Privacy policy
This policy describes what we collect when you use ganttry.app and the Ganttry application, why we collect it, and what we will never do with it. The short version: your schedules are yours, we collect only what running the service requires, and we don't sell or advertise with anything.
What we collect
- Account information — the name, email address, and company name you (or the admin who invited you) provide when an account is created.
- Customer content — the schedules, tasks, notes, calendars, baselines, and related material your team creates or imports. This content belongs to your company and is visible only to the accounts your admins authorize.
- Billing records — your subscription plan, seat count, and billing status. Payments are processed by Stripe; your card number goes to Stripe directly and never touches our servers. We see only what Stripe reports back (subscription status, last-4 style summaries on invoices).
- Operational logs — IP address, browser type, sign-in and administrative events (for example account creation, password resets, schedule deletion). We keep these for security: detecting abuse, diagnosing problems, and giving your admins an audit trail. Security logs are retained for approximately 90 days.
What we don't do
- We don't sell, rent, or share your data with advertisers or data brokers.
- We don't run third-party analytics or advertising trackers on the site or in the app.
- We don't mine, train on, or otherwise use your schedules for anything except serving them back to you and your team.
- We don't send marketing email. Every message we send is transactional: invitations, password resets, and billing notices.
Cookies
The application uses a single, essential session cookie to keep you signed in. It carries a random token, nothing else, and expires after inactivity. The marketing site sets no cookies at all. Because we use no tracking cookies, there is no cookie banner — there is nothing to consent to.
Who processes data on our behalf
We use a small number of infrastructure providers, each receiving only what their function requires: Stripe (payment processing), SMTP2GO (delivery of transactional email), and Cloudflare (network routing and DDoS protection in front of our servers). Your schedule data itself is stored on servers we operate in the United States.
How we protect it
All traffic is encrypted in transit (TLS). Passwords are stored only as salted, industry-standard hashes — we cannot read them. Each company's data is strictly partitioned from every other company's, administrative actions are logged to a per-company audit trail, and nightly backups are kept on- and off-site on hardware we control.
Export and deletion
You can export everything at any time — JSON, MS Project XML, Excel, CSV, PDF — from inside the app; no request or waiting period needed. If you cancel, your schedules remain read-only for 60 days so you can take copies, then they are deleted. You can also email us to have an account or a company's data removed sooner, and we'll confirm when it's done. Data in routine backups ages out on the backup retention schedule (about 30 days).
Your rights
Wherever you are, we honor the basics: you can ask what we hold about you, get a copy, correct it, or have it deleted. Email [email protected] and a human will handle it.
Children
Ganttry is a business tool, not directed at children, and we don't knowingly collect information from anyone under 16.
Changes
If we make material changes to this policy, we'll email your account admins before the changes take effect and update the date at the top of this page.
Contact
Questions about privacy or your data: [email protected].