GRAFTDAY. hello@graftday.com

Privacy notice

Last updated 27 August 2026

The short version.

Graftday is a job management app for trade businesses. We hold what a business needs us to hold to run its work, we sell nothing to anyone, we show no adverts, we use no tracking, and one essential cookie keeps you signed in. Questions: hello@graftday.com.

Who we are

Graftday is run from the United Kingdom. For anything in this notice, email hello@graftday.com.

Whose data is whose

Your account with us (your name, email, business details, billing status) is ours to look after: we are the controller for it. Everything your business puts in (customers, jobs, quotes, invoices, photos, leads, signed waste transfer notes) belongs to your business: you are the controller, and we process it only on your instructions. If you are a customer of a business that uses Graftday, contact that business about your details first; we help them answer.

Passwords are stored scrambled and we cannot read them. Card numbers never touch us: billing runs through Stripe. A log of sign-ins and key account changes, with the network address each came from, is kept about a year so you can spot anyone else in your account, under Settings.

Who helps us run it

None of them may use your records for their own purposes. If you subscribe the calendar feed, your calendar provider fetches your job list; tapping a navigation or WhatsApp button hands that address or number to that app, as if you typed it there. If you create an accountant link, whoever you give it to can see your sales figures, invoices and who owes you, read only, until you switch it off in Settings.

Facebook and Instagram posting

If you connect your Facebook Page we ask Facebook for five permissions: pages_show_list, pages_read_engagement (required by Facebook alongside publishing; we never use it beyond confirming the connection works), pages_manage_posts, instagram_basic and instagram_content_publish. We store your Page's name and id, the linked Instagram account's id and username, and the access token, which is encrypted. We never read your messages, notifications, friends, feed or followers.

We publish only what you compose and approve, and only where your customer agreed to their photos being shared. A published post then lives with Meta under Meta's own terms. While publishing, the finished image is briefly reachable at an unguessable expiring link, because that is how Instagram collects it. Disconnecting in Settings deletes the stored token immediately.

How long we keep things

How it is protected

Connections use HTTPS and the app tells browsers to insist on it. Every business is isolated from every other at the database level, enforced by the database itself and tested on every release. Stored credentials are encrypted, sign-in is protected against brute force, and changing your password signs out every other device.

Your rights

You can see what we hold, correct it, delete it, object, or take it elsewhere; businesses can export their records, documents and figures from inside the app any time. Email hello@graftday.com to exercise any of this, and you can complain to the ICO at ico.org.uk.

Cookies and changes

One essential sign-in cookie, no analytics, no advertising, no tracking, hence no banner. If this notice changes in a way that matters we will say so in the app, and the date at the top is always the date of these words.