1. Who we are
This Privacy Policy explains how GROW SRP Ltd ("we", "us" or "our") collects, uses and protects personal data when you use GROW Online our website at https://grow.online, and our related services.
For the purposes of data protection law, we are the data controller for the personal data described in this Privacy Policy, except where we process data on behalf of our customers as explained in section 11.
Our details
Company name: GROW SRP Ltd
Registered address: Neptune House, Staffordshire Technology Park, Stafford. UK. ST18 0WQ
Company number: 10344679
Email address: appsupport at grow dot online
If you have any questions about this Privacy Policy or how we handle personal data, please contact us using the details above.
2. What this policy covers
This Privacy Policy applies to personal data we collect when:
- you visit our website;
- you create or use an account on our platform;
- you sign in using Google OAuth;
- you contact us;
- you sign up for emails, newsletters or marketing;
- you connect third-party services such as Google Ads and Google Merchant Center to our platform; or
- we otherwise provide services to you or your business.
3. The personal data we collect
We may collect and use the following categories of personal data.
A. Account and profile information
This may include:
- your name;
- email address;
- business name;
- job title;
- account login details;
- account preferences and settings;
- Google account identifier (where you sign in using Google OAuth).
B. Contact and communication information
This may include:
- information you provide when you contact us;
- support requests and correspondence;
- email preferences;
- records of our communications with you.
C. Technical and usage information
This may include:
- IP address;
- browser type and version;
- device type;
- operating system;
- referral source;
- pages viewed;
- dates and times of access;
- login activity;
- usage logs and audit logs;
- session and cookie identifiers.
D. Billing and transaction information
If you purchase a subscription or paid service, we may collect:
- billing name and address;
- subscription details;
- payment status;
- limited transaction information.
Payments are processed by Stripe Payments. We do not store full payment card details on our own systems.
E. Connected service data (Google APIs)
If you connect Google services to our platform using OAuth, we may access and process data made available through those services.
Google Account (OAuth Sign-In)
When you sign in with Google, we access:
- your name;
- your email address;
- your Google account identifier (sub claim) for authentication purposes.
Google Ads
When you connect Google Ads, we may access:
- advertising account identifiers;
- campaign, ad group, and ad data;
- performance metrics including impressions, clicks, conversions, and spend;
- product group and listing data;
- account configuration and settings.
Google Merchant Center
When you connect Google Merchant Center, we may access:
- merchant account identifiers;
- product feed data including titles, descriptions, prices, and availability;
- product status and diagnostics;
- account configuration information.
Google Sheets (optional)
Where you choose to connect Google Sheets for data synchronisation, we may access:
- spreadsheet data you specifically authorise for synchronisation.
We only access and use data from Google APIs to provide our services, improve platform functionality, maintain security, and support our customers. Data accessed through Google APIs is not used for advertising purposes or sold to third parties.
Actions we take on your behalf via Google APIs
Where you authorise it, GROW will take automated actions in your connected Google Ads and Google Merchant Center accounts. These may include:
- creating, updating, pausing or removing campaigns, ad groups and ads;
- adjusting bids, budgets, targeting and exclusions;
- uploading or modifying product feed data;
- applying optimisation rules and automation you have configured.
All such actions are taken using OAuth credentials you have authorised, and you can disable automation features or revoke access at any time. We will not use Google user data to take any action you have not authorised.
How to revoke our access to your Google data
You have two ways to disconnect Google services from GROW:
1. Unlink within GROW (subscription-linked):
Open Account Settings → Connected Accounts and click Unlink on the relevant Google service. Because the operation of the GROW platform depends on this connection, clicking Unlink will start the cancellation of your GROW subscription with 30 days’ notice. During that notice period, your Google integration remains active so the platform can continue to operate for you. At the end of the notice period, when your subscription access ends, your OAuth tokens are revoked at Google and deleted from our systems immediately. See section 12 for full retention details.
2. Immediate revocation via your Google Account:
You can revoke our access to your Google data at any time, immediately, by visiting https://myaccount.google.com/permissions and removing access for GROW Online. Once you do this, the revocation takes effect at Google immediately, we will stop accessing your Google data straight away, and we will delete the corresponding OAuth tokens from our systems on detection. Note that revoking access this way will not, by itself, cancel your GROW subscription — to also close your account, please contact us at appsupport at grow dot online.
