One policy in two parts: Mantelin's Core Terms, shared by every Mantelin product, and the Sprooster Schedule with this product's specifics.
Core Terms (Part A) version 1.0 · effective July 25, 2026
Sprooster Schedule (Part B) version 1.1 · effective August 25, 2026
Core Terms version: 1.0 · Effective date: July 25, 2026 Applies to: all products and services operated by Mantelin LLC ("Mantelin," "we," "us"), including Sprooster, HomeTabs, BleacherFund, and other Mantelin services (each a "Product").
How this document works. Every Mantelin Product publishes its privacy policy as one document in two parts: Part A, these Core Terms, identical across all Mantelin Products; and Part B, that Product's Schedule, which describes the Product's specific data practices using a fixed set of sections (S1–S11) that supplement the Core Terms.
Order of precedence. A Schedule adds to and specifies these Core Terms. If a Schedule genuinely conflicts with these Core Terms, the Schedule controls for that Product — except that no Schedule may weaken the commitments in Section 8 (Three commitments) or the obligations in Section 3 (When we act as a processor), which are a floor for every Product. If a customer organization has entered into a Data Processing Agreement (DPA) with us, that DPA controls over both parts for that customer's Organization Data.
Versions. Part A and Part B carry independent version numbers and effective dates, shown on each Product's policy page. A history of changes is published at each Product's /legal/changelog page (for Sprooster, sprooster.com/legal/changelog).
Mantelin LLC is a Tennessee limited liability company. For every Product, the party responsible for handling your information under this policy is Mantelin LLC.
Some Products are used by individuals directly; others are used by organizations (for example, a company that connects its employee directory). For data you provide about yourself, Mantelin decides how it is handled under this policy — we act as the "controller." For data a customer organization provides about its own people, the organization makes those decisions and we act on its behalf — see Section 3. Each Product's Schedule (section S1) states which role applies to which data.
Capitalized terms used in this policy have the meanings given in the Mantelin Definitions, published at sprooster.com/legal/definitions and incorporated into these Core Terms — including "Personal Data," "Organization," "Workspace," "Organization Data," "Content," "Sub-processor," "De-identified Data," "Schedule," and "DPA." The Definitions are versioned once, there; a material change to a definition is treated as a material change to this policy.
Some Products hold Personal Data about people who never signed up with us — employees, students, or members whose information an Organization supplied or synced into a Product ("Organization Data"). For Organization Data, the Organization is the controller: it decides why and how that data is used, and it is responsible for having the right to provide it and for informing its people. Mantelin acts as the Organization's processor, and commits that we will:
Where a Product offers a DPA, that DPA governs Organization Data for customers who enter into it and controls over this section if they differ.
Across Products, the information we handle falls into these categories. Each Product's Schedule (section S2) states which apply and lists the exact data involved.
Information you give us. Account details when you sign up (name, email, authentication information handled by our sign-in provider), Content you submit within a Product, messages you send us through support or help forms, and details you provide when booking time with us (name, email, meeting information).
Information provided about you by an Organization. Some Products display information supplied by your employer, school, or organization rather than by you personally. The relevant Schedule describes exactly what that includes.
Information collected automatically. We use PostHog, a product-analytics service, to understand how our Products are used: pages and features used, actions taken, approximate location derived from IP address, and device/browser information. PostHog sets analytics cookies for this purpose. We use Sentry for error monitoring; error reports are configured to scrub Personal Data where feasible.
Payment information. Where a Product offers paid plans, payment is handled by our payment processors; we do not store full card numbers. The Schedule (section S5) identifies the processor.
Sensitive information. We do not seek sensitive Personal Data — such as financial account details, precise geolocation, health information, or government identifiers — except where a Product's Schedule expressly describes the sensitive data involved, why the Product needs it, and the protections applied. Where a Product does handle sensitive Personal Data, we use it only to provide the Product's services — never for inference, profiling, or any secondary purpose.
We use cookies and similar technologies for three purposes: keeping you signed in (authentication), remembering your settings (preferences), and product analytics as described above.
We do not use advertising cookies, and we do not participate in cross-site tracking or ad networks. Because our cookies are limited to operating and improving our own Products, we do not sell or share cookie data for advertising purposes. We honor opt-out preference signals, such as Global Privacy Control, where applicable law requires.
