Privacy Policy
Last updated: August 25, 2026
Gridd ("we", "us") provides warehouse management software for online retailers, available at griddwms.com and as an application you connect to your store. This policy explains what data we collect, why, and how it is deleted. It covers both the Gridd application and this website.
Our role
For data about a store's customers that reaches Gridd from a connected store, the merchant is the data controller and Gridd acts as a data processor / service provider, handling it only on the merchant's instructions to provide the service. For the account details of the people who sign in to Gridd (merchant staff), Gridd is the controller.
What we collect
Synced from your store
- Store profile — store domain, store name, contact email, timezone, and location identifiers.
- Orders — order number, dates, financial and fulfillment status, tags, shipping method, order totals, and shipment tracking numbers.
- Order line items — SKU, product title, and quantities.
- Products — titles, SKUs, barcodes, and product images.
Customer personal information: by default, Gridd does not import customer names, email addresses, phone numbers, or shipping addresses. If a merchant asks us to enable ship-to details on printed packing slips, Gridd stores the recipient name, shipping address, email, and phone number attached to each order, uses them solely to produce packing slips, and deletes them under the same rules as all other order data (see "Data retention and deletion" below).
Created inside Gridd
- Warehouse structure — bins, zones, carts, and staging locations.
- Inventory records — stock levels, the movement ledger (receipts, picks, transfers, adjustments, cycle counts), pick lists, and purchase orders including supplier names and unit costs.
- App settings and configuration.
Account and usage data
- Staff sign-in details — email address and a securely hashed password. Warehouse actions (who picked, received, or counted) are attributed to the signed-in user.
- Error and diagnostic data — if the app encounters an error, technical details (which may include IP address and browser information) are recorded so we can fix it.
How we use data
- To provide the service: syncing orders and products, generating pick lists, tracking inventory, printing labels and packing slips, and pushing stock levels back to your store.
- To provide support and communicate about the service.
- To bill subscriptions — handled through your store platform's billing system; Gridd never sees or stores payment card details.
- To secure and improve the service, including error monitoring.
We do not sell data, use it for advertising, or use one merchant's data for any other merchant's benefit.
How data is protected
- All data is encrypted in transit (TLS) and at rest.
- Store API credentials are held in an encrypted secrets vault, never in ordinary database tables.
- Every record is scoped to your organization and enforced at the database level (row-level security) — one merchant's data is never visible to another.
- All incoming webhooks are cryptographically signature-verified before any data is touched.
Service providers
We share data only with the categories of service providers needed to run Gridd, each bound by contract to process it solely on our instructions:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Database, authentication, application and website hosting |
| Error monitoring | Diagnosing faults in the application |
| Email delivery | Support and transactional messages |
| Your store platform | The platform your store runs on — the source and destination of synced data, and the processor of subscription billing |
Data may be stored and processed in the United States. A current list of the specific providers we use is available to merchants on request at hello@griddwms.com. We may also disclose data where required by law.
Data retention and deletion
- While connected — we keep your data for as long as you use Gridd, so your inventory ledger and order history remain accurate.
- On disconnection — syncing stops immediately and your store access token is deleted right away. Your warehouse data is held briefly so that reconnecting restores your account intact.
- Permanent deletion — when your store platform confirms the removal (48 hours after disconnection), we permanently purge all of the store's data: orders, products, inventory records, settings, and staff accounts associated only with that store.
- Customer redaction — on a customer-redaction request, we erase all personal fields we may hold on that customer's orders (name, email, phone, shipping address, and shipment tracking).
Merchants can also request earlier deletion at any time by emailing hello@griddwms.com.
Platform data requests
Gridd implements the mandatory privacy and deletion requests sent by the store platforms it connects to. If a store's customer asks the merchant for a copy of their data, note that Gridd holds no customer data beyond what the store platform itself stores for the same orders — the merchant can fulfil such requests directly from the platform, and we will assist on request.
Your rights
Depending on where you live (including under the GDPR, UK GDPR, and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict its processing. Merchant staff can exercise these rights by emailing hello@griddwms.com. If you are a customer of a store that uses Gridd, please contact that store directly — as the data controller, the merchant handles your request, and we support them as described above. We do not discriminate against anyone for exercising their privacy rights.
Cookies
The Gridd app uses only the strictly necessary browser storage needed to keep you signed in and remember in-app preferences. This website sets no advertising or analytics cookies.
Children
Gridd is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If we make material changes, we will update this page and notify merchants by email or in-app notice before the changes take effect. The "Last updated" date above always reflects the current version.
Contact
Questions about this policy or your data? Email hello@griddwms.com.