Scope and our role
This Privacy Policy applies to the ServicesGrid OS marketing website, business account and authentication surfaces, administrator dashboard, member portal, APIs, support services, and related applications (together, the “Service”). It applies to information processed by ServicesGrid OS (“ServicesGrid”, “we”, “us”).
At the effective date, ServicesGrid OS is an owner-operated remote online business based in Ghana. It is not yet registered as a business name or company and has no public office. Privacy requests must be sent to privacy@servicesgridos.com.
We act as a data controller when we decide why and how to use information—for example, website enquiries, account administration, subscription billing, platform security, and our own communications.
We act as a data processor or service provider when a subscribing business uses the Service to manage information about its customers, members, guests, staff, dependants, suppliers, or other people. In that situation, the business is normally the data controller and its privacy notice should explain its processing. Please direct requests about a business's records to that business first.
This policy is designed to reflect Ghana's Data Protection Act, 2012 (Act 843) and other privacy laws that may apply to a particular person or deployment.
Information we process
Identity and contact information
Names, email addresses, telephone numbers, usernames, profile photographs, postal or business addresses, job titles, organisations, and communication preferences.
Account, profile, and security information
Password hashes, MFA status, passkey public-credential information, recovery and verification status, active sessions, role and permission assignments, login timestamps, IP addresses, device or browser information, security events, API-key metadata, and audit records. We do not receive the biometric unlock data stored on a person's device for a passkey.
Business and workspace information
Business names, service categories, locations, staff, operational settings, subscription tier, enabled modules, billing region, tax configuration, merchant setup, and workspace activity.
Operational and customer records
Depending on the features a business uses, the Service may process membership and guest profiles, dates of birth, gender or pricing category, emergency contacts, guardian and dependant relationships, bookings, room stays, check-ins, orders, table or service details, inventory activity, subscriptions, attendance, staff activity, notes, uploaded files, and communications.
Payment, billing, and transaction information
Subscription status, invoice and receipt records, payment references, provider customer or subscription identifiers, currency, amount, payment status, refunds, settlement records, and limited payment-method details returned by a payment provider. Raw card numbers and card security codes are handled by supported payment providers rather than stored by ServicesGrid.
Communications and support information
Contact-form submissions, support requests, email and SMS delivery records, notification preferences, survey or feedback responses, and messages you send to us or that an authorised business user sends through configured communication tools.
Technical and usage information
Request and response metadata, pages or features used, timestamps, referral URLs, error reports, performance information, approximate location inferred from IP or browser settings, and local browser preferences. We may associate technical records with an account where necessary for security and support.
Where information comes from
- From you, when you enquire, register, configure a workspace, upload data, make a purchase, contact support, or use the Service.
- From a subscribing business, when its administrators or staff add members, guests, dependants, employees, bookings, orders, or other records.
- Automatically, through requests, security logs, cookies, local storage, session storage, and similar application technologies.
- From providers, such as payment status from a payment processor, delivery results from communication providers, or verification results from anti-abuse services.
- From authorised integrations selected or configured by a subscribing business.
How and why we use information
We process information to:
- create and secure accounts; authenticate users; provide MFA, passkeys, and session controls;
- provide bookings, memberships, accommodation, POS, inventory, payments, reporting, communication, and other requested product features;
- process subscriptions, invoices, renewals, refunds, and payment-provider events;
- respond to enquiries, deliver service messages, and provide customer support;
- monitor reliability, diagnose errors, prevent fraud and abuse, enforce access controls, and investigate security incidents;
- comply with law, accounting obligations, lawful requests, and contractual commitments; and
- analyse aggregated or de-identified service usage and improve features and user experience.
Depending on the context and applicable law, we rely on performance of a contract, steps requested before entering a contract, legal obligations, legitimate interests in operating and protecting the Service, consent, or another lawful ground. Where consent is required, you may withdraw it, but withdrawal does not make earlier lawful processing unlawful.
We do not sell personal information. We do not use Customer Data to build advertising profiles. We send direct marketing only where permitted and provide a way to opt out.
Information controlled by business customers
Each subscribing business determines which operational information it enters, who can access it, how long it should be kept, and which communications or workflows it enables. The business is responsible for:
- giving appropriate privacy notices to its staff and customers;
- having a lawful reason and appropriate permission for collection and use;
- configuring roles and permissions and reviewing who has access to its workspace;
- handling requests from its data subjects and instructing us where our assistance is required;
- setting lawful retention, communication, cancellation, and business policies; and
- applying additional safeguards to children's data, identity records, health-related notes, or other sensitive information.
We process this information under the business's instructions, our agreement, and applicable law. We may decline an instruction that we reasonably believe is unlawful, insecure, or outside the Service.
When we disclose information
We may disclose information to:
- Authorised workspace users, according to the roles, permissions, service scopes, and customer relationships configured in the Service.
