Caitlin Mellor
EU/EEA representative (Art. 27 GDPR)Caitlin Mellor
UK representative (Art. 27 UK GDPR)Caitlin Mellor

We aim to acknowledge privacy enquiries within 5 business days and to respond substantively within 30 days, or within any shorter period required by applicable law.

2. Information We Collect

The categories of personal information we collect depend on how you use the Services. We collect only what is necessary to provide, secure, and improve the Services.

2.1 Information You Provide Directly

When you register, configure your account, or use the Services, you may provide:

  • Account and identity information: your name, email address, username, password (stored as a salted hash), and profile photograph.
  • Business and professional information: your business name, business or billing address, industry, social media handles, audience size, niche, services offered, rate card information, portfolio links, and similar information used to populate media kits, invoices, and deal records. Address information is optional and is collected only where you choose to provide it for inclusion on invoices generated through the Services or for similar business identification purposes.
  • Financial information: invoice amounts, descriptive payment references, records of brand deals and sponsorships, and income and expense data you log in the financial tracking feature. Where you choose to enter sensitive financial identifiers (such as bank account numbers or routing numbers) for record-keeping, we treat that information as "sensitive personal information" under the CCPA/CPRA and apply heightened safeguards. We do not process payments to or from third parties on your behalf – see Section 7.
  • Communications content: emails, notes, and messages you compose, send, or receive via our Gmail integration; deal notes; task descriptions; and any other content you create within the platform.
  • AI assistant inputs: prompts, questions, instructions, and any context you submit to our AI manager assistant.
  • Support communications: messages, attachments, and other information you send us when you contact support, including any screenshots or screen recordings you choose to share.

2.2 Information We Collect Automatically

When you use the Services, we automatically collect:

  • Usage data: features accessed, pages viewed, actions taken, timestamps, and session duration.
  • Device and technical data: IP address, browser type and version, operating system, device identifiers, screen size, language settings, and referring URLs.
  • Approximate location (automatically): derived from your IP address at country and city level only. We do not automatically collect precise (GPS-level) geolocation. Where you choose to provide your business or billing address (see Section 2.1), that information is collected only as you submit it.
  • Log data: server logs, error reports, and performance data.
  • Email engagement: where we send transactional or marketing email, we may use industry-standard tracking pixels or links to record whether the message was opened or links clicked, in order to confirm delivery and (for marketing only) measure effectiveness. You can disable image loading in your email client to prevent open tracking.
  • Cookies and similar technologies: see Section 10 for full details.

2.3 Information from Third-Party Services You Connect

When you connect a third-party account or service to Sunday, we receive information from that service as authorised by you:

Gmail and Google Workspace. If you connect your Gmail account, we access information from your Gmail account using the Google API. You will be shown a Google consent screen listing the specific OAuth scopes we request. The scopes we use, and the purpose of each, are:

OAuth scopePurpose within Sunday
gmail.readonlyAccess your inbox, threads, and message content to provide Sunday's email, deal-management and AI-assisted creator-business features. This includes allowing Sola to identify potential or existing deals, extract relevant deal information, suggest actions, and assist with managing communications within your private Sunday workspace.
gmail.sendSend emails on your behalf when you initiate a send action from within Sunday (for example, replying to a brand, sending a media kit, or issuing an invoice email).
gmail.modifyMark emails as read or unread, archive, label, and perform similar mailbox actions that you initiate or explicitly confirm within Sunday.
gmail.metadata (where used in lieu of full content access)Read message headers and labels for organisation features when full content access is not required.
userinfo.email and userinfo.profileIdentify your Google account during sign-in.

Through the Google OAuth scopes you authorise, Sunday may process email message bodies and subjects; sender, recipient and CC/BCC addresses; thread and conversation structure; attachments; labels; message metadata; and other information contained in your Gmail account that is necessary to provide the Google-connected features you choose to use. Unless separately disclosed and authorised through the Google OAuth consent screen, Sunday does not access your Google Contacts address book.

