Privacy Policy
Last updated: 19 July 2026
This policy explains what personal data GTM Grid (“we”, “us”) collects when you use the GTM Grid desktop application, website, and cloud services (together, the “Service”), why we collect it, who we share it with, and the choices you have. It sits alongside our Terms of Service.
1. Who we are
The Service is operated by Aphex Automate LTD, 86 Broadway, Cowbridge, CF64 1TR, United Kingdom. For data you put into a workspace about your own prospects and customers, you are the data controller and we act as your processor. For your account and billing data, we are the controller. Privacy questions: legal@gtmgrid.dev.
2. Data we collect
Account data
- Your name, email address, and whether that email has been verified.
- An avatar image, if you set one or your identity provider supplies one.
- Sign-in records: a record of each active sign-in session, including the IP address and browser user-agent captured at sign-in, which we hold for the life of that session so we can show you where your account is signed in and investigate suspicious access.
- If you sign in with an email and password, a cryptographic hash of that password — never the password itself. If you sign in with a third-party provider instead, that provider’s account identifier and access tokens.
- A last-active timestamp, and your email preferences, so we can send lifecycle mail you have not opted out of.
Workspace and collaboration data
Workspace names, membership and roles, and invitations you send (including the invitee’s email address). Realtime collaboration broadcasts presence — who is viewing a grid — to other members of that workspace while you are connected.
Customer Data in your grids
Grid content — tables, columns, rows, and cells — is stored in our cloud database. This frequently contains personal data about third parties (for example prospect names, job titles, company details, and email addresses) that you import, sync from a connected CRM, or generate with a column. We process it on your instruction to operate the Service; we do not sell it, and we do not use it to train AI models.
Credentials
API keys and connector credentials you supply are envelope-encrypted before they are written to the database and are never stored in plaintext. They are decrypted only to run the feature you invoked.
Usage and diagnostic data
Product analytics events (features used, coarse device, app version and browser information, approximate location derived from IP) and operational logs. We use these to understand how the product is used and to keep it working.
When the app hits an error we capture an automatic error report containing the error message, stack trace, and the app state around the failure. Error messages can incidentally include fragments of the data being processed at the time. We use these reports only to diagnose and fix faults.
We may occasionally run an in-product survey or show a feedback widget. Anything you write into one of those is sent to our analytics provider along with the identifiers already attached to your session. Answering is always optional.
We do not record your screen or your sessions. Session replay is disabled in our analytics across both the desktop app and this website, so the contents of your grids are never captured to video or DOM recordings. If we ever turn it on we will update this policy and tell you before it takes effect.
Billing data
Plan, seat count, and metered usage. Card details go directly to our payment processor — we never see or store full card numbers.
3. What stays on your machine
By default, column execution runs locally in the desktop app rather than on our servers. Where you bring your own AI provider key, prompts and row content are sent from your machine directly to that provider; we do not receive or retain that traffic. Local-only projects are stored on your device and their contents are not uploaded to us. The one exception is error reporting: if a run fails, the desktop app and its local engine send us an error report as described above, which can contain fragments of the data being processed.
The exceptions are server-side runs you explicitly choose — pipelines you set to run on the cloud target, scheduled syncs, and inbound webhook auto-enrichment. These execute in our cloud worker and therefore do pass through our infrastructure, including the row content they process. Cloud runs use workspace-shared credentials only; they never use a member’s personal keys or the local coding-agent fallback.
4. Why we process it, and on what basis
- To provide the Service — hosting your workspaces, authenticating you, syncing and enriching your data. Basis: performance of our contract with you.
- To bill you — subscriptions, seats, and usage metering. Basis: contract and legal obligation.
- To keep the Service secure and reliable — abuse prevention, debugging, capacity planning. Basis: our legitimate interests.
- To improve the product and send lifecycle email — analytics and onboarding or digest mail. Basis: on this website, your consent, collected via the cookie banner before anything is stored on your device. In the desktop app we currently rely on legitimate interests: it records product analytics to local storage on launch and does not yet offer an in-app opt-out. We are adding one; until then, email legal@gtmgrid.dev and we will exclude you. Lifecycle email relies on legitimate interests, and you can opt out of non-transactional email at any time.
