Grids ("we", "us") is operated by (營運公司名稱,上線前填入). This policy explains what personal data we collect when you use grids.tw, app.grids.tw and websites built with Grids, how we use it, and what rights you have. This policy is made under the Personal Data Protection Act of the Republic of China (Taiwan). Effective date: October 2, 2026.
1. Data we collect
- Account data: the name and email address you give when you sign up, and your password in hashed form (we cannot know your actual password).
- Content you put on the platform: website text, images, video links, details of your works, and settings.
- Payment data: your plan, the amount, the time of payment, and invoice details (Taiwan uniform invoice: Unified Business No., buyer name, and e-invoice carrier). Card numbers are handled by our payment service provider; we never receive or store them.
- Usage records: sign-in times, and IP addresses recorded briefly to prevent abuse.
- Social sign-in: when you choose to sign in with or connect LINE, Google, Facebook or Instagram, we receive only the basic data that platform provides: account ID, name, profile picture, email address (if the platform provides it), Instagram username and bio, and profile link (if you authorize it). We never receive your password and never post on your behalf. Only when you use "Import post images from Instagram" do we store your Instagram access token, encrypted, and use it to read the images you choose to import.
- Data of your website's visitors: the name, contact details and message that visitors enter in the inquiry form on your website. You (the website owner) decide the purpose of collecting this data; we keep and process it on your behalf, as entrusted by you.
2. Purposes of collection and how we use data
We use personal data only for the following purposes: providing and maintaining the service, verifying identity and keeping accounts secure, processing payments and issuing invoices, sending notices the service requires (for example password resets, new inquiries and payment results), answering your questions, preventing abuse and fraud, and matters we must handle under law.
We do not sell your personal data, and we do not use your data or your visitors' data to serve ads.
3. Retention period, location and recipients
- Period: for as long as your account exists. After you delete your account, we delete your data from our production systems within 30 days; backups are kept for at most 90 days and then overwritten. Transaction and invoice records that tax law requires us to keep are kept until the statutory retention period ends.
- Location: data is stored on the cloud hosting and database services we use; their data centers may be located outside Taiwan.
- Recipients: to provide the service, we pass the necessary data to service providers we engage, such as cloud hosting, database, email delivery and payment service providers. They may process the data only on our instructions.
- Except as described above, with your consent, or as required by law, a court or a competent authority, we do not provide your data to any third party.
4. Cookies and tracking
We use only the cookies necessary to keep you signed in. We do not use advertising tracking cookies.
Websites built with Grids do not set tracking cookies on visitors by default.
- Website analytics: websites built with Grids include built-in visitor statistics that use no cookies or other device identifiers. We combine a visitor's IP address and browser information with a random value that changes every day and is never stored, apply a one-way hash, and use the result only to count unique visitors for that day. The IP address itself is not stored; the next day the result can no longer be linked to the same visitor, and it cannot be used to track visitors across websites. The statistics record the pages viewed, the domain of the referring website, utm parameters on links, device type, browser, country (estimated by the CDN from the connection; the IP is not stored), interactions such as clicks on buttons, links and videos, and whether the inquiry form was submitted (not what was in it). This data is deleted after 400 days and is available only to that website's owner and collaborators; platform administrators see only platform-wide totals.
- A/B testing: when a website owner tests two versions of the same page, a first-party cookie (its name starts with gs_exp_; kept for 30 days) is set in the visitor's browser. It records only which version the visitor was assigned to, so the same visitor sees the same version each time. It contains no personal data and is not provided to third parties. Search engine crawlers are not assigned to a version.
If a website owner turns on Google Analytics or Meta Pixel, or embeds third-party content (for example YouTube or Vimeo), those services may set cookies under their own policies, and the website owner is responsible for informing visitors.
5. Your rights
Under Article 3 of the Personal Data Protection Act, you may exercise the following rights over your personal data with us: to make an inquiry or request to review it, to request a copy, to request supplementation or correction, to request that its collection, processing or use be stopped, and to request its deletion.
