Privacy notice
How Grain Manager handles your data.
Plain-English privacy notice covering what's collected, why, and your rights under the UK GDPR. The legal counterpart sits in the terms.
Last updated: May 2026 — Draft v0.3
Who we are
Grain Manager is operated by James Mugleston, a sole trader based in Stapleford Abbotts, Essex, England. Contact: sales@grainmanager.uk. A registered company may take over operation before public release; this notice will be updated at that point.
What we collect
Two broad categories:
Account information
- Your name, email address and (optionally) farm name and address.
- Authentication details — hashed password, session tokens, two-factor settings.
- Basic usage logs — login times, IP, browser — kept for security purposes.
Farm records you enter
- Stores, bins, capacities, hygiene and treatment records.
- Crop lots — variety, harvest year, weights, quality samples.
- Contracts — counterparty, tonnage, price, spec, movement windows.
- Passports and movement records, including counterparty contact details you provide.
- Files you upload — assurance certificates, invoices, statements, photos.
Why we collect it
- To provide the service to you. The records above are what the product manages on your behalf — this is the lawful basis (contract).
- To keep the service secure. Usage logs are kept to investigate suspicious activity and protect accounts (legitimate interests).
- To support you. When you email us, we keep the conversation for as long as needed to help you.
What we do not do
- We do not sell your data.
- We do not share your records with merchants, traders or third parties without your action (e.g. sending a passport).
- We do not use your data to train AI or other models.
- We do not run advertising trackers across the site or product.
Who processes data on our behalf
We use a small number of well-known sub-processors:
- Render — application and database hosting (UK / EU regions).
- Neon / managed Postgres — database service.
- Cloudflare R2 — encrypted file storage.
- Resend — transactional email (account, passport delivery).
- Google Workspace — business email for sales@grainmanager.uk.
Each is bound by appropriate data processing terms.
Where data is stored
Personal data is stored in the UK and/or EEA. Transfers outside the UK/EEA (for example, to a US-based sub-processor like Cloudflare or Resend) are governed by appropriate safeguards such as Standard Contractual Clauses or the UK Data Bridge mechanism.
How long we keep it
- Account information: while your account is active, plus up to 12 months after closure for legal and tax purposes.
- Farm records: while your account is active. After closure, deleted within 90 days unless you ask for a longer export window.
- Backups: rolling 30-day window. Data in backups is overwritten on the same schedule.
- Security logs: 12 months.
Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you.
- Correct anything that's wrong.
- Ask for deletion ("right to erasure"), subject to legal retention.
- Receive a portable export of your records (CSV).
- Object to or restrict processing in certain situations.
- Complain to the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these, email sales@grainmanager.uk.
Cookies and similar technologies
Grain Manager uses strictly necessary cookies for authentication and a small amount of anonymous, privacy-respecting usage analytics to understand how the product is being used. No third-party advertising cookies are set.
Changes to this notice
We'll update this notice when the product or our processors change. Material changes will be flagged by email to active users.