Privacy Policy
Last Updated: August 3, 2026
Welcome to Ngris. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS product. ngris (registered form and address pending) is the controller of the personal data described here, and we process this data in the European Union under the General Data Protection Regulation (GDPR) as our primary framework.
1. Information We Collect
We may collect personal information that you provide to us directly, as well as information that is automatically collected when you use our service.
- Account Information: When you create an account, we collect your name, email address, and password.
- Payment Information: If you subscribe to a paid account, we collect payment information via our payment processor (Stripe). We never store raw card numbers on our servers.
- Usage Data: We automatically collect information about your interactions with our service, such as the features you use and the pages you visit.
2. Cookies & Analytics
We use strictly necessary cookies to run the service (session, security) and — only with your consent — Google Analytics 4 to understand aggregate, non-identifying usage (GA may collect a pseudonymous identifier, IP-derived approximate location, and device/usage data). Analytics cookies are disabled by default in the EEA, the UK and Switzerland until you accept them, and we honor the Global Privacy Control opt-out signal. You can change your choice at any time via Cookie settings. Our lawful basis is your consent for analytics, and contract performance / our legitimate interest in operating a secure service for necessary cookies. See the Cookie Policy for the full list.
3. How We Use Your Information
We use the information we collect to provide, operate, and maintain our service, to process your transactions, and to communicate with you about your account.
3.1 Marketing Communications (draft — pending counsel review)
We send marketing emails — such as product updates, tips, re-engagement/win-back messages, and occasional offers. How we treat your marketing preference depends on the country associated with your account, which we determine from your approximate location (geo-IP) at the time you sign up. If we cannot reliably determine your country, we treat you as an opt-in-required user and do not send marketing email unless you actively opt in.
Opt-in regions — European Union / EEA, United Kingdom, Switzerland, and Canada. If you sign up from one of these regions, we send marketing email only where you have given us your prior, explicit, opt-in consent. The marketing consent checkbox at sign-up is optional and unchecked by default — we use no pre-ticked boxes — and creating an account or using the service never requires it. You can also opt in later, and manage your choice at any time, from Email Preferences in your account settings. Our lawful basis for these messages is your consent (GDPR Art. 6(1)(a) and Art. 7 and applicable ePrivacy rules in the EEA/UK; the Swiss Federal Act on Data Protection (FADP) in Switzerland; and Canada's Anti-Spam Legislation (CASL) in Canada).
Opt-out regions — United States and the rest of the world. If you sign up from outside the opt-in regions above, we may send you marketing email by default (you are enrolled at sign-up based on your sign-up country), and you can opt out at any time. Every marketing email carries a working one-click unsubscribe — an RFC 8058 one-click List-Unsubscribe mechanism, a footer unsubscribe link (no login required), and a link to your preference center. We honor unsubscribe requests immediately by adding you to a suppression list and stopping further marketing email. Our basis for this default-in model is compliance with the U.S. CAN-SPAM Act and equivalent local rules; where GDPR or another opt-in regime applies to you, the opt-in rules above govern instead.
Everyone, everywhere. Regardless of your region, you can opt out of marketing at any time (one-click, no login) or opt in via Email Preferences, and we act on your choice promptly. Withdrawing consent or opting out does not affect the lawfulness of any marketing we sent beforehand. Note: accounts created via single sign-on (SSO) are currently treated as opt-in-only and are not enrolled by default, even in opt-out regions — a known current limitation. (Pending counsel review.)
Some emails are not marketing and are sent regardless of your marketing preferences because they are necessary to operate your account or provide the service you asked for — for example email address verification, password resets, billing and invoice notices, security alerts, and other account, service, and lifecycle-activation messages. Our lawful basis for these is performance of our contract with you and/or our legitimate interests in operating a secure, functioning service (GDPR Art. 6(1)(b) and 6(1)(f)); these messages are transactional and fall outside marketing-consent and unsubscribe requirements under the applicable rules above.
4. How We Share Your Information
We may share your information with service providers who process it on our behalf — including Stripe (payments), our email provider, and, where you consent, Google (Google Analytics 4). We may also share information in connection with a merger, sale of company assets, or other business transfer. We do not sell your personal information.
5. Where Your Data Is Stored & International Transfers
We store and process your personal data in the European Union. We do not routinely transfer personal data outside the EU. A limited number of sub-processors may process specific data outside the EU where their service requires it — most notably our payment processor, Stripe, and, only where you consent to analytics, Google (Google Analytics 4). Where personal data is transferred outside the EEA/UK in those cases, we rely on an adequacy decision, the EU-U.S. Data Privacy Framework, and/or the Standard Contractual Clauses as the transfer mechanism, together with any required supplementary measures.
6. Data Security
We use administrative and technical security measures to help protect your personal information. Data in transit is encrypted using TLS 1.3, and sensitive stored data (such as auth tokens and endpoint credentials) is encrypted at the application layer. See our Security page for more detail.
7. Data Retention
Inspector request data is retained based on your plan's retention window (24 hours to 30 days). Account data is retained for the duration of your account and deleted within 30 days of account closure, except where required by law.
8. Your Rights & Choices
Depending on where you live, you have the right to access, correct, delete, or port your personal data, and to object to or restrict processing. EEA/UK residents may withdraw analytics consent at any time via Cookie settings and may lodge a complaint with a supervisory authority.
Marketing opt-out: you can stop marketing email at any time, wherever you live — via the one-click unsubscribe link in any marketing email (no login required) or from Email Preferences in your account settings — and we honor it promptly. Whether we send marketing by default or only after you opt in depends on your region: opt-in is required in the EEA, UK, Switzerland, and Canada, while a default opt-out model applies in the US and rest of world (see §3.1). Account, service, security, billing, and other transactional emails necessary to operate your account are always sent. (Draft — pending counsel review.)
California (CCPA/CPRA): you have the right to know, delete, and correct your personal information and to opt out of any "sale" or "sharing." We do not sell personal information; the use of analytics cookies may be considered "sharing" — opt out via Cookie settings ("Do Not Sell or Share"), and we honor Global Privacy Control signals. To exercise any right, contact us at the email below.
9. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, contact us at privacy@ngris.com — an actively monitored address. Business customers can reach our data protection team for DPA and data-subject matters at dpa@ngris.com.