Third-party information contained in Gmail. When you connect Gmail, your communications may contain personal information relating to people other than you, such as brand representatives, agency employees, clients, collaborators, friends, or other contacts. Sunday and Sola may process this information where necessary to provide Google-connected functionality to you. For example, Sola may identify a brand partnership from an email thread, extract information about the brand, campaign, deal value, deliverables, deadlines or deal status, identify relevant contacts, suggest tasks or actions, or propose creating or updating a record within your private Sunday workspace. Google-derived information is processed for the benefit of the user who authorised access to the relevant Google account. Information obtained from Google Workspace APIs, including information derived from that data, is not used to populate, enrich, or maintain Sunday's shared brand or contact database and is not made available to other Sunday users through that database. Where Sunday enables you to contribute professional contact information to a shared Sunday database, that information must be provided separately and directly to Sunday by you through the relevant contribution or submission feature. Sunday does not automatically transfer contact email addresses identified through Gmail into the shared Sunday database. Sunday may separately obtain professional brand and contact information from independent sources, including third-party data providers, direct brand submissions, publicly available professional sources, and direct user contributions. Those data sources are separate from information obtained through Google Workspace APIs.

Special category and sensitive information. Emails may incidentally contain special category data under GDPR Article 9, sensitive personal information under applicable US privacy laws, or other sensitive information. Sunday does not use such information to infer sensitive characteristics about you or third parties and does not use it for advertising or unrelated profiling.

Google Limited Use compliance. Sunday's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy and Google Workspace API User Data and Developer Policy, including the Limited Use requirements. See Section 6.2 for the full Limited Use disclosure.

Authentication providers. If you sign in with Google Single Sign-On (SSO), we receive your name, email address, profile identifier, and (where you authorise it) profile picture from that provider. We do not receive your password.

Other integrations. If you connect other platforms in future (for example, social media analytics tools, e-signature providers, or accounting software), we will update this Policy and our sub-processor list to describe the data we receive and how we use it. We will obtain your consent at the point of connection.

2.4 Information in the Sunday Brand and Contact Database

Sunday maintains a shared database of brands and professional business contacts that is available through certain features of the Services.

Information in this database may be obtained from third-party professional data and enrichment providers; direct submissions from brands or their representatives; publicly available professional and business sources, where permitted by applicable law; Sunday's own research; and information that Sunday users intentionally provide directly through designated contribution or submission features.

Where a user directly submits professional contact information to Sunday for inclusion in a shared feature, we process that information in accordance with this Policy and the terms presented at the point of submission.

Google User Data obtained through Google Workspace APIs, and information derived from Google User Data, is not used to populate, enrich, or maintain this shared database.

2.5 Information We Infer or Generate

We may derive information about your preferences, business performance, and use of the Services from data you provide, data processed within your private workspace, or information we collect automatically. Examples include:

  • Personalised income trends, deal insights, and rate recommendations generated for you from information contained in your private Sunday workspace.
  • Suggested rate cards generated from information you have provided to Sunday and your historical deal information.
  • Task, follow-up, and deal-management suggestions generated from your private deal pipeline and, where you have connected Gmail, your Google-connected activity.
  • Shared or platform-wide benchmarks and aggregated platform metrics are generated only from information Sunday is permitted to use for that purpose, such as information submitted directly for benchmarking, product usage data, or information obtained independently from Google Workspace APIs.

These inferences are produced to provide and improve the Services to you. Google User Data, including data derived from Google Workspace APIs, is not used to create shared deal-value datasets, global rate benchmarks, shared contact intelligence, or other cross-user datasets. If you separately and intentionally submit information to Sunday for inclusion in a community review, benchmarking, or data-contribution feature, that submission is processed separately in accordance with the disclosures presented when you submit it. We do not use inferences to build advertising profiles or to make decisions that produce legal or similarly significant effects on you (see Section 5).

3. Notice at Collection (CCPA/CPRA Summary)

This section provides a summary "notice at collection" for California residents and others entitled to similar disclosures. The categories below correspond to the categories enumerated in California Civil Code §1798.140.

CategoryExamples we collectPurpose
IdentifiersName, email, username, IP address, account ID, profile photo, postal address (where provided)Account creation and authentication; service delivery; invoice generation; security
Customer recordsBusiness name, business/billing address, billing details, support historyService delivery; invoice generation; billing; support
Commercial informationSubscription and usage history, transactions with usService delivery; analytics; billing
Internet/network activityPages viewed, features used, device data, log dataService delivery; security; product improvement
Geolocation (approximate only)Country and city derived from IPLocalisation; security; tax determination
Professional informationNiche, audience size, rate card, deal recordsService delivery (media kits, deal management)
InferencesSuggested rates, deal-close suggestions, task suggestionsService delivery (AI assistant, recommendations)
Sensitive personal informationAccount credentials; bank or payment identifiers you choose to log; financial data; contents of your communications via Gmail integrationService delivery only – we do not use sensitive personal information to infer characteristics about you, and we do not sell or share it

We retain each category for the periods set out in Section 8. We do not sell or share any category for cross-context behavioural advertising. We disclose categories to the sub-processors listed in Section 6 for the purposes described in Section 4.

