Effective date: 25 July 2026
Last updated: 25 July 2026
This notice explains how GRIPT MEDIA LIMITED processes personal data when you use the Gript website at gript.ie, the Gript mobile app, or related Gript services.
GRIPT MEDIA LIMITED, company number 640146, is the controller for the processing described in this notice.
Depending on the feature you use, this may include:
Payment-card and payment-account credentials are handled by the relevant payment provider. Gript may receive an order or transaction reference, status and related account information, but does not need your full payment-card details to provide the website service.
When you use the website, standard network and device information is processed. This can include Internet Protocol address, browser and device type, operating system, referring page, pages requested, timestamps, security events and similar technical data.
The website uses cookies and similar technologies for essential operation and, where you allow them, analytics, personalisation, advertising and embedded content. The current cookie categories and available controls are explained in the Gript Cookie Policy and the on-site cookie preference tool.
The app requests articles, images, categories, public comments and search results from Gript.ie. Those requests send standard network information, including Internet Protocol address and request details, to Gript.ie and its hosting and security providers. A search term is sent to Gript.ie only when you use search.
The app stores up to five recent search terms on your device so that you can reuse them. You can remove them by clearing the app’s storage or uninstalling the app.
The app does not create membership accounts or take payments. If you already have a Gript membership, you may choose to sign in through Memberful. The app then processes:
The app does not request or store your Memberful password, postal address, phone number or payment-card details. Authentication credentials are kept in the device’s secure credential store and are not sent to crash reporting, the notification service or analytics.
If you enable notifications, the app may send a Firebase Cloud Messaging registration token, app version, platform and schema version to the Gript notification service. The token identifies an app installation for delivery. Under the current design, it is not stored with a Memberful identity, email address, device model, manufacturer, advertising identifier or usage profile.
The app also obtains short-lived Firebase App Check evidence so the service can verify that a request came from the production Gript Android app. The evidence is used for verification and is not intended to be retained in application logs.
You can disable notifications in the app or device settings. The app then makes a best-effort request to remove the server-held registration.
When crash reporting is enabled in a production build, the app may send Sentry:
root-boundary plus a limited component stack.The configured boundary excludes Memberful credentials and profile data, push tokens, request URLs, headers, bodies and query strings, user objects, screenshots, view hierarchy, breadcrumbs, session replay, tracing, profiling, sessions and performance telemetry. Sentry is used for crash diagnosis, not advertising or audience analytics.
Articles may contain video, audio or social-media embeds. Standard YouTube, BeyondWords or similar resources may load when you open an article that contains them. Those providers may receive an Internet Protocol address or IP-derived general area, the article or media URL, browser or device identifiers, and interaction data. Depending on the provider and your settings, that information may be used for content delivery, analytics, security, personalisation or advertising under the provider’s privacy terms. The app itself does not build a cross-app advertising profile. External links open outside the article view and are governed by the destination’s privacy notice.
The app stores:
| Purpose | Legal basis |
|---|---|
| Deliver requested website and app content, search, support and account or membership services | Performance of a contract or steps requested by you before a contract |
| Process subscriptions, donations, orders and related administration | Performance of a contract and compliance with legal obligations |
| Protect services, prevent abuse and diagnose faults | Legitimate interests in providing reliable and secure services |
| Send newsletters, marketing or push notifications you choose | Consent, which you may withdraw |
| Use non-essential analytics, advertising or personalisation technologies on the website | Consent where required |
| Maintain records, respond to lawful requests and establish or defend legal claims | Legal obligations and legitimate interests |
Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights. Withdrawing consent does not affect processing that was lawful before withdrawal.
We use service providers only where needed to operate, secure, measure or fund the services. Depending on the feature and your choices, recipients may include:
| Recipient or category | Purpose |
|---|---|
| Kinsta and Cloudflare | Website hosting, delivery, security and technical logs |
| WordPress/Automattic and website plug-in providers | Website publishing and enabled site features |
| Memberful | Hosted sign-in, membership and entitlement verification |
| Stripe, PayPal, WooPayments and related commerce providers | Payment, order and transaction processing |
| Mailchimp and form providers | Newsletters, forms and requested communications |
| Google services, WP Statistics, Meta and Adnimation | Analytics, site tooling and advertising where enabled and permitted by your cookie choices |
| CookieYes and consent-management providers | Record and apply website cookie choices |
| Google Firebase and Firebase Cloud Messaging | App authenticity, push registration and notification delivery |
| Sentry | Restricted mobile-app crash diagnostics |
| Embedded-media and social providers | Media or external content you choose to open |
We may also disclose information when required by law, to protect legal rights or service security, or as part of a genuine business transfer subject to appropriate safeguards.
GRIPT MEDIA LIMITED does not sell mobile-app data. The mobile app does not use behavioural advertising, cross-app tracking or audience analytics.
Some providers may process information outside Ireland or the European Economic Area. Where data-protection law requires it, we use an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer safeguard and apply additional protections where appropriate.
We keep personal data only for as long as necessary for the purpose described, including legal, accounting, security and dispute-resolution requirements.
When data is no longer needed, we delete or anonymise it. Backup copies may remain isolated until the backup rotation expires.
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent. You may also complain to the Irish Data Protection Commission.
You can:
The app does not create a Memberful account. To close or change an existing membership, use the applicable Gript/Memberful account process or contact us. For any data-rights request, email privacy@gript.ie. We may need to verify your identity before acting on a request.
We use technical and organisational measures intended to protect personal data, including access controls, encrypted transport and restricted app credential storage. No internet service can guarantee absolute security.
The services are general news services and are not directed to children. We do not knowingly solicit personal data from or market membership services to children under 18.
We do not use the app data described in this notice to make automated decisions that produce legal or similarly significant effects.
The website and app may link to third-party sites, advertisements or services. Their processing is governed by their own privacy notices.
We may update this notice when the services, providers, legal requirements or data practices change. The effective and last-updated dates at the top identify the current version. We will provide an additional notice where a material change requires it.
Reference points for this notice include the Irish Data Protection Commission transparency guidance, the DPC explanation of Articles 13 and 14 and the official GDPR text.