1. Who we are
Graftie is a trade business management platform operated by Robert Brewer, trading as Graftie ("we", "us", "our"). We are a UK-based business providing software-as-a-service (SaaS) to tradespeople and small businesses.
For data protection queries, contact: [email protected]
2. What data we collect
We collect the following categories of personal data:
- Account data: Your name, email address, and company information provided during sign-up and onboarding.
- Authentication data: We use Clerk for authentication. Clerk processes your login credentials. We do not store your password.
- Business data: Customer contacts, job details, quotes, invoices, certificates, expenses, and scheduling information you enter into the platform.
- Communication data: Messages sent through the platform (WhatsApp, SMS, email), including content and metadata.
- Usage data: How you interact with the platform — pages visited, features used, IP address, browser type. Collected via standard server logs and analytics.
- Payment data: We use Stripe for payment processing. We do not store your card details — Stripe handles all payment information securely.
3. How we use your data
- To provide and maintain the Graftie service
- To generate AI-powered quotes, messages, and certificate drafts using our AI engine
- To send you notifications about your account, jobs, and invoices
- To process payments through Stripe
- To provide customer support
- To improve our features and develop new ones
- To detect, prevent, and address fraud, abuse, and security issues
4. Legal basis for processing (GDPR)
We process your personal data under the following legal bases:
- Contract: Processing necessary to provide the service you signed up for (Art. 6(1)(b))
- Legal obligation: Compliance with tax, accounting, and other legal requirements (Art. 6(1)(c))
- Legitimate interests: Improving our service (including product analytics), preventing fraud, and ensuring security (Art. 6(1)(f))
- Consent: For marketing communications (Art. 6(1)(a)) — you can withdraw consent at any time
5. Data sharing
We share data with the following third-party processors, all of whom have their own privacy policies:
- Clerk — Authentication and user management
- Stripe — Payment processing
- OpenRouter / AI providers — AI quote generation, message drafting, and other AI features
- Twilio — WhatsApp and SMS messaging (when configured)
- Resend — Transactional email delivery (when configured)
- Vercel / Neon — Hosting and database infrastructure
We do not sell your personal data to anyone. We do not share your data with third parties for their own marketing purposes.
6. Data retention
- Account data: Retained while your account is active. Deleted within 30 days of account closure.
- Business data: Retained while your subscription is active. You can export your data at any time. Deleted within 60 days of account closure.
- Server logs: Retained for 90 days for security and debugging purposes.
- Payment records: Retained as required by UK tax law (typically 6 years).
7. Your rights under GDPR
You have the following rights regarding your personal data:
- Right of access — Request a copy of your data
- Right to rectification — Correct inaccurate or incomplete data
- Right to erasure — Request deletion of your data ("right to be forgotten")
- Right to restrict processing — Ask us to limit how we use your data
- Right to data portability — Receive your data in a machine-readable format
- Right to object — Object to processing based on legitimate interests
- Right to withdraw consent — For processing based on consent, withdraw at any time
To exercise any of these rights, contact [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Data security
- Multi-tenant database isolation — your data is never accessible to other tenants
- Authentication via Clerk with encrypted credentials
- All data encrypted in transit (HTTPS/TLS)
- Database encrypted at rest (Neon PostgreSQL)
- Regular security reviews and dependency updates
9. International data transfers
Some of our processors (Clerk, Stripe, Vercel) may process data outside the UK/EEA. All transfers are made under appropriate safeguards (UK adequacy decisions, Standard Contractual Clauses, or equivalent).
10. AI data processing
When you use AI features (quote generation, message drafting, certificate pre-fill), your input data is sent to our AI provider (OpenRouter) for processing. We instruct our AI providers not to store or train on your data. AI-generated content is clearly marked in the platform.
11. Children's privacy
Graftie is a business-to-business (B2B) platform. We do not knowingly collect data from anyone under 16. If you believe we have collected data from a minor, please contact us immediately.
12. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes via email or in-app notification. The "last updated" date above indicates when the policy was last revised.