What we collect, why, who it goes to, how long we keep it, and what you can do about it. Named providers, not 'trusted partners'.
This Privacy Policy explains how GRAJ ("GRAJ", "we", "us") collects, uses, shares, and protects personal information when you use getreadyandjump.com and the GRAJ Protocol (the "Protocol").
For data protection purposes GRAJ is the controller of the information described here. Where you transact with another participant, that participant is an independent controller of the information they receive about you, and their own practices govern what they do with it.
Contact us about privacy at ilove@getreadyandjump.com.
Account and profile. Name, preferred name, email, phone, password credentials, handle, role, business name, logo and images, bio, location (city/state/country), and the entities you operate.
Addresses. Home and shipping addresses, used for deliveries, samples, tax determination, and correspondence.
Identity and verification. Date of birth, nationality, government identification, and — where you use identity verification — a photograph of your identity document and a selfie, which are processed as biometric identifiers by our verification provider to confirm you are the person on the document. See Section 4.
Background checks. Where you request or consent to one, the results of a background check performed by a consumer reporting agency. See Section 5.
Business and compliance documents. Tax forms (such as a W-9), EIN, business licences, certificates of insurance, resale certificates, food-safety and other permits, and signed agreements.
Financial. Bank and payout details held by our payment processor, transaction history, amounts owed and paid, protocol fees, funding arrangements and repayment schedules. We do not store full card or bank account numbers — those sit with Stripe.
Work and proof. Records of work performed and the evidence attached to it, which may include photographs, GPS coordinates, timestamps, signatures, and the name of the person who received goods.
Communications. Messages between participants on the Protocol, notifications, support correspondence, and — where used — SMS.
AI interactions. The prompts you send to AI assistants, the context of the transaction or page you are on, and the responses generated.
Technical and usage. IP address, device and browser information, pages viewed, actions taken, timestamps, and cookies (see the Cookie Policy).
Location. Approximate location from your IP, coordinates you supply on your profile, and — where you enable it for delivery or proof features — device location.
If you complete identity verification, biometric information about you is processed. Our provider, Stripe Identity, compares a photograph of your government identification with a selfie you take, generating facial-geometry data to confirm they are the same person.
Purpose. Solely to verify your identity, prevent fraud and impersonation, and meet the identity requirements that apply to moving money. It is not used for advertising, profiling, or training AI models, and we do not sell it or otherwise disclose it for anything other than performing verification.
Consent. Identity verification is optional and initiated by you. You will be asked to consent before any biometric processing occurs. You can decline — but some capabilities, particularly receiving payouts, may be unavailable without verification.
Who holds it. The images and biometric data are processed by Stripe under Stripe's privacy terms. GRAJ receives the verification outcome and limited details — not your biometric template.
Retention. Biometric identifiers are retained no longer than needed for the verification purpose, and in any event are destroyed when that purpose is satisfied or within three years of your last interaction, whichever comes first.
Residents of Illinois, Texas, Washington and other states with biometric privacy statutes have specific rights under those laws; contact us at ilove@getreadyandjump.com to exercise them.
Where you request or consent to a background check, it is performed by a consumer reporting agency and the resulting report is a consumer report under the US Fair Credit Reporting Act (FCRA).
We will obtain your written authorisation before ordering one and provide the disclosures the FCRA requires. If information in a report would lead to an adverse decision about your participation, you will receive the required pre-adverse and adverse action notices, a copy of the report, and a summary of your rights — including the right to dispute the accuracy of the information with the agency that supplied it.
Background-check results are used only to assess trust and eligibility on the Protocol, are visible only to GRAJ and to you, and are not published to other participants. A participant may see that you are verified; they do not see the underlying report.
To operate the Protocol — create and run your account, connect you with counterparties, record agreements, compute what is owed, and move money. Basis: performance of a contract.
To verify identity and prevent fraud — verification, screening, monitoring for abuse, and protecting participants from loss. Basis: legitimate interests; legal obligation; your consent for biometric processing.
To meet legal and financial obligations — tax reporting, sanctions and anti-money-laundering screening, recordkeeping, and responding to lawful requests. Basis: legal obligation.
To provide AI features — generate responses, draft text you request, and answer questions in context. Basis: performance of a contract; legitimate interests.
To communicate — transactional notifications about your agreements, work, money and account; service announcements; support. Basis: performance of a contract; legitimate interests.
To improve and secure the Protocol — diagnostics, aggregate analytics, debugging, and security. Basis: legitimate interests.
Marketing — only where you have opted in, or as otherwise permitted, and you can withdraw at any time. Basis: consent; legitimate interests.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
We do not use your content to train third-party AI models. AI features are delivered through Anthropic's API, which does not train models on data submitted through it.
Other participants. The Protocol is shared infrastructure two parties trade on, so some information is shared by design: your public profile, and — with a counterparty you transact with — the details of your agreement, work records, proof you submit, messages, and amounts owed or paid. Consider proof carefully: a photograph or GPS coordinate you attach will be visible to the counterparty.
Service providers (subprocessors). We use:
Each is bound by contract to use the information only to provide its service to us.
Minor third-party utilities. Some pages generate a QR code through an external QR service; the only thing sent is a GRAJ link (for example the address of a sample bag or kiosk), never your personal information. We also source stock and country photography from Unsplash — that sends a search term, nothing about you.
Not subprocessors. Some services we use never touch participant personal information and are therefore not listed above — for example GitHub, which hosts our source code. Our source code contains no participant data.
Legal and safety. We may disclose information where required by law, subpoena, or regulator; to establish or defend legal claims; or to protect the rights, safety and property of participants, the public, or GRAJ.
Business transfers. If GRAJ is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a materially different policy.
GRAJ operates from the United States and our providers may process information in the United States and other countries. Those countries may not provide the same level of protection as your own.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses and the UK Addendum — together with additional measures where required. Contact ilove@getreadyandjump.com for details.
We keep personal information for as long as your account is active and afterwards only as long as needed for the purposes described here.
Where we must keep a record we cannot delete, we will restrict its use to that purpose.
Depending on where you live, you may have the right to:
To exercise any right, email ilove@getreadyandjump.com. We will verify your identity before acting and respond within the time the law allows — generally 30 days (GDPR) or 45 days (CCPA/CPRA), extendable where permitted. An authorised agent may act for you with proof of authority.
If you are in the EEA or UK you may also complain to your local supervisory authority. If you are in California you may have additional rights under the CCPA/CPRA, including the right to know the categories of information collected, the purposes, and the categories of recipients — all set out in Sections 2, 6 and 7 above.
Communication choices. You can turn off marketing email at any time. Transactional messages about your money, agreements and account are part of the service and cannot be switched off while your account is open.
We protect information with encryption in transit and at rest, row-level access controls in the database, scoped credentials, restricted staff access on a need-to-know basis, an append-only financial ledger, and an append-only event log of protocol activity.
Payment credentials are held by Stripe. Biometric processing happens at Stripe, not on GRAJ's systems.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials safe. If we become aware of a breach affecting your personal information we will notify you and the relevant authorities as required by law.
The Protocol is for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact ilove@getreadyandjump.com and we will delete it.
We may update this Policy as the Protocol changes or the law requires. We will change the "last updated" date and, where the change is material, give reasonable notice by email or in the product before it takes effect.
Questions, requests, or complaints about privacy: ilove@getreadyandjump.com.
We will acknowledge and work with you to resolve any concern. If you are unsatisfied, you may contact your local data protection authority.