Groundcraft legal
Privacy Policy
What we hold, why, where it lives, and what you can ask us to do about it.
In force 12 August 2026 · Version 1.0
Who we are: Mind Hack, Inc., 651 N Broad St Ste 104, Middletown, DE 19709-6401, United States, operating the Groundcraft platform at groundcraft.dev (“Groundcraft,” “we,” “us”).
Effective date: 12 August 2026. Version: 1.0.
This policy explains what personal data we handle, why, where it lives, and what rights you have. We have tried to keep it short and true.
1. Two roles, stated plainly
Groundcraft wears two hats, and your rights differ depending on which applies to you:
- For our customers (the businesses that buy hosting, builds and tooling from us): we decide how account data is handled — we are the controller.
- For visitors to our customers’ sites (e.g., you filled in a contact form on a business site that happens to be hosted by us): that business is the controller of your data. We host and process it on their instructions — we are a processor. Our Data Processing Addendum governs that relationship. If you want your data corrected or deleted from a site we host, the fastest route is the business itself; if you contact us instead, we will pass your request to them and help them honor it.
2. What we collect
Customer account data (we are controller):
- Name and email address (account identity, via Firebase Authentication).
- Billing records: plan, invoices, billing address. Card numbers never touch our servers — payment is handled by WooCommerce Payments (Stripe); we hold a payment token reference, not the card.
- Support tickets and the correspondence in them.
- Build intake material you choose to give us: business details, brand preferences, logos, imagery, copy, and anything else you upload.
- Operational logs: sign-ins, admin actions, service events — the record needed to run and secure a hosting platform.
Customer site content (we are processor for the parts about other people):
- Everything that makes up a hosted site: pages, media, databases, backups.
- Lead-form and similar submissions captured on customers’ sites. This is the clearest processor case: a visitor’s name, email, or message submitted to a customer’s form belongs to that customer’s relationship with their visitor.
What we do not collect: we do not buy data about you, we do not run third-party advertising trackers on groundcraft.dev, and we do not sell or share personal information for cross-context behavioral advertising as those terms are defined in the CCPA/CPRA.
3. Why we use it
- To provide the service: host sites, build sites, run backups, authenticate you, deliver the features your plan includes.
- To bill you and keep the records the law requires.
- To communicate operationally: invoices, renewal and dunning notices, incident and maintenance notices, support replies. Operational email is sent through Mailee, our own email platform (see §5).
- To secure the platform: abuse detection, incident investigation, logs.
- Product features you invoke: if you enable a feature that calls an external API (e.g., Google Business Profile for reviews, Google/DataForSEO data for SEO tooling, Places data for Prospector), we send that provider only what the feature needs to work.
We do not use your site content or your visitors’ form submissions to train AI models.
4. Legal bases (for readers in the EU/UK)
Where GDPR-style law applies: performance of contract (running your account, hosting and building), legitimate interests (security, service communication, defending claims), legal obligation (tax and accounting records), and consent where we ask for it specifically. As processor for customer sites, our legal basis is our customer’s instructions under the DPA.
5. Processors and subprocessors
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Stripe (via WooCommerce Payments) | Payment processing, card storage, subscription charges | Card details (held by Stripe only), billing name/email, transaction records | US |
| Google Cloud Platform / Firebase | Platform hub hosting, Firebase Authentication (identity), backup storage | Account identity (name, email, auth records), platform data, site backups | US |
| Contabo GmbH | Physical hosting servers for customer sites | Site content, databases, form submissions — everything a hosted site contains | Germany (EU) |
| Google APIs (Business Profile, Search Console, Places) | Feature data, only when a customer enables the relevant feature | Business listing data, search performance data, place data for the customer’s own business | US |
| DataForSEO | SEO/rank data for growth tooling, when enabled | Keywords, domains, ranking data (typically not personal data) | US/EU |
Mailee is not a third party. It is our own email platform, built and operated by Mind Hack, Inc. on our own infrastructure. Mail we send you goes from our servers to yours; no outside email vendor sits in between. If that ever changes, this table gains a row and customers on a DPA get the notice period it promises.
We will update this table when subprocessors change; customers with a DPA receive advance notice of changes as described there.
6. Where data lives — international transfers, honestly
Our architecture spans two regions, and we would rather say so plainly than bury it:
- Customer site content lives in the EU: the hosting servers are Contabo machines in Germany. A form submitted by an EU visitor to a site we host is stored in the EU.
- The platform hub lives in the US: account identity (Firebase Auth), billing, support, backups in Google Cloud Storage, and platform operations run on Google Cloud in the United States. Operating the platform therefore involves transfers of account data — and of site data when platform features touch it (backups, tooling) — to the US.
For transfers of EU/UK personal data to the US we rely on the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), with the UK Addendum where applicable, incorporated into our DPA, together with whatever additional safeguards each provider offers under its own data-processing terms. Each provider above publishes its current transfer mechanism and certifications; we link to our own commitments rather than restating theirs, because theirs can change without us knowing.
7. Retention
| Data | Kept for |
|---|---|
| Site content and backups | Life of the subscription + the 30-day post-termination window in Terms §11, then deleted |
| Account identity | Life of the account + the same 30-day window |
| Build intake material (logos, imagery, copy you upload) | Life of the account + the same 30-day window |
| Invoices and tax records | As required by US tax law (typically 7 years) |
| Support tickets | 24 months after closure |
| Operational/security logs | 12 months |
| Dunning/suspension records | With the billing record |
8. Your rights
Everyone: you can ask us what we hold about you, ask for corrections, and ask for deletion of what we are not legally required to keep. Write to the privacy contact below; we will respond within the time the applicable law requires (and aim for much faster).
California residents (CCPA/CPRA baseline): you have the rights to know, delete, correct, and to opt out of sale/sharing. As stated in §2, we do not sell personal information or share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights.
EU/UK residents: you have GDPR-style rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. If your data was collected by a site we merely host, those rights run against the site owner (the controller); we will forward your request to them and assist — that is the practical, honest answer, and it is also what the law expects of a processor.
Our customers can export their site content at any time (Terms §11) and can serve their own visitors’ rights requests using their site’s admin tools; where they need our help (e.g., purging backups), the DPA obliges us to assist.
9. Cookies — minimal
groundcraft.dev and the customer portal use only the cookies needed to sign you in and keep your session working (Firebase Auth session state), to keep a shopping cart and checkout working (WooCommerce), and, during payment, the cookies Stripe’s payment element requires for fraud prevention.
We run no analytics and no advertising or tracking cookies on our own properties — not Google Analytics, not a third-party alternative, not a first-party one. What we know about traffic, we know from server logs. If we ever add analytics, this section will name the tool and what it records before we turn it on.
Sites our customers run may set their own cookies — that is the site owner’s responsibility as controller.
10. Security
Card data is isolated to Stripe by design. Access to production systems is key-based (no passwords over SSH) and limited to people who operate the platform. Backups are taken nightly (hourly on higher plans) and stored in Google Cloud Storage. If a breach affects your personal data, we will notify you and, where we act as processor, notify the affected customer within the time the DPA requires.
11. Children
Groundcraft is a business service and is not directed at children under 13. We do not knowingly collect children’s data; if you believe we hold some, contact us and we will delete it.
12. Changes
We will post changes here with a new effective date and version number, and email account holders about material changes before they take effect.
13. Contact
Mind Hack, Inc. 651 N Broad St Ste 104, Middletown, DE 19709-6401, United States Privacy contact: hello@groundcraft.dev · (240) 573-1425
Privacy requests reach a person, not a queue. Put “privacy” in the subject line and we will treat it as a rights request from the moment it arrives.