5. Who we share it with
We do not sell personal data. We share it with service providers who process it on our behalf under contract:
- Supabase — the managed Postgres database holding everything in section 2 that lives in our cloud: your account, your workspaces, your encrypted connector credentials, and all grid content, including personal data about the prospects and customers in it.
- Vercel — hosting for the website and API, and our operational logs.
- Autumn — subscription and seat management, which receives your account and workspace identifiers. Stripe sits underneath it and handles payment processing and card details.
- Resend — transactional and lifecycle email delivery.
- PostHog — product analytics and error reporting.
- Inngest — durable background job processing. Inbound webhook records and cloud pipeline runs pass through Inngest as event payloads, so it receives Customer Data, not only job metadata.
- PartyKit — realtime presence.
Connectors you choose to enable (your CRM, data providers, AI model providers) receive the data needed to fulfil the request you made — their own privacy policies govern that processing. We may disclose data where the law requires it — and we will notify you when we are legally permitted to do so, which court orders and similar requests sometimes forbid. If we are ever part of a merger or acquisition we will tell you before your data moves.
6. International transfers
Our providers may process data in the United States and elsewhere. Where data leaves the UK or EEA we rely on appropriate safeguards, including the UK Addendum and EU Standard Contractual Clauses in our agreements with those providers.
7. How long we keep it
- Account, workspace, and grid data: we do not apply an automatic expiry — this data is kept for as long as you want it, and is deleted when you ask us to delete it. You can request deletion at any time using the contact address below, and we will action it unless we are legally required to keep a record.
- Operational logs: held by our hosting provider, Vercel, and kept only for the short period their platform retains them, for fault diagnosis.
- Analytics and error reports: held by PostHog under their retention schedule for our plan.
- Pipeline run data: execution history for pipeline runs is retained for 30 days, after which completed runs are deleted automatically. Results a pipeline writes into your grid cells are your data, not execution logs, and are kept until you overwrite or delete them.
- Inbound webhook deliveries: we keep the most recent 50 payloads per webhook so you can debug a failing integration. Older ones are discarded as new deliveries arrive, rather than on a fixed schedule.
- Billing records: retained as long as tax and accounting law requires.
8. Security
Data is encrypted in transit and at rest. Connector secrets are additionally envelope-encrypted at the application layer. Access to production data is limited to people who need it. Inbound webhooks are authenticated with an HMAC signature. No system is perfectly secure, but we work to keep the risk low and will notify you of a breach affecting your data as the law requires.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Much of this you can do yourself in the app; for anything else, email legal@gtmgrid.dev and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to your local data protection authority. In the UK that is the Information Commissioner’s Office (ico.org.uk).
If your data is in a customer’s workspace and you are not a GTM Grid user, that customer is the controller — contact them directly, or contact us and we will pass the request on.
10. Cookies
We use cookies that are strictly necessary to keep you signed in and to remember your cookie choice. These do not need your consent because the site cannot work without them.
We would also like to use analytics cookies to understand how the product is used. We ask first: until you accept, our analytics tool keeps its state in memory only and sets no analytics cookies or identifiers on your device. We do not use advertising cookies, and we do not record your screen.
If you decline, our analytics tool records that refusal in a single local flag (__ph_opt_in_out_…) so we can honour it on your next visit. That flag is strictly necessary — it exists only to keep you opted out — but we mention it because it is the one thing declining does write.
You can change your mind at any time — re-opens the banner. Declining opts you out, clears the identifiers our analytics tool was holding, and stops anything further being written to your device, apart from a single flag recording your refusal.
This section describes this website. The desktop application is not a browser and does not use cookies, but it does write analytics identifiers to local storage on your machine when it launches — see section 4 for the basis we rely on there and how to opt out.
11. Children
The Service is a business tool and is not directed at anyone under 16. We do not knowingly collect their data; if we learn we have, we will delete it.
12. Self-hosting
GTM Grid is source-available and can be self-hosted. If you run your own instance, your data stays in your infrastructure and this policy does not apply to it — you become the controller for everything in that deployment.
13. Changes to this policy
We may update this policy. If a change is material we will notify you (for example by email or in the app) before it takes effect, and we will always move the “last updated” date above.
14. Contact
Questions about this policy or your data: legal@gtmgrid.dev.