Legal
Privacy Policy
Last updated August 17, 2026
This policy describes how Griddex (“we”) handles personal information for people in the United States, the European Economic Area, the United Kingdom, and elsewhere. It is meant to satisfy U.S. state privacy laws (including the CCPA/CPRA) and the GDPR/UK GDPR.
Who we are
Griddex is an independent closet and catalog tool for Second Life residents. We are not Linden Research, Inc. The operator of this site is the controller of personal data processed here. Contact: the email address on your Griddex account.
What we collect
If you only browse the public catalog, we process:
- Technical logs (IP address, user agent, time, URL) needed to run and secure the site
- A cookie-consent flag in your browser if you tap OK on the banner
If you create an account, we also process:
- Email address and a hashed password (we do not store the password in plain text)
- Session cookies so you stay signed in
- Closet pointers — encrypted references to public catalog items, not a second copy of creator meshes or listing photos
- Inventory names, folders, and types from a viewer cache file you choose to upload (not meshes, textures, or your Second Life password)
Account data and the public Marketplace catalog live in separate databases. A leak of one side is not a complete map of who owns what.
What we do not collect
We do not ask for your Second Life password. We do not ship software that scans your disk. We do not log into Linden systems as you. We do not sell personal information. We do not run advertising pixels. We do not buy broker lists.
Why we process it (legal bases)
- Contract — creating an account and running your closet
- Legitimate interests — securing the service, indexing publicly listed Marketplace titles/photos/contents so search works
- Consent — optional cookie acknowledgement; you can clear site data anytime
- Legal obligation — if we must keep a record of a takedown or a lawful request
How long we keep it
Account and closet data stay until you delete the account or ask us to erase it. Server logs are rotated on a short cycle. Public catalog rows (creator-facing Marketplace data) stay as long as the index is maintained and are not treated as your personal data.
Who we share with
Hosting (the VPS and database), email/sign-in infrastructure if you use a social login, and Google Fonts if your browser loads type from fonts.googleapis.com. We do not sell or “share” personal information for cross-context advertising.
Your rights (GDPR / UK GDPR)
You may request access, correction, deletion, restriction, portability, and to object to processing based on legitimate interests. You may withdraw consent without affecting prior lawful use. You may lodge a complaint with your supervisory authority. We will answer requests sent to the email address on your Griddex account within one month (or the time the law allows).
Your rights (California and other U.S. states)
You may request to know, access, correct, or delete personal information we hold about you. We do not sell personal information or share it for targeted advertising. We will not discriminate against you for exercising these rights. You may use an authorized agent as the statute allows. Email the email address on your Griddex account with the subject “Privacy request.”
Children
Griddex is not directed at children under 16. We do not knowingly collect their data. If you believe we have, write to the email address on your Griddex account and we will delete it.
Security and international transfers
The service is hosted in the United States. If you access it from the EEA or UK, you understand your data is processed in the U.S. We use TLS in transit and split user data from the public catalog. No method is perfect; we will notify you of a breach as the law requires.
Changes
If we change this policy in a material way, we will update the date at the top and, for account holders, note it in the product when we can.