Legal
Privacy Policy
Last Updated: March 30, 2026
1. Introduction
Grainline ("we," "us," or "our") operates the Grainline marketplace platform at thegrainline.com (the "Platform"). We are committed to protecting your privacy and handling your personal information with care and transparency.
This Privacy Policy explains what information we collect about you, how we use it, with whom we share it, and the choices you have regarding your information. It applies to all users of the Platform, including Makers (sellers) and Buyers.
By using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Platform.
This policy should be read together with our Terms of Service.
2. Information We Collect
We collect information you provide to us directly, information generated through your use of the Platform, and information from third-party services.
2.1 Account Information
When you create an account, we collect your name, email address, and password (hashed and managed securely through our authentication provider, Clerk). We may also collect a profile photo if you upload one.
2.2 Profile Information
Makers may provide additional profile information including a shop display name, biography, story, profile and banner photos, workshop photos, social media links, website URL, years in business, shop policies, and location (city and state for public display; precise latitude/longitude for map features, only if you choose to set it).
2.3 Transaction Information
When you make or receive a purchase, we collect information about the transaction including item details, amounts, shipping address, and order status. Payment card data is processed directly by Stripe and is not stored by Grainline. We do store Stripe transaction identifiers, payout information, and sales tax records as required by law.
2.4 Communications
We store messages sent between users through the Platform's messaging system, including buyer-seller conversations, custom order requests, and case messages. We also store reviews, blog posts, and comments you submit.
2.5 Usage Data
We collect information about how you use the Platform, including pages visited, listings viewed and clicked, searches performed, filters applied, features used, and the times and dates of your activities.
2.6 Device Information
We automatically collect certain technical information when you use the Platform, including your IP address, browser type and version, operating system, device type, and referring URL. This information is used for security, fraud prevention, and platform analytics.
2.7 Location Data
We collect approximate location data (city, state, country) derived from your IP address for general analytics and to improve location-based features. For map features, Makers may optionally provide precise workshop location coordinates. Your precise GPS coordinates are stored securely but only your approximate location (city/region level) is displayed publicly on the Grainline map. You may remove your location at any time through your dashboard settings. We do not track your precise device GPS location without your explicit permission.
2.8 Photo Metadata
Photos you upload may contain embedded EXIF metadata, which can include location coordinates, device information, and timestamps. Grainline makes commercially reasonable efforts to strip location-related EXIF data from uploaded photos. Photos are processed through our upload provider (UploadThing) which may retain or strip metadata according to their own practices. Other non-identifying EXIF metadata may be retained for technical purposes.
2.9 Newsletter and Marketing
If you subscribe to our newsletter, we collect your email address and optional name. You may unsubscribe at any time via the unsubscribe link in any email or by contacting privacy@thegrainline.com. Unsubscribing from marketing emails does not affect transactional emails related to your orders or account activity.
2.10 Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Platform. See Section 5 for details.
2.11 Information from Third Parties
We may receive information about you from third-party services integrated with the Platform, including authentication events from Clerk, payment events from Stripe, and shipping events from Shippo.
2.12 Commission Room Data
Buyers who post Commission Requests provide a description, budget range, timeline, category, and optional reference images. This information is displayed publicly on the Commission Room board. Location data may be used for locally-scoped requests as described in Section 2.7.
2.13 Following and Feed Data
We store records of which Makers you follow. Your following activity is used to generate your personalized feed and to enable seller broadcasts. Follower counts are displayed publicly on Maker profiles.
2.14 Back-in-Stock Subscriptions
When you subscribe to receive a notification when an out-of-stock item becomes available, we store a record linking your account to that listing. You may unsubscribe at any time from the listing page.
2.15 Seller Performance Metrics
For Makers participating in the Guild Verification Program, we calculate performance metrics including average rating, on-time shipping rate, response rate, total sales, and open case count. These metrics are calculated automatically from Platform activity data and are used to determine Guild badge eligibility and maintenance.
2.16 Listing Snapshots
When a purchase is completed, we capture and store a snapshot of the listing details at the time of the transaction, including the title, description, price, images, category, tags, and seller name. This snapshot is retained as part of the order record for dispute resolution, order history display, and archival purposes.
2.17 Saved Searches
If you save a search, we store your search filters including search query, category, price range, and tags. You may delete saved searches at any time from your dashboard.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide the Platform. To operate, maintain, and improve the Platform, including processing transactions, facilitating communications between users, and displaying listings.
- Process transactions. To process payments, issue payouts, calculate shipping rates, generate shipping labels, collect and remit sales tax, and fulfill orders.
- Tax compliance. To calculate, collect, and remit applicable sales tax as required by marketplace facilitator laws; to generate and issue 1099-K forms as required by IRS regulations; and to maintain transaction records for tax and legal compliance.