4. How and Why We Use Your Information

Data protection law requires us to have a lawful basis for every processing activity. The table below sets out our purposes, the types of information used, and the legal bases we rely on under GDPR/UK GDPR Article 6 (and, where relevant, Article 9). Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) balancing our interests against your rights and freedoms; you may request a summary of the relevant LIA by contacting admin@withsunday.io.

PurposeInformation usedLegal basis (GDPR / UK GDPR)
Providing and operating the Services (invoice generation, financial tracking, deal management, task tracking, media kit generation)Account info, business info (including business/billing address where provided), financial info, usage dataPerformance of contract – Art. 6(1)(b)
Operating Google-connected email, deal-management, and Sola functionalityGmail messages, metadata, sender and recipient information, attachments, and information derived from relevant communicationsPerformance of contract – Art. 6(1)(b), in relation to the user who connected the Google account
Operating Google-connected functionality involving third-party content within your emailsNames, email addresses, and content of senders/recipients other than youLegitimate interests (Art. 6(1)(f)) – processing information contained in communications is necessary to provide the email, CRM-style deal-management, and AI-assistance functionality requested by the user, balanced by access controls and prohibitions on unrelated secondary use. Google-derived third-party information is not used to populate shared Sunday contact databases.
Operating the AI manager assistant (per-prompt service delivery)AI assistant inputs, deal history, financial data, task dataPerformance of contract – Art. 6(1)(b)
Improving the AI manager assistant (quality evaluation, debugging, abuse detection)AI assistant inputs and outputs, in pseudonymised form where feasibleLegitimate interests (Art. 6(1)(f)) – improving the assistant for all users; you may opt out – see Section 5
Account authentication and security; fraud preventionAccount info, device data, log dataLegitimate interests – securing the platform (Art. 6(1)(f)); legal obligation in some cases (Art. 6(1)(c))
Improving and developing the Services generallyPseudonymised usage data; anonymised aggregatesLegitimate interests – product improvement (Art. 6(1)(f)); anonymous data falls outside GDPR scope
Customer supportSupport communications, account infoPerformance of contract; legitimate interests (Art. 6(1)(b)/(f))
Sending service notifications and transactional emailEmail address, account infoPerformance of contract; legitimate interests (Art. 6(1)(b)/(f))
Marketing communications about Sunday's own servicesEmail address, nameConsent (Art. 6(1)(a)) for new contacts; legitimate interests / soft opt-in (Art. 6(1)(f), PECR Reg. 22(3) UK / national ePrivacy implementations) for existing customers – opt-out always available
Complying with legal obligations (tax record-keeping, lawful requests, accessibility)As required by the obligationLegal obligation – Art. 6(1)(c)
Establishing, exercising, or defending legal claims; enforcing the Terms of ServiceAccount info, usage data, communicationsLegitimate interests (Art. 6(1)(f)); for special category data, Art. 9(2)(f)

What we do not do. We do not use personal information to serve targeted advertising. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA and similar US state laws. We do not use Google User Data, including information derived from Google Workspace APIs, to develop, improve, or train generalised artificial-intelligence or machine-learning models. We do not use Google User Data to populate, enrich, or maintain Sunday's shared contact database, shared deal-value database, global benchmarking datasets, or other cross-user information products. We do not provide Google User Data to data brokers or information resellers. We do not use AI assistant inputs containing Google User Data to train third-party foundation models.

5. The AI Manager Assistant – Important Limitations

Sunday includes an AI manager assistant that can help you draft emails, review deal terms, summarise contracts you provide, suggest task lists, generate invoice text, and provide general guidance on creator business management, as examples.

5.1 The assistant is a productivity tool, not a professional advisor

The AI assistant is a productivity tool only. It is not a licensed attorney, accountant, financial advisor, tax preparer, agent, talent manager, or business manager. Nothing produced by the AI assistant constitutes legal advice, accounting advice, tax advice, financial advice, regulated investment advice, or professional representation of any kind. You should not rely on AI-generated output as a substitute for qualified professional advice in any regulated domain.

