Effective date: September 30, 2026 · MKC KOREA CO., LTD.
| Item | Purpose | Retention |
|---|---|---|
| Email address | Account creation, service notifications | 30 days after account deletion |
| Name / company name | Service personalization | 30 days after account deletion |
| Payment identifiers (Paddle transaction / subscription ID) | Subscription and credit management, accounting records | 5 years after payment |
| Service usage records (AI usage per action, amount drawn) | Billing, usage display, service quality improvement | 1 year; on a team workspace, records of usage drawn from the team pool are kept with the owner's billing history, with the member identifier removed when the member deletes their account |
| Team activity log (seat, floor and approval events; which team plans and costing sheets a person opened, and when) | Team administration and accountability, shown to the workspace owner and admins | 400 days (visible 30 / 90 / 365 days by plan) |
| Active-session record (session ID, sign-in time, browser user agent) | Security: one active session per account | Until the next sign-in or account deletion |
| Feedback posts and error reports you submit | Product improvement; shown to other users on the Feedback board (tokens and emails masked) | Until you or we delete the post, or account deletion |
| Price history (the reason codes and notes given for each price change and price decision, who gave them and when) | Negotiation record and audit trail for the plan owner; shown to users with access to the plan, and to a factory only for entries it wrote | For as long as the plan owner's account exists; kept if the style is deleted — see section 4 |
| Device info / IP | Security and error analysis | 6 months |
| Contacts you enter about other people (factory department contacts; factory contacts you invite): name, email, department | Sending the orders and invitations you ask us to send | Until you remove them or delete your account; send records (recipient, time, subject) are kept with the order |
| Order approval records (who asked to send an order to departments, who approved it or sent it back, when, and the notes) | Accountability for orders sent to departments; shown to the workspace owner and admins and to the people involved | With the order for as long as it exists; the matching activity-log entry for 400 days |
* Sensitive payment information such as card numbers is handled directly by Paddle and is not stored by the Company.
As a rule, we do not provide users' personal data to third parties. However, we share personal data with the following providers for service operation.
| Provider | Purpose | Items shared |
|---|---|---|
| Supabase Inc. (USA) | Database & authentication | Email, account info |
| Paddle.com (UK) | Payment processing | Payment-related info |
| Resend Inc. (USA) | Email delivery | Recipient addresses and the content of emails sent or received through the Service (order details and attached files, invitations, negotiation messages, replies) |
| Anthropic PBC (USA) | AI analysis (Claude API) | Analysis request data only* |
| OpenAI, L.L.C. (USA) | Text embeddings for reference search | File names, product category, country; if you opted in, anonymized cost-structure patterns* |
| Google LLC (USA) | Google sign-in, optional Google Drive sync | Email, profile name; synced files† |
| Vercel Inc. (USA) | Website hosting | IP address, access logs |
| Railway Corp. (USA) | Application server hosting | IP address, uploaded files, access logs |
| Functional Software, Inc. dba Sentry (USA) | Error monitoring | IP address, account ID, error diagnostics |
* The contents of files you upload (spreadsheets, PDFs, documents, photos) and your chat messages may be sent to Anthropic to run the analysis, and a question you type into AI search in Cost Sheets is sent with the names of your buyers, seasons, categories and materials so it can be turned into a search filter; short search text may be sent to OpenAI to find comparable references. Under both providers' API terms this data is not used for training.
Emails you ask us to send: when you send an order to your departments — and when an order that was sent is later revised, cancelled or reopened — we email the contacts you listed, including the order's attached files. Invitations go to the factory addresses you enter. You are responsible for having their permission to receive these emails.
† Google sign-in and Google Drive sync are optional and off by default. If you connect Drive, costing sheets and related files are copied into a folder in your own Google Drive at your request. On a team workspace, copies of team files go to one team folder in the owner’s Google Drive instead, and that folder is shared view-only with each active seat’s sign-in email through Google (so the owner and other seats can see who it is shared with); access is removed when a seat leaves.
Within a team workspace: if you accept a seat on someone else's Team, Scale or Custom workspace, your usage drawn from the team pool (in US dollars) and your team activity log entries (including which team plans and costing sheets you opened) are shown to that workspace's owner and admins. The team plans, masters and costing archive you work on there are shared with the workspace.
Price history: reasons and notes a factory gives when it submits a new costing version are provided to the buyer who invited it and stored as part of that buyer's data. A factory sees only the entries it wrote itself, never the buyer's entries or another factory's. The name (or, if no name is set, the email) of a buyer-side user who records a reason is shown to other users with access to that plan.
Where a company uses GRAINSIFT through a team workspace, the workspace owner decides who is invited and uses the usage view and activity log to administer the team. For that team data, the Company processes personal data on the workspace owner's behalf. Members may also contact the workspace owner about it. Requests sent to info@grainsift.com are handled and, where needed, coordinated with the workspace owner.
You may exercise the following rights at any time.
To exercise your rights: info@grainsift.com
The Service uses essential cookies and browser storage (local storage) to keep you signed in and secure. This includes the time of your last activity, shared across your open tabs, used to sign you out after 30 minutes without activity, and a session identifier that lets us keep one active session per account. If you arrive from a link with a campaign tag or from another website, the browser keeps where you came from (the tag or that site’s name) and sends it once with your account after you sign in, so we can see which channels bring people. We do not use third-party cookies for advertising or behavioral tracking.
This policy may be revised due to changes in law, policy, or the Service. Any change will be announced by email and in-service notice at least 7 days before its effective date.
Contact: info@grainsift.com · MKC KOREA CO., LTD. · Effective date: September 30, 2026