Privacy Policy


Effective date: 14th Aug 2026
Last updated: 14th Aug 2026


This Privacy Policy explains how personal information is collected, used, shared and protected when you visit www.storesense.tech (the “Site”), contact us, request a demo, subscribe to our updates, or meet us at an industry event.


StoreSense™ is a product of the GrayMatter group of companies. In this Policy, “GrayMatter”, “we”, “us” and “our” refer to the GrayMatter entity responsible for your information, as set out in section 2. “You” means any visitor to the Site or person who contacts us.


We have written this Policy to be readable rather than defensive. If anything in it is unclear, please ask us — our contact details are in section 16.

1. What this Policy covers — and what it does not


This Policy covers personal information we handle as a business in our own right (as a “controller”): information about Site visitors, prospective customers, event contacts, partners and people who contact us.


This Policy does not cover the data that the StoreSense platform processes for our customers. When an airport, airport authority, concessionaire or other customer deploys StoreSense, we process transaction and operational data on their instructions and on their behalf as a “processor” or “service provider”. That processing is governed by our contract with that customer, including a data processing agreement, and by the customer’s own privacy notice, not by this Policy. If you are a passenger, retail customer or employee at a location that uses StoreSense and you have questions about your data, please contact that organization directly; we will support them in responding.


This Policy also does not apply to third-party websites we link to, or to our recruitment process, which is covered separately by the notice provided during application.

2. Who is responsible for your information


The GrayMatter entity that determines how your information is used depends on where you are and who you deal with:

  • United States and the Americas – GrayMatter Software Services Inc, Millennium Centre, 15455 Dallas Parkway, Suite 600, Addison, TX 75001, USA
  • United Kingdom and Europe – GrayMatter Software Solutions Ltd., 107–111 Fleet Street, London EC4A 2AB, United Kingdom
  • India, Asia-Pacific and elsewhere – GrayMatter Software Services Pvt. Ltd., 4th Floor, Building No. 1, West Wing, Arliga Eco World SEZ, Outer Ring Road, Bangalore 560 103, India
  • Malaysia – GrayMatter Software Services Sdn. Bhd., Unit 621, 6th Floor, Block A, Kelana Centre Point, No. 3 Jalan SS7/19, Kelana Jaya, 47301 Petaling Jaya, Selangor Darul Ehsan, Malaysia


These entities operate as a group and may share your information with one another for the purposes described in this Policy. Whichever entity you deal with, you can reach our privacy through contact us page.

3. Information we collect

3.1 Information you give us


You can browse most of this Site without telling us who you are. When you choose to contact us, request a demo, ask to meet us at an event, or subscribe to updates, we collect what you submit typically:

  • name and job title;
  • business email address and telephone number;
  • organisation name, and the airport, terminal or portfolio you are asking about;
  • country or region;
  • the content of your message or enquiry, and any details you volunteer about your requirements;
  • any figures you enter into an interactive tool or calculator on the Site, together with your email address if you ask us to send you the results.


We ask only for business contact information. Please do not send us sensitive personal information (for example health, biometric, racial or ethnic, religious, political, trade union, sexual orientation or precise geolocation data) — we do not need it and do not want it.

3.2 Information we collect automatically


When you visit the Site, our servers and analytics tools automatically record technical information, including:

  • IP address and approximate location derived from it (typically country, region or city – not a precise location);
  • browser type and version, operating system and device type;
  • the pages you view, the time and duration of your visit, and the links you click;
  • the website or search engine that referred you, and any campaign parameters in the link you followed;
  • whether you opened or clicked a link in an email we sent you.


We use this mainly in aggregate, to measure how the Site is used and to improve it. Where it is combined with information that identifies you, we treat it as personal information under this Policy.

3.3 Information from other sources


We may receive information about you from:

  • conference and exhibition organisers, where you visit our stand, scan your badge with us, or attend a session we host;
  • business contact and enrichment providers, and publicly available professional sources such as company websites, industry publications and professional networks, used to keep our records accurate and to identify organisations that may benefit from our products;
  • our group companies, partners and resellers;
  • referrals, where a colleague or contact introduces you to us.


Where we obtain your information from a third party and use it to contact you, we will tell you where we got it if you ask.

