This Privacy Policy explains how TurfGrown LLC, doing business as Fresh Cut Boards (“we”, “us”), handles personal information when you visit freshcutboards.com or use the Fresh Cut Boards service.
Two roles matter here. For the website and your account, we decide how personal information is used (we are the “controller”). For the content your organization puts into the service — documents, evidence, vendor answers, staff and vendor contact details — your organization is in charge and we process it on its behalf under our Data Processing Addendum. If your question is about data your employer or a customer entered, contact them first; we'll help them respond.
1.What we collect
You give us:
- Account details: your name (if you provide one) and email address.
- Organization details: organization name, email domains you verify, join settings, and the groups each member belongs to.
- Messages you send us (for example to support@freshcutboards.com).
Your organization puts into the service (we process it for them):
- Documents, policies, controls, evidence files and links, obligations, audit dates, comments.
- Vendor records, vendor contacts' names and email addresses, questionnaire answers and uploaded files.
- An audit log of actions taken in the organization (who did what, and when).
- When a vendor first opens a questionnaire link (so the requesting organization can see it was received).
Collected automatically:
- A small number of strictly necessary cookies to keep you signed in, protect forms and remember which organization you're working in — see the Cookie Notice. We use no analytics, advertising or tracking cookies and no third-party trackers.
- To prevent abuse of sign-in emails, we keep short-lived counters keyed by email address and network (IP) address. They are deleted within about two days.
- Our hosting provider keeps standard server logs (such as IP address, time and requested page), and our application logs can include email addresses — for example when a sign-in email is throttled. We use them only for security and operations.
2.How we use it
- To provide the service: sign you in, run your organization's workspace, send the emails the product sends (sign-in links, invitations, questionnaires, reminders, approval notices).
- To keep it secure: rate limiting, abuse prevention, investigating incidents, keeping audit trails.
- To support you and tell you about important changes to the service or these policies.
- To meet legal obligations and enforce our Terms.
3.What we don't do
- We don't sell personal information, and we don't “share” it for cross-context behavioral advertising.
- We don't use customer content to train AI models or for advertising.
- We don't send marketing email from the product.
- We don't knowingly collect information from children; the service is for business use by adults.
4.Legal bases (EEA, UK and similar laws)
Where these laws apply, we rely on performing our contract with you (running the service), our legitimate interests (security, abuse prevention, improving reliability) balanced against your rights, compliance with legal obligations, and consent where we ask for it.
6.How long we keep it
- Account and organization data: while the account or organization is active.
- Customer content: until your organization deletes it, or 30 days after the organization closes (then deleted from the live service; backups roll off on their normal schedule).
- Sign-in links expire after 24 hours and work once; expired links are purged daily. Sessions last 12 hours.
- Your user account: until you ask us to delete it. When we delete an account we remove your name and email and keep anonymized audit entries, so organizations' records stay intact.
- Messages you send us: up to 3 years, then deleted unless needed for a legal claim.
- Database backups: kept by our provider for up to 7 days.
- Sign-in rate-limit counters: about two days.
- Server logs: per our hosting provider's retention.
7.Your rights and choices
Depending on where you live (for example under the New Jersey Data Privacy Act, the California Consumer Privacy Act, or the GDPR), you may have the right to access, correct, delete or receive a copy of your personal information, and to opt out of the sale of personal information, targeted advertising or profiling (we don't do these). You can also appeal a decision we make about your request.
Email privacy@freshcutboards.com. We'll verify the request and respond within the time the law requires (generally 30–45 days). We won't discriminate against you for exercising your rights. For content your organization controls, we'll pass the request to that organization.
Appeals. If we decline your request, reply with “Appeal” in the subject line and we'll review it and answer within 45 days. If you're still unsatisfied, you can contact your state attorney general (in New Jersey, the Division of Consumer Affairs) or, in the EEA/UK, your data protection authority.
We don't track you across sites, so there's nothing for Global Privacy Control or Do Not Track signals to opt out of; we treat them as an opt-out request anyway.
8.Security
Data is encrypted in transit between your browser, our service and our providers, and our database and file-storage provider encrypts it at rest. Access inside the service is limited by security groups, organizations are isolated from each other, and actions are written to an audit log. More detail is on the Security & Trust page. No system is perfectly secure; if we learn of a breach affecting your information, we'll notify you as the law requires.
9.Where data is processed
The service is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the U.S. Where required, we rely on our providers' recognized transfer mechanisms (such as Standard Contractual Clauses).
10.Changes and contact
We'll post changes here and update the effective date; for material changes we'll notify organization owners by email at least 30 days before they take effect. Questions or requests: privacy@freshcutboards.com — TurfGrown LLC, d/b/a Fresh Cut Boards.