Privacy Notice
Effective date: 2026-05-17 · Last updated: 2026-09-11
1. Who we are
MintGrid (operated by The MintGrid, Inc.) provides a multi-tenant SaaS platform for land-surveying firms. Our customers (the surveying firms) are the data controllers; MintGrid acts as a data processor on their behalf for the operational data they bring into the platform. We are an independent controller for the limited workforce and account data we collect about our customers' staff who use MintGrid.
Contact for privacy questions: info@themintgrid.com.
2. What information we collect
- Account identity — name, email, role, organization membership (workforce + client_admin accounts).
- Authentication metadata — login timestamps, IP addresses (for security), MFA enrollment state.
- Project and operational data uploaded by our customers — property addresses, parcel coordinates, deed search results, project documents, field notes, timesheet entries. Some of this data may relate to identifiable property owners or third parties; MintGrid handles it on behalf of the customer.
- Usage telemetry — error reports (via Sentry, with PII scrubbing), aggregated feature usage metrics.
3. Why we use it (lawful basis)
- Provide the service — performance of contract (GDPR Art. 6(1)(b)).
- Security and fraud prevention — legitimate interest (GDPR Art. 6(1)(f)).
- Legal and professional record-keeping — legal obligation (GDPR Art. 6(1)(c)) — surveying records may be retained for up to 7 years to satisfy state professional requirements.
- Optional marketing communications — consent (GDPR Art. 6(1)(a)), which you may withdraw at any time.
4. Who we share it with
We use a small set of vetted sub-processors to operate the service. The current list is maintained at /sub-processors. We notify customer admins at least 30 days before adding a new sub-processor that handles personal data.
We do not sell personal information. We do not share personal information with advertisers.
5. How long we keep it
We keep data only as long as needed for the purpose it was collected for, or as required by contract or law. Summary of our internal retention schedule:
- Account profiles — while account is active + up to 30 days after offboarding.
- Project records and documents — up to 7 years (professional record-keeping).
- Deed search results — 90 days (customer-configurable); enforced by an automated daily cleanup.
- Audit logs — target 2 years. The automated cleanup that enforces this cap is scheduled but not yet built; logs are retained (not auto-deleted) until it ships.
- Database backups — 7 days (managed by Supabase).
6. How we protect it
TLS 1.2+ in transit; encryption at rest via Supabase; multi-factor authentication via email-OTP; multi-tenant isolation enforced at the data layer (RLS); centralized server-side authorization; CI-time dependency and secret scanning; production error monitoring with PII scrubbing.
7. Your rights
Subject to applicable law (GDPR / CCPA / CPRA / other), you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Request deletion ("right to be forgotten").
- Receive a portable copy of your data.
- Object to processing or restrict processing.
- Withdraw consent for processing based on consent.
- Lodge a complaint with a supervisory authority (e.g., your national Data Protection Authority in the EU/UK; the California Attorney General).
To exercise any of these rights, email info@themintgrid.com from the address associated with your account. We respond within 30 days (extendable to 60 days for complex requests, with notice).
8. International transfers
Our infrastructure is hosted in the United States (Supabase and Vercel). If we process personal data of users in regions with cross-border restrictions (e.g., EU/UK), we rely on Standard Contractual Clauses or equivalent safeguards with our sub-processors. When the first EU customer signs, we will publish a transfer impact assessment.
9. Cookies and similar technologies
We use a small number of strictly necessary cookies for authentication and session management. We do not use cross-site tracking cookies or advertising cookies.
10. Children's data
MintGrid is not directed at, and we do not knowingly collect personal information from, individuals under 13.
11. Changes to this notice
We update this notice as our practices evolve. Material changes will be communicated to account admins by email and posted here with an updated "Last updated" date. The current version is always at /privacy.
12. How to contact us
Email: info@themintgrid.com
Subject prefix: [privacy]
13. The Deed Companion browser extension
The Deed Companion fetches the deeds, plans and search results you ask for, from this browser, under your name, for your firm.
- What it can open — It can only open the registry sites listed below, and only while it is running a fetch you requested. The list is shown in MintGrid before you connect, and again in the extension's own popup.
- What it never does — It never reads passwords or anything you type.
- What it never does — It only checks whether you are on a registry site, so it can pause; it never records or sends where you browse.
- What it never does — It never runs work for anyone else, only what you request.
- What it never does — It never runs while you have paused it.
- What it stores on your computer — a device credential for your MintGrid account (revocable from Settings → Paired browsers), the address of your MintGrid workspace, a short list of recent fetches for its popup, and its own working state (the current fetch, pause, and which registry sites it may open). When you pair, it sends a coarse platform name (such as “Linux x86_64”) to label this computer in Paired browsers; on Firefox that follows the same optional data setting as below. Each request for work carries the version of the extension's recipe interpreter, so MintGrid never sends it a registry recipe it cannot run. Each report of how a fetch ended carries that version and the version of the recipe it ran.
- If a fetch fails — If a fetch fails, a short excerpt of the registry page and the reason are sent to MintGrid so the registry recipe can be repaired. On Firefox you can turn this off under the add-on's Permissions and data.
- Filing a page — When you file a registry page into a project, it sends which registry site the page is on and the book and page you chose, never the page's full address.
- Where documents go — a fetched deed or plan is sent only to your firm's MintGrid workspace, where it is recorded under your name as an uncertified registry copy.
- Tracking — the extension contains no analytics and no third-party code.
- Removing it — Pause or disconnect it any time from the companion icon, or revoke this computer under Settings → Paired browsers.
This notice is provided in good faith. It is not legal advice. Customers (surveying firms) who use MintGrid to process data about identifiable individuals remain responsible for their own privacy notices to those individuals.