You can change or delete most data yourself in the dashboard (account settings, deleting a website, deleting your account). For other requests, email [email protected]; we will reply within 15 days.
You may choose not to provide certain data, but you may then be unable to use some features (for example, you cannot sign up without an email address).
Unlinking a social account: in "Account settings → Linked accounts", click "Unlink", and we will delete that platform's account ID, basic data and access token. You can also remove Grids' access in that platform's settings (for example Facebook "Settings → Apps and websites"). To delete an entire Grids account created with a social account, together with all its data, delete the account in "Account settings", or email [email protected] stating how you sign in; we will complete the deletion within 15 days and reply to confirm.
6. Data of your website's visitors
You are responsible for informing visitors about, and using, the inquiry data they leave on your website in accordance with the law. Grids automatically gives every website a "Privacy notice" page (at /privacy) that explains what data the form collects and why; you can create a page at the same address to replace it with your own content.
Inquiries and bookings that visitors submit on your website are kept until the website owner deletes them; the website owner can delete them in the dashboard at any time.
If a visitor asks us to look up or delete the data they left on your website, we will pass the request on to you to handle.
7. Explore, profile pages and collaboration records
- Profile page: once you set a username, grids.tw/@username shows what you have filled in: photo, cover, name, one-line intro, bio, roles, location, showreel, skills and equipment, social links, experience, awards and website, plus the works on your published websites, collaboration history you have confirmed, recommendations you have agreed to show, and public crew projects. Contact details such as email, phone and LINE are visible only to signed-in Grids users and never appear on the public page; your availability status, the list of people you follow, and unpublished content are not shown.
- Visitor analytics: when someone views your profile page, we record the number of views per day; if the viewer is signed in to Grids, we also record which account it was (once per day). Pro and Studio users can see in the dashboard the names of visitors who are listed in Explore; other visitors are counted only as a number.
- Websites and works in Explore: the first time you publish a website, we ask whether you want to show it in grids.tw/explore (Explore). If you choose to, the website and the works on it that are set to be shown appear in Explore with the website name, cover, work titles, clients, years, categories and credits, linking to your website. You can change "Show this website and its works in Grids Explore" in the website's "Settings" at any time; turning it off removes them immediately. You can also hide a single work in Works. Grids may pick works or websites for the featured section of the Explore home page.
- Creators list in Explore: you are not listed by default. Only after you turn on public visibility in "Profile" does your profile page appear in grids.tw/explore/creators, the sitemap and search engines, and under "People they've worked with" on other people's profile pages. Turning it off removes you immediately; anyone who knows the address can still see your profile page, but the page asks search engines not to index it.
- Collaboration records: other users can tag your account or email address in the credits of a work. Until you confirm it, the record does not appear on your profile page; you can decline it, and you can remove a confirmed entry from your profile page at any time in "Collaborations". If you are tagged by email address and have not signed up, we send only one notification email to that address.
- Crew projects: when you join a public crew project, your name and role appear on the project page; photos you upload can be deleted by you, and also by the project's creator.
- Following and the activity feed: who follows whom is not made public, and there are no like counts. Your follower count is hidden by default and the choice is yours: only after you turn on "Show follower count" in "Profile" does your profile page show "N followers", and you can turn it off at any time. The feed is ordered by time only. You can turn off the weekly activity digest email in "Profile".
- To delete your profile page, clear your username. Deleting your account also deletes your profile page, collaboration records, follow relationships and the photos you uploaded.
8. Data security
We protect data with encryption in transit (HTTPS), password hashing, access controls and regular backups. No system can guarantee absolute security; if a personal data breach occurs, we will notify affected users as required by law.
9. Minors
Users under 18 must have the consent of their legal representative (such as a parent or guardian) to use the service.
10. Changes to this policy
When we change this policy, we will update the effective date on this page; for material changes, we will notify you by email or by an announcement in the dashboard.
11. Contact us
(營運公司名稱,上線前填入)
Address: (公司登記地址,上線前填入)
Email: [email protected]