Privacy Policy
Last updated: September 7, 2026
1. Introduction
This Privacy Policy explains how GridDash ("we", "our", "us") collects, uses, and shares information when you use our website, Chrome new-tab extension, and desktop app.
GridDash is a customizable, tile-based start page and bookmark manager operated by the operator of GridDash, based in United Kingdom. For privacy questions or data requests, email support@griddash.com.
2. Products covered
This policy applies to:
- The GridDash website at www.griddash.com
- The GridDash Chrome extension (new tab and toolbar popup)
- The GridDash desktop app
These products use the same accounts, grids, and servers. Using the extension or desktop app is using GridDash — it does not create a separate privacy regime.
3. Information we collect
Information you provide
- Account details such as email address and authentication credentials
- Grid layouts, tiles, bookmarks, widget settings, notes, and other preferences you save
- Photos or other media you upload to widgets such as photo frames
- Optional Discord connection: if you connect Discord, we store an OAuth token (encrypted in a cookie) and load the server list you can manage, so the Discord widget can show online members
- Optional AI keys: if you add your own OpenAI, Anthropic, or xAI key for GridBot, we store it encrypted and use it only to run your GridBot requests
- Reports you submit about a shared grid
- Support emails and other communications you send us
Information collected automatically
- Device and browser information
- IP address and approximate location
- Usage and diagnostics (pages or screens used, interactions, performance logs)
Billing and subscription data
- Subscription status and plan type
- Payment-related metadata processed by Stripe — we do not store full card numbers or other complete payment details
4. How we use your information
- Provide, operate, and maintain GridDash
- Sync your settings across devices and products
- Authenticate users and secure accounts
- Provide customer support
- Process subscriptions and enforce plan features
- Improve performance, reliability, and user experience
- Detect fraud, abuse, or security issues
- Support optional outbound-link features after you allow the Outbound links cookie category
5. Cookies and similar technologies
We use cookies, local storage, and similar technologies to:
- Keep you signed in and run core features
- Store preferences and layouts on your device
- Measure usage when you allow Analytics
- Support optional outbound-link partner scripts when you allow Outbound links
Categories
- Essential — required for the service to function. Always on.
- Analytics — Vercel Analytics, in aggregate, to understand usage and reliability. Optional.
- Outbound links — if you opt in, an optional third-party partner script may load to support link monetization on our pages. No ads on your dashboard. Optional.
Where required by law (including the UK and EEA), we ask before setting non-essential cookies. You can change or withdraw that choice at any time in the cookie banner or Profile → Cookie preferences.
6. Affiliate and outbound links
GridDash has no ads on your dashboard and does not run third-party sponsored ad widgets. We may monetize outbound links — including bookmarks you add to your grid — by appending affiliate parameters, redirecting through an affiliate or partner network, or using similar methods where permitted. Bookmarks appear as normal tiles. When you click supported merchant links, we may receive a commission or other compensation at no additional cost to you unless the merchant says otherwise.
If you allow Outbound links in cookie settings, we may load a third-party partner script on our pages for that purpose. If you turn it off, that script will not load. Other disclosures still apply when you follow links to third-party sites.
When you open outbound links from your grid, affiliate networks or partners may receive technical data such as IP address, device or browser information, and referral or click data, under their own privacy policies.
Paid plans may limit or change monetization-related features as described in your plan. See our Terms of Service for the same disclosure.
7. Browser extension
The GridDash Chrome extension replaces the new tab page and can open GridDash from the toolbar. It redirects to www.griddash.com and requests host access only for griddash.com so it can load our site.
The extension does not collect extra account, browsing, or bookmark data beyond what the GridDash website already processes. Sign-in, cookies, analytics, and outbound-link behavior are the same as using the website directly. The URL bar shows our site after the new tab opens.
8. Third-party services
We use service providers to operate GridDash, including:
- Supabase — authentication, database, and file storage
- Vercel — hosting and optional Analytics
- Stripe — subscription billing and payments
- Cloudflare Turnstile — bot protection on sign-in, sign-up, and reports
- Discord — optional server-roster widget if you connect Discord
- OpenAI, Anthropic, and xAI — GridBot replies (our server key or a key you add)
- TradingView — market widgets and share snapshots you add to a grid
- Logo.dev — site icons for bookmarks
- Placid — optional images for shared-grid link previews
- Resend — email us when a shared grid is reported
- Skimlinks or similar affiliate networks — optional outbound-link script, only if you consent
These providers process data under their own privacy policies. Widget content (for example weather, stocks, or embeds you add) may also be requested from third parties you choose to use.
9. Legal bases for processing (UK / EEA)
Where UK GDPR or EU GDPR applies, we rely on:
- Contract — to provide the service you asked for
- Legitimate interests — to secure, maintain, and improve the platform
- Consent — for optional Analytics and Outbound links cookies, and for optional connections such as Discord or your own AI key
- Legal obligation — where the law requires us to keep or disclose information
10. Data retention
We keep personal data only as long as needed to provide the service, meet legal requirements, resolve disputes, and prevent fraud or abuse. When it is no longer needed, we delete or anonymize it.
You can delete your account from Profile settings. That removes your GridDash account data we control, including grids, uploads, Discord tokens we hold, and stored AI keys, subject to limited records we may need to keep for billing, security, or law — for example an email address recorded so a used Pro trial or free GridBot trial cannot be claimed again. You can also email support@griddash.com with the subject "Privacy Request".
11. Data security
We use appropriate technical and organizational measures, including HTTPS in transit, access controls, and monitoring. No system is completely secure, and we cannot guarantee absolute security.
12. Your rights
Depending on your location (including the UK and EEA), you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time
To exercise these rights, email support@griddash.com with the subject "Privacy Request", or delete your account in Profile settings.
13. Children's privacy
GridDash is not intended for children under 13 (or a higher age where local law requires). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it.
14. International data transfers
Your information may be processed in countries outside your own, including by the providers listed above. Where required, we use appropriate safeguards such as standard contractual clauses.
15. Data controller
For applicable data protection laws, the data controller is the operator of GridDash, based in United Kingdom, reachable at support@griddash.com. GridDash is operated from United Kingdom.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above. Continued use of GridDash after an update means the revised policy applies to that use.
17. Contact us
Privacy questions and data requests: support@griddash.com. See also our Contact page.