Privacy Policy
This policy explains how Gridstate handles personal information. Grayhaven Industries operates Gridstate from Oklahoma City, Oklahoma.
Effective August 31, 2026
Information we collect
- Account information, such as your name, email address, authentication identifiers, and organization membership.
- Billing and subscription metadata. Payment-card details are processed by our payment provider and are not stored by Gridstate.
- API and product activity, including endpoint, timestamp, response status, usage totals, key identifiers, and security events. API-key secrets are stored as one-way hashes after their initial display.
- Information you submit to the service, including search parameters, site coordinates, support requests, and configuration choices.
- Technical information such as IP address, browser type, device information, and cookies required for authentication, security, and service operation.
How we use information
- Provide, secure, maintain, and troubleshoot the Gridstate service.
- Authenticate users, isolate customer accounts, enforce usage limits, and prevent abuse.
- Process subscriptions, measure API usage, and provide customer support.
- Improve product reliability and data quality using aggregated operational signals.
- Comply with law, enforce our agreements, and protect Gridstate, our customers, and the public.
Service providers
Email tyler@grayhavenindustries.com to request our data processing addendum. We will post material changes to this provider list before they take effect when practical.
- Vercel: Public website and customer console hosting. Data: IP address, browser details, and web request metadata.
- Railway: API, worker, and monitor hosting. Data: API request data and service logs.
- Supabase: PostgreSQL, PostGIS, and managed database backups. Data: Account, usage, audit, billing metadata, and published grid data.
- Clerk: Account authentication and session management. Data: Name, email address, account identifier, and session data.
- Stripe: Subscriptions, invoices, and payment processing. Data: Customer, subscription, invoice, and payment details.
- Google Workspace: Customer, privacy, legal, and security email. Data: Message contents and contact details that you send by email.
Other disclosure
We may disclose information when required by law, to investigate fraud or security incidents, during a business transaction, or with your direction. We do not sell personal information or use it for third-party behavioral advertising.
Retention schedule
- Active account data stays in the service while the account remains open.
- A verified account-deletion request disables access at once. Primary account data is removed within 30 days.
- API activity, security audit events, and revoked API-key hashes are retained for no more than 12 months.
- Closed support, privacy, legal, and security requests are retained for no more than 24 months.
- Billing and invoice records can be retained for seven years when tax, accounting, or legal rules require them.
- Backups expire through the provider backup cycle. Gridstate does not restore deleted data except for disaster recovery or legal requirements.
Security and incidents
Gridstate uses access controls, encryption in transit, tenant isolation, audit logs, rate limits, and one-way API-key hashes.
No system can guarantee absolute security. Gridstate will notify affected customers when applicable law requires notice of a security incident.
Gridstate uses Mistral AI to extract public-source documents outside customer request handling. Gridstate does not send customer queries or API keys to Mistral.
Data location
Gridstate operates from the United States. Some providers can process limited data in other countries under their published privacy and transfer terms.
Email tyler@grayhavenindustries.com before purchase if your organization requires a fixed processing region.
Your choices
You can request access, correction, export, or deletion by emailing tyler@grayhavenindustries.com. We will acknowledge a verified request within ten business days.
Gridstate will complete a verified deletion request within 30 days. Legal, billing, fraud, or security requirements can require longer retention.
Changes and contact
We will post policy changes on this page. Send privacy questions and requests to tyler@grayhavenindustries.com.