- Infrastructure and technology providers that support hosting, databases, storage, monitoring, security, support, and service delivery.
- Payment providers such as supported checkout, subscription, settlement, and refund processors.
- Communication providers used for email, SMS, and transactional notifications.
- Security and verification providers, including anti-abuse, CAPTCHA, authentication, and error-monitoring services.
- Professional advisers and auditors under appropriate duties of confidentiality.
- Authorities or other parties where disclosure is required by law, a valid legal process, or reasonably necessary to protect rights, safety, users, or the Service.
- A successor organisation in connection with a merger, financing, reorganisation, or sale, subject to applicable confidentiality and privacy requirements.
Providers are permitted to process information only for the services they provide to us or the subscribing business, subject to contractual and legal safeguards. The providers actually used may vary by feature, payment method, and deployment. See our Subprocessors page for the current provider disclosures.
International processing and data location
ServicesGrid and its providers may process information in Ghana and in other countries where infrastructure, payment, communication, security, or support providers operate. Those countries may have different privacy laws.
Where required, we use contractual, organisational, and technical safeguards for cross-border processing. Enterprise customers with specific residency or transfer requirements should confirm them in writing before deployment; the public Service does not promise a particular country of storage unless a written agreement says so.
How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, resolve disputes, enforce agreements, maintain security and audit records, and meet accounting, tax, fraud-prevention, or other legal obligations.
- Account and workspace information is generally kept while the account or subscription remains active.
- A workspace deletion request suspends access and begins a 30-day restoration period. After that period, active application records become eligible for scheduled deletion, subject to successful processing and legal retention requirements.
- Tenant-controlled records follow the subscribing business's instructions and configured lifecycle, subject to technical and legal limits.
- Billing, security, audit, and legal records may be retained after account closure where needed for compliance, claims, fraud prevention, or legitimate record-keeping.
- Deleted information may remain for a limited period in protected backups before normal backup rotation removes it. Cached copies and third-party provider records follow their applicable deletion or retention lifecycle.
At the end of the applicable retention period, we delete, securely destroy, or de-identify the information unless continued retention is required or permitted by law.
How we protect information
We use reasonable technical and organisational safeguards designed for the nature of the Service and information involved. Current application controls include HTTPS transport, password hashing, hashed API keys, encrypted storage for selected secrets, role and workspace scoping, MFA and passkey support, rate limiting, security logging, and time-bounded privileged support sessions.
Infrastructure storage, backup, network, and encryption controls depend on the active hosting environment. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account or information has been compromised, contact support@servicesgridos.com immediately.
Where applicable law requires it, we will notify affected data controllers, individuals, and the relevant authority of a qualifying personal-data breach as soon as reasonably practicable.
Learn more on our Security page.
Cookies, local storage, and similar technologies
The Service uses cookies and browser storage for functions such as authenticated sessions, security, portal selection, theme preference, consent preference, onboarding drafts, interface state, and temporary workflow continuity. Some of these technologies are essential for requested functionality.
Cloudflare Turnstile or a similar security provider may use technical information to distinguish legitimate users from abuse. Error-monitoring or limited diagnostics may be enabled to understand failures and performance. We do not currently describe the Service as using third-party behavioural advertising.
Browser controls can remove or block storage, but doing so may sign you out, reset preferences, or prevent parts of the Service from working. A marketing-site consent choice is stored locally so the site can remember it.
Your privacy rights
Depending on your location and the context, you may have the right to:
- know whether and why your personal information is being processed;
- request access to and a description or copy of your information;
- correct information that is inaccurate, incomplete, or misleading;
- request deletion or destruction where the information is no longer authorised or required;
- object to or request restriction of processing that causes unwarranted damage or distress;
- withdraw consent where processing relies on consent;
- opt out of direct marketing; and
- complain to the relevant data-protection authority.
To exercise a right concerning information directly controlled by ServicesGrid, email privacy@servicesgridos.com with “Privacy Request” in the subject. We may ask for information needed to verify your identity and locate the relevant records. We will respond within the period required by applicable law and explain any lawful limitation.
For information entered by a subscribing business, contact that business first. We will assist the business with verified requests as required by our agreement and applicable law.
Children and dependant information
Business administrator accounts are intended for adults. The Service may allow an authorised parent, guardian, or business to maintain dependant records for bookings, memberships, accommodation, coaching, or similar services.
The subscribing business is responsible for determining whether it may lawfully collect and use a child's or dependant's information, obtaining guardian authority or consent where required, limiting collection, and applying suitable safeguards. A child should not independently create a business account or submit personal information to us without appropriate adult involvement.
Changes and contact details
We may update this policy when the Service, providers, law, or our practices change. We will publish the updated effective date and provide additional notice where a material change or applicable law requires it.