F. Marketing information
This may include:
- whether you have opted in or out of marketing;
- your engagement with our emails;
- records of your communication preferences.
4. How we collect personal data
We collect personal data:
- directly from you, when you create an account, contact us, request information, or use our services;
- through Google OAuth, when you sign in with your Google account (we receive your name, email, and Google account identifier);
- automatically, through cookies, logs and similar technologies when you use our website or platform;
- from third-party services you choose to connect, such as Google Ads and Google Merchant Center;
- from payment providers in connection with subscriptions and transactions; and
- from service providers who help us operate our platform.
5. How we use personal data
We use personal data for the following purposes:
- to create and manage user accounts;
- to provide and operate our platform and services;
- to connect and process third-party integrations, including Google Ads and Google Merchant Center;
- to analyse performance and generate reporting, insights and recommendations;
- to respond to enquiries and provide customer support;
- to manage subscriptions, billing and payments;
- to monitor usage, maintain logs and protect the security of our systems;
- to improve our website, platform and services;
- to send service-related messages, such as account, billing, technical or security notices;
- to send marketing communications where permitted by law;
- to comply with legal and regulatory obligations; and
- to establish, exercise or defend legal claims.
Google API Services Limited Use Disclosure
GROW Online's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we limit our use of Google user data to providing and improving the user-facing features of our platform that are visible and prominent in the GROW interface. Where Google user data may be used for more than one of the purposes listed in this Privacy Policy, all such uses (both primary and secondary) are described in section 5; we do not use Google user data for any purpose not listed here without first obtaining your consent (see section 18). We do not use, retain, or transfer Google user data for:
- serving advertisements, including retargeted, personalised, or interest-based advertising;
- selling, licensing, or transferring Google user data to third parties, data brokers, or information resellers;
- determining creditworthiness or for lending purposes;
- developing, improving, or training generalised or non-personalised artificial intelligence (AI) or machine learning (ML) models;
- any purpose unrelated to the core, user-facing functionality of our platform.
AI and machine learning: We do not retain, use, or transfer Google user data to create, train, or improve any generalised or non-personalised AI or ML models. Where AI features within our platform process Google user data, that processing is limited to providing the user-facing features of the platform for the specific account that authorised access, and is not used to develop, improve, or train models that are available to other accounts or to the public.
Human access: We do not allow humans to read Google user data unless: (a) we have your affirmative agreement to view specific data; (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) our use is limited to internal operations and the data has been aggregated and anonymised.
6. Our lawful bases for processing
Data protection law requires us to have a valid legal basis for processing personal data. Depending on the circumstances, we rely on one or more of the following:
A. Contract
We process personal data where it is necessary to provide our services, manage your account, process subscriptions, or take steps before entering into a contract with you.
B. Legitimate interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and interests. This includes:
- operating and improving our platform;
- providing customer support;
- keeping our services secure;
- preventing fraud and misuse;
- maintaining internal records and logs;
- understanding how our website and platform are used.
C. Consent
We rely on consent where required by law, including for certain cookies and similar technologies, and for certain marketing communications.
You can withdraw your consent at any time, but this will not affect processing already carried out before you withdrew it.
D. Legal obligation
We may process personal data where necessary to comply with legal or regulatory obligations, including tax, accounting, fraud prevention and law enforcement requirements.
7. Marketing communications
We may send you marketing communications about our services where we are allowed to do so by law, or where you have given us your consent.
You can opt out of marketing emails at any time by:
- clicking the unsubscribe link in any marketing email; or
- contacting us at appsupport at grow dot online.
Even if you opt out of marketing, we may still send you service messages that are necessary for your account or our ongoing business relationship with you.
10. International data transfers
Some of our service providers may process personal data outside the UK or the European Economic Area.
Where personal data is transferred internationally, we take steps to ensure it remains protected. Where required, this includes using appropriate safeguards such as:
- adequacy regulations or adequacy decisions; or
- standard contractual clauses and the UK International Data Transfer Addendum, where appropriate.
You can contact us at appsupport at grow dot online if you would like more information about the safeguards we use.
11. When we act as a controller and when we act as a processor
In most cases, we act as a data controller for personal data relating to our website visitors, users, leads, contacts and customers.
