What this covers
This policy covers modgr.id, run by modgrid LLC. It applies both to creators with a page here and to anyone who opens one.
What we collect
When you join the waitlist
Your email address, and optionally the handle you want and your handle elsewhere. If you arrived from a creator’s page we record which one, because knowing where creators come from is how we decide who to build for next.
When you have an account
Your sign-in details are held by our authentication provider, not by us — we store the identifier they give us, your email, and your handle. If you signed in through a social account, we see the name, email and profile picture it hands over, and nothing else about it.
What you put on your page
Everything you type or upload: your bio, your builds, your photos, your parts and prices, your links and your codes. That is the product, and it is public by design once you publish it.
What the site records by itself
Events on public pages — a view, a link click, a code copied, a part tapped — and, on our own screens, how the product itself is used. What each of those records is set out below.
Page analytics
We count what happens on public pages so creators can see what is working. Each event stores:
- What happened, and what it happened to — which link, code, build or part.
- The page it happened on, and the site you arrived from.
- Your country and city, worked out at the network edge by our host from the connection — the city is as precise as it gets.
- Your browser’s user-agent string, and whether that reads as a phone, a tablet or a desktop.
- A random identifier stored in a cookie on your device, so a creator can tell one visitor returning from two different people. It is not derived from anything about you and it is not shared with anyone.
- Campaign tags (
utm_sourceand friends), where the link that brought you carried them.
We do not store IP addresses. Addresses are used in the moment to work out roughly where a request came from and to stop one machine hammering a form — for the second we keep only a one-way hash, so there is no address in the database to hand over or to lose.
Product analytics
We also use PostHog, a product analytics service, to understand how modgr.id itself is used: which screens people reach, where a sign-up stalls, whether a feature gets used. It works for us as a processor and for nothing else — no ad networks, no fingerprinting, no profiles of you across other sites. It records the same kinds of event described above, plus the page you were on and how you got there, and it drops your IP address the moment your country has been worked out. Until you create an account it knows you only as a random identifier; once you have one, that identifier is joined to your account so we can see the product as you experienced it.
On our own screens — sign-up, onboarding and the studio — it may also record how the interface is used, as a replay of clicks and scrolling. Everything you type is masked out of it, and it never records a creator’s public page.
Cookies
We use as few as we can, and none of them for advertising.
- Session cookies — set by our authentication provider so you stay signed in.
- A visitor identifier— a random value, set when a public page reports its first event, kept for a year, and used only to distinguish one visitor from another in a creator’s own counts.
- An analytics identifier — set by PostHog, a random value kept for a year so a return visit is not counted as a new person. It identifies nobody until an account is joined to it.
- A claim token — set for thirty days when you open a private invite link, so the page knows the invitation is yours. It is moved out of the URL and into a cookie deliberately: a token left in the address bar leaks to every site you click through to.
- A handle you picked — held for an hour so the handle you chose survives the trip out to sign-up and back.
If you’re visiting a creator’s page
The creator can see the totals: how many views, which links were clicked, which codes were copied, which countries people came from. They cannot see who you are, and neither can we — there is no name, email or address attached to any of it.
When you tap through to a shop, you leave modgr.id and that shop’s own privacy policy takes over. We have no control over what they do.
Why we’re allowed to hold it
If you are in the UK, the EU or somewhere with similar law, our lawful bases are: contract, for everything needed to give you the account and page you asked for; legitimate interests, for keeping the service up, preventing abuse, and counting page events so creators get the analytics the product exists to provide; and consent, where you gave it — such as joining the waitlist.
We are in the United States and your information is processed there. Where transfers out of the UK or EEA need a legal mechanism, our providers use the Standard Contractual Clauses.
Who else sees it
We do not sell your information, and we never will.We also do not use your content or your analytics to train machine learning models, ours or anyone else’s.
We use a small number of providers to run the service:
- Clerk — accounts and sign-in.
- Neon — the database everything is stored in.
- Vercel — hosting, and the edge that serves pages.
- Cloudflare R2 — the photos you upload.
- Resend — the emails we send you.
- PostHog — product analytics: how modgr.id itself is used.
Each of them only gets what they need to do their job. Beyond that we disclose information only when the law requires it, or if the business were ever sold or merged — in which case this policy follows the data, and we would tell you before anything changed.
How long we keep it
- Your account and page: until you delete them.
- Page event records: kept while they are useful to a creator’s analytics, and deleted with the page they belong to.
- Product analytics events: up to a year.
- Waitlist entries: until you ask us to remove yours.
- Abuse-prevention counters: minutes, then they expire.
Backups are cycled, so a deleted item can persist in one for a short while.
Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live you may also have the right to restrict or object to certain processing, to take your data elsewhere in a portable form, and to complain to your local data protection authority.
Email support@modgr.id and we will answer within thirty days. We will not charge you for it, and we will not make the service worse for you because you asked.
Children
modgr.id is not for under-13s and we do not knowingly collect anything from one. If you believe a child has given us information, email us and we will delete it.
Changes
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your information, we will email accounts it affects rather than quietly editing the page.
Contact
Anything at all: support@modgr.id.