1. Scope and contact
For support, privacy questions, access/correction/deletion requests, waitlist withdrawal, complaints or concerns about these policies, email support@grantnivo.com. Use “Grantnivo privacy” or “Leave waitlist” as the subject and contact us from the address you registered with where possible. Do not send identity documents or sensitive beneficiary information unless we explain why a limited verification step is necessary.
This notice covers the public opportunity directory, platform/about pages, waitlist, staff administration and related support. It concerns personal information about people, including people acting for organisations. It does not turn public grant listings into confidential submissions.
The current service does not offer customer workspaces, proposal uploads or AI proposal generation. Descriptions of planned features explain the product direction. If those features launch, we will explain their data handling and any additional terms before collecting information for them. Joining the waitlist does not grant us permission to train AI models on your organisation’s materials.
2. Information we collect
- Waitlist information: your name, work email, organisation, signup source and signup time. We normalize email addresses for duplicate detection. New signups also record the acceptance time and the versions of the Terms, Privacy notice and checkbox statement presented to you. Historical signups are not automatically treated as having accepted a later policy.
- Messages you send: your contact details and the information in a support, correction, complaint or privacy request, if you contact the operator. Avoid including information about other people unnecessarily.
- Staff accounts: name, email, password hash, account/verification details and administrator permissions. Authentication uses session information and password-reset records. Passwords are not stored as readable account passwords.
- Administrative activity: staff identifiers, actions, timestamps, affected records and changes to opportunity content or account access. This supports accountability and investigation.
- Optional usage records: after you enable analytics, a random visitor identifier and hashed visitor/session identifiers, visit timestamps, opportunity identifiers and view/funder/application/learn-more click events. These records are pseudonymous, not guaranteed anonymous. The application’s analytics tables do not store raw IP addresses or user agents.
- Operational information: requests necessarily reach hosting infrastructure with an IP address, browser information, requested URL and timing. Infrastructure/session/security logs may retain these details depending on deployment settings. The application also uses an IP-derived rate-limit key to reduce repeated or abusive signup attempts. Do not confuse this operational processing with optional analytics.
- Public listing content: funder names, URLs, programme descriptions and images added by staff. These can contain publicly available professional information. Staff-supplied image URLs are fetched by the server and stored as image files; the origin host receives that server request.
Required waitlist fields and the consent checkbox are marked in the form. Without them we cannot complete the requested signup. You can browse public opportunities without joining the waitlist or accepting optional analytics.
3. Purposes and legal grounds
We use information for the purpose it was collected for. Depending on the law that applies, the relevant grounds are your consent, providing a service you request or administering a contract, legitimate operational interests balanced against your rights, and compliance with applicable legal duties.
- Waitlist administration and emails: register your interest, prevent duplicate entries, manage invitations and send the waitlist updates you request. Your checkbox choice is recorded as evidence of that request. It is not permission for unrelated advertising.
- Optional analytics: understand visits and opportunity engagement only after you choose to enable it. Necessary operation, security and form protection remain available without this choice.
- Service delivery and support: display opportunities, provide staff access, respond to requests and maintain the website.
- Security and accountability: authenticate staff, prevent abuse, audit changes, investigate incidents and protect the service and its users.
- Legal matters: respond to valid legal requirements, protect rights and establish or defend legal claims where necessary.
We do not use waitlist information to make automated funding, employment, credit or other similarly significant eligibility decisions. Funders independently decide their own applications. We do not sell waitlist contact information, publish it in the opportunity directory or supply it to funders as an application.
4. Waitlist, consent and email choices
The checkbox asks you to accept the Terms, acknowledge this notice and request waitlist emails. Acknowledging this notice does not waive your data rights or make every processing activity consent-based. Analytics is a separate choice. The waitlist is free and does not create a paid subscription.
Waitlist communications may include signup administration, early-access availability, invitations, changes affecting your participation and relevant launch progress. We do not treat signup as consent to unrelated marketing or to marketing by a funder or partner. Any materially different optional communication should have its own choice.
You can withdraw your request for future waitlist emails or ask to leave the list using the contact details above. Withdrawal does not invalidate processing that lawfully occurred earlier. It does not require you to accept optional analytics. We may need limited confirmation that a request comes from the registered person before changing or deleting their information.
A duplicate attempt shows that the submitted email is already registered; it does not disclose the registered name or organisation or overwrite those details. If the email is yours and you need to correct the entry, contact us. A service provider delivering email may process delivery and error information; provider-specific practices must be checked against the operator’s actual mail configuration.
5. Cookies, preferences and usage measurement
Necessary session and anti-forgery cookies support navigation, staff sign-in and secure forms. A preference cookie remembers whether you accept or decline optional analytics. The optional visitor cookie is used only after analytics is enabled. Details and controls are in our Cookie Policy & Preferences.
