GrowthProof
Privacy
How GrowthProof collects, uses, shares, retains, and protects personal data when providing the service.
Effective and last updated: July 31, 2026
Information we collect
- Account data includes email addresses, names when provided, authentication metadata, tenant membership, and role assignments.
- Workspace data includes client workspace names, contacts, checklist tasks, report settings, evidence metadata, notes, links, and uploaded files.
- Marketing data includes waitlist email addresses, communication preferences, and related submission information.
- Operational data includes audit logs, webhook records, notification records, billing status, and security diagnostics.
- Usage data may include visited product areas, feature events, device and browser information, approximate location derived from an IP address, and error diagnostics.
How and why we use information
- We use account and workspace data to provide, secure, support, and improve GrowthProof; authenticate users; enforce permissions; generate reports; and deliver requested communications.
- We use billing and transaction metadata to administer subscriptions, enforce plan limits, prevent fraud, and maintain accounting records. GrowthProof does not receive or store complete payment-card details.
- We use limited analytics and diagnostics to understand product reliability and usage. Evidence contents, internal notes, secrets, and signed file URLs must not be sent to analytics or error-monitoring providers.
- Where applicable law requires a legal ground, processing may be necessary to perform a contract, comply with law, protect the service and users, pursue legitimate business interests that do not override individual rights, or act on consent for optional marketing or analytics.
Service providers and disclosures
- Supabase provides database, authentication, storage, and scheduled job infrastructure.
- Vercel hosts the web application and provides web analytics, while Cloudflare supports domain, network, and security services.
- Google supports optional account sign-in, Resend sends transactional email, and Loops receives marketing waitlist submissions.
- Sentry provides error monitoring and PostHog provides product analytics.
- Lemon Squeezy acts as merchant of record for checkout, subscriptions, taxes, payments, refunds, and chargebacks. GrowthProof receives the order and subscription metadata needed to provide the service but not complete payment-card details.
- Information may also be disclosed when required by law, to protect users or the service, or as part of a merger, financing, acquisition, or sale subject to appropriate confidentiality protections.
Cookies and analytics
- GrowthProof uses cookies and browser storage for authentication, tenant selection, temporary invitation and report workflows, security, and waitlist rate limiting.
- When enabled, Vercel Analytics and PostHog receive usage events and technical information. PostHog events are filtered to exclude evidence content, file names, raw tenant IDs, personal notes, and signed file URLs.
- After a successful waitlist submission, GrowthProof creates a one-way hash of the submitted email as a pseudonymous PostHog identifier; the submitted email itself is sent to Loops.
- Browser or device controls may limit non-essential storage or analytics. Individuals may also contact GrowthProof to object to or ask about analytics processing where applicable law provides that right.
Retention and deletion
- Tenant data is retained while an account remains active and as needed to provide the service. Cancellation alone does not request deletion, and inactive tenant data may remain stored until an account owner requests deletion.
- Evidence that an authorized user deletes or replaces is queued for permanent file and metadata removal.
- An owner deletion request starts a 30-day read-only grace period before tenant-scoped files and database records are permanently deleted, subject to legal or operational holds.
- Billing records, webhook logs, notification records, and minimal audit logs may be retained longer for accounting, fraud prevention, security, and legal defense. Provider-managed backups may remain protected until their ordinary deletion cycles complete.
- Account owners may request an export or deletion from Settings or by contacting support. Support can cancel a pending request during the grace period, and some records cannot be deleted immediately where continued retention is legally required.
Your rights
- Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing and to receive a portable copy of personal data.
- GrowthProof primarily handles tenant data on the MSP customer's instructions. Requests concerning data uploaded by an MSP may be referred to that MSP as the responsible controller.
- Individuals may unsubscribe from marketing communications and may withdraw consent where processing relies on consent, without affecting processing that occurred before withdrawal.
- Identity may be verified before a request is completed. Individuals may also complain to the data-protection authority responsible for their location.
International transfers, children, and changes
- Service providers may process information in countries other than the user's country. Where required, transfers must rely on an applicable legal mechanism, such as an adequacy decision or valid contractual safeguards. Customers requiring specific residency or transfer terms should contact GrowthProof before uploading personal data.
- GrowthProof is a business service and is not directed to children. Users must not intentionally provide or upload children's personal data.
- Material policy changes will be posted on this page and, where appropriate, communicated to account owners before they take effect.
Contact
Questions about this policy may be sent to Shawal Kabir Chy, trading as GrowthProof at support@getgrowthproof.com.
Business address: Road 8, House 405, Block D, Bashundhara R/A, Dhaka 1229, Bangladesh