Last updated 7 October 2026

Privacy Policy

This policy describes data BizzGrid stores when you use the website and the signed-in workspace. It is written for the product as shipped, not for features that are not built.

Who is responsible

The operator of this deployment is the controller of account and workspace data. If you add your own customers into BizzGrid, you are responsible for having a lawful reason to store their names, phones, and notes.

Data we store

  • Account: name, email, password hash, email verification time, session tokens.
  • Workspace: business profile (name, category, contact, location, hours, social links), onboarding status, plan and trial fields.
  • Operational records you enter: customers, services, bookings, website drafts and published snapshots, notifications, assistant conversations, uploaded images.
  • Technical logs: audit actions, request ids, and system errors visible to the platform operator.

Processors that may see data

  • PostgreSQL on the operator’s host — system of record.
  • The configured email provider (Resend or Twilio SendGrid) — verification, password reset, and notification email, only when that provider is connected.
  • WhatsApp — when a business number is connected, for messages the business chooses to send.
  • OpenAI — if connected, for assistant chat and website copy drafts. Prompts can include the business name, category, and city.
  • Cashfree — if connected, for online payment orders.
  • Google Analytics — only when a measurement id is configured and you choose “Allow analytics” on the cookie banner. The measurement id is not an account secret.

If email or the assistant is not connected, those messages are not sent to an outside provider. A Google Maps embed appears only when the business has saved a maps link.

Cookies

Signed-in sessions use necessary httpOnly cookies (bg_access for 15 minutes, bg_refresh for 30 days when you remember the device, or this browser session otherwise). Passwords and one-time codes are not stored in the browser. The operator console uses bg_admin. On HTTPS those cookies are marked secure. Optional analytics is stored only after you allow it. You can choose “Necessary only” and the analytics script is not loaded.

Retention and your choices

You can archive customers and services from the app. There is no self-serve account deletion screen in this version. Contact the operator through the deployment owner to ask for account removal. A platform operator can disable a workspace.

Children

BizzGrid is for business owners. It is not directed at children.

Related: Terms.