Legal
Back to GriddedPrivacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how Gridded processes personal data in connection with the website, user accounts, site analyses, project storage, payments, analytics, and customer support.
1. Data Controller
Controller: Michał Dyra, Szyszkowa 32, Opypy, 05-825, Poland (operating as an unregistered business / działalność nierejestrowana). Contact email: support@gridded.pro. Contact phone: +48 503 925 360.
2. Categories of Data
- account data, including email address and authentication identifiers
- project data, location data, and analysis settings saved inside the application
- billing and transaction data connected with subscriptions and extra token purchases
- technical and usage data, including IP-related request data, logs, device/browser information, and analytics events
- support, complaint, and billing correspondence
- student verification data, including academic email verification status, verified email, and verification timestamp where the Student plan flow is used
3. Purposes and Legal Bases
- to create and maintain user accounts and project workspaces
- to provide site analyses, project storage, exports, and related product features
- to process subscriptions, extra token purchases, invoices, and payment records
- to handle support, complaints, abuse prevention, and security monitoring
- to meet accounting, tax, and other legal obligations
- to measure product usage and improve the service where analytics consent has been given
- to measure website conversions and advertising campaign effectiveness where marketing consent has been given
- to verify eligibility for a student plan where that plan is requested
4. Recipients and Processors
Gridded currently uses or plans to use processors and infrastructure providers such as:
- Supabase for authentication, database, and storage
- Hetzner for application hosting (web, API, and background worker infrastructure)
- Cloudflare for DNS, content delivery, and email routing
- Stripe for payment processing and billing services
- Brevo for newsletter and transactional email delivery
- Google Analytics 4, subject to consent
- PostHog, subject to consent
- Metricool, subject to consent
- Meta Platforms Ireland Limited for Meta Pixel advertising and conversion measurement, subject to consent
- Stadia Maps or MapTiler for mapping, basemaps, and geocoding support
5. Cookies, Analytics and Advertising Measurement
Necessary technologies are used for authentication, security, session continuity, and core application functionality. Product analytics and advertising measurement are separate optional choices. PostHog tracking is not initialized, and the external Google Analytics 4, Metricool, and Meta Pixel scripts are not added to the page, before the relevant consent is granted. Meta PageView and configured conversion events are not sent before advertising measurement consent. Gridded does not send GA4 page views, application events, or user properties before product analytics consent. Users can change or withdraw either optional choice through the Cookie Policy page.
6. International Transfers
Some providers may process data outside Poland or the European Economic Area. Where this happens, Gridded aims to rely on appropriate safeguards such as standard contractual clauses or equivalent legal transfer mechanisms offered by the relevant provider.
7. Data Retention
- account and project data: for as long as the account remains active and for a reasonable period needed for backup, security, and claims defense
- billing and invoice data: for the period required by tax, accounting, and legal obligations
- support and complaint records: for as long as needed to handle the case and defend claims
- analytics and advertising measurement data: according to provider retention settings or until consent is withdrawn, subject to provider capabilities and without affecting processing completed before withdrawal
8. User Rights
Users may have the right to access, rectify, erase, restrict processing, object, and request portability where applicable under GDPR. Where consent is the legal basis, users may withdraw consent at any time. Users may also lodge a complaint with the President of the Personal Data Protection Office in Poland.
9. Data Needed for Billing and Student Plans
Payment data is processed to provide subscriptions and extra tokens. If a user requests a Student plan, the provider processes the signed-in account email, student verification status, and related verification records needed to confirm eligibility and prevent misuse of non-commercial pricing.