Specifically, the AI assistant cannot: provide legal advice on contract enforceability or dispute resolution; prepare or file tax returns; sign contracts on your behalf; provide regulated financial or investment advice; provide medical advice; or take any action with legal effect on your behalf without your explicit confirmation.

5.2 Accuracy, hallucination, and your responsibility

Large language models can produce outputs that are inaccurate, incomplete, fabricated, biased, or out of date. You are responsible for reviewing all AI-generated outputs before relying on or acting upon them. We recommend that you independently verify any factual, legal, financial, or contractual statement produced by the assistant before using it, for example, to respond to third-parties via our Gmail integration.

5.3 No automated decision-making with legal effect

The AI assistant generates suggestions, drafts, and recommendations only. It does not make decisions that produce legal or similarly significant effects on you. All consequential actions – sending an email, issuing an invoice, transferring data, or paying a tax liability – require your review and explicit confirmation. We do not engage in profiling that produces legal or similarly significant effects on you within the meaning of GDPR Article 22.

5.4 Third-party AI providers and how your inputs are handled

The AI assistant is powered by large language models supplied by third-party AI providers, listed in our sub-processor table (Section 6). We have configured these integrations so that, to the extent the relevant provider offers it:

  • Your inputs and the assistant's outputs are not used by the AI provider to train or improve their foundation models;
  • Inputs are subject to short retention periods (typically 30 days or zero retention) under our agreement with the provider; and
  • Inputs and outputs are processed under data processing terms that pass through GDPR-compliant safeguards.

We will update this Policy and our sub-processor list if we materially change AI providers.

5.5 Use of AI Inputs and Outputs to Improve Sunday

We may use certain AI inputs and outputs generated from information provided directly to Sunday to evaluate the quality of the assistant, debug errors, detect abuse or policy violations, and improve our prompts and product. We use pseudonymisation or other appropriate safeguards where feasible. Google User Data, including raw or derived information received through Google Workspace APIs, is excluded from any processing used to develop, train, or improve generalised or non-personalised AI or machine-learning models. Google User Data may be processed by AI systems only where necessary to provide the personalised, user-facing Sunday functionality requested by the user whose Google account authorised access. We do not permit third-party AI providers to use Google User Data to train or improve their foundation or generalised models. Where applicable, you may opt out of Sunday's internal product-improvement processing through your account settings or by emailing admin@withsunday.io. Opting out will not affect your ability to use the assistant.

6. Who We Share Your Information With

We share your personal information only where necessary and only with the categories of recipients described below. We do not sell your data. We do not share your data for cross-context behavioural advertising.

6.1 Service providers (sub-processors)

We engage third-party companies to help us operate the Services. These companies act as data processors on our behalf – they may only use your data in accordance with our written instructions, the data processing terms we have executed with them, and this Policy. The categories below show the structure of our sub-processor stack and may also be requested by emailing admin@withsunday.io.

Sub-processorCategoryPurpose
Supabase & VercelCloud infrastructureHosting, storage, and compute
OpenAI GPT-5.4-miniAI / large language modelPowering the AI manager assistant
Google LLCTransactional emailSending account, billing, and notification emails
StripePaymentsProcessing your subscription payments to Sunday
VercelReliability and securityCrash reporting, error monitoring, performance
Google LLCEmail APIGmail integration via the Google API Services

6.2 Google Workspace API Services – Limited Use Disclosure

Sunday's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Google User Data received or derived through Google Workspace APIs:

  • Is used only to provide or improve user-facing Google-connected functionality for the user who authorised access;
  • May be processed by Sola to provide personalised email, deal-management, task-management, and creator-business functionality requested by that user;
  • Is not used to populate, enrich, or maintain Sunday's shared brand or contact database, shared deal-value datasets, global benchmarking datasets, or other cross-user information products;
  • Is not made available to other Sunday users via automated extraction to the authorising user's private Sunday workspace;
  • Is not used to develop, train, or improve generalised or non-personalised AI or machine-learning models; is not sold or provided to data brokers or information resellers; and is not used or transferred for advertising, including personalised, interest-based, retargeted, or cross-context behavioural advertising. Google User Data may be transferred to service providers only where necessary to provide or secure the Google-connected functionality requested by the user and subject to appropriate contractual and data-protection requirements. It may also be disclosed where required by applicable law or valid legal process. Where a user separately and intentionally provides information directly to Sunday through a contribution, review, or shared-database submission feature, that submission is treated as information provided directly to Sunday and is subject to the disclosures and terms applicable to that feature. Sunday does not automatically convert or transfer Google-derived information into shared database data.

