Privacy policy

Last updated July 15, 2026


This Privacy Policy explains how Member Mind, a trading name of Grand Digital (ABN 68 768 628 295) ("Member Mind", "we", "us", "our"), collects, uses, stores, and protects personal data in connection with the Member Mind service ("Service").

Member Mind is a multi-tenant analytics platform for MemberPress membership sites. If you are a website owner using Member Mind (a "Customer"), this policy explains what we collect about you and about the members of your website (your "End Users") when you connect your site to our Service.

1. Who This Policy Covers

This policy applies to three categories of people, and we handle their data differently:

Customers — the people who sign up for a Member Mind account.
We collect your account details directly (name, email, password, billing information) and act as the data controller for this information.

End Users — the members of your MemberPress website.
When you connect your MemberPress site, we receive data about your End Users (their memberships, transactions, and page views) in order to provide analytics back to you. For this data, we act as a data processor on your behalf — you remain the controller, and you are responsible for having a lawful basis to share this data with us (for example, through your own privacy policy and terms with your End Users).

Visitors to our marketing website.
If you visit membermind.co without an account, see Section 4 (Cookies and Analytics) for what we collect.

2. What We Collect

From Customers (account holders)

  • Name and email address
  • Password (stored as a salted hash, never in plain text)
  • Billing details, processed via Stripe (we do not store full card numbers)
  • Your MemberPress API key and webhook key, provided by you to connect your site
  • Usage data about how you use the Member Mind dashboard

From End Users (via your connected MemberPress site)

  • Membership and subscription data: plan, status, join/cancel dates
  • Transaction data: amounts, payment status, dates (we do not receive full card numbers)
  • Name and email address, as stored in your MemberPress installation
  • Page view data: which pages on your site were visited, associated with a membership level and content category. We do not associate page views with an individual End User's identity.
  • IP address, collected with page view data for basic analytics purposes

3. How We Use Data

We use the data described above to:

  • Provide the analytics dashboard and reports you see as a Customer
  • Calculate metrics such as churn, revenue, and member engagement
  • Send you scheduled email reports, if you have enabled them
  • Maintain and improve the Service, including diagnosing technical issues
  • Communicate with you about your account or the Service

We do not sell personal data. We do not use End User data for advertising, and we do not use it to train any third-party AI models.

4. Cookies and Analytics

Our marketing website (membermind.co) uses Google Analytics and Google Search Console to understand how visitors find and use our site. These tools may set cookies and collect information such as your browser, device, approximate location, and the pages you visit. You can opt out of Google Analytics tracking using Google's browser opt-out tools, or by declining non-essential cookies if prompted.

The Member Mind application itself (app.membermind.co) uses only the essential session cookie required to keep you logged in. It does not use advertising or third-party tracking cookies.

5. Third Parties We Share Data With

We use the following subprocessors to operate the Service. Each has its own privacy and security practices:

  • Supabase — database hosting and backend infrastructure (all Customer and End User data described above is stored here)
  • Stripe — payment processing for Customer subscriptions
  • Resend — transactional and scheduled report emails
  • Google Analytics / Search Console — marketing website analytics only (Section 4)

We do not share personal data with any other third party except where required by law, or with your consent.

6. Data Storage and Security

Data is stored using Supabase. All data is encrypted at rest and in transit by default. Access controls (row-level security) keep each Customer's data isolated from other Customers. We take reasonable technical measures to protect data, but no system is completely secure.

Your MemberPress API key and webhook key are protected by this same infrastructure-level encryption, though they do not currently have additional field-level encryption on top of it. We may add this as an extra safeguard in future.

As the Service operator, we retain the administrative ability to access stored data, consistent with providing and supporting the Service. This access is not used for routine purposes.

7. Data Retention and Deletion

We retain Customer and End User data for as long as your account is active, or as needed to provide the Service. If you cancel your account, we will delete your data within a reasonable period, except where retention is required by law.

At present, Member Mind does not yet have a fully automated self-service account deletion feature. If you would like your account and associated data deleted, please contact us at the email below and we will process this manually.

IP addresses collected with page view data are currently retained for as long as the underlying page view record is kept. We intend to introduce a fixed retention schedule for this data.

8. Your Rights

Depending on where you or your End Users are located, you may have rights under applicable law (such as the GDPR in the EU/UK, the CCPA in California, or the Australian Privacy Act) including the right to access, correct, delete, or export personal data, and the right to object to certain processing.

As a Customer, you can exercise these rights over your own account data by contacting us. If an End User of your website wishes to exercise these rights over their own data, they should contact you directly, as you are the controller of that relationship; you may then contact us if you need our assistance to fulfil that request.

If you are in the EU or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

9. Automated Insights

Member Mind's Insights feature analyses aggregate account-level data (such as revenue trends and membership changes) to surface automated observations about your business. These insights are generated from patterns in your own data and are not used to make decisions about, or profile, individual End Users.

10. International Data Transfers

Grand Digital is based in Australia. Our subprocessors (Supabase, Stripe, Resend, Google) may store or process data in other countries, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

11. Children's Privacy

The Service is not directed at children, and we do not knowingly collect personal data from children. If you believe a child's data has been provided to us, please contact us so we can remove it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above, and for material changes we will make reasonable efforts to notify Customers directly.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Member Mind, a trading name of Grand Digital (ABN 68 768 628 295)
info@granddigital.com.au


Stop guessing. Run a better membership business

For use with:

Get the clear view of your membership business you've been missing.

Get started FREE