← SnagGrid

Privacy notice

How this SnagGrid instance handles personal data, consistent with applicable data-protection laws — including the GDPR (EU/UK), the California Consumer Privacy Act (CCPA) and Canada's PIPEDA, each where it applies to you.

Who is responsible for your data

Each SnagGrid instance is operated by the organization group that set it up — the data controller is that group, represented by its SnagGrid administrator. For questions about your data, or to exercise any of the rights below, contact the administrator who invited you, or use the contact details in the emails this instance sends.

What we hold and why

Account data — your name, email address, site, report delivery addresses, signature, and a securely hashed password (we can never read your password). If you enable two-factor authentication, a secret used only to verify your codes. Held to operate your account.

Report data — the photographs, locations, addresses, descriptions and generated emails of issues you report. Photographs of public places may incidentally capture people or vehicles; reports are sent to the relevant recipient as part of a team member's casework, which is the lawful basis for this processing (legitimate interests / performance of a task in the public interest).

Public reports — if you report an issue without an account, we use the name, email, location and photos you provide to handle the report, pass it to the right team and reply to you. You can optionally create an account to track it.

Contacts — when a report is handled, we may keep a contact record (your name and email) so theorganization can group your issues together and follow them through.

Activity records — an audit log of sign-ins and significant actions (reports created, emails sent, settings changed), kept for security and accountability. Follow-up reminders you set are stored until done.

Who processes data on our behalf

To do its job, SnagGrid shares specific data with these processors:

  • OpenAI— report text and (only when you tap the describe button) photographs are sent to OpenAI's API to draft and improve report wording. OpenAI states API data is not used to train its models.
  • Resend — delivers the emails this instance sends (reports, invitations, password resets, reminders).
  • OpenStreetMap / Nominatim — map tiles, and coordinates sent for address lookup when you set a report location. No name or account data is included.
  • Cloudflare— when a workspace turns on onward relay, replies to a report are routed through Cloudflare's email service so the conversation can be passed between you and the organisation. The content of those replies (including any attachments) is kept on the case as a record.

OpenAI and Resend are US providers, and Cloudflare operates globally; data they process may be handled outside the UK. Report and account data itself is stored on this instance's own server.

How long we keep things

Reports stay until a team member archives them or an administrator deletes them — deletion permanently removes the report, its photographs and its reminders. Accounts persist until removed by an administrator. Server backups are retained for 14 days. Expired invitation and password-reset links are purged automatically.

Cookies

SnagGrid sets one essential cookie: an encrypted session token that keeps you signed in (7 days). There is no advertising, analytics or tracking of any kind. Your light/dark theme choice is stored on your own device.

Your rights

You can ask for access to, correction of, or deletion of your personal data, and you can object to or ask us to restrict processing. California residents have additional rights under the CCPA (including the right to know and to delete, and not to be discriminated against for exercising them); Canadian residents have rights under PIPEDA; and the GDPR applies where you are in the EU/UK. You can download a copy of your data at any time from My Account → Your data, and reporters can delete their account and reports from My Account. For anything else, contact your instance administrator.

Security

All traffic is encrypted (HTTPS). Passwords are hashed with bcrypt, uploaded photographs are stored privately and served only to signed-in users, optional two-factor authentication is available to every account, and administrative actions are audit-logged.