4. Cookies and similar technologies


We use cookies and similar technologies to make the Site work, to understand how it is used, and to measure our marketing. Broadly:

  • Strictly necessary – required for the Site to function, including security and basic navigation. These cannot be switched off.
  • Analytics and performance – help us understand which pages are useful and where visitors have difficulty. We use Google Analytics for this.
  • Functionality – remember preferences such as your cookie choices.
  • Marketing and advertising – used to measure campaigns and, where enabled, to show you relevant advertising on other platforms.


Where required by law, we set non-essential cookies only after you consent, and you can change or withdraw your choice at any time using our cookie preferences control. You can also block or delete cookies in your browser settings, though parts of the Site may then not work properly.


Some pages embed third-party content – for example YouTube videos – and those providers may set their own cookies when the content loads. Their use of your information is governed by their own privacy policies.


A current list of the cookies we set, their purpose and their duration is set out below:

5. How we use your information, and our legal grounds


We use personal information for the purposes below. For visitors in the UK, EU and other regions with similar laws, the corresponding legal basis is shown.

PurposeLegal basis
Responding to your enquiry, arranging and delivering a demo, and providing the information you asked forPerformance of a contract, or our legitimate interest in responding to a business request
Sending you the output of a calculator or tool you used, or a document you requestedYour request / consent
Operating, securing and improving the SiteLegitimate interest in running a safe, effective website; legal obligation for security matters
Analytics and understanding how the Site is usedConsent, where required for cookies; otherwise legitimate interest
Marketing communications about our products, events and contentConsent where required; otherwise legitimate interest in marketing to business contacts, subject to your right to opt out at any time
Managing our relationship with customers, partners and prospects, including keeping records accuratePerformance of a contract, or legitimate interest in managing our business
Meeting legal, tax, accounting and regulatory obligations, and responding to lawful requestsLegal obligation
Establishing, exercising or defending legal claims, and in connection with a merger, acquisition or reorganisationLegitimate interest; legal obligation where applicable


Where we rely on legitimate interests, we have considered whether that interest is fair to you, and you can object at any time (see section 12).

6. Marketing, and how to stop it


If you have asked us for information, met us at an event, or are a business contact at an organisation we believe would benefit from StoreSense, we may send you occasional emails about our products, events, research and content.


Every marketing email includes a one-click unsubscribe link. You can connect through contact us page. and ask us to stop, and we will action it promptly. Opting out of marketing does not stop necessary messages about a demo you have booked or a contract we have with you.

7. When we share information


We do not sell your personal information, and we do not share it with third parties for their own independent marketing. We share it only as follows:

  • Within the GrayMatter group – with the entities listed in section 2, so that the right team can respond to you.
  • Service providers acting on our instructions – including website hosting, customer relationship management, email delivery, analytics, event and webinar platforms, scheduling tools and IT support. They may use your information only to provide services to us, under contract and subject to confidentiality and security obligations.
  • Professional advisers – lawyers, auditors, insurers and accountants, where necessary.
  • Partners and resellers – where you have asked to be introduced, or where a partner is involved in a deployment you are discussing with us. We will make this clear at the time.
  • Legal and regulatory – where we are required to disclose information by law, court order or a valid request from a public authority, or where disclosure is necessary to protect our rights, safety or property, or those of others.
  • Corporate transactions – in connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality protections. If your information would become subject to a materially different privacy policy, we will tell you.


8. International transfers


GrayMatter operates in the United States, the United Kingdom, India and Malaysia, and some of our service providers operate elsewhere. Your information may therefore be transferred to, stored in, or accessed from a country other than your own, including countries that may not provide the same level of data protection as your home country.


Where we transfer personal information out of the UK, the European Economic Area or another region with transfer restrictions, we rely on an appropriate safeguard – normally the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or a finding of adequacy – together with additional measures where necessary. You can ask us for details of the safeguards that apply to a particular transfer.

9. How long we keep information


We keep personal information only as long as we need it for the purposes described in this Policy, and then delete it or securely anonymise it. In practice:

  • Enquiries and demo requests – retained for the duration of the discussion and then for a defined period afterwards, in case you come back to us.
  • Marketing contacts – retained until you opt out, or after a defined period of no engagement, whichever comes first.
  • Customer and contract records – retained for the life of the relationship and then for the period required by tax, accounting and limitation laws.
  • Website analytics – retained according to the retention setting configured in our analytics tools.


