1. Introduction
Local Sigma and its operators ("we," "us," or "our") operate the Local Sigma website at localsigma.xyz. Local Sigma provides AI consulting and pilot-development services. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website, submit our contact form, book a meeting with us, or use our invite-only internal platform.
It should be read together with our Terms of Service. We aim to comply with applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA) where applicable.
2. Information We Collect
Contact form
When you submit the contact form on the website, we collect:
- your name
- your email address
- your message
- the date and time of submission
We use this information to reply to your inquiry and to plan follow-up conversations, proposals, or discovery calls.
Booking pages
When you book a meeting through a Local Sigma booking page, we collect:
- your name and email address
- the meeting type and time you selected
- your timezone
- any optional message you include
- for meetings requiring it, a phone number or a meeting location you provide (link, address, etc.)
We use this information to schedule and manage the meeting, notify both parties, and generate calendar events. If you later reschedule or cancel the booking, the associated reason (if provided) is stored alongside the booking record.
Invited platform accounts
Local Sigma runs an invite-only internal platform for our team and selected collaborators. If you are invited, we collect:
- your email address (from the invitation)
- a name you set on your profile
- a hashed password
- your role (member/admin) and account status
- optional profile details you add (display name, bio, avatar image, timezone, working hours, meeting-type configuration)
We use this information to operate the platform, authenticate you, manage bookings you host, and administer accounts.
External calendar feeds
If you connect an external calendar (e.g., Google, Outlook, iCloud) to your booking availability, we store the calendar URL you provide and periodically fetch busy/free time only. We do not read event titles, guest lists, descriptions, or attachments.
Operational log data
Our infrastructure providers automatically process operational data when you visit the website. This can include your IP address, approximate location, browser type and version, pages accessed, timestamps, request metadata, and session or security identifiers. We do not use this information for advertising profiling.
Cookies and local storage
We use strictly necessary technical storage required for the site to function securely — including a Supabase session cookie/local-storage entry for signed-in platform users, and short-lived session storage used during the invite-acceptance flow. We do not currently use analytics or advertising cookies on the live site.
3. How We Use Information
We use personal data to:
- respond to contact-form inquiries and consulting requests
- schedule, confirm, reschedule, and cancel meetings booked through the site
- operate, secure, and maintain the website and the internal platform
- authenticate invited platform users and administer accounts
- send transactional emails (booking confirmations, password reset, invitations, account changes)
- improve our services and understand demand for them
- comply with legal obligations and protect our rights
4. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Consent — for information you submit through the contact form or the public booking form, which you provide by checking the consent box before submission
- Contract / pre-contract steps — to arrange meetings you request, and to operate accounts for invited platform users
- Legitimate interests — to operate, secure, and improve the website, to respond to inquiries proportionately, and to communicate with people who have engaged with us
- Legal obligations — where processing is required by applicable law
We do not intentionally seek special-category data. If you voluntarily include sensitive information in an optional message field, we will handle it with additional care and only for the purpose for which you submitted it.
5. How We Share Information
We do not sell or share your personal information as those terms are used under the CCPA/CPRA.
We share personal data with carefully selected service providers that help us operate the website and platform, deliver communications, and provide technical infrastructure. At present these include:
- Lovable (privacy policy) — website hosting, database, and related technical infrastructure
- Resend (privacy policy) — email delivery for transactional and notification emails
- External calendar providers — only if you (as a host) opt to add an external calendar feed to your availability; we fetch busy times from the URL you provide
We may also disclose information where required by law, to respond to lawful requests, or to protect our rights, security, and operations.
6. Data Retention
- Contact submissions are retained as long as they remain relevant to responding to you and to our ongoing business relationship, unless you request deletion earlier.
- Booking records are retained after a meeting takes place for record-keeping, dispute resolution, and follow-up communications. Cancelled bookings remain in our records with their cancellation reason.
- Platform accounts are retained for as long as the account is active. On deactivation, we retain minimal identifying information needed to enforce access controls and honour audit requirements.
- Locally stored browser data remains on your device until you clear it or your browser removes it.
- Operational and security logs may be retained according to the standard retention periods of our infrastructure providers.
7. International Transfers
Our service providers may process personal data in countries outside your country of residence. Where required, we rely on appropriate safeguards for international transfers under applicable data protection law.
8. Your Rights
Depending on your location and applicable law, you may have the right to:
- access the personal data we hold about you
- request correction of inaccurate data
- request deletion of your data
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- request portability of data where applicable
To exercise any of these rights, please contact us at stefan@localsigma.xyz.
If you are a California resident, you may also have the right, where applicable, to know what categories of personal information we collect, request deletion of personal information, request correction of inaccurate personal information, and exercise your rights without discrimination.
You may also have the right to lodge a complaint with the supervisory authority in the country where you live, work, or where you believe a data protection issue has arisen.
9. Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. These include row-level security on our database, TLS in transit, hashed passwords, and least-privilege access to production systems. No system is completely secure, and we cannot guarantee absolute security.
10. Children
The website and platform are not directed to children under 18, and we do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through a prominent notice on the website before taking effect.
12. Contact
For questions about this policy or to exercise your data rights, contact us at stefan@localsigma.xyz.