6.3 Legal and regulatory disclosure

We may disclose your information to law enforcement, regulators, courts, or other authorities where we are required to do so by law, where necessary to comply with valid legal process, where necessary to enforce our Terms of Service, or where necessary to protect our rights or the safety of any person. Where legally permitted, we will notify affected users before producing data in response to government requests.

6.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you and provide a meaningful opportunity to object before your information becomes subject to a materially different privacy policy.

6.5 With your consent or at your direction

We may share your information with additional third parties where you direct us to do so or have given specific consent (for example, when you choose to email a media kit to a brand).

7. Financial Data and Payments

Our financial tracking feature allows you to log income, invoices, and deal values. This data is stored securely and used only to provide the tracking and reporting features to you, and to feed the AI assistant where you have not disabled that feature.

We are not a money services business. We do not hold, move, or transmit funds on your behalf. We do not currently process payments between you and any third party. Invoice amounts and payment details you log in the platform are stored as records you maintain – payments are made and received directly to you, outside Sunday.

Subscription payments to Sunday itself are processed by our payment processor (named in Section 6). The payment processor collects and processes your payment card details directly under its own privacy policy. Sunday receives a tokenised reference and limited descriptive information (such as the last four digits of the card and the card brand). We do not store full payment card numbers on our systems and Sunday's environment is not in scope for storage of cardholder data under PCI-DSS, although we maintain SAQ-A scope for our integration with the payment processor.

We may issue invoices to you in respect of your Sunday subscription that comply with applicable VAT, GST, and similar tax invoicing requirements in your jurisdiction. Where you generate invoices for your own clients using Sunday's invoice generation feature, you are solely responsible for ensuring that the format, content, and retention of those invoices comply with the laws applicable to your business.

8. How Long We Keep Your Information

We keep your personal information only for as long as necessary for the purposes described in this Policy or as required by law. The following retention periods apply (where two or more periods could apply, the longer applies):

Category of informationRetention period
Account information (name, email, profile)Duration of your account, plus 14 days following account closure (or longer where required by law).
Financial tracking data (invoices, deal records, income logs)Duration of your account, plus the longest applicable tax record retention period in jurisdictions where you do business and where we have related obligations (this is currently up to 10 years for some EU member states, 7 years for the United States, and 6 years for the United Kingdom). After that period, we delete or anonymise the records. Financial tracking data (invoices, deal records, income logs, and any address information included on issued invoices) is retained on this same basis.
Google Workspace / Gmail dataRaw email content is fetched and processed as necessary to provide Google-connected features. Sunday does not retain complete copies of users' Gmail mailboxes as a separate shared database. Technical metadata necessary to maintain the Gmail integration, such as message identifiers associated with emails a user has saved, linked, or acted upon within Sunday, may be retained for the duration of the relevant account or feature. Where Sola identifies information from Gmail and the user chooses to create or update a record within their private Sunday workspace, such as a deal, task, deadline, deal value, or brand record, Sunday may retain the resulting structured information for as long as the relevant record is maintained by the user. Such records remain subject to the restrictions applicable to Google-derived information and are not used to enrich Sunday's shared contact database or other cross-user datasets. Professional contact email addresses contributed by a user directly through a separate shared-database submission process are treated separately from Google-derived data. OAuth tokens are stored only while the Google integration remains active and are revoked and deleted when the user disconnects the integration or deletes their account, subject to any limited technical delay necessary to complete deletion securely.
AI assistant inputs and outputsUp to 30 days from the date of each interaction within Sunday's systems, unless you save a record within the platform. Our AI provider may retain inputs separately under its own retention schedule (typically 30 days or less, with zero-retention configured where available).
Usage and log dataUp to 12 months. Aggregated/anonymised statistics may be retained indefinitely.
Security logs and incident recordsUp to 24 months for security investigation and incident response purposes.
Support communications3 years from closure of the support ticket.
Marketing consent recordsUntil consent is withdrawn, plus 3 years to evidence the basis on which marketing was sent.
BackupsEncrypted backups containing your information may persist for up to 90 days after deletion from production systems, after which they are overwritten in the normal backup rotation.
OAuth tokens (Gmail and other connected accounts)Stored only for as long as the integration is active; revoked and deleted immediately on disconnect or account deletion.