- Transactional communications. To send order confirmations, shipping notifications, case updates, review requests, and other communications necessary to fulfill your transactions or platform activities.
- Marketing communications.With your consent, to send newsletters, promotional emails, and updates about new features. You may opt out at any time by clicking "unsubscribe" in any marketing email or contacting privacy@thegrainline.com.
- Fraud prevention and security. To detect, investigate, and prevent fraudulent transactions, abuse, and other harmful activities, and to protect the security of the Platform and our users.
- Legal compliance. To comply with applicable laws, regulations, legal processes, and governmental requests, including marketplace facilitator tax obligations.
- Analytics and improvement. To analyze usage patterns, understand how users interact with the Platform, and improve our features, content, and user experience.
- Customer support. To respond to your inquiries, resolve disputes, and provide technical support.
- Personalization. To personalize your experience, including showing relevant listings, search results, and recommendations.
- Automated content review. We use automated tools, including artificial intelligence provided by third-party services, to review listing content for potential violations of our Terms of Service. This review may occur before a listing is made publicly visible. Automated review does not replace human judgment — flagged listings are reviewed by Grainline staff before final decisions are made.
- Seller performance evaluation. We automatically calculate seller performance metrics to determine eligibility for the Guild Verification Program. While metrics are calculated automatically, all badge approval and revocation decisions include human review.
- Algorithmic recommendations.We use Platform activity data (views, favorites, sales, search behavior) to generate personalized recommendations including "Similar Items," "Buyer Favorites," and search relevance ranking. We do not use external data sources or build advertising profiles for these features.
6. Data Retention
- Account data. Retained while your account is active plus 30 days after a deletion request is processed. Upon account deletion, personal data is anonymized within 30 days except where retention is legally required.
- Transaction records. Order and payment records are retained for a minimum of 7 years to comply with tax, accounting, and legal requirements.
- Sales tax records. Sales tax records, including transaction details relevant to tax remittance, are retained for a minimum of 4 years per Texas Comptroller requirements and applicable state laws.
- 1099-K records. IRS reporting records are retained for a minimum of 7 years as required by federal tax law.
- Messages. Messages between users are retained for 3 years then deleted, unless the messages are subject to an open case, legal hold, or fraud investigation. After account deletion, messages may be retained in anonymized form for safety and fraud prevention for the remainder of the 3-year period.
- Notification data. Read notifications are automatically deleted after 90 days. Unread notifications are retained until read or until account deletion.
- Legal holds. If your information is subject to a legal hold, dispute, investigation, or law enforcement request, we may retain it beyond the standard retention periods.
- Administrative action logs. Records of administrative actions including account suspensions, content removal decisions, listing review decisions, and Guild badge actions are retained permanently for legal compliance and audit purposes.
- Seller performance metrics.Calculated seller metrics are refreshed monthly and retained for the duration of the seller's account. Historical daily view and click data is retained for 2 years.
- Commission Requests. Commission Request data (descriptions, reference images, interest records) is retained for the lifetime of the request plus 1 year after the request is closed, fulfilled, or expired.
- Following data. Records of which Makers you follow are retained while your account is active and deleted upon account deletion.
7. Your Rights
Depending on your location, you may have certain rights regarding your personal information. We honor the following rights for all users regardless of location:
- Access. Request a copy of the personal information we hold about you.
- Correction. Correct inaccurate or incomplete personal information. You can update most account information directly in your account settings.
- Deletion. Request deletion of your account and associated personal data, subject to our legal retention obligations (e.g., transaction records required for tax compliance cannot be deleted before the required retention period).
- Data portability. Request an export of your personal data in a commonly used, machine-readable format. Data export requests are processed manually and fulfilled within 30 days of a verified request. Exports typically include your account information, transaction history, messages, reviews, and listing data in JSON or CSV format. For Makers, data exports may also include listing data, order fulfillment history, seller analytics (views, clicks, conversion data), and Guild program data. Customer personal data (buyer names, addresses) is not included in seller data exports except as required by applicable law.
- Opt out of marketing.Opt out of marketing emails at any time by clicking "unsubscribe" in any marketing email or contacting privacy@thegrainline.com. Opting out does not affect transactional emails related to your orders or account.
7.1 How to Exercise Your Rights
To exercise any of the rights described in this section, please contact us at privacy@thegrainline.com. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
7.2 California Residents (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know — the categories and specific pieces of personal information we have collected, used, disclosed, or sold about you in the past 12 months
- Right to delete — personal information we have collected, subject to certain exceptions
- Right to correct — inaccurate personal information we maintain about you
- Right to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising, so this right is not applicable
- Right to limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the Platform
- Right to non-discrimination — we will not discriminate against you for exercising your CCPA/CPRA rights
To exercise California rights, contact us at privacy@thegrainline.com.
