Mintgrove

Privacy Policy

Last updated: 2026-07-19

1. Introduction

This Privacy Policy explains how Mintgrove LLC (“Mintgrove,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with the Mintgrove platform.

Mintgrove serves two distinct categories of people, and — as explained in Section 2 — plays a different legal role for each:

  • App Companies— businesses that use the Mintgrove platform to offer enterprise seat licenses to their customers. Mintgrove is the controller of App Company account and billing data.
  • Buyers and Seat Holders— enterprise organizations and their individual employees who purchase or use seat licenses through Mintgrove. Mintgrove is only a processor of this data, acting on the instructions of the App Company that issued the license. If you are a Buyer or Seat Holder, the App Company whose product or service you use is the controller of your data — see Section 2 for how to direct a request to them.

This policy describes all personal data processed by Mintgrove in connection with the platform, regardless of which category you fall into, and is explicit throughout about which role Mintgrove is acting in.

2. Mintgrove's Roles: Controller and Processor

As a controller— for App Company account and billing data (Section 3.1), and for narrow security, fraud-prevention, and platform-integrity purposes that may touch any data on the platform, Mintgrove determines the purposes and means of processing, and this Privacy Policy is Mintgrove's own notice to you about that processing. For the purposes of the UK GDPR and EU GDPR, the data controller is:

Mintgrove LLC
790 Newark Rd, Island Pond, VT 05846
Email: privacy@mintgrove.co

Mintgrove does not currently have an establishment in the European Union or United Kingdom, and does not currently offer goods or services to, or monitor the behavior of, individuals located in the EEA, UK, or Switzerland on more than an occasional, non-targeted basis. Mintgrove has not registered with the UK Information Commissioner's Office and has not appointed an EU or UK representative under Article 27 GDPR / UK GDPR. If Mintgrove begins offering services to EU/UK-based Buyers, Seat Holders, or App Companies on a regular or targeted basis, it will register and appoint the required representative(s) before doing so.

As a processor— for Buyer organization and Seat Holder data (Section 3.2), Mintgrove acts only as a processor on behalf of the App Company that issued the seat license, under the Data Processing Agreement between Mintgrove and that App Company. Mintgrove does not determine the purposes or means of processing this data beyond what is necessary to operate the platform on the App Company's documented instructions. If you are a Buyer or a Seat Holderand have a question or request about how your personal data is used, please contact the App Company whose product or service you use — they are the controller of your data and are responsible for responding to your request. Mintgrove will assist that App Company in responding, as required under the Data Processing Agreement, but cannot act directly on a request from a Buyer or Seat Holder about data it processes only as a processor.

3. Data We Collect

3.1 App Company data

When an App Company registers for and uses Mintgrove, we collect (as controller):

  • Account information: Name, business name, email address, account credentials
  • Business information: Business type, registered address, tax identification number (as required for billing and compliance)
  • Payment information: Billing contact details, payment method information. Note: card details are handled directly by your connected payment processor and are not stored by Mintgrove
  • Connected Billing Account data: Payment processor account identifiers and connection status
  • Integration credentials: API keys for connected integrations (e.g., Adapty) stored in encrypted form
  • Usage data: Platform usage logs, settings configuration, session data
  • Communications: Support tickets, emails, and other communications you send to us

3.2 Buyer and Seat Holder data

When a Buyer organization purchases seat licenses and assigns them to Seat Holders, the following data is processed through Mintgrove on the instructions of the relevant App Company (as processor):

  • Buyer organization data: Organization name, billing contact name and email address, seat license terms (seats purchased, license period)
  • Seat Holder data: Email address, name (where provided), seat assignment status, access grant/revoke history
  • Transaction data: Purchase amounts, dates, payment status (processed through your Connected Billing Account)
  • Magic link authentication data: Email addresses used for Buyer login via magic link

3.3 Technical and usage data

For all users, we may collect:

  • IP addresses and general location data (country/region)
  • Browser type, device type, and operating system
  • Pages visited and features used within the platform
  • Error logs and performance data

4. How We Use Personal Data

4.1 App Company data — purposes and legal basis (Mintgrove as controller)

PurposeData usedLegal basis
Providing the Mintgrove platform and associated servicesAccount, integration, usage dataPerformance of contract
Processing payments and managing billingBilling, payment dataPerformance of contract
Communicating about your account, updates, and supportEmail, contact dataPerformance of contract / Legitimate interests
Complying with legal and regulatory obligationsBusiness, financial dataLegal obligation
Fraud prevention and platform securityAccount, usage, technical dataLegitimate interests
Improving and developing the Mintgrove platformAggregated / anonymized usage dataLegitimate interests
Sending product updates and marketing (with opt-out available)EmailLegitimate interests (or consent where required)