However, when we process certain data through our platform on behalf of a customer, we may act as a data processor and the customer may act as the data controller. This may apply, for example, where we process advertising or performance data connected to a customer's third-party accounts in order to provide our services.
Where we act as a processor, we process personal data in accordance with our customer's instructions and our contractual obligations.
12. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to meet legal, accounting, tax, security and reporting requirements.
Typical retention periods may include:
- Account information: for as long as the account remains active, and for a reasonable period afterwards;
- Support and correspondence records: up to 31 days;
- Usage logs and security logs: up to 31 days;
- Marketing records: until you unsubscribe or object, and for a limited period afterwards to maintain suppression records;
- Billing and transaction records: for up to 10 years where required for tax and accounting purposes;
- Connected service data (general): for as long as needed to provide the service and in line with customer instructions, contractual terms and legal obligations.
Google user data, OAuth tokens, and GROW platform data
We treat the data involved in your Google integration in three distinct categories:
1. OAuth tokens
- When you unlink via Account Settings → Connected Accounts, the unlink starts your GROW subscription cancellation with 30 days’ notice. At the end of that notice period — when your subscription access ends — your OAuth refresh and access tokens are revoked at Google and deleted from our systems immediately.
- If you instead revoke our access via your Google Account at myaccount.google.com/permissions, the revocation takes effect at Google immediately, and we delete the corresponding OAuth tokens from our systems on detection.
2. Live data fetched from Google APIs
- Performance and reporting data fetched from Google Ads and Google Merchant Center APIs (for example, impressions, clicks, conversions, spend, product feed status and diagnostics) is held only in short-term cache for no longer than 24 hours, and is never persisted long-term in our database.
- Account-level identifiers needed to link your GROW account to your Google Ads or Merchant Center account (such as customer ID, account name, currency and timezone) are retained while you remain a GROW customer.
- Once your OAuth tokens are revoked, we no longer fetch any data from Google APIs on your behalf.
3. GROW platform data
Configuration and operational data you create within GROW — including campaign builds, optimisation settings, product-link mappings, cost tracking entries and similar — is generated by you through your use of the GROW platform. This is your GROW account data, not Google user data. We retain it against your GROW account so that you can resume your work seamlessly if you reconnect and reactivate your subscription.
If you make a formal erasure request under data protection law (see section 14), we will action it within one calendar month, regardless of any subscription notice period.
We may keep data for longer where necessary to comply with legal obligations, resolve disputes, prevent fraud, or enforce our agreements.
13. How we protect personal data
We use appropriate technical and organisational measures to protect personal data. These may include:
- secure hosting and infrastructure;
- encryption in transit (TLS/HTTPS);
- encryption of OAuth tokens and API credentials at rest;
- access controls and authentication measures;
- restricted staff access on a need-to-know basis;
- system monitoring, logging and security controls;
- procedures for handling suspected data breaches.
No method of transmission or storage is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.
14. Your data protection rights
Depending on your location and the circumstances, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- request transfer of your personal data to you or another provider, where applicable;
- withdraw consent where we rely on consent;
- complain to a relevant supervisory authority.
To exercise any of these rights, please contact us at appsupport at grow dot online.
We may need to verify your identity before responding to your request.
UK users
If you are in the UK, you have the right to complain to the Information Commissioner's Office (ICO).
EU users
If you are in the EU, you also have the right to complain to the data protection authority in the country where you live, work, or where you believe a breach has occurred.
15. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on individuals.
If this changes, we will update this Privacy Policy and provide any information required by law.
16. Children
Our website, platform and services are intended for businesses and are not directed at children.
We do not knowingly collect personal data from children under 18. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps.
17. Third-party websites and services
Our website or platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties.
If you use or connect third-party services, your use of those services will also be subject to their own terms and privacy policies.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our business, services, technology, legal requirements or data practices.
When we make changes, we will update the "Last updated" date at the top of this policy. Where we change how we access, use, store or share Google user data, we will notify you and obtain your consent to the updated policy before making any new use of your Google user data. For other material changes, we will notify you by email or through the platform.
19. Contact us
If you have any questions about this Privacy Policy or how we handle personal data, please contact us:
GROW SRP Ltd
Neptune House,
Staffordshire Technology Park, Stafford.
United Kingdom.
ST18 0WQ
appsupport at grow dot online