Privacy relationship map
This is a relationship overview, not a guaranteed data flow or processing sequence.
- You and your teamAccount, workspace, billing, support, and authorized context
- Connected platformsData and permissions you authorize for Growomo features
- Service providersSupport the hosting, security, payment, email, storage, and product operations described below
- AI processingDecision-support outputs that remain subject to human review
Growomo provides an AI-powered marketing platform and related marketing services for campaign analytics, recommendations, experimentation, reporting, and growth operations.
For privacy questions or data requests, contact us at hello@growomo.com.
Depending on how you use Growomo, we collect account details, contact details, authentication identifiers, company details, billing details, trial eligibility details, subscription records, support messages, device and usage logs, and information you submit through forms.
When you connect third-party platforms, we collect the data you authorize Growomo to access so we can sync performance, build dashboards, generate recommendations, and perform approved actions.
- Meta Ads data: ad account identifiers, campaign, ad set, ad, creative metadata, statuses, budgets, targeting-related fields, spend, impressions, clicks, leads, CTR, and related insight metrics.
- Google Ads and YouTube Ads data: customer account identifiers, campaign, ad group, budget metadata, statuses, bids, cost, impressions, clicks, conversions, CTR, and video campaign metrics.
- Google Analytics 4 data: property identifiers, campaign and session dimensions, sessions, users, conversions, engagement metrics, audiences, key events, and property configuration metadata where you authorize access.
- Email marketing data: account metadata, campaign identifiers, subject, preheader, template, schedule metadata, delivery, open, click, bounce, unsubscribe, complaint, and related campaign statistics.
- OAuth and API credential data: access tokens, refresh tokens, granted scopes, expiry timestamps, and connection status needed to keep integrations working while connected.
- Trial abuse-prevention data: phone number, company name, website domain, GST number where provided, hashed trial fingerprint, signup IP, login IP, user agent, and device data used to review free-trial eligibility.
We use information only for legitimate business and product purposes connected to Growomo.
- Provide, operate, secure, and improve the Growomo platform.
- Authenticate users and maintain account sessions.
- Sync and normalize campaign, analytics, and email marketing performance data.
- Generate dashboards, reports, anomaly alerts, experiments, and AI recommendations.
- Execute platform actions only when supported, authorized, and approved through the product workflow.
- Process subscriptions, invoices, taxes, payments, refunds, and customer support requests.
- Determine free-trial eligibility, prevent duplicate free trials, review indications of possible abuse, and support eligibility appeals.
- Prevent abuse, debug errors, enforce terms, and comply with legal obligations.
Growomo uses Google APIs only to provide and improve user-facing Growomo features that are visible in the product, such as Google Ads, YouTube Ads, and Google Analytics reporting, recommendations, and approved account actions.
Growomo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell Google user data.
- We do not transfer Google user data to advertising platforms, data brokers, or information resellers.
- We do not use Google user data for serving ads, retargeting, personalized ads, credit-worthiness, or lending decisions.
- We do not allow humans to read Google user data except when necessary for support with your consent, security, abuse investigation, legal compliance, or aggregated internal operations.
- When you disconnect a Google integration, Growomo deletes usable stored Google OAuth credentials and attempts to revoke Growomo provider access through Google OAuth revocation where technically possible.
Growomo may process your campaign, analytics, and account data to generate AI-powered insights, recommendations, summaries, forecasts, and experiment ideas.
We do not use your customer data or connected platform data to train models for other customers. Outputs are decision-support content and should be reviewed before you act on them.
We keep personal data for as long as needed to provide Growomo, maintain records, comply with legal obligations, resolve disputes, and enforce agreements.
- Integration tokens and API keys are kept while the integration is connected and deleted or made unusable when you disconnect the platform or delete your account, subject to backup retention.
- After disconnect, Growomo may retain non-sensitive audit metadata such as platform, user, disconnect time, local disconnect status, and provider revocation status.
- Synced platform data and snapshots are kept while your account is active or as needed to provide historical reporting and recommendations, unless this policy, your plan, or an approved deletion request requires deletion.
- Deleted account data may remain in backups for a limited period, typically up to 30 days, before routine deletion.
- Invoices, tax records, payment records, and audit logs may be retained longer where required by law.
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, or disclosure.
- Encryption in transit using HTTPS/TLS.
- Encrypted storage for persisted OAuth tokens and API credentials.
- Role-based access controls, tenant scoping, and access logging where applicable.
- Security monitoring, rate limits, and safeguards against unauthorized account access.
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal data. You can also unsubscribe from non-essential emails.
You can disconnect third-party platforms in Growomo or revoke access directly from the relevant platform account settings. If provider revocation fails or is not supported, Growomo will disconnect locally and tell you to remove Growomo access or rotate the API key in the provider dashboard. To make a privacy request, email hello@growomo.com.
Growomo and its service providers may process information in countries other than where you live. When we transfer information internationally, we use reasonable safeguards appropriate to the data and processing activity.
Growomo is intended for business users and is not directed to children under 13. We do not knowingly collect personal data from children under 13.
We may update this Privacy Policy to reflect product, legal, or operational changes. If changes are material, we will provide reasonable notice through the product, website, or email where appropriate.