Privacy Policy
Last updated: March 11, 2026
1. Introduction
SettleGrid ("we," "us," or "our") operates the settlegrid.ai platform and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, SDK, API, and tool showcase (collectively, the "Service"). By using the Service you agree to the practices described below.
2. Information We Collect
We collect the following categories of information:
- Account information — name, email address, and password when you register. Developers also provide Stripe Connect onboarding details (handled by Stripe).
- Billing data — credit purchases, payout history, and transaction records. Payment card details are processed and stored exclusively by Stripe; we never see or store full card numbers.
- Usage data — API call logs, method names, timestamps, latency metrics, error codes, and IP addresses used for rate limiting and security.
- Device and browser data — browser type, operating system, referral URLs, and pages visited, collected automatically through server logs.
- Cookies — session cookies for authentication and CSRF protection. We do not use third-party advertising cookies.
3. How We Use Your Information
- Provide, operate, and maintain the Service.
- Process transactions, calculate payouts, and prevent fraud.
- Enforce rate limits, detect abuse, and protect platform security.
- Generate analytics dashboards and usage reports for your account.
- Send transactional emails (receipts, payout confirmations, security alerts).
- Improve the Service through aggregated, anonymized usage analysis.
- Comply with legal obligations and respond to lawful requests.
4. Information Sharing
We do not sell your personal information. We share data only in these circumstances:
- Service providers — Stripe (payments), Resend (email), Vercel (hosting), and Sentry (error monitoring) receive data necessary to perform their services under contractual data-protection obligations.
- Developer–consumer relationship — when a consumer calls a developer’s tool, the developer receives the consumer’s display name and usage metadata. No email addresses or billing details are shared.
- Legal requirements — we may disclose information when required by law, regulation, or valid legal process.
- Business transfers — in connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Cookies and Tracking
We use strictly necessary cookies for session management and CSRF protection. We use PostHog for product analytics with anonymized identifiers. You can disable analytics cookies in your browser settings without affecting core Service functionality.
6. Data Security
We implement industry-standard security measures including API key hashing (SHA-256), HMAC-signed webhooks, encrypted data in transit (TLS 1.2+), CSRF protection, and role-based access controls. While we strive to protect your information, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
Account data is retained for as long as your account is active. API call logs and usage data are retained for 90 days for analytics and debugging purposes, then aggregated and anonymized. Billing records are retained as required by applicable tax and financial regulations. You may request deletion of your account and associated data at any time by contacting us.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data.
- Correct inaccurate or incomplete information.
- Request deletion of your personal data.
- Object to or restrict certain processing activities.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at privacy@settlegrid.ai.
9. International Transfers
Our Service is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for any international data transfers in accordance with applicable data protection laws.
10. Children
The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy, contact us at privacy@settlegrid.ai.