Cresco Grants

Privacy Policy

Version 1.0 · Effective 2026-07-21 · Last updated 2026-07-21

This Privacy Policy explains how Cresco Grants (Cresco Group Holdings Ltd) collects, uses, stores, and protects personal information when you use our grant intelligence platform at https://grant-inteligent-platform.vercel.app.

1. Who we are

Controller: Cresco Group Holdings Ltd, trading as Cresco Grants.
Registered country: United Kingdom.
Contact address: United Kingdom (registered office address available on request from privacy@crescogrants.com).Company number: 16677374.
Privacy contact: privacy@crescogrants.com.
Support: support@crescogrants.com.

2. Scope

This policy applies to visitors, registered users, and organisation administrators who useCresco Grantsto discover, assess, prepare, and manage grant opportunities. It does not cover third-party grant funders, payment processors' own privacy notices, or websites we link to.

3. Personal information we collect

We may collect the following categories of information:

  • Account and profile: name, email address, job title, timezone, password hash, authentication identifiers, and session metadata.
  • Organisation and grant workflow: organisation name, sector, mission, eligibility-related profile fields, applications, deadlines, matches, notes, and team membership.
  • Documents and content you upload: files and text you submit for grant applications, reviews, and AI-assisted drafting (subject to your permissions).
  • Technical and device data: IP address, browser type, device identifiers sent by your browser, request timestamps, and diagnostic logs.
  • Security logs: login attempts, CSRF validation events, rate-limit events (using hashed client identifiers), and audit entries for sensitive actions.
  • Billing (if applicable): subscription status, Stripe customer and payment references; we do not store full card numbers.
  • Communications: support requests, email delivery metadata, and product notifications you opt into.

4. How we use information

We use personal information to:

  • provide, secure, and improve the platform;
  • authenticate users and enforce access controls;
  • match grants and generate recommendations and drafts you request;
  • process subscriptions and usage limits;
  • send service, security, and (where permitted) product communications;
  • comply with law and respond to lawful requests.

5. Lawful bases (UK GDPR)

Depending on the activity, we rely on:

  • Contract — to deliver the service you sign up for;
  • Legitimate interests — security, fraud prevention, product improvement, and B2B administration, balanced against your rights;
  • Consent — where required (for example optional marketing emails);
  • Legal obligation — where we must retain or disclose data.

6. Service providers and subprocessors

We use vetted providers for hosting, database, storage, email, payments, monitoring, and AI processing. They process data only on our instructions and under appropriate contracts. Typical categories include cloud hosting (for example Vercel), database and object storage (for example Supabase), email (Resend), payments (Stripe), error monitoring (Sentry when enabled), and AI model providers when you use AI features. A current subprocessor list is available on request from privacy@crescogrants.com.

7. International transfers

Your data may be processed in the United Kingdom, European Economic Area, United States, or other countries where our providers operate. Where required, we use appropriate safeguards such as UK IDTA/SCCs or equivalent mechanisms.

8. Retention

We retain personal data while your account is active and for a limited period afterwards for backup, billing, dispute resolution, and legal compliance. Retention periods vary by data type and are reviewed periodically.

9. Security

We implement technical and organisational measures including encryption in transit, access controls, audit logging, and secure session handling. No method of transmission or storage is completely secure; we work to reduce risk proportionate to the data we hold.

10. Automated processing and AI

The platform may use automated matching, scoring, and AI-assisted drafting. Outputs are assistive and require human review. We do not make solely automated decisions with legal or similarly significant effects without appropriate safeguards and transparency.

11. Your rights

Under UK GDPR you may have rights to access, rectify, erase, restrict, object, and port certain data, and to withdraw consent where processing is consent-based. Contact privacy@crescogrants.com. You may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

12. Cookies and similar technologies

We use essential cookies and similar storage only for core functionality:

  • grant_session — HttpOnly authentication session (essential).
  • grant_csrf — cross-site request forgery protection (essential).

We do not use non-essential analytics or advertising cookies in the application at this time. The client may cache a CSRF token in memory for API requests and use localStorage for onboarding UI preferences (for example dismissing a checklist); these are not used for cross-site tracking. No cookie consent banner is required while only essential technologies are used.

13. Children

The service is intended for organisations and professionals. It is not directed at children under 16, and we do not knowingly collect their data.

14. Changes

We may update this policy. Material changes will be communicated via the service or email where appropriate. The version and dates below identify the current policy.

Document version 1.0 · Effective 2026-07-21 · Last updated 2026-07-21. See also our Terms of Service.