Grid Marks
Security & your data
The short version: Grid Marks has no accounts and no central database. The marks and jobs you create stay on your own device — we never receive or store a copy. There is no pool of customer data for us to lose.
Where your data lives
Everything you create — marks, projects, categories, notes, downloaded offline maps — is stored in your browser on your device (using standard browser storage). It is never sent to a Grid Marks server, because there isn't one holding user data. You can export a project file to back it up or move it, and clearing your browser removes it. In practical terms: your data is as private as the device it's on.
Protected in transit
The whole site is served over HTTPS/TLS with HSTS enforced, plus a set of protective HTTP security headers (including a Content-Security-Policy, strict framing and referrer controls) to guard against common web attacks.
Hosting & infrastructure
Grid Marks is hosted on Cloudflare, whose infrastructure is independently audited and certified to SOC 2 Type II and ISO 27001 (Cloudflare Trust Hub). Those certifications cover the hosting platform; Grid Marks itself deliberately holds no customer data on servers, which keeps our own data-security surface minimal by design.
Third-party services
When you use certain features, your device contacts specialist services directly — map tiles (Ordnance Survey, OpenStreetMap, Esri), postcode and address lookup (postcodes.io, Nominatim), routing (OSRM), what3words, Google Maps, and land registries. Those services receive your IP address and the coordinates or search terms involved, under their own policies. Our access keys to these services are domain-restricted. Full detail is in our Privacy & Cookie notice.
Privacy, cookies & the law
We follow UK GDPR and PECR. There are no accounts and no marketing emails. We use privacy-friendly, cookieless analytics; any cookie-based analytics loads only with your consent. See the Privacy & Cookie notice for lawful bases, your rights, and how to manage cookies.
Kept up to date
We keep the app's components current and patch known vulnerabilities. Every release is versioned and logged, so it's clear what changed and when.
For procurement & security reviews
Because Grid Marks stores no customer data on its servers, most standard security-questionnaire items (data-at-rest, access control, breach exposure) are minimal or not applicable. If your organisation needs a security fact sheet or has specific questions, contact contact@gridmarks.co.uk.