Our current retention periods are:

10. How we protect information


We maintain technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. These include encryption of data in transit, access controls on a need-to-know basis, staff confidentiality obligations, security awareness training, supplier due diligence, and internal information security and IT policies.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant authorities where the law requires it.

11. Your privacy rights


Depending on where you live, you may have some or all of the following rights. We apply them as broadly as we reasonably can, regardless of location.

  • Access – ask what personal information we hold about you and receive a copy.
  • Correction – have inaccurate or incomplete information corrected.
  • Deletion – ask us to delete your information where we no longer have a valid reason to keep it.
  • Objection – object to processing based on legitimate interests, and object to direct marketing at any time.
  • Restriction – ask us to pause processing in certain circumstances.
  • Portability – receive certain information in a portable format, or have it sent to another provider.
  • Withdraw consent – where we rely on consent, withdraw it at any time. This does not affect processing already carried out.
  • Opt out of “sale” or “sharing” and of targeted advertising – we do not sell personal information or share it for cross-context behavioural advertising, but you may still exercise this right.
  • Non-discrimination – we will not treat you less favourably for exercising your rights.
  • Human review – we do not make decisions about you that produce legal or similarly significant effects using solely automated means. If that changes, we will update this Policy and provide the safeguards the law requires.


California residents. Under the CCPA as amended by the CPRA, you have the rights to know, delete, correct and to opt out of sale or sharing, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information for purposes requiring a limitation right. You may use an authorised agent to make a request on your behalf, with proof of authorisation.

Other US states. Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and others, have broadly similar rights, including the right to appeal a decision we make on a request. To appeal, reply to our decision and mark it “Privacy Appeal”.

UK and EEA. You may lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.

India. Under the Digital Personal Data Protection Act, 2023, you have rights of access, correction, completion, updating, erasure and grievance redressal, and may nominate another person to exercise your rights in the event of death or incapacity. Our grievance contact is the privacy address in section 16.

12. How to exercise your rights


Contact us with the words “Privacy Request” in the message box, telling us what you would like us to do. We may ask for information to verify your identity, so that we do not disclose your data to someone else.

We will respond within the time the applicable law allows – generally one month in the UK and EEA, and 45 days in the United States, each extendable where permitted, in which case we will tell you. There is no charge unless your request is manifestly unfounded or excessive.

13. Children


This Site and our products are intended for business users. We do not knowingly collect personal information from children under 16, and we do not direct the Site to children. If you believe a child has provided us with personal information, contact us and we will delete it.

14. Links to other sites


This Site links to other websites, including those of our group companies, partners, industry associations and event organisers. We try to link only to organisations that take privacy seriously, but we do not control them and we are not responsible for their content or their privacy practices. Please read their privacy policies before providing personal information.

15. Changes to this Policy


We may update this Policy to reflect changes in our practices, technology or the law. We will change the “Last updated” date at the top, and if the changes materially affect how we use your information we will provide a more prominent notice, such as an on-site banner or an email. Previous versions are available on request.

16. Contact us


For any privacy question, request or complaint:

Privacy team
Contact Us Page

United States
GrayMatter Software Services Inc
Millennium Centre, 15455 Dallas Parkway, Suite 600, Addison, TX 75001, USA
Telephone: +1 469-730-0117
Email: info@graymattersoftware.us

United Kingdom
GrayMatter Software Solutions Ltd.
107–111 Fleet Street, London EC4A 2AB, United Kingdom
Telephone: +44 20 3769 2876
Email: info@graymattersoftware.us

India
GrayMatter Software Services Pvt. Ltd.
4th Floor, Building No. 1, West Wing, Arliga Eco World SEZ, Outer Ring Road, Bangalore 560 103, India
Telephone: +91 80 6715 6666
Email: info@graymatter.co.in

Malaysia
GrayMatter Software Services Sdn. Bhd.
Unit 621, 6th Floor, Block A, Kelana Centre Point, No. 3 Jalan SS7/19, Kelana Jaya, 47301 Petaling Jaya, Selangor Darul Ehsan, Malaysia
Email: info@graymattersoftware.us