7.3 Texas Residents (TDPSA)
Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), including rights to:
- Access your personal data
- Correct inaccuracies in your personal data
- Delete personal data you have provided to us
- Obtain a copy of your personal data in a portable format
- Opt out of the processing of personal data for targeted advertising (we do not engage in targeted advertising)
- Opt out of the sale of personal data (we do not sell personal data)
- Appeal a decision regarding a rights request
To exercise Texas TDPSA rights or to appeal a rights decision, contact us at privacy@thegrainline.com. We will respond within 45 days as required by the TDPSA, with a possible 45-day extension where reasonably necessary.
7.4 EU, EEA, and UK Residents (GDPR)
If you are located in the European Union, European Economic Area, or United Kingdom, you have rights under the General Data Protection Regulation (GDPR) or UK GDPR, including:
- Right of access — obtain confirmation of whether we process your data and a copy of that data
- Right to rectification — have inaccurate personal data corrected
- Right to erasure ("right to be forgotten") — have your personal data deleted in certain circumstances
- Right to restrict processing — limit how we use your data in certain circumstances
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making — not be subject to solely automated decisions that produce significant effects
Note regarding automated processing: Grainline uses automated systems to calculate seller performance metrics and to perform initial content review of listings. However, all consequential decisions (Guild badge approval/revocation, listing rejection, account suspension) include human review. You have the right to request human review of any automated decision that significantly affects you.
Legal basis for processing: We process your data on the basis of contract performance (to provide the Platform), legal obligation (tax compliance, legal holds), and legitimate interests (fraud prevention, security, analytics). Marketing is processed with your consent.
Data transfers to the US are covered by Standard Contractual Clauses where required. You also have the right to lodge a complaint with your local data protection supervisory authority.
To exercise GDPR rights, contact privacy@thegrainline.com.
7.5 Additional US State Privacy Rights
In addition to the California and Texas rights described above, residents of other US states — including Virginia, Colorado, Connecticut, Utah, Iowa, Tennessee, Montana, Oregon, Delaware, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Indiana, Kentucky, and Rhode Island — may have similar rights under their respective state privacy laws, including rights to access, correct, delete, and port personal data, and to opt out of targeted advertising and data sales. We do not sell personal data or engage in targeted advertising. To exercise any privacy right regardless of your state of residence, contact us at privacy@thegrainline.com. We will respond within the timeframe required by your applicable state law (typically 30–45 days). If we decline a request, you may have the right to appeal — contact us for appeal instructions.
8. Children's Privacy
The Platform is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information as promptly as possible.
If you are a parent or guardian and believe that your child under 13 has provided personal information to us, please contact us at privacy@thegrainline.com and we will take appropriate action.
9. Security
We implement industry-standard security measures designed to protect your personal information against unauthorized access, disclosure, alteration, and destruction:
- Encryption in transit. All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- Access controls. Access to personal data is limited to Grainline personnel who need it to perform their job functions.
- Payment security. Payment card data is handled exclusively by Stripe, which maintains PCI DSS Level 1 compliance. Grainline never stores full card numbers.
- Authentication security. Account authentication is managed by Clerk, which provides secure password hashing, multi-factor authentication options, and session management.
- Error monitoring. We use Sentry for error tracking to detect and respond to security incidents promptly.
No guarantee. Despite our efforts, no security system is completely impenetrable. We cannot guarantee that unauthorized parties will never circumvent our security measures or misuse your information.
Data breach notification.In the event of a data breach that affects your personal information, we will notify affected users and applicable regulatory authorities as required by applicable law. Texas law requires notification "as quickly as possible." California requires notification to the Attorney General within 72 hours if more than 500 residents are affected. We will comply with the most stringent applicable notification timeline in each case.
10. International Data Transfers
Grainline is based in the United States. The Platform is intended for use within the United States. If you access the Platform from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
If you access the Platform from outside the United States, you consent to the transfer and processing of your data in the United States. We maintain appropriate safeguards with our service providers as required by applicable law.
11. Third-Party Links
The Platform may contain links to third-party websites, social media platforms, and services. These third parties have their own privacy policies, and Grainline is not responsible for their privacy practices or content. We encourage you to review the privacy policies of any third-party sites you visit.
Maker shop profiles may link to external websites, social media accounts, and portfolios. These links are provided by Makers and Grainline has no control over the privacy practices of these external sites.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice by sending an email to the address associated with your account and posting a prominent notice on the Platform.
Your continued use of the Platform after the effective date of any revised Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the revised policy, you must stop using the Platform and may request deletion of your account.
The "Last Updated" date at the top of this page will always reflect the date of the most recent revision.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Grainline — Privacy Team
Email: privacy@thegrainline.com
[YOUR ADDRESS]
For general legal inquiries: legal@thegrainline.com