Privacy Policy
Last updated: May 7, 2026
This Privacy Policy explains how Gripp ("Gripp," "we," "us," or "our") collects, uses, shares, and protects information when you use our website at gripp.run, our web and mobile applications, and any related APIs or integrations (collectively, the "Service"). By using the Service, you agree to the practices described below.
1. Information We Collect
1.1 Information you provide
- Account information: name, email, password (hashed), phone number (optional), organization name, role, and profile settings.
- Procurement content: purchase requests, purchase orders, invoices, contracts, vendor records, quotes, shipments, and related messages and attachments.
- Billing information: when you subscribe to a paid plan, our payment processor (Stripe) collects payment details. We receive limited billing metadata (last four digits, card brand, status); we do not store full card numbers.
- Communications: support requests, feedback, and messages you send us.
1.2 Information from integrations
When you connect a third-party service to Gripp, we receive data from that service in accordance with the permissions you grant. Examples include:
| Integration | Data we receive |
|---|---|
| Slack | workspace ID, user ID/email, slash command and message content, channel metadata |
| WhatsApp (Meta) | phone number, message content, delivery receipts |
| Email (inbound forwarding) | sender, recipient, subject, body, attachments of forwarded messages |
| X (Twitter) | X user ID, handle, profile metadata, and any content you direct Gripp to read or post on your behalf |
| ERP (QuickBooks, SAP, Oracle, NetSuite) | vendor records, GL accounts, purchase orders, invoices, and other procurement objects you choose to sync |
| Bill.com / Stripe | payment status, invoice IDs, subscription state |
1.3 Information collected automatically
- Usage data: pages viewed, features used, request timestamps, referring URLs, and interactions with the Service.
- Device and log data: IP address, browser type, operating system, device identifiers, and crash logs.
- Cookies and similar technologies: session cookies, preference cookies, and analytics cookies (Vercel Analytics, Vercel Speed Insights). You can manage cookie preferences in your browser.
2. How We Use Information
- To provide, maintain, and improve the Service;
- To run AI parsing, vendor matching, three-way matching, and other features you request;
- To authenticate users, prevent fraud, enforce our Terms, and secure the Service;
- To process payments, manage subscriptions, and send billing-related communications;
- To send transactional messages (approval emails, status updates, notifications) and, with your consent, marketing communications;
- To analyze usage and improve performance and reliability;
- To comply with legal obligations and enforce our rights.
3. AI and Automated Processing
We use machine learning models, including models provided by Anthropic and other third parties, to parse free-text procurement requests, classify line items, suggest vendors, match invoices to purchase orders, and power conversational features. Customer Data sent to these providers is processed solely to deliver the Service and is not used to train Gripp's or our providers' general-purpose models, except as permitted by your account configuration or required to operate the feature you requested.
4. How We Share Information
- With members of your organization: Customer Data is accessible to other authorized users in your workspace based on their role.
- Service providers: we share information with vendors who process data on our behalf — including Supabase (database and auth), Railway and Vercel (hosting), Resend (email delivery), Stripe (payments), Anthropic (AI), Slack and Meta/WhatsApp (messaging), and analytics providers. These providers are contractually bound to use data only as needed to provide their services.
- Integration partners: when you enable an integration, we share data with the connected provider (for example, posting on X or syncing invoices to QuickBooks) as you direct.
- Legal and safety: we may disclose information when required by law, to enforce our Terms, or to protect the rights, property, or safety of Gripp, our users, or the public.
- Business transfers: if Gripp is involved in a merger, acquisition, or asset sale, information may be transferred to the successor entity, subject to this Policy.
We do not sell personal information.
5. X (Twitter) Data
If you connect Gripp to your X account, we receive and store the data described in section 1.2 to deliver the integration features you request. We use this data only for the integration purposes you authorize, and we handle it in accordance with the X Terms of Service and X Developer Agreement and Policy. You can disconnect the integration at any time from your Gripp account settings or your X account's connected apps page; on disconnect, we delete tokens and stop accessing your X data.
6. Data Retention
We retain Customer Data for as long as your account is active and as needed to provide the Service. After account closure, we retain data for up to 90 days for backup, audit, and legal purposes, then delete or anonymize it, except where longer retention is required by law (for example, financial records). You can request earlier deletion as described below.
7. Security
We use technical and organizational safeguards to protect your data, including TLS encryption in transit, encryption at rest for sensitive fields, hashed passwords, scoped access controls, two-factor authentication, audit logging, and secrets management. No system is 100% secure; if we learn of a security incident affecting your information, we will notify you in accordance with applicable law.
8. International Transfers
Gripp is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other jurisdictions where our service providers operate. We use appropriate safeguards (such as Standard Contractual Clauses) where required by law.
9. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, email privacy@gripp.run from the address associated with your account. We will respond within the timeframe required by applicable law.
You can also manage many settings directly in the Service, including updating your profile, disconnecting integrations, exporting data, and deleting your account.
10. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or through the Service) before the changes take effect. The "Last updated" date at the top reflects the most recent revision.
12. Contact Us
Questions about this Privacy Policy or your data? Email privacy@gripp.run or hello@gripp.run.