We use the information described above to provide, maintain, and improve the Products; to create and secure your account; to respond when you contact us; to understand usage so we can make the Products better; to detect, investigate, and prevent abuse, fraud, and security incidents; to comply with legal obligations; and, where you've opted in, to send you Product updates — every such message includes a way to unsubscribe, and opting out never affects your use of the Products. Each Schedule adds any Product-specific purposes.
Some Products include features that use artificial intelligence to process your data in order to provide the feature to you — for example, categorizing, summarizing, or suggesting based on your Content or Workspace. Data processed by an AI feature is used to deliver that feature's output to you or your Organization, subject to this policy. It is not used to train AI models (Section 8), and Organization Data processed by AI features remains subject to Section 3. Each Product's Schedule identifies its AI features and any options to disable them.
Across every Mantelin Product, without exception, and unalterable by any Schedule:
We share information only with:
Service providers (Sub-processors) that help us run the Products — hosting, databases, authentication, analytics, error monitoring, payments — under contracts limiting their use of the data to providing services to us. Each Product maintains a current Sub-processor list at its /legal/subprocessors page; Organizations can subscribe to be notified of changes.
Your Organization, where applicable: your Organization's administrators can see the data in their Workspace.
Authorities and other parties in legal matters. If we receive a subpoena, court order, or other legal demand, we review it for validity, seek to narrow demands that are overbroad, and disclose only what we are legally required to disclose. Unless we are legally prohibited from doing so, we notify the affected user or Organization before disclosure so they may seek protection. We may also disclose information where necessary to enforce our terms or to protect the rights, safety, or security of any person or of Mantelin.
A successor entity, if Mantelin is involved in a merger, acquisition, or sale of assets — in which case this policy continues to apply to previously collected data, and we will notify you of any change in ownership.
Our Products are operated by one company on shared infrastructure, and some services are shared across Products — for example, sign-in, scheduling and booking, support and help systems, analytics, and (where applicable) billing. Because of this:
Some Products let you or your Organization publish or share information deliberately — for example, a shareable read-only link. Anything shared through those features is visible to whoever receives the link or view. Those choices are made by you or your Organization's administrators, not by us, and each Product's Schedule (section S6) describes the controls available.
We may create De-identified Data and aggregated statistics from information we handle — for example, feature-usage metrics across customers. We maintain De-identified Data without attempting to re-identify it, we require the same of anyone we share it with, and we use it only in forms that do not identify any person or, in published forms, any Organization. De-identified and aggregated data may be retained after account or Workspace deletion.
We keep Personal Data while your account or your Organization's Workspace is active. When an account or Workspace is deleted, we delete associated Personal Data within 30 days, and it ages out of encrypted backups within 90 days. We may retain limited records longer where the law requires it (for example, billing and tax records), and De-identified Data as described in Section 12. Any Product-specific deviation appears in that Product's Schedule (section S8).
We use industry-standard measures to protect information, including encryption in transit and at rest, encrypted storage of connection credentials, access controls limiting who can reach production data, and tenant isolation between customer Workspaces. No system is perfectly secure; if we learn of a breach affecting your Personal Data, we will notify affected users and Organizations consistent with applicable law (and, for Organization Data, Section 3).
You can access, correct, or delete your account information at any time from within the Product, or by emailing privacy@sprooster.com. We respond to all requests, and we do not discriminate against you for exercising privacy rights.
Depending on your state of residence, you may have specific legal rights to access, correct, delete, or receive a copy of your Personal Data. To exercise them, email privacy@sprooster.com with the Product and account involved. We acknowledge requests within 10 business days, may need to verify your identity before acting, and respond substantively within 45 days (extendable once by 45 days where the law allows, with notice). You may use an authorized agent to submit a request on your behalf; we may require proof of the agent's authority and verification of your identity. If we decline a request, we will explain why, and you may appeal by replying to our decision.
Where your data is Organization Data, your Organization controls it — direct requests to your administrator, and we will support their response as described in Section 3.
Mantelin's Products are operated from the United States and our services are directed to U.S. users. Your information is stored and processed in the United States.
Mantelin Products do not knowingly collect personal information from children, except where a specific Product is designed to serve schools or youth organizations and its Schedule (section S7) expressly provides for it — in which case that Schedule describes the consents required (parental or school authorization) and the protections applied. If you believe a child has provided personal information to a Product outside those provisions, contact privacy@sprooster.com and we will delete it.
