Last updated: September 2026
What is actually true about how OneGrid handles your data. Every line here describes something the product does today — not something planned.
Meta. Connecting an ad account goes through Facebook's own login. We ask for the narrowest set of permissions the features need, we never see your Facebook password, and you can revoke OneGrid's access in one click — from your Facebook settings, or from the disconnect button inside OneGrid.
Spotify, Google, Shopify and the rest. Same shape: the provider's own login screen, scoped permissions, and a disconnect that takes effect immediately.
We store the access tokens those connections issue, never the passwords behind them.
Public pages can load a Meta, TikTok or Google Analytics pixel so an artist can measure and retarget their own traffic. In the EU, EEA, the UK and Switzerland none of that loads until the visitor accepts it, and a decline — or simply closing the banner — means the pixel is never rendered on the page and no conversion is reported from our servers either.
We do not sell personal information. We do not buy fan lists. We do not use your data to train models for anyone else. We do not send fan messages on your behalf without your instruction.
If you think you have found a vulnerability, email onyx@gridlocktalent.com with enough detail to reproduce it. Please give us a reasonable window to fix it before publishing. We will not pursue anyone acting in good faith.
The application is hosted on Vercel; the database, authentication and file storage are Supabase. Both are in the United States. onegrid.team is the product's home.