Effective July 13, 2026 · version 2026-07-13
Privacy notice
This notice describes the current design-partner service. It is intentionally specific about prospect data, repository content, service providers, and retention.
Commercial identity notice
A paid engagement begins only under an Order Form or statement of work that identifies the contracting service provider, legal address, and governing terms. Those operator-supplied facts are not inferred on this preview site. Privacy questions can be sent to privacy@garrid.com.
Information we collect
- Guided Pilot applications: name, work email, company, role, use case, timing, build-volume and budget signals.
- Limited attribution: UTM campaign fields, landing path, referring origin and path, and user-agent. Query strings and IP addresses are not written to the lead record.
- Account data: OAuth identity, name, email, avatar, organizations, membership roles, sessions, and API-token metadata.
- Build data: frozen specifications, repository coordinates, source and patch artifacts, verifier/reviewer results, usage, cost, lifecycle events, and proof receipts.
- Operational data: security, rate-limit, dispatcher, error, and availability records needed to operate and protect the service.
How we use information
We use information to qualify and respond to Guided Pilot requests; create and secure workspaces; execute, meter, review, and evidence builds; provide support; prevent abuse; maintain audit and financial records; and improve service reliability. We do not sell personal information or use Guided Pilot application data for third-party advertising.
Service providers and transfers
Depending on the selected workflow, information may be processed by:
- Cloudflare for application delivery, Worker execution, D1 persistence, networking, and abuse protection.
- GitHub or Google for OAuth identity; GitHub for explicitly authorized repository access.
- OpenAI or another provider named in the applicable build contract for model execution through Garrid's governed gateway.
- Stripe for checkout, invoicing, subscription, tax, and payment records once live billing is activated.
- Upstash for rate limiting when the production Redis integration is enabled.
These providers may process data in other jurisdictions under their own contractual safeguards. A paid customer's Order Form or DPA controls any stricter processor and regional commitments.
Retention
- Guided Pilot application records expire no later than 180 days after their most recent workflow activity unless an active engagement or legal duty requires a documented hold.
- Expired sessions and revoked or expired API-token records are removed through the maintenance workflow.
- Non-customer internal and smoke build records are eligible for deletion after 30 days.
- Customer build and audit evidence is append-only for seven years, then eligible for governed deletion. This longer period supports delivery, security, billing, and audit disputes and must be reflected in the applicable Order Form.
Security and customer choices
The service uses tenant authorization, scoped credentials, bounded execution, budget admission, append-only evidence, and controlled retention. See the security page for current boundaries. No internet service is risk-free, and public application forms should not contain source code, credentials, secrets, regulated records, or confidential repository content.
Subject to applicable law and contractual audit duties, a person may request access, correction, export, restriction, or deletion by emailing privacy@garrid.com. We may need to verify identity and explain when immutable contractual evidence cannot yet be deleted.
Cookies and changes
The current service uses essential session, organization-selection, OAuth-state, and theme storage. It does not currently install advertising cookies. Material changes will receive a new version date; consent captured with a Guided Pilot application remains tied to the version shown at submission.