Third-party sites and services. Our Products may link to or interoperate with sites and services we don't operate (including the directory and identity services an Organization chooses to connect). This policy does not cover those third parties; their own policies apply to data they hold.
Our personnel. This policy covers the Products. It does not cover Personal Data Mantelin handles about its own personnel, contractors, or job applicants, which is addressed separately.
When we make changes, we update the version number and effective date of the affected part (Core Terms or a Schedule) and record the change in the changelog.
For individual users: if a change is material, we will notify you through the Product or by email before it takes effect; continued use after the effective date means the updated policy applies.
For Organizations: we will give administrators at least 30 days' advance notice of material changes affecting Organization Data or our processor obligations. If an Organization reasonably objects to such a change, it may terminate the affected Workspace before the change takes effect and receive deletion of its data per Section 13.
We handle disagreements the same way across all Products: talk to us first. Our Terms of Service provide for a 30-day informal-resolution period before any formal claim, and any disputes are governed by Tennessee law in the courts of Tennessee. See each Product's Terms of Service for details.
Mantelin LLC 116 Agnes Rd, Ste 200, Knoxville, TN 37919 privacy@sprooster.com
Schedule version: 1.1 · Effective date: August 25, 2026
This Schedule supplements the Mantelin Core Privacy Terms (Part A) for Sprooster, the employee directory and org chart product. It uses the fixed section set S1–S11; sections that don't apply say so.
Sprooster is sold to organizations. When an Organization connects its directory (or uploads a CSV of its people), everything synced or imported from it is Organization Data: the Organization is the controller and Mantelin is its processor under Section 3 of the Core Terms. For the data you provide about yourself — your account, and profile fields you add to your own entry — Mantelin is the controller under the Core Terms.
Account data (Section 4, "information you give us"): name, email, and sign-in identifiers, handled by our sign-in provider; we never hold your password.
Organization Data (Section 4, "information provided about you by an Organization") — exactly the fields needed for a directory and org chart, synced from the systems in S3:
Members may add optional profile details to their own entry (pronunciation, bio, skills, interests, work history). We do not request or receive email content, files, calendars, chat messages, login history, salary, performance data, or any other HR record. Sprooster collects no sensitive Personal Data as defined in Section 4. Profile photos are display-only: we never run face detection, face recognition, or any other biometric processing on them.
Administrators connect one or more of: Google Workspace (read-only, limited to
admin.directory.*.readonly scopes), Microsoft Entra ID (read-only directory sync),
SCIM provisioning, SAML single sign-on, or CSV upload. Data flows one way — from
the Organization's directory into Sprooster; we never write back to a connected directory.
Directory credentials are encrypted before storage and are write-only through our interface.
Sprooster's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The current list, and a way to be notified of changes, is at /legal/subprocessors.
Payments are processed by Stripe, Inc. Card details are submitted directly to Stripe and never reach Mantelin's systems; we hold only the billing contact, the plan, and the payment status Stripe reports back to us. Stripe processes that data as an independent controller under its own privacy policy for the purposes of payment processing and fraud prevention.
Billing information is Account data, not Organization Data. The number of people in a synced directory determines the price of a plan, but no directory record is sent to Stripe.
Administrators and authors can publish read-only views of an org chart or OrgStudio document via a shareable link. Publishing is off by default, per-link, with an audience choice and a field mask controlling which columns the link discloses; links can be frozen to a snapshot and revoked at any time. Anything shared through a link is visible to whoever holds it — that choice is the Organization's, per Section 11.
Not applicable — Sprooster is a workplace product and is not directed to children.
None. The Section 13 defaults apply: deletion within 30 days of account or Workspace deletion, out of encrypted backups within 90 days.
Not enabled for Sprooster. Our analytics configuration has session recording explicitly disabled.
Sprooster uses these shared Mantelin services (Section 10): sign-in, scheduling and booking, support and help systems, product analytics, and error monitoring. The Organization Data carve-out holds: directory data synced into Sprooster is used only to provide Sprooster to that Organization and is never shared with or used by other Mantelin Products.
A Data Processing Agreement is available to customer Organizations on request at privacy@sprooster.com.