GRIT BOARD
Games How it works Playbook Open app ↗
See pricing
⚠ DRAFT SCAFFOLD — structure only, not legal copy. Replace each section with generator output (Termly / iubenda) and have it reviewed before launch.
LEGAL · PRIVACY

Privacy Policy

LAST UPDATED · [DATE]

How we handle your account information and the sales-rep performance data you upload to Grit Board. This page is a working scaffold — final copy is pending.

01 · Overview & scope02 · Data we collect03 · Controller vs. processor04 · How we use data05 · Legal bases06 · Sub-processors07 · Data retention08 · Disclosure & sharing09 · Security10 · International transfers11 · Your rights12 · Children's data13 · Changes to this policy14 · Contact

01Overview & scope

[ Who Grit Board is, what this policy covers, and the distinction between data about our customers (managers) and the sales-rep data they upload. ]

02Data we collect

[ Account data (manager name, email, org). Uploaded roster data — sales-rep names, teams, activity metrics (dials/convos/meetings/deals), pipeline, quota. Usage/log data. ]

03Controller vs. processor

[ For uploaded rep data, the customer is the data controller and Grit Board is the processor acting on their instructions. Clarify each party’s responsibilities. ]

04How we use data

[ To provide the boards/games, authenticate managers, operate and improve the service. State what we do NOT do (e.g. no selling of data). ]

05Legal bases

[ If serving EU/UK/LATAM users: lawful bases for processing (contract, legitimate interest, consent) per GDPR/LGPD as applicable. ]

06Sub-processors

[ Third parties that process data on our behalf — e.g. Supabase (database + auth), hosting provider, email/SMTP provider. Link to a maintained sub-processor list. ]

07Data retention

[ How long account and uploaded season data is kept, and what happens on account deletion or cancellation. ]

08Disclosure & sharing

[ When data may be disclosed (legal requirements, service providers, business transfers). Reaffirm no sale of personal data. ]

09Security

[ Technical and organizational measures (encryption in transit, access scoping per org, etc.). Avoid over-promising. ]

10International transfers

[ Data is stored in the US (Supabase us-east-2). Mechanisms for cross-border transfer if serving non-US users (SCCs etc.). ]

11Your rights

[ Access, correction, deletion, portability, objection — and how managers exercise them, plus how rep-data subject requests are routed to the customer (controller). ]

12Children's data

[ Service is not directed to children; not knowingly collecting their data. ]

13Changes to this policy

[ How we notify of updates and how the “last updated” date works. ]

14Contact

[ How to reach us with privacy questions — email and (if required) a postal address / data-protection contact. ]

GRIT BOARD
Open app Playbook Privacy Terms hello@gritboard.io

© 2026 Grit Board · Season 01