When your account is closed, we delete or anonymise your personal information within 14 days of confirmation, except where retention is required for the categories above, by law, or by legitimate business necessity (for example, financial records, fraud prevention, or pending legal claims).

10. Cookies

The following table lists every cookie currently set in connection with the Services. Because our current cookie footprint is limited to authentication and security, all cookies listed below are strictly necessary – they are required for the platform to function and cannot be disabled without breaking core functionality. We have not set non-essential cookies.

Cookie typeSet byPurposeDuration
Sunday session cookieSunday (first party)Maintain your authenticated session after login. Without this cookie, you would need to log in on every page load.Session (expires when you close your browser) or up to 30 days if you select "Stay signed in"
Sunday CSRF tokenSunday (first party)A security token that prevents cross-site request forgery attacks on form submissions and API calls.Session
Google authentication cookies (e.g. GAPS, LSID, SSID, SID, __Secure-1PSID, __Secure-3PSID, and related)Google LLC (third party)Set by Google when you sign in or sign up using Google Single Sign-On (SSO). These cookies allow Google to authenticate your identity and pass a verified credential to Sunday. They are controlled by Google and governed by Google's Privacy Policy. Sunday does not read or write these cookies directly.Varies – typically 1 to 2 years, as determined by Google
Google state / nonce cookiesGoogle LLC (third party)Short-lived cookies set during the OAuth 2.0 flow to prevent replay attacks and verify that the authentication response corresponds to a request Sunday initiated.Session or a few minutes

A note on Google cookies: the specific cookie names Google sets may change as Google updates its authentication infrastructure. Sunday has no control over which cookies Google sets, their duration, or their content. For the current, authoritative list of cookies set by Google, please refer to Google's cookie policy.

10.1 Consent and Your Choices

Because all cookies we currently set are strictly necessary for authentication and security, we do not present a cookie consent banner for these cookies – consent is not required under EU, UK, or other applicable law for strictly necessary cookies. If you sign in using Google SSO, Google's own cookies are set as a direct consequence of that authentication flow; by choosing to use Google SSO, you are directing us to initiate that flow.

You may refuse or delete cookies using your browser settings. If you delete or block the Sunday session cookie, you will be logged out and will need to sign in again. Blocking Google's authentication cookies will prevent Google SSO from functioning; you will not be able to sign in using that method.

10.2 Global Privacy Control and Do Not Track

We honour Global Privacy Control (GPC) signals as a valid opt-out request from California residents and residents of other US states whose laws recognise GPC (currently including Colorado, Connecticut, and others). Because we do not currently engage in the sale or sharing of personal information for cross-context behavioural advertising, and because all cookies we set are strictly necessary, a GPC signal currently has no material effect on our cookie practices – but we record it and will honour it for any future non-essential processing.

11. Your Privacy Rights

Depending on where you are located, you may have the rights set out below. We honour the substantive rights below regardless of your jurisdiction, subject to the verification process and any applicable legal exceptions.

11.1 Rights available to all users

  • Right to access – request a copy of the personal information we hold about you.
  • Right to correction – ask us to correct inaccurate or incomplete information.
  • Right to deletion – ask us to delete your personal information, subject to applicable legal retention obligations and the exceptions in Section 11.5.
  • Right to withdraw consent – where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right to opt out of marketing – by clicking "unsubscribe" in any marketing email or contacting us at admin@withsunday.io.

11.2 Additional rights for EU, EEA, and UK users (GDPR / UK GDPR)

  • Right to restriction of processing – ask us to pause processing in certain circumstances (for example, while a correction request is pending).
  • Right to data portability – receive a copy of your information in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
  • Right to object – object to processing based on legitimate interests; we will stop unless we have compelling legitimate grounds that override your interests, or where the processing is necessary for the establishment, exercise, or defence of legal claims.
  • Rights related to automated decision-making – we do not make solely automated decisions producing legal or similarly significant effects on you (see Section 5.4).
  • Right to lodge a complaint – you have the right to complain to your local supervisory authority. The UK ICO can be reached at ico.org.uk or 0303 123 1113. EU residents can find their national authority at edpb.europa.eu/about-edpb/about-edpb/members_en.

11.3 Additional rights for California residents (CCPA/CPRA)

If you are a California resident, in addition to the rights above you have the right to:

  • Know the specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we disclose it.
  • Opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioural advertising.
  • Limit the use and disclosure of sensitive personal information to that necessary to provide the Services. We do not use sensitive personal information for any secondary purpose that would require this right to be available, but you may submit a "Limit Use" request and we will confirm receipt.
  • Non-discrimination – we will not discriminate against you, including by denying services or charging different prices, for exercising any CCPA/CPRA right.

California residents may submit requests by emailing admin@withsunday.io. We will acknowledge receipt within 10 business days and respond substantively within 45 days, with a 45-day extension available where reasonably necessary. You may designate an authorised agent to make requests on your behalf – we will require written authorisation signed by you and may require you to verify your identity directly.

11.4 Additional rights for residents of other US states

If you are a resident of Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Nebraska, Rhode Island, or any other US state with a comprehensive consumer privacy law, you have rights similar to those described above, including the rights to access, correct, delete, and obtain a copy of your personal information; to opt out of targeted advertising, sale of personal data, and certain types of profiling; and (in most of these states) to appeal a denial of a privacy request.

Appeals. If we refuse to act on your privacy request, you may appeal our decision by replying to our response email or by emailing admin@withsunday.io with the subject line "Privacy Request Appeal". We will review the appeal and respond within 60 days (or any shorter period required by your state's law). If your appeal is denied, you may contact your state Attorney General.

11.5 Exceptions to deletion

We may decline a deletion request, in whole or in part, where retention is permitted or required by law, including to: complete a transaction; detect security incidents or protect against fraud; comply with a legal obligation; exercise or defend legal claims; comply with tax, accounting, or regulatory record-keeping requirements; or maintain backups awaiting overwrite in our normal backup cycle. Where we decline a request, we will explain the basis for our decision and inform you of any partial action taken.

11.6 How we verify your identity

To protect your information, we will take reasonable steps to verify that the person making a request is the data subject. For most requests, replying from the email address registered to your Sunday account is sufficient. For more sensitive requests (for example, large data exports or deletion of business records), we may ask you to confirm additional account-specific information or to authenticate via a logged-in session. For authorised agent requests, we will require written authorisation and verification of your identity. We will not require you to create a new account in order to make a request.

11.7 How to exercise your rights

To exercise any of these rights, please contact us at admin@withsunday.io. We will respond within 30 days (or within any shorter period required by applicable law). We do not charge a fee for reasonable requests but may charge a reasonable fee, or refuse the request, where it is manifestly unfounded or excessive, as permitted by law.

12. Children's Privacy

The Services are designed for adult professionals. You must be at least 18 years old to register an account. Where applicable law sets a different minimum age, you must meet that age.

We do not knowingly collect personal information from children under the age of 16 (or under any higher age set by applicable law, including under COPPA in the United States and Article 8 GDPR in EU member states, where the digital age of consent ranges from 13 to 16 depending on the member state).

If we become aware that we have inadvertently collected personal information from a child, we will close the relevant account and delete the information promptly. If you believe we hold information about a child, please contact us at admin@withsunday.io.

13. International Users and Cross-Border Transfers

Sunday Inc. is based in the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from those in your country.

13.1 EU and EEA users

For transfers of personal information from the European Economic Area to countries that the European Commission has not recognised as providing an adequate level of protection, we rely on one or more of the following lawful transfer mechanisms, depending on the recipient and circumstances:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented where appropriate by additional technical, organisational, and contractual measures identified through a Transfer Impact Assessment;
  • Certification under the EU-US Data Privacy Framework (DPF), where the recipient is certified – note that the legal status of the DPF remains subject to challenge, and we monitor developments;
  • Binding Corporate Rules of the recipient, where applicable;
  • Other lawful transfer mechanisms permitted under Chapter V of the GDPR.

You may request a copy of the applicable transfer mechanism by emailing admin@withsunday.io.

EU representative (Article 27 GDPR). Sunday Inc. has appointed Caitlin Mellor as its representative in the European Union under Article 27 GDPR. The representative can be contacted at admin@withsunday.io. EU data subjects and supervisory authorities may contact the representative on all issues related to the processing of their personal information.

