Privacy Policy
Grandline Studio (“Grandline”, “we”, “us”, or “our”) is committed to protecting the privacy, security, and integrity of personal data collected through our public digital flagships, interactive project scoper, and authenticated client operating systems.
01.Scope & Purpose
This Privacy Policy explains how Grandline Studio collects, uses, processes, stores, and protects personal information when you visit our website (grandline.studio), utilize our interactive Project Scoper, submit inquiries, or log into the Grandline Client Portal.
By accessing our website or engaging our services, you acknowledge that you have read and understood the data practices described in this policy.
02.Categories of Information We Collect
We collect information in three distinct contexts to deliver our engineering and sprint services:
A. Inquiries & Project Scoper Information
When you initiate a project scope or submit a contact request, we collect: full name, business email address, company/brand entity name, existing storefront or brand URL, project budget allocation, target timeline, and custom technical requirements.
B. Authenticated Client Portal Data
When an authorized stakeholder logs into the Grandline Client Portal, we process: user identity credentials (email, hashed authentication records), organizational billing address, tax identification numbers (e.g. GSTIN, VAT ID), sprint task comments, milestone deliverable approvals, and encrypted session security cookies.
C. Technical & Telemetry Information
To ensure edge delivery performance and protect against malicious cyber activity, our edge servers automatically log: IP addresses (anonymized for analytics), browser engine, operating system, page response latency, and referrer URLs.
03.Lawful Bases for Processing (GDPR Compliance)
Under Regulation (EU) 2016/679 (“GDPR”) and UK GDPR, we process personal data under the following recognized legal bases:
- Contractual Performance (Article 6(1)(b)): Processing necessary to fulfill Statements of Work, deliver codebases, invoice milestone payments, and provide client dashboard access.
- Legitimate Interests (Article 6(1)(f)): Processing necessary for infrastructure security, fraud prevention, server uptime telemetry, and direct business communications regarding prospective sprints.
- Legal Compliance (Article 6(1)(c)): Retention of financial invoices, tax compliance filings, and corporate governance records required by law.
- Explicit Consent (Article 6(1)(a)): When you opt-in to non-essential communications or specific media showcase permissions.
04.Sub-Processors & Infrastructure Architecture
We select enterprise-grade infrastructure providers that adhere to rigorous data protection standards (SOC 2 Type II, ISO 27001, and GDPR adequacy):
05.Client Portal Multi-Tenant Cryptographic Isolation
The Grandline Client Operating System implements strict logical and cryptographic tenant isolation:
- All project milestones, tasks, brand vault assets, and invoices are strictly bound to verified Organization IDs.
- Client users are restricted by Row-Level Security (RLS) policies and cannot query, view, or extrapolate data belonging to other client organizations.
- Session cookies are configured with
SameSite=Lax,Secure, and explicit 15-minute inactivity timeouts.
06.Data Retention & Deletion
We retain personal data only as long as necessary to fulfill the purposes for which it was gathered:
- Prospective Scopes & Inquiries: Retained for twelve (12) months following inactivity to facilitate future sprint discussions, after which records are permanently purged.
- Active Client Projects & Deliverables: Maintained for the duration of the engagement plus thirty (30) days for warranty support. Source repositories are transferred to the client upon project sign-off.
- Financial & Invoicing Records: Preserved for seven (7) years in accordance with statutory accounting and tax regulations.
07.Your Legal Rights (GDPR & CCPA / CPRA)
Depending on your jurisdiction, you are entitled to exercise the following rights regarding your personal information:
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete records.
- Right to Erasure (“Right to be Forgotten”): Request permanent deletion of personal data where retention is no longer legally necessary.
- Right to Data Portability: Receive your data in a structured, machine-readable format (JSON/CSV).
- Right to Restrict or Object: Restrict certain processing activities or opt-out of marketing communications.
- California Consumer Rights (CCPA/CPRA): We do not sell or share personal information for cross-context behavioral advertising. You have the right to non-discrimination for exercising these statutory rights.
To exercise any of these rights, email our Data Protection team at grandlinestudio10@gmail.com. We will respond within thirty (30) calendar days.
08.Cookies & Tracking Technologies
We prioritize privacy-first engineering. Our website does not utilize invasive third-party tracking scripts, cross-site spyware, or unsolicited ad trackers. We utilize only essential cookies required for session authentication, security, and theme preferences.
For complete technical details, consult our dedicated Cookie Policy →.
09.International Data Transfers
Grandline Studio operates globally. When personal data is transferred outside the European Economic Area (EEA) or the United Kingdom to our edge computing infrastructure or sub-processors, we ensure appropriate safeguards are enacted, including standard contractual clauses (SCCs) approved by the European Commission.
10.Data Protection Officer & Privacy Inquiries
For privacy-related inquiries, data access requests, or compliance auditing, reach out directly to our Data Protection dispatch: