Grain Manager is in active beta. Built with growers in real harvests. Request early access →

Privacy notice

How Grain Manager handles your data.

Plain-English privacy notice covering what's collected, why, and your rights under the UK GDPR. The legal counterpart sits in the terms.

Draft. This privacy notice is a working draft and will be reviewed by a UK data protection adviser before public launch. It accurately describes current intent. Email sales@grainmanager.uk for the authoritative current version.

Last updated: May 2026 — Draft v0.3

Who we are

Grain Manager is operated by James Mugleston, a sole trader based in Stapleford Abbotts, Essex, England. Contact: sales@grainmanager.uk. A registered company may take over operation before public release; this notice will be updated at that point.

What we collect

Two broad categories:

Account information

  • Your name, email address and (optionally) farm name and address.
  • Authentication details — hashed password, session tokens, two-factor settings.
  • Basic usage logs — login times, IP, browser — kept for security purposes.

Farm records you enter

  • Stores, bins, capacities, hygiene and treatment records.
  • Crop lots — variety, harvest year, weights, quality samples.
  • Contracts — counterparty, tonnage, price, spec, movement windows.
  • Passports and movement records, including counterparty contact details you provide.
  • Files you upload — assurance certificates, invoices, statements, photos.

Why we collect it

  • To provide the service to you. The records above are what the product manages on your behalf — this is the lawful basis (contract).
  • To keep the service secure. Usage logs are kept to investigate suspicious activity and protect accounts (legitimate interests).
  • To support you. When you email us, we keep the conversation for as long as needed to help you.

What we do not do

  • We do not sell your data.
  • We do not share your records with merchants, traders or third parties without your action (e.g. sending a passport).
  • We do not use your data to train AI or other models.
  • We do not run advertising trackers across the site or product.

Who processes data on our behalf

We use a small number of well-known sub-processors:

  • Render — application and database hosting (UK / EU regions).
  • Neon / managed Postgres — database service.
  • Cloudflare R2 — encrypted file storage.
  • Resend — transactional email (account, passport delivery).
  • Google Workspace — business email for sales@grainmanager.uk.

Each is bound by appropriate data processing terms.

Where data is stored

Personal data is stored in the UK and/or EEA. Transfers outside the UK/EEA (for example, to a US-based sub-processor like Cloudflare or Resend) are governed by appropriate safeguards such as Standard Contractual Clauses or the UK Data Bridge mechanism.

How long we keep it

  • Account information: while your account is active, plus up to 12 months after closure for legal and tax purposes.
  • Farm records: while your account is active. After closure, deleted within 90 days unless you ask for a longer export window.
  • Backups: rolling 30-day window. Data in backups is overwritten on the same schedule.
  • Security logs: 12 months.

Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you.
  • Correct anything that's wrong.
  • Ask for deletion ("right to erasure"), subject to legal retention.
  • Receive a portable export of your records (CSV).
  • Object to or restrict processing in certain situations.
  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these, email sales@grainmanager.uk.

Cookies and similar technologies

Grain Manager uses strictly necessary cookies for authentication and a small amount of anonymous, privacy-respecting usage analytics to understand how the product is being used. No third-party advertising cookies are set.

Changes to this notice

We'll update this notice when the product or our processors change. Material changes will be flagged by email to active users.