This Privacy Policy describes how GGR Data LLC ("GGR Data," "we," "us") collects, uses, and shares personal information when you visit ggrdata.com, use the GGR Data terminal at dashboard.ggrdata.com, or communicate with us (together, the "Service").
GGR Data is a business-to-business data service directed to professional users in the United States. It is not directed to children and is not intended for persons under 18.
1. Information We Collect
Information you provide:
- Account and contact information — your name, work email address, and organization, provided when you request access, accept an invitation, or correspond with us.
- Credentials — a password you set. We do not store plaintext passwords; credentials are stored in hashed form by our authentication provider (Supabase).
- Billing information — billing contact details for paid subscriptions. Invoices are currently paid by ACH or wire transfer; we retain billing contact and remittance records but do not collect or store payment-card numbers. If we add card payments, they will be processed by a payment provider we will name here.
- Communications — the contents of emails, feedback, and data-issue reports you send us.
Prospective-customer information. For business-development outreach we maintain contact information about prospective professional users (name, firm, work email, and role) obtained from public and professional sources or provided to us directly. We use it only for B2B outreach about the Service, and we honor opt-outs as described in Section 6.
Information collected automatically when you use the Service:
- Log and usage data — IP address, browser type and version, device information, pages and API endpoints requested, timestamps, and referring pages. Standard server and security logs are generated by our hosting and network-security providers, and we also log account activity in the Service (such as sign-ins, queries, and exports) for security, support, and capacity purposes.
- Authentication session data — a session token stored in your browser's local storage to keep you signed in (see Section 5).
- Email delivery data — delivery, bounce, and open events for the transactional emails we send (such as invitations and password resets).
We do not collect precise geolocation, biometric information, or any special categories of personal information, and we do not use third-party advertising trackers.
2. How We Use Information
We use personal information to:
- provision, authenticate, secure, and operate the Service;
- send transactional messages (invitations, password resets, receipts, and service or security notices);
- respond to inquiries and provide support;
- bill and collect fees;
- monitor usage, debug, and improve the Service;
- protect against unauthorized access, abuse, scraping, and fraud;
- comply with law and enforce our agreements; and
- with your consent or as you otherwise direct, send occasional product updates. Every marketing message includes an unsubscribe mechanism, and we honor opt-outs promptly (see Section 6).
3. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only with:
Service providers (subprocessors) that host and operate the Service on our behalf, under agreements limiting their use of the data:
| Provider | Function | Data handled | Location |
|---|---|---|---|
| Supabase | Authentication and database hosting | Email, hashed password, account records | United States |
| Fly.io | Application hosting | Server logs (IP, requests) | United States |
| Cloudflare | DNS, content delivery, and security | IP address, request metadata | United States (global network) |
| Resend | Transactional email delivery | Email address, delivery events | United States |
| Netlify | Marketing-site hosting (ggrdata.com) | Server logs (IP, requests) | United States |
Professional advisers (lawyers, accountants) under duties of confidentiality; legal and safety recipients where disclosure is required by law, subpoena, or to protect rights, safety, or the integrity of the Service; and a successor entity in connection with a merger, financing, or sale of assets, in which case this Policy will continue to apply until amended.
4. Retention
We retain account information for as long as your account is active and for a reasonable period afterward as needed for legal, accounting, and security purposes. Server and security logs are retained on rolling schedules set by our hosting providers. You may request deletion as described in Section 6.
5. Cookies, Local Storage, and "Do Not Track"
The Service does not use advertising cookies or cross-site tracking. The dashboard stores an authentication session token in your browser's local storage strictly to keep you signed in; deleting it signs you out. Our infrastructure providers (e.g., Cloudflare) may set strictly necessary cookies for security purposes.
Because we do not track users across third-party websites or services, and do not permit third parties to collect personal information about your online activities over time and across different websites through the Service, the Service does not respond differently to browser "Do Not Track" signals.
6. Your Choices and Rights
- Access, correction, deletion. You may request a copy of, correction of, or deletion of your personal information by emailing [privacy@ggrdata.com]. We will respond within a reasonable time and honor the request except where retention is required for legal, security, or billing purposes. If your access is provisioned through your employer's subscription, we may route the request through your employer.
- Marketing opt-out. You may opt out of non-transactional email at any time via the unsubscribe link in the message or by emailing us. Opt-outs are honored within 10 business days. Transactional messages (password resets, invoices, security notices) are sent as needed to operate the Service.
- California. GGR Data does not currently meet the thresholds that make the California Consumer Privacy Act applicable to a business. We nevertheless will review and respond in good faith to verifiable privacy requests from California residents consistent with the choices above.
7. Security
We use commercially reasonable technical and organizational safeguards that include, as appropriate, TLS encryption in transit, hashed credential storage, database access controls, and invitation-only account provisioning. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
8. United States Only
The Service is operated from the United States and directed to users in the United States. If you access the Service from elsewhere, you understand your information will be processed in the United States. The Service is not directed to persons in the European Economic Area or the United Kingdom, and we make no representation of compliance with the GDPR or UK GDPR.
9. Changes to This Policy
We may update this Policy from time to time. We will post the revised version with a new effective date and, for material changes, notify account holders by email or in-Service notice before the changes take effect.
10. Contact
GGR Data LLC
[MAILING ADDRESS]
[privacy@ggrdata.com]