LEGAL
Privacy Policy
Effective: July 15, 2026
1. What we collect
- Work requests & inquiries: name, email, phone, company, website, and the requirements you describe.
- Portal accounts (invite-only): your profile (name, email, company, phone), intake submissions, messages, consultation requests, uploaded documents, and contract signature records (timestamp, network address, browser identifier, document fingerprint).
- Authentication: handled by Google Firebase Authentication (Google sign-in or email/password). We never see or store your password.
2. How we use it
To evaluate and respond to your request, deliver engagements, operate the portal (messaging, scheduling, e-signature), send transactional email about your account and requests, and keep an auditable history of the engagement. We do not sell personal data and we do not send marketing email.
3. Where it lives
Data is stored on Google Cloud Platform (us-central1): PostgreSQL (Cloud SQL) for structured data and Cloud Storage for uploaded documents. Transactional email is delivered via Resend. Access is restricted to GrandLine staff who need it for the engagement.
4. Cookies
The portal uses a single httpOnly session cookie (__session) strictly for authentication. The public site sets no tracking cookies and runs no third-party analytics.
5. Retention
Work requests and engagement records are retained while relevant to an active or prospective business relationship, and as required for legal and accounting purposes. Signed contracts and their audit records are retained for the legally required period.
6. Your rights
You can request a copy, correction, or deletion of your personal data (subject to legal retention duties) by emailing hello@grandline.solutions. We respond within 30 days.
7. Changes
Updates to this policy will be posted here with a new effective date.