You can change your choice there at any time. Declining stops future optional analytics recording and removes the visitor cookie through this browser. It does not automatically delete historical server records. The application also suppresses analytics when it receives Do Not Track or Global Privacy Control signals, for staff traffic and for recognized bots. This is not a claim that those signals govern every third-party service you visit.
Third-party funder websites are separate services. Following an external link can reveal your IP address and browser information to that destination. The application does not append your waitlist details to these links. Older externally hosted images, fonts or infrastructure services may also receive the requests needed to deliver their resources; blocking optional analytics does not prevent all network communication needed to load a page.
6. Sharing and international processing
Access is limited to staff who need it and service providers supporting hosting, storage, database operations, email delivery, security and maintenance. Providers receive only the information required for their role and must be selected and instructed appropriately. We may disclose information when required by a valid legal process or when reasonably necessary to protect safety, rights or the service. A business reorganisation may involve a controlled transfer subject to applicable protections and notice requirements.
Hosting, backup and email providers may process information in countries other than yours. Applicable safeguards depend on the countries and law involved and may include contractual and organisational measures. This notice does not claim a particular hosting region, certification or transfer agreement that the operator has not verified. Contact the operator for the current provider locations and relevant safeguards before supplying information if these matter to your organisation.
We do not give funders access to the waitlist simply because their opportunity appears here. Applications you submit directly to a funder are governed by that funder’s notice and terms, not this notice.
7. Retention and deletion
Retention depends on the purpose, whether you remain on the waitlist, legal obligations, security needs and whether a dispute or request remains open. The operator must review these needs and avoid keeping identifiable information after it is no longer needed.
- Waitlist: information is held while managing your requested participation, unless you withdraw or request deletion. Limited consent, withdrawal or suppression evidence may need to remain to respect your choice or establish what was agreed. It must not be reused as a marketing list.
- Analytics: the browser identifiers have the lifetimes described in the Cookie Policy. Cookie expiry is not automatic deletion of database analytics. The current application has no scheduled analytics-retention purge; an operational retention and deletion schedule must be maintained separately.
- Staff and security records: account data, logs and audit evidence may be needed during authorised access and afterwards for security, legal or accountability purposes. Ending staff access is distinct from erasing the audit history.
- Images and opportunities: an archived opportunity keeps its image so it can be restored. Replacing an image removes the previous file after a successful save. Public information may still exist in search caches or copies held by others.
- Backups and legacy archives: copies may remain until a controlled backup expiry or recovery cycle completes. Any earlier confidential workspace archive is encrypted and is not made public or reactivated by waitlist signup. Recovery and legal holds can limit immediate deletion.
A request is not fulfilled merely by hiding a row from an interface. Where deletion cannot be completed immediately or some information must be retained, the operator should explain the reason, scope and applicable next steps. This policy does not promise an automatic deletion deadline that the application does not implement.
8. Security
The application uses staff access controls, repeated authorization checks, password hashing, validation, request throttling, anti-forgery protection and administrative audit records. Deployment must also provide HTTPS, restricted database/storage access, protected secrets, suitable backups, patching and monitoring. No internet service or security measure can guarantee that every incident will be prevented.
Report suspected misuse through the contact above. Do not include passwords or unnecessary sensitive material. If a personal-data incident requires notification under applicable law, the operator must assess and meet that obligation. We do not promise a certification or security audit that has not been performed.
9. Your rights and complaints
Depending on your location and applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability and withdrawal of consent. These rights can have exceptions; they are not identical in every jurisdiction. You can ask what information is held, how it is used, who receives it and how to exercise the rights available to you.
Send a request using the contact above, describe what you need and identify the email involved. We should verify identity proportionately and respond within the applicable legal timeframe, explaining any lawful limitation. You may complain to the relevant data-protection authority without first waiving other rights. For example, Ghana’s Data Protection Commission and the UK’s Information Commissioner’s Office explain rights in their jurisdictions. These links do not assert that either regime applies to every visitor.
10. Children and sensitive information
The service is intended for adults working with organisations. Do not sign up on behalf of a child or enter beneficiary case files, health information, government identifiers, bank details, passwords or other sensitive personal information into the waitlist. If you believe such information or a child’s information has been supplied, contact us so it can be assessed and addressed appropriately.
11. Changes and contact
This notice is version 2026-08-31. We will update the date and explain material changes where required. A later notice does not retroactively establish consent for a new purpose. New features, providers or uses must be assessed before launch, with additional choices where appropriate.
For support, privacy questions, access/correction/deletion requests, waitlist withdrawal, complaints or concerns about these policies, email support@grantnivo.com. Use “Grantnivo privacy” or “Leave waitlist” as the subject and contact us from the address you registered with where possible. Do not send identity documents or sensitive beneficiary information unless we explain why a limited verification step is necessary.