Privacy Policy

Last updated: 15 August 2026

1. Who we are

Graftie is a trade business management platform operated by Robert Brewer, trading as Graftie ("we", "us", "our"). We are a UK-based business providing software-as-a-service (SaaS) to tradespeople and small businesses.

For data protection queries, contact: [email protected]

2. What data we collect

We collect the following categories of personal data:

  • Account data: Your name, email address, and company information provided during sign-up and onboarding.
  • Authentication data: We use Clerk for authentication. Clerk processes your login credentials. We do not store your password.
  • Business data: Customer contacts, job details, quotes, invoices, certificates, expenses, and scheduling information you enter into the platform.
  • Communication data: Messages sent through the platform (WhatsApp, SMS, email), including content and metadata.
  • Usage data: How you interact with the platform — pages visited, features used, IP address, browser type. Collected via standard server logs and analytics.
  • Payment data: We use Stripe for payment processing. We do not store your card details — Stripe handles all payment information securely.

3. How we use your data

  • To provide and maintain the Graftie service
  • To generate AI-powered quotes, messages, and certificate drafts using our AI engine
  • To send you notifications about your account, jobs, and invoices
  • To process payments through Stripe
  • To provide customer support
  • To improve our features and develop new ones
  • To detect, prevent, and address fraud, abuse, and security issues

4. Legal basis for processing (GDPR)

We process your personal data under the following legal bases:

  • Contract: Processing necessary to provide the service you signed up for (Art. 6(1)(b))
  • Legal obligation: Compliance with tax, accounting, and other legal requirements (Art. 6(1)(c))
  • Legitimate interests: Improving our service (including product analytics), preventing fraud, and ensuring security (Art. 6(1)(f))
  • Consent: For marketing communications (Art. 6(1)(a)) — you can withdraw consent at any time

5. Data sharing

We share data with the following third-party processors, all of whom have their own privacy policies:

  • Clerk — Authentication and user management
  • Stripe — Payment processing
  • OpenRouter / AI providers — AI quote generation, message drafting, and other AI features
  • Twilio — WhatsApp and SMS messaging (when configured)
  • Resend — Transactional email delivery (when configured)
  • Vercel / Neon — Hosting and database infrastructure

We do not sell your personal data to anyone. We do not share your data with third parties for their own marketing purposes.

6. Data retention

  • Account data: Retained while your account is active. Deleted within 30 days of account closure.
  • Business data: Retained while your subscription is active. You can export your data at any time. Deleted within 60 days of account closure.
  • Server logs: Retained for 90 days for security and debugging purposes.
  • Payment records: Retained as required by UK tax law (typically 6 years).

7. Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access — Request a copy of your data
  • Right to rectification — Correct inaccurate or incomplete data
  • Right to erasure — Request deletion of your data ("right to be forgotten")
  • Right to restrict processing — Ask us to limit how we use your data
  • Right to data portability — Receive your data in a machine-readable format
  • Right to object — Object to processing based on legitimate interests
  • Right to withdraw consent — For processing based on consent, withdraw at any time

To exercise any of these rights, contact [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Data security

  • Multi-tenant database isolation — your data is never accessible to other tenants
  • Authentication via Clerk with encrypted credentials
  • All data encrypted in transit (HTTPS/TLS)
  • Database encrypted at rest (Neon PostgreSQL)
  • Regular security reviews and dependency updates

9. International data transfers

Some of our processors (Clerk, Stripe, Vercel) may process data outside the UK/EEA. All transfers are made under appropriate safeguards (UK adequacy decisions, Standard Contractual Clauses, or equivalent).

10. AI data processing

When you use AI features (quote generation, message drafting, certificate pre-fill), your input data is sent to our AI provider (OpenRouter) for processing. We instruct our AI providers not to store or train on your data. AI-generated content is clearly marked in the platform.

11. Children's privacy

Graftie is a business-to-business (B2B) platform. We do not knowingly collect data from anyone under 16. If you believe we have collected data from a minor, please contact us immediately.

12. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes via email or in-app notification. The "last updated" date above indicates when the policy was last revised.