4.2 Buyer and Seat Holder data — processing on the App Company's instructions (Mintgrove as processor)

Mintgrove processes Buyer and Seat Holder data only as a processor, on the instructions of the App Company that issued the license. Those instructions include the ordinary operation of the platform: processing seat license purchases, managing access grants and revocations, sending the transactional communications the App Company has authorized Mintgrove to send on its behalf, authenticating Buyer logins via magic link, and maintaining an audit trail of the above. Mintgrove does not independently determine a separate lawful basis for processing this data — establishing a lawful basis for this data is the App Company's responsibility as controller, consistent with the Data Processing Agreement between Mintgrove and the App Company.

5. How We Share Personal Data

We do not sell personal data. We share personal data only as described below.

With App Companies:When a Buyer or Seat Holder interacts with the platform, their data (including seat assignment status and email address) is visible to the App Company that issued the license, consistent with Mintgrove's role as that App Company's processor (Section 2). App Companies act as independent data controllers with respect to their own Buyers and Seat Holders.

With service providers:We use third-party service providers to help us operate the platform. Depending on their role, these providers act either as Mintgrove's own sub-processors (bound by the Data Processing Agreement between Mintgrove and each App Company) or as the App Company's own independent vendor:

  • Supabase— database and authentication infrastructure (Mintgrove sub-processor)
  • Vercel— cloud hosting and infrastructure (Mintgrove sub-processor)
  • Resend— transactional email delivery (Mintgrove sub-processor)
  • Adapty— in-app access/entitlement sync, only where an App Company has connected this integration (Mintgrove sub-processor)
  • Stripe— bound to Mintgrove under two separate relationships: (1) as a sub-processor, for checkout and transaction metadata Mintgrove processes via your Connected Billing Account on the App Company's instructions; and (2) in an independent relationship for Mintgrove's own Platform Fee billing to App Companies via Stripe Billing, which the App Company is not a party to and which is Mintgrove's own controller relationship with Stripe.
  • Klaviyo— Klaviyo is the App Company's own vendor, not Mintgrove's. Where an App Company connects a Klaviyo integration, Mintgrove forwards data to Klaviyo on the App Company's direct instruction and configuration; Klaviyo is not a Mintgrove sub-processor and does not appear in the Data Processing Agreement's sub-processor list.

Each Mintgrove sub-processor is bound by a data processing agreement no less protective than Mintgrove's own DPA with App Companies, recorded in Mintgrove's internal vendor register. Mintgrove will maintain a public list of its current sub-processors, with change history and a subscription option for update notifications, referenced from the Data Processing Agreement.

For legal reasons: We may disclose personal data if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, the safety of users, or the public.

Business transfers: If Mintgrove is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected parties of any such transfer and any changes to privacy practices.

6. International Data Transfers

Mintgrove is based in the State of Vermont, United States. If you are located in the European Economic Area, UK, or Switzerland, your personal data may be transferred to and processed in countries outside those regions.

Mintgrove's mechanism for these transfers is the European Commission's 2021 Standard Contractual Clauses (Module Two: Controller to Processor), together with the UK Information Commissioner's International Data Transfer Addendum for UK transfers, executed as Exhibit A to the Data Processing Agreement and auto-incorporated at clickwrap acceptance for EEA/UK-based App Companies. Mintgrove does not rely on the EU-U.S. Data Privacy Framework (or its UK/Swiss extensions) as a transfer mechanism, regardless of whether an individual sub-processor separately holds that certification, because DPF's legal durability is currently unsettled following Trump v. Slaughter— SCCs are the more durable mechanism and are used consistently across all sub-processors:

  • Supabase (database and authentication infrastructure), Vercel (application hosting), Stripe (payment processing), Resend (transactional email), and Adapty(in-app access sync, where connected) are each bound, through Mintgrove's data processing agreements with them, to the same Standard Contractual Clauses / UK IDTA framework described above.
  • A lightweight transfer impact assessment accompanies this mechanism; see the Data Processing Agreement, Exhibit A.

