TidyMessages
Privacy Policy
This notice explains how Grid Heap, Inc. handles personal data through the TidyMessages public site, administrative console, and business messaging service.
1. Scope and roles
Grid Heap, Inc. controls data used for this website, account administration, security, and its own business operations. For customer conversations operated for a brand, that brand generally determines the purpose and means of processing and TidyMessages acts under the applicable service agreement. Apple and other enabled providers process data under their own terms and roles.
2. Data we process
Depending on the enabled brand journey, the service may process workspace identity and role data, brand and channel configuration, message content and delivery metadata, opaque Apple customer identifiers, Invitation phone numbers and consent evidence, attachments, interactive responses, authentication events, payment-session events, audit records, and security telemetry. Public pages use no advertising trackers or third-party scripts.
3. Why we process data
We process data to provide and secure the messaging service, authenticate authorized users, route and deliver conversations, enable requested brand workflows, prevent abuse, preserve consent and opt-out decisions, recover failed operations, meet audit obligations, and improve reliability using content-free operational measurements.
4. Service providers and recipients
Data is disclosed only as needed to the relevant brand and its authorized agents, Apple for Messages for Business delivery, Cloudflare for infrastructure, approved brand integration providers, and optional TidyAnswer services when the brand has an explicit mapping and approval. We do not sell message content or use it for third-party advertising.
5. Retention
Data is retained only for the periods approved in the relevant customer agreement and documented retention schedule. Pending or rejected attachments use bounded transient lifecycle deletion; clean conversation objects follow the approved schedule and legal holds. Secrets and payment credentials are not written to message logs.
6. Locations and transfers
Infrastructure and authorized providers may process data outside the user's location. Transfer location and safeguards are selected according to the brand agreement, approved data-residency plan, and applicable requirements in Delaware, United States and the relevant customer region.
7. Security
Controls include tenant and Business ID isolation, Clerk Organization membership with least-privilege product roles, application-layer encryption for sensitive payloads, private object storage, ID-only queues, ordered delivery, auditable mutations, restricted logs, explicit opt-out enforcement, and fail-closed attachment release. No system is risk-free; incidents follow the applicable response and notification process.
8. Choices and rights
Access, correction, deletion, objection, restriction, portability, and complaint rights vary by location and role. Contact legal@gridheap.com. We verify requests and, where a brand controls the conversation data, route the request to that brand without exposing another tenant's records.
9. How to request data deletion
To request deletion of your data, email legal@gridheap.com from the address or account associated with the data, or include enough detail to identify the records: the brand or business you messaged, the channel used, and the approximate dates. We acknowledge every request, verify it before acting so that one person cannot erase another person's records, and confirm in writing once it is complete. Where a brand controls the conversation data we act on that brand's instruction and forward your request to them, and we tell you when we have done so. Some records are kept where law, an active legal hold, or a documented retention obligation requires it; when that applies we identify the category and the reason rather than retaining it silently.
10. Changes to this notice
We may update this notice when the service, subprocessors, legal requirements, or brand deployments change. The effective date above identifies the published version. Material updates follow the applicable notice and approval process.
11. Contact
Privacy questions and verified rights requests may be sent to legal@gridheap.com or to Grid Heap, Inc., 1111B S Governors Ave # 51059, Dover, DE 19904, United States.