EXPLOREINDUSTRIESGUIDESLEARNGLOSSARYBOOKSWHITEPAPERTOOLSRESOURCESPIONEERMARKETSCOUNTRIESFEESMISSION FUNDPASSPORT
SUPPORTLOGINJOIN THE PROTOCOL →
GETREADYANDJUMP.COM · BUILT IN DETROIT

PRIVACY
POLICY.

What we collect, why, who it goes to, how long we keep it, and what you can do about it. Named providers, not 'trusted partners'.

Last updated: 9 August 2026

The short version, which does not replace the text below:

  • We do not sell your personal information, and we do not share it for advertising.
  • We do not use your content to train AI models.
  • Identity verification uses biometric data — read Section 4.
  • Proof you attach to work — photographs, GPS, signatures — is shared with your counterparty.
  • The financial ledger is append-only and is never deleted; corrections are reversing entries.
  • You can access, correct, export or delete your data — see Section 10.
Section 1

Who we are and what this covers

This Privacy Policy explains how GRAJ ("GRAJ", "we", "us") collects, uses, shares, and protects personal information when you use getreadyandjump.com and the GRAJ Protocol (the "Protocol").

For data protection purposes GRAJ is the controller of the information described here. Where you transact with another participant, that participant is an independent controller of the information they receive about you, and their own practices govern what they do with it.

Contact us about privacy at ilove@getreadyandjump.com.

Section 2

What we collect

Account and profile. Name, preferred name, email, phone, password credentials, handle, role, business name, logo and images, bio, location (city/state/country), and the entities you operate.

Addresses. Home and shipping addresses, used for deliveries, samples, tax determination, and correspondence.

Identity and verification. Date of birth, nationality, government identification, and — where you use identity verification — a photograph of your identity document and a selfie, which are processed as biometric identifiers by our verification provider to confirm you are the person on the document. See Section 4.

Background checks. Where you request or consent to one, the results of a background check performed by a consumer reporting agency. See Section 5.

Business and compliance documents. Tax forms (such as a W-9), EIN, business licences, certificates of insurance, resale certificates, food-safety and other permits, and signed agreements.

Financial. Bank and payout details held by our payment processor, transaction history, amounts owed and paid, protocol fees, funding arrangements and repayment schedules. We do not store full card or bank account numbers — those sit with Stripe.

Work and proof. Records of work performed and the evidence attached to it, which may include photographs, GPS coordinates, timestamps, signatures, and the name of the person who received goods.

Communications. Messages between participants on the Protocol, notifications, support correspondence, and — where used — SMS.

AI interactions. The prompts you send to AI assistants, the context of the transaction or page you are on, and the responses generated.

Technical and usage. IP address, device and browser information, pages viewed, actions taken, timestamps, and cookies (see the Cookie Policy).

Location. Approximate location from your IP, coordinates you supply on your profile, and — where you enable it for delivery or proof features — device location.

Section 3

Where it comes from

  • From you — what you type, upload, and submit.
  • Automatically — from your device and your use of the Protocol.
  • From other participants — for example a brand recording that you completed work, a counterparty confirming or disputing a claim, or a rating you receive.
  • From service providers — verification results from Stripe Identity, background-check results from Checkr, payment and payout status from Stripe.
  • From public sources — business registry and similar public information, where used to verify a business.
Section 4

Biometric information

If you complete identity verification, biometric information about you is processed. Our provider, Stripe Identity, compares a photograph of your government identification with a selfie you take, generating facial-geometry data to confirm they are the same person.

Purpose. Solely to verify your identity, prevent fraud and impersonation, and meet the identity requirements that apply to moving money. It is not used for advertising, profiling, or training AI models, and we do not sell it or otherwise disclose it for anything other than performing verification.

Consent. Identity verification is optional and initiated by you. You will be asked to consent before any biometric processing occurs. You can decline — but some capabilities, particularly receiving payouts, may be unavailable without verification.

Who holds it. The images and biometric data are processed by Stripe under Stripe's privacy terms. GRAJ receives the verification outcome and limited details — not your biometric template.

Retention. Biometric identifiers are retained no longer than needed for the verification purpose, and in any event are destroyed when that purpose is satisfied or within three years of your last interaction, whichever comes first.

Residents of Illinois, Texas, Washington and other states with biometric privacy statutes have specific rights under those laws; contact us at ilove@getreadyandjump.com to exercise them.

Section 5

Background checks

Where you request or consent to a background check, it is performed by a consumer reporting agency and the resulting report is a consumer report under the US Fair Credit Reporting Act (FCRA).

We will obtain your written authorisation before ordering one and provide the disclosures the FCRA requires. If information in a report would lead to an adverse decision about your participation, you will receive the required pre-adverse and adverse action notices, a copy of the report, and a summary of your rights — including the right to dispute the accuracy of the information with the agency that supplied it.

Background-check results are used only to assess trust and eligibility on the Protocol, are visible only to GRAJ and to you, and are not published to other participants. A participant may see that you are verified; they do not see the underlying report.

Section 6

How we use it, and our lawful bases

To operate the Protocol — create and run your account, connect you with counterparties, record agreements, compute what is owed, and move money. Basis: performance of a contract.

To verify identity and prevent fraud — verification, screening, monitoring for abuse, and protecting participants from loss. Basis: legitimate interests; legal obligation; your consent for biometric processing.

To meet legal and financial obligations — tax reporting, sanctions and anti-money-laundering screening, recordkeeping, and responding to lawful requests. Basis: legal obligation.