13.2 UK users

For transfers of personal information from the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, the UK Extension to the Data Privacy Framework (where the recipient is certified), or another lawful UK transfer mechanism, in each case supplemented where appropriate by a transfer risk assessment.

UK representative (Article 27 UK GDPR). Sunday Inc. has appointed Caitlin Mellor as its representative in the United Kingdom. The representative can be contacted at admin@withsunday.io. UK data subjects may contact the representative or the ICO at ico.org.uk.

13.3 Switzerland

If you are located in Switzerland, we process your personal information in accordance with the revised Swiss Federal Act on Data Protection (FADP). For transfers from Switzerland, we rely on SCCs (with the Swiss adaptations of the European Commission's SCCs), the Swiss-US Data Privacy Framework (where the recipient is certified), or another lawful Swiss transfer mechanism.

13.4 Canada

If you are located in Canada, we handle your personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, if you are a resident of Quebec, the Act respecting the protection of personal information in the private sector (Law 25). You have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca).

13.5 Australia

If you are located in Australia, we handle your personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You have the right to complain to the Office of the Australian Information Commissioner (oaic.gov.au).

13.6 Brazil

If you are located in Brazil, we handle your personal information in accordance with the Lei Geral de Proteção de Dados (LGPD). You have the right to complain to the Autoridade Nacional de Proteção de Dados (gov.br/anpd).

13.7 Other jurisdictions

If you are located in another jurisdiction with applicable privacy law (for example, South Africa under POPIA, Singapore under the PDPA, or Japan under the APPI), we process your personal information in accordance with the requirements of that jurisdiction. Please contact us if you have questions about how your local law applies.

14. Data Protection Impact Assessments

Because the Services involve processing of communications content via the Gmail integration, financial information, and AI-driven analysis at scale, we will conduct before launch a Data Protection Impact Assessment (DPIA) under GDPR Article 35 to identify and mitigate risks to your rights and freedoms. We update the DPIA when we materially change the Services or introduce new features that involve high-risk processing. Supervisory authorities and certain business customers may request a summary.

15. Beta and Early-Access Features

From time to time we may make beta or early-access features available, including new AI-powered features. Beta features may have different data handling characteristics than the general Services – for example, additional logging for debugging, more limited retention controls, or use of a different sub-processor. We will tell you when a feature is in beta, describe any material differences in data handling at the point you opt in, and update this Policy where appropriate.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in the Services, our data practices, or applicable law. The "Last Updated" date at the top of this Policy indicates the latest revision. If we make material changes that affect your rights or how we use your information, we will notify you by email (to the address associated with your account) and/or by displaying a prominent notice within the platform in advance of the changes taking effect, where reasonably practicable. We will seek your consent to material changes where required by law. Where a change is required by law to take immediate effect (for example, an emergency security or compliance update), we may implement it immediately and notify you as soon as reasonably possible afterwards.

Your continued use of the Services after the effective date of a revised Policy constitutes your acceptance of the changes to the extent permitted by law.

17. Definitions

In this Policy:

  • "Personal information" and "personal data" are used interchangeably and mean any information that identifies, relates to, describes, or could reasonably be linked to you as an identified or identifiable individual.
  • "Sensitive personal information" has the meaning given by the CCPA/CPRA (California Civil Code §1798.140(ae)) and includes account credentials, financial account information, contents of communications, and similar categories.
  • "Special category data" has the meaning given by GDPR Article 9 and includes data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, and data concerning a person's sex life or sexual orientation.
  • "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, or deletion.
  • "Controller" (or "business" under the CCPA/CPRA) means the entity that determines the purposes and means of processing personal information.
  • "Processor" (or "service provider" under the CCPA/CPRA) means an entity that processes personal information on behalf of a controller.
  • "Sub-processor" means a processor engaged by another processor.
  • "Sale" and "share" (with respect to personal information) have the meanings given by the CCPA/CPRA.
  • "Anonymised" means information from which all identifiers have been irreversibly removed such that the data subject cannot be re-identified, taking into account all means reasonably likely to be used.
  • "Pseudonymised" means information that has been processed so that it can no longer be attributed to a specific data subject without the use of additional information held separately and protected by technical and organisational measures.

Sunday HQ, Corp. · www.sundayforcreators.com · admin@withsunday.io