This Privacy Policy explains how the operator of MiniGantt (“we”, “us”, “our”) processes personal data when you visit https://minigantt.com, create an account, or use the MiniGantt application (together, the Service). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable laws.
By creating an account or using the Service, you acknowledge that you have read this Privacy Policy. Where consent is required (for example marketing emails or optional cookies), we ask for it separately.
1. Data controller and contact
The data controller is the business entity operating MiniGantt. For privacy requests, questions, or to exercise your rights, contact us at hello@minigantt.com or via our contact page.
This Privacy Policy is always available at https://minigantt.com/privacy. Archived versions remain available when we publish updates.
2. What personal data we process
Depending on how you use the Service, we may process:
- Account data: name, email address, password (stored hashed), optional profile photo, language and interface preferences, two-factor authentication settings.
- Sign-in data: if you use Google Sign-In, we receive your Google account identifier, name, and email address from Google as needed to create or link your account. We do not receive your Google password.
- Workspace and content data: projects, boards, columns, tasks, deadlines, estimates, assignees, comments, uploaded files, chat messages, calendar/meeting details, time entries, and similar collaboration data you or your teammates create.
- Subscription and billing data: selected plan, billing name and address, tax/VAT number if provided, payment status, and payment provider transaction identifiers. Card details are handled by our payment provider and are not stored in full on our servers.
- Support and communication data: messages you send via the contact form or email, and our replies.
- Marketing data: if you opt in, your email address, consent timestamp, and unsubscribe choices.
- Technical and security data: IP address, browser and device information, approximate location derived from IP where relevant for security, session identifiers, login and activity logs, cookie identifiers, and error diagnostics.
- Legal acceptance records: which Privacy Policy and Terms of Service versions you accepted, with timestamp, IP address, and user agent where recorded for audit purposes.
3. Purposes and legal bases
- Providing the Service and managing your account (GDPR Art. 6(1)(b) — contract performance), including authentication, workspaces, collaboration features, and customer support.
- Billing, invoicing, and accounting (Art. 6(1)(b) and Art. 6(1)(c) — legal obligation), including tax and bookkeeping retention.
- Security, abuse prevention, and service integrity (Art. 6(1)(f) — legitimate interests), including logging, rate limiting, fraud and abuse detection, and troubleshooting.
- Improving and operating the product (Art. 6(1)(f)), for example understanding feature usage in aggregated or de-identified form where feasible.
- Optional AI-assisted features (Art. 6(1)(b) and/or Art. 6(1)(f)), such as task time estimates. Relevant task context you choose to process may be sent to our AI provider solely to generate the requested output.
- Marketing emails (Art. 6(1)(a) — consent), only if you opt in. You may withdraw consent at any time.
- Optional cookies and similar technologies (Art. 6(1)(a) where required), set only after you consent via the cookie banner, except strictly necessary cookies.
4. Google Sign-In and profile photos
If you choose Google Sign-In, Google authenticates you and shares limited profile information with us under Google’s terms and your Google account settings. We use that information only to sign you in, create or link your MiniGantt account, and display your identity in the Service.
If you upload a profile photo, we store it to show your avatar in the product. If no photo is uploaded, we may display initials or a publicly available Gravatar image associated with your email, where available.
5. Who can see your workspace data
Project and workspace content is visible to users you invite or who otherwise have access to that project or workspace. We do not sell your content. Our staff may access account or content data only when needed for support, security, legal compliance, or to operate the Service, and subject to confidentiality obligations.
6. Processors and international transfers
We use trusted service providers (processors) to operate the Service, which may include:
- hosting, storage, CDN, and infrastructure providers,
- database and cache services,
- payment providers (for example Stripe),
- invoicing providers (for example Billingo),
- email delivery providers for transactional and — with consent — marketing messages,
- authentication providers when you use Google Sign-In,
- AI providers when you use optional AI features,
- error monitoring or analytics tools, where enabled.
We enter into data processing terms with processors where required. If personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms.
7. Retention
We keep personal data only as long as needed for the purposes above:
- Account and workspace data: while your account is active, and for a limited period after deletion or closure to complete deletion, resolve disputes, or meet legal obligations.
- Billing and invoicing records: for the period required by tax and accounting law.
- Security and server logs: for a limited period consistent with security and operational needs.
- Marketing records: until you withdraw consent or unsubscribe, and thereafter for a short period to evidence compliance.
- Legal acceptance records: for as long as needed to demonstrate consent and compliance.
When retention ends, we delete or anonymize the data, unless a longer period is required by law.
8. Cookies
We use cookies and similar technologies that are necessary for the Service to work (for example session, authentication, CSRF protection, and remembering cookie preferences). Optional cookies (such as analytics) are used only if you consent through the cookie banner. Details are in our Cookie Policy.
9. Your rights
Under the GDPR, you may have the right to:
- access your personal data,
- rectify inaccurate data,
- erase data (“right to be forgotten”) where applicable,
- restrict processing,
- data portability,
- object to processing based on legitimate interests,
- withdraw consent at any time (without affecting prior lawful processing),
- lodge a complaint with a supervisory authority (in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság — NAIH — or your local EU authority).
To exercise these rights, email hello@minigantt.com. We may need to verify your identity before fulfilling a request.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
11. Security
We apply appropriate technical and organizational measures to protect personal data, including encrypted transport (HTTPS), hashed passwords, access controls, and optional email two-factor authentication. No method of transmission or storage is completely secure; please keep your credentials confidential and enable available security features.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is published at https://minigantt.com/privacy. For material changes, we may notify you in the Service or by email, and where required we will ask you to accept the updated version before continuing.
13. Related documents
Use of the Service is also governed by our Terms of Service and Cookie Policy.
Last updated: 2026-07-18
Current