To provide AI features — generate responses, draft text you request, and answer questions in context. Basis: performance of a contract; legitimate interests.

To communicate — transactional notifications about your agreements, work, money and account; service announcements; support. Basis: performance of a contract; legitimate interests.

To improve and secure the Protocol — diagnostics, aggregate analytics, debugging, and security. Basis: legitimate interests.

Marketing — only where you have opted in, or as otherwise permitted, and you can withdraw at any time. Basis: consent; legitimate interests.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

We do not use your content to train third-party AI models. AI features are delivered through Anthropic's API, which does not train models on data submitted through it.

Section 7

Who we share it with

Other participants. The Protocol is shared infrastructure two parties trade on, so some information is shared by design: your public profile, and — with a counterparty you transact with — the details of your agreement, work records, proof you submit, messages, and amounts owed or paid. Consider proof carefully: a photograph or GPS coordinate you attach will be visible to the counterparty.

Service providers (subprocessors). We use:

  • Supabase — database, authentication and file storage. Your account, agreements, orders, messages and uploaded documents are stored here.
  • Vercel — application hosting and delivery. Processes requests to the site, including IP addresses.
  • Stripe — payments, payouts, Connect accounts, and identity verification (including the biometric processing described in Section 4).
  • Anthropic — the AI models behind assistant and drafting features. Receives the prompts and context you send to an assistant. Data submitted through Anthropic's API is not used to train its models.
  • Amazon Web Services (Amazon IVS) — live video broadcasting, where you use live shopping. Processes the video and audio of a broadcast, which includes the image and voice of anyone appearing in it.
  • Resend — transactional email. Receives your email address and the contents of messages we send you.
  • Twilio — SMS, where used. Receives your phone number and the message.
  • Checkr — background checks, where you request one. See Section 5.

Each is bound by contract to use the information only to provide its service to us.

Minor third-party utilities. Some pages generate a QR code through an external QR service; the only thing sent is a GRAJ link (for example the address of a sample bag or kiosk), never your personal information. We also source stock and country photography from Unsplash — that sends a search term, nothing about you.

Not subprocessors. Some services we use never touch participant personal information and are therefore not listed above — for example GitHub, which hosts our source code. Our source code contains no participant data.

Legal and safety. We may disclose information where required by law, subpoena, or regulator; to establish or defend legal claims; or to protect the rights, safety and property of participants, the public, or GRAJ.

Business transfers. If GRAJ is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a materially different policy.

Section 8

International transfers

GRAJ operates from the United States and our providers may process information in the United States and other countries. Those countries may not provide the same level of protection as your own.

Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses and the UK Addendum — together with additional measures where required. Contact ilove@getreadyandjump.com for details.

Section 9

How long we keep it

We keep personal information for as long as your account is active and afterwards only as long as needed for the purposes described here.

  • Account and profile — for the life of the account, then deleted or anonymised.
  • Transaction, money and tax records — generally at least seven years after the transaction, because tax and financial recordkeeping law requires it.
  • Agreements, work records and proof — for the life of the agreement and for as long afterwards as either party could bring a claim.
  • Ledger entries — the financial ledger is append-only and is not deleted; corrections are made by posting reversing entries, so the audit trail stays intact.
  • Biometric identifiers — as described in Section 4.
  • Messages and support — while relevant to the relationship, then deleted on a rolling basis.
  • Logs and technical data — typically 12 months.

Where we must keep a record we cannot delete, we will restrict its use to that purpose.

Section 10

Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you, and get a copy.
  • Correct information that is inaccurate or incomplete.
  • Delete your information, subject to records we must keep by law.
  • Port your information to another service in a machine-readable format.
  • Object to or restrict processing based on our legitimate interests.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Opt out of the sale or sharing of personal information — we do not sell or share it, so there is nothing to opt out of, but the right stands.
  • Not be discriminated against for exercising any of these rights.

To exercise any right, email ilove@getreadyandjump.com. We will verify your identity before acting and respond within the time the law allows — generally 30 days (GDPR) or 45 days (CCPA/CPRA), extendable where permitted. An authorised agent may act for you with proof of authority.

If you are in the EEA or UK you may also complain to your local supervisory authority. If you are in California you may have additional rights under the CCPA/CPRA, including the right to know the categories of information collected, the purposes, and the categories of recipients — all set out in Sections 2, 6 and 7 above.

Communication choices. You can turn off marketing email at any time. Transactional messages about your money, agreements and account are part of the service and cannot be switched off while your account is open.

Section 11

Security

We protect information with encryption in transit and at rest, row-level access controls in the database, scoped credentials, restricted staff access on a need-to-know basis, an append-only financial ledger, and an append-only event log of protocol activity.

Payment credentials are held by Stripe. Biometric processing happens at Stripe, not on GRAJ's systems.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials safe. If we become aware of a breach affecting your personal information we will notify you and the relevant authorities as required by law.

Section 12

Children

The Protocol is for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact ilove@getreadyandjump.com and we will delete it.

Section 13

Changes to this policy

We may update this Policy as the Protocol changes or the law requires. We will change the "last updated" date and, where the change is material, give reasonable notice by email or in the product before it takes effect.

Section 14

Contact us

Questions, requests, or complaints about privacy: ilove@getreadyandjump.com.

We will acknowledge and work with you to resolve any concern. If you are unsatisfied, you may contact your local data protection authority.