Privacy Policy
Last updated 29 July 2026.
This describes what GrantsFeed actually collects — written from the code that runs the site, not from a template. GrantsFeed is operated by Tesserra, the data controller for the purposes of the UK GDPR and EU GDPR. Reach us at hello@grantsfeed.com.
The short version
- You can use the whole site without giving us anything. Browsing, searching, filtering, the feeds, and the public statistics API need no account and no email address.
- We set no cookies. None — not for analytics, not for preferences, not for sessions. We store nothing in your browser's local storage either. That is why you see no cookie banner: there is nothing to consent to.
- We do not log your IP address or your browser user-agent. The application never reads them.
- No advertising networks, no tracking pixels, no data brokers, no third-party marketing tags. We do not sell or rent personal data, and we never will.
- The only personal data we hold is what you type into a form: essentially, an email address.
What we collect, and why
1. Email alerts
When you subscribe we store your email address and the filters you chose — sector, region, amount band, audience, opportunity type — plus your chosen frequency, the date you signed up, the date we last emailed you, and a random unsubscribe token. The filters are how we decide what to send you; without them we would have to send you everything.
Lawful basis: consent, which you give by submitting the form and can withdraw at any time with the one-click unsubscribe link in every email.
2. Enquiry and waitlist forms
The “help me apply” form, the alerts waitlist, and the data-API enquiry form store your email address, which form you used, the opportunity you were looking at (where relevant), and any note you type — so please do not put anything sensitive in that box. Where a form offers an introduction to a grant or bid writer, we record whether you ticked that box, and we only pass your details to a partner if you did.
We are emailed a copy of your enquiry so we can respond, and that notification includes the page you submitted from. Submitting the “help me apply” form also starts a matching weekly alert; the reply we send you says so and carries an unsubscribe link.
Lawful basis: consent for the alert and for any partner introduction; our legitimate interest in answering an enquiry you sent us, for the reply itself.
3. Unsubscribes
When you unsubscribe we keep your email address on a suppression list, along with the reason (you asked, it bounced, or it was reported as spam). This may look counter-intuitive, but deleting the record entirely would destroy the only evidence that you asked us to stop — and a later signup path could then quietly put you back on the list. The suppression list is checked before any email is ever added. It is used for nothing else.
Lawful basis: legal obligation and legitimate interest — honouring and evidencing your opt-out.
4. API keys
For data-API customers we store a customer or organisation label, the plan, and the dates the key was created, first used, expired, or revoked. We store only a SHA-256 hash of the key itself plus its last eight characters — the raw key is shown once at issue and is never written to our database, so we cannot recover it for you, only replace it. We record the time of last use to run the trial clock; we do not build a log of your individual queries.
Lawful basis: performance of our contract with you.
5. Analytics
We use Vercel Web Analytics, which is cookieless and does not track visitors across sites or sessions. It gives us aggregate page views, referrers, and countries. We cannot identify you from it and it is not joined to anything else we hold.
Lawful basis: legitimate interest in understanding, in aggregate, which pages are useful.
Who processes it
A short list, because we keep the stack small:
- Vercel — hosting, serverless functions, and the cookieless analytics above.
- Supabase — the managed PostgreSQL database where the records described above are stored.
- Resend — sends the alert emails, the auto-replies, and our internal notifications.
- ImprovMX and Google (Gmail) — forward and hold mail sent to our addresses, so anything you email us lives in an ordinary mailbox.
These providers act as processors on our instructions. Some are based in, or route data through, the United States; transfers out of the UK/EEA rely on the providers' standard contractual clauses. We do not sell, rent, or share personal data for anyone else's marketing. We will disclose data if the law genuinely requires it.
How long we keep it
- Subscriptions — until you unsubscribe or ask us to delete them.
- Enquiries — while we are dealing with them and for a reasonable period afterwards; ask and we will delete yours.
- Suppression list — indefinitely, by design, for the reason given above. Asking to be erased from it would put you back at risk of being emailed, so we will explain the trade-off before acting on such a request.
- API key records — for the life of the account and then as long as we need them for billing and tax records.
Your rights
Depending on where you live, you can ask for a copy of the data we hold about you, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw consent at any time. Email hello@grantsfeed.com and we will action it within 30 days — in practice, much faster, because the volume is small and there is no account system to untangle. Unsubscribing needs no email to us at all: the link is in every message we send.
If you are in the UK or EEA and think we have got this wrong, you may complain to your national data protection authority — in the UK, the Information Commissioner's Office. We would rather you told us first.
Children
GrantsFeed is aimed at organisations and professionals. It is not directed at children, and we do not knowingly collect their data.
The funding data itself
The opportunities we list come from official open-data feeds and may name the officials or organisations that published them. That information is published by those bodies, not by us — we only aggregate what they already make public. How we source and handle it is set out on our methodology and data sources pages. If a record about you is wrong, the origin needs to fix it at source, but tell us and we will correct our copy.
Changes
If we change this policy the date at the top will change, and for anything material we will say so in the next alert email rather than change it quietly. These terms sit alongside our terms of service.