This section should be reconfirmed against each sub-processor's current DPA before publication and periodically thereafter.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention works differently depending on Mintgrove's role (Section 2):

  • App Company account and billing data(Mintgrove as controller): the periods below are Mintgrove's own retention policy.
  • Buyer and Seat Holder data(Mintgrove as processor): the periods below are Mintgrove's default retention, applied absent a different documented instruction from the App Company that controls that data. App Companies may specify a different period consistent with their own legal obligations, under the Data Processing Agreement.
Data categoryRetention period
App Company account dataDuration of account + 3 years after closure
Transaction and financial records7 years (tax/legal recordkeeping)
Seat Holder access recordsDuration of active license + 3 years for audit purposes (App Company may instruct otherwise)
Authentication logs (magic link)90 days
Support communications3 years from last contact
Technical/server logs90 days

When data is no longer needed, it is securely deleted or anonymized.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or disclosure. These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Encrypted storage of all API keys and credentials
  • Row-level security policies scoping data access by organization
  • Role-based access controls within the platform
  • PII masking in logs and internal systems (format: a.c***@acme.org)
  • Recurring security review of new features before they ship

These measures are described in full, in their current version-controlled form, in the Data Processing Agreement's Technical and Organizational Measures annex. No method of transmission or storage is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law, consistent with the breach-notification terms in the Data Processing Agreement.

9. Your Rights

If you are located in the European Economic Area, UK, or a jurisdiction with similar data protection laws, you have the following rights with respect to your personal data:

  • Right of access— You can request a copy of the personal data we hold about you.
  • Right to rectification— You can request that we correct inaccurate or incomplete data.
  • Right to erasure— You can request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction— You can request that we restrict processing of your data in certain circumstances.
  • Right to data portability— You can request a copy of your data in a structured, machine-readable format.
  • Right to object— You can object to processing based on legitimate interests, including for direct marketing.
  • Right to withdraw consent— Where processing is based on consent, you can withdraw it at any time.
  • Right to lodge a complaint— You can lodge a complaint with your local data protection authority (for UK residents: the Information Commissioner's Office; for EU residents: your national supervisory authority).

If you are an App Company exercising these rights over your own account data (where Mintgrove is controller), contact us at privacy@mintgrove.co. We will respond, including completing any erasure request, within 30 days (or the legally required period for your jurisdiction), subject to legal retention obligations.

If you are a Buyer or a Seat Holder, these rights apply to your data too, but Mintgrove processes your data only as a processor (Section 2) — please direct your request to the App Company whose product or service you use, as they are the controller responsible for responding. Mintgrove will assist that App Company in fulfilling your request as required under the Data Processing Agreement.

10. US State Privacy Rights

If you are a resident of California or another US state with a comprehensive consumer privacy law, you may have additional rights with respect to your personal information, including the right to know the categories of personal information we collect (Section 3), the right to delete it, and the right to non-discrimination for exercising these rights.

We do not sell or share personal information, as those terms are defined under applicable state privacy laws.

If you are a Seat Holder or a member of a Buyer organization, please direct requests to the App Company whose product or service you use, consistent with Section 9 — they are the business responsible for your data under these laws. App Companies can exercise these rights over their own account data by contacting privacy@mintgrove.co.

Mintgrove is a small, early-stage company currently below the applicable thresholds for most state comprehensive privacy laws; we will revisit this section's applicability annually as the platform grows.

11. Cookies and Tracking

Mintgrove uses cookies and similar tracking technologies for authentication, security, and basic platform functionality. We do not currently use third-party advertising or behavioral tracking cookies.

Because the cookies we currently use are strictly necessary for authentication, security, and core platform functionality, they are exempt from cookie-consent requirements under the EU ePrivacy Directive and UK PECR, and no cookie-consent banner is currently required. If Mintgrove later adds analytics, marketing, or other non-essential cookies, a consent mechanism will be added before those cookies are deployed, and this section will be updated accordingly.

12. Children's Privacy

Mintgrove is a business-to-business platform and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will delete it promptly.

13. App Company Responsibilities

App Companies use Mintgrove to process personal data of their own Buyers and Seat Holders. With respect to that data, App Companies are independent data controllers (Section 2) and are responsible for:

  • Maintaining their own privacy policy and notices for their Buyers and Seat Holders, including disclosure of Mintgrove's role in processing that data as their processor
  • Obtaining any required consents for data processing activities
  • Responding to data subject requests from their own customers (with Mintgrove's assistance as required under the Data Processing Agreement)
  • Complying with applicable data protection laws in their own operations, including establishing a lawful basis for the processing described in Section 4.2

Mintgrove's processing on an App Company's behalf is governed by the Data Processing Agreement between the parties.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address and/or by a prominent notice in the platform. The updated policy will indicate the date of the last revision.

15. Contact Us

For privacy-related questions, requests, or complaints:

Mintgrove LLC
790 Newark Rd, Island Pond, VT 05846
Email: privacy@mintgrove.co

If you are a Buyer or Seat Holder, please see Section 2 — contact the App Company whose product or service you use, rather than Mintgrove directly, for requests about your own data.