Privacy Policy

Plain English. Last updated 10 September 2026.

1. Who we are

Green Grant Finder is a trading name of Green Grant Finder Ltd, a company registered in England and Wales (company number 17446312). We're the "data controller" for the personal information described in this policy — which means we're responsible for deciding how it's used. You can reach us at info@greengrantfinder.com or by post at the address in section 12.

2. What data we collect

We only collect what we need to run the service. That includes:

  • Account information — your email address, name, and any company details you add to your profile (such as Companies House number or trading address).
  • Google user data — if you choose “Continue with Google”, we receive your name, email address, Google user id, and public profile photo. See section 7 for the full disclosure.
  • Billing information — handled by Stripe. We store whether you have an active subscription and the last four digits of your card. We never see or store your full card number.
  • Grant searches and applications — what you search for, which grants you save, and any application content or AI drafts you create.
  • Contact-form messages — anything you send us through the contact form .
  • Basic device information — IP address and browser type, kept for up to 30 days for security and fraud prevention.
  • Cookie consent record — we log which categories of cookies you accepted or rejected, and when. See section 9 for what each category does.

3. How we use it

  • To run the service and show you the grants you've asked for.
  • To create or sign you into your account, including via Google Sign-In.
  • To process payments and prevent fraud.
  • To send grant alerts and weekly digests, but only when you've opted in. You can unsubscribe at any time from your account or by clicking the link at the bottom of any email.
  • To send service emails — password resets, receipts, security notices. You can't opt out of these because they're necessary to keep your account working.
  • To improve the product — for example, spotting which grants people search for but can't find, so we can prioritise adding more sources.

4. Our legal basis

Under the UK GDPR, we need a legal reason to use your personal data. Ours are:

  • Contract (UK GDPR Article 6(1)(b)) — to provide the service you've signed up for, take payment, and support your account.
  • Consent (UK GDPR Article 6(1)(a)) — for marketing emails and for non-essential cookies. You can withdraw consent at any time; it doesn't affect anything we've already done lawfully under that consent.
  • Legitimate interests (UK GDPR Article 6(1)(f)) — for keeping the service secure, preventing fraud, basic product analytics, and recording your cookie choices. We balance these against your rights and only use what's proportionate.
  • Legal obligation (UK GDPR Article 6(1)(c)) — for tax records and responding to lawful requests from authorities.

5. How long we keep it

  • Account data, including Google user data stored on your account — while your account is active, plus up to 30 days after deletion for the recovery window. After that, we delete it.
  • Billing and tax records — 7 years from the transaction, as required by HMRC. These records are not Google-originated.
  • Contact-form messages — 12 months, then deleted.
  • Cookie-consent records — 24 months, so we can prove what you agreed to.
  • Security logs (IP, browser) — 30 days, then deleted.

6. Who we share it with

We don't sell your data. We don't share it with advertisers. We only share it with the following service providers, each bound by a data-processing agreement:

  • Stripe — payment processing. Stripe handles your card details on our behalf. See their privacy policy at stripe.com/privacy.
  • Google Sign-In (Google LLC) — only if you choose “Continue with Google”. Google authenticates you and sends us the Google user data described in section 7. See policies.google.com/privacy.
  • Google Analytics (Google LLC) — only if you opt in to Analytics cookies. Google receives page URLs, device and browser information, and anonymous usage events. We do not send your name, email, or Google user id. See policies.google.com/privacy.
  • Companies House — when you look up a UK company on us (for example, to attach your business profile), we query their public API. They don't see who you are.
  • Hosting (DigitalOcean) — your data lives on servers in the UK or EU.
  • Transactional email (Mailgun or Postmark) — sends password resets, receipts, and security notices. We share only the email address needed to deliver the message.
  • Marketing email — only if you opt in. We share only the email address needed to send the messages you asked for.

If we're ever required by law (a court order, a regulator's lawful request), we may have to disclose information. We'll challenge any request that we think is too broad.

7. Google user data (Sign in with Google)

This section explains how Green Grant Finder accesses, uses, stores, and shares Google user data. It applies only if you choose “Continue with Google” on Green Grant Finder.

What Google user data we access

We request the OpenID Connect scopes openid, email, and profile. Through those scopes, Google shares with us:

  • your name
  • your email address
  • your Google user id
  • your public profile photo, if you have one

We do not access Gmail, Google Drive, Google Calendar, Contacts, or any other Google user content. We do not use Google Workspace APIs.

