Privacy policy
Effective 25 September 2026
This policy explains what personal data graspy processes, why, for how long, and what your rights are. It follows the EU General Data Protection Regulation (GDPR).
1. Who is responsible
graspy ("we") is the controller for the data described here. Our company details are on the company details page. Contact: support@graspy.app.
For the data you put in your own workspace about other people (for example the SWAPD usernames of your buyers), you decide what goes in. If you use graspy for your business, we process that data for you as a processor under our data processing terms.
2. What we process
| Data | Why | Legal basis | How long |
|---|---|---|---|
| Email address, sign-up date, account status, last seen | Your account, signing in, approving access | Contract (art. 6(1)(b)) | Until you delete your account. Sign-ups that are never approved: 180 days |
| Acceptance of the Terms (version and time) | Proof of what you agreed to | Legitimate interest (art. 6(1)(f)) | Until you delete your account |
| Your workspace: tickets, counterparties, prices, notes, templates, services, payout addresses, settings | Providing graspy | Contract | Until you delete it or your account |
| Sign-in codes (stored only as a keyed hash) with the email they were sent to | Signing in | Contract | Valid 10 minutes; deleted within the hour |
| Session records (a hash of your session token, times) | Keeping you signed in | Contract | 30 days after sign-in (8 hours for the admin), or until you sign out |
| Security log: IP address, time and type of sign-in and account events | Preventing abuse and investigating incidents | Legitimate interest | 180 days |
| SWAPD link, only if you connect it: your SWAPD username and a read-only access key that SWAPD issues to graspy (stored encrypted). What graspy then reads from SWAPD: your own checkout tickets (title, status, times, the buyer, seller, price and service from the ticket terms), the titles of your messages and who they are with, and new posts in #buyer-requests | Filling your workspace so you do not have to copy it by hand | Contract | The key until you disconnect (in graspy or on SWAPD) or delete your account; what was read stays in your workspace until you delete it |
| Logbook: time, your account, your SWAPD username, IP address, every request graspy made to SWAPD for you (the address and the result, never message content), connects and disconnects, sign-in and account events. Each entry is sealed so it cannot be changed unnoticed | Showing exactly what graspy did and did not do, handling disputes, security | Legitimate interest | 400 days |
| Rate-limit counters (IP address, a hash of the email) | Stopping brute force and email bombing | Legitimate interest | At most 2 days |
| Bot check signals on the sign-in page (Cloudflare Turnstile) | Stopping automated sign-ups | Legitimate interest | Processed by Cloudflare for the check |
| Product news choice and its history (opt-in and opt-out times) | Sending product news only if you asked for it, and proving it | Consent (art. 6(1)(a)) | Until you delete your account |
| Emails you send us | Answering you | Contract or legitimate interest | Up to 2 years after the conversation ends |
Market statistics
Prices shows per-category totals of closed deals on the SWAPD marketplace: a median rounded to $50 and a count for groups of 5 or more, and a typical range only for groups of 20 or more. No names, buyers, sellers or deal list are shown. The underlying deal records are never stored by graspy.
Find a seller shows, for top sellers on SWAPD, their SWAPD username with performance numbers (completed deals, completion rate, median price and delivery time, member-since year). This is SWAPD marketplace data about sellers acting commercially. We show it because buyers have a legitimate interest in finding reliable sellers (art. 6(1)(f)). If you are listed and do not want to be, email support@graspy.app and we remove you from the next update and the current one.
3. Who else processes it
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, network security, bot check | Worldwide network; transfers covered by the EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend | Sending sign-in codes, account emails and, if you opted in, product news | USA; Data Privacy Framework and/or Standard Contractual Clauses |
| Google (Gmail) | Our support mailbox, only for emails you send us | EU and USA; Data Privacy Framework and Standard Contractual Clauses |
When paid plans start we add a payment provider and update this policy before any payment data is processed. We do not sell data, show ads, or use analytics or tracking cookies.
4. Security
Sign-in uses one-time codes instead of passwords. Sessions use a secure, HttpOnly cookie. Workspaces and market statistics are encrypted at rest with AES-256-GCM on top of the provider's encryption. All traffic uses HTTPS. See Security.
5. Your rights
You can ask for access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. You can withdraw consent for product news any time (in Settings or with the link in every email). In graspy you can download all your data and delete your account yourself, in Settings. Or email support@graspy.app; we answer within one month.
You can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or the authority where you live.
6. Other
graspy is for people aged 18 and over. We make no automated decisions with legal or similarly significant effects. Deleted data can remain in the database provider's point-in-time recovery for up to 30 days before it is gone for good. If we change this policy in a way that matters, we email account holders before it takes effect.