How we use Google user data

We use Google user data only to provide and improve Green Grant Finder's user-facing sign-in and account features:

  • to create your Green Grant Finder account, or to recognise you when you come back
  • to link a Google account to an existing Green Grant Finder account that already uses the same email address
  • to show your name and profile photo in the product
  • to send necessary account emails to the email address Google provided (for example password-reset alternatives, receipts, and security notices)

How we store Google user data

We store your name, email address, Google user id, and profile photo URL in our user database on DigitalOcean servers in the UK or EU. We never receive or store your Google password. We do not retain Google OAuth access tokens or refresh tokens after sign-in completes.

Who we share, transfer, or disclose Google user data to

We do not sell Google user data. We do not share, transfer, or disclose Google user data to advertisers, data brokers, or information resellers. We do not transfer Google user data to third parties except:

  • our hosting provider (DigitalOcean), which stores the account fields listed above as infrastructure
  • our transactional email provider, which receives only the email address in order to send account emails you need
  • when required by law, such as a court order or a regulator's lawful request

Google Analytics is separate from Google Sign-In. Analytics runs only if you opt in to Analytics cookies, and it does not receive your Google Sign-In name, email address, or Google user id.

How we protect Google user data

Security procedures are in place to protect the confidentiality of your data. We use HTTPS/TLS encryption to protect information in transit, restrict staff access to what they need to run the service, and rely on our hosting provider's access controls and encryption to protect information at rest. See section 8 for the same protections applied to personal data generally.

How long we keep Google user data and how you can delete it

We store Google user data for as long as your account is active, plus up to 30 days after deletion for the recovery window. You may request for your data to be deleted by deleting your account from your profile page, or by emailing info@greengrantfinder.com. We will then delete the stored Google user id, name, email, and profile photo from our systems. When the data retention period expires for a given type of data, we will delete or destroy it. Billing and tax records we must keep for HMRC are not Google-originated and follow the 7-year rule in section 5.

Limited use of Google user data

We limit our use of Google user data to providing or improving Green Grant Finder's user-facing functionality. We do not use Google user data for:

  • targeted, personalised, retargeted, or interest-based advertising
  • selling to data brokers or providing it to information resellers
  • determining credit-worthiness or lending
  • creating databases of Google users for unrelated purposes
  • training generalised or non-personalized AI and/or ML models

Green Grant Finder's AI features (eligibility analysis, application drafting, and the weekly digest) use information you enter in the product — for example your company profile and grant text. They do not use Google Sign-In data, and we do not use Google Workspace APIs, to develop, improve, or train non-personalized AI or ML models.

8. How we protect data

Security procedures are in place to protect the confidentiality of your data. In particular:

  • We use HTTPS/TLS encryption to protect your information in transit.
  • Account access requires authentication; staff access is limited to what is needed to operate the service.
  • Data is hosted in the UK or EU with access controls and encryption provided by our hosting and database infrastructure.
  • We do not store full payment-card numbers, and we do not store Google passwords or Google OAuth tokens after sign-in.

9. Cookies

When you first visit, we show you a cookie banner with three choices: Accept all, Reject all, or Customise. You can change your mind at any time using the "Cookie settings" link in the corner of every page.

  • Necessary — always on. These keep you signed in, remember your session, and make the site work. They don't track you across other sites.
  • Analytics — optional. When you say yes, we load Google Analytics (Google LLC) so we can see which pages people use and where things break. We do not send your name or email. The script is not loaded at all until you opt in, and you can switch it off any time from Cookie settings.
  • Marketing — optional. We don't run advertising on this site. This category is reserved for future use if we ever embed third-party content that needs it. Right now it's off by default and stays off.

10. Your rights

Under UK data-protection law, you can:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectify — ask us to correct anything that's wrong. You can do this yourself from your profile page.
  • Erase — ask us to delete your data. You can do this yourself by deleting your account from your profile page; otherwise, email us and we'll do it within a month.
  • Restrict — ask us to stop using your data while a question about its use is resolved.
  • Portability — ask for a machine-readable copy of the data you've given us.
  • Object — to us using your data for direct marketing or based on our legitimate interests.
  • Withdraw consent — at any time, for anything we've relied on your consent for.
  • If we mess up, you can complain to the ICO at ico.org.uk or call 0303 123 1113.

11. How we notify you of changes

If we make a material change — for example, a new type of data we collect, a change in how we use Google user data, or a new third party we share with — we'll email every active account at least 30 days before it takes effect. Minor clarifications and typo fixes don't get an email; the "Last updated" date at the top will change.

12. How to contact us

The quickest way is email: info@greengrantfinder.com . Or write to us at:

Green Grant Finder Ltd
36 Grinstead Lane
Lancing
BN15 9DY

13. Effective date

This policy takes effect on 10 September 2026.