Legal
Privacy Policy
Last updated: September 4, 2026
1. Introduction
GrowLocal, LLC ("GrowLocal," "we," "us," or "our") values your privacy. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use growlocal.site, our customer dashboard, onboarding forms, and the websites we host on your behalf.
By using our services, you acknowledge that you have read and understood this Privacy Policy. If you have questions, contact us at [email protected].
2. What We Collect
(a) Information you provide directly:
- Account information -- name, email address, and password
- Business information -- business name, description, address, phone number, and other details submitted during onboarding
- Content -- logos, photographs, written text, and other materials you upload for your website
- Payment information -- processed through Stripe. We never directly store your credit card number, CVV, or full card details. Stripe handles payment data under its own PCI-compliant systems
- Communications -- messages you send us through support channels or your dashboard
(b) Information collected automatically:
- IP address and approximate geolocation
- Browser type and version, operating system, and device information
- Pages visited, time spent on pages, and navigation patterns
- Referral source -- where you came from before visiting our site
- Cookies and similar tracking technologies (see Section 8)
(c) Information from third parties:
- Etsy -- product catalog data, if you connect your Etsy shop
- Stripe -- payment confirmations and subscription status
- Affiliate referral sources -- if you were referred by an affiliate partner, we receive a referral identifier
3. How We Use Your Information
We use the information we collect to:
- Build and host your website -- using your business information, content, and preferences to design and maintain your site
- Process payments -- managing your subscription billing through Stripe
- Communicate with you -- sending service updates, responding to support requests, and notifying you of important changes
- Improve the service -- analyzing usage patterns to make GrowLocal better for everyone
- Feature your site in our portfolio -- showcasing your website in our marketing materials (you can opt out -- see our Terms of Service)
- Comply with legal obligations -- responding to lawful requests and protecting our rights
- Prevent fraud and abuse -- detecting and blocking unauthorized or malicious activity
4. Who We Share Your Information With
We do not sell your personal information. We share information only with the following parties and only as necessary:
- Stripe -- payment data for processing your subscription, and, for your store, your buyers' payments on your own connected Stripe account (see Section 6)
- Cloudflare -- site content, images, and traffic data for CDN delivery, DNS, file storage, and email routing
- Mailgun -- email addresses and message content for the email we send and receive on your behalf
- Twilio -- phone numbers and message content for business phone numbers and text messaging (see Section 7)
- PostForMe -- your connected social accounts and the posts published to them (see Section 13)
- Recall.ai -- meeting audio and video, to produce your recording and transcript
- EasyPost -- shipping addresses and parcel details, for carrier rates and labels
- AI providers (Anthropic, Recraft) -- your business information may be sent as prompts during AI-assisted site generation, content writing, and image generation. This data is used solely to produce your website, posts, and images and is subject to the provider's data handling policies
- Advertising measurement providers (Meta and Google) -- if you explicitly allow marketing cookies, we share limited browser identifiers, contact-data hashes, and signup, lead, or purchase events to measure and improve GrowLocal's advertising. We do not send customer-site visitor activity to these providers
- Affiliates -- limited information (that you signed up and your subscription status) for commission tracking purposes
- Legal authorities -- if required by law, subpoena, court order, or to protect our rights, property, or safety
- Business transfers -- if GrowLocal is acquired, merged, or sells substantially all of its assets, your information may be transferred as part of that transaction. We will notify you of any such change
5. Your Site Visitors
When we host a website for you, we serve it to your visitors. In this context:
- You are the data controller for the personal information of visitors to your website
- GrowLocal is the data processor -- we host and serve your site on your behalf, but you are responsible for how visitor data is collected and used
- If your site collects visitor information (e.g., through contact forms or lead capture), you are responsible for your own privacy policy and compliance with applicable data protection laws
We provide the tools; you are responsible for using them lawfully and transparently.
6. Your Customers and Contacts
Separate from the information we hold about you, GrowLocal stores the customers, leads, and subscribers your business collects -- through your site's forms, your store's orders, and your own entries. For that data you are the data controller and GrowLocal is the data processor: we hold it and act on it on your instructions. We do not sell it, and we do not market to your customers on our own behalf.
What we store: name, email address, phone number, a postal or shipping address where a purchase needed one, which forms and orders each person came through, their consent status per channel, and the marketing messages we sent them with what happened to each one.
- Consent is recorded per person and per channel, with when and where it was given. Only a genuine opt-in creates consent -- a completed purchase does not
- Unsubscribing is honoured immediately and permanently. Marketing emails carry one-click unsubscribe headers and a link that needs no login; a text reply of STOP unsubscribes that number on the spot. Unsubscribes, spam complaints, and hard bounces go onto a suppression list that every later marketing send is checked against
- We do not track opens or clicks on marketing email. We record whether a message was delivered, bounced, or reported as spam -- nothing about reading behaviour
- Store payments -- when someone buys from your store, their card details go from their browser to Stripe and are charged on your own Stripe account. We never see or store card numbers. We do receive the order, contact, and shipping details needed to fulfil it, and shipping addresses go to our shipping provider where you use built-in shipping
- Access and deletion -- you can export your contacts as a CSV at any time. Ask us and we will delete a single contact or your entire contact list
If you are a customer of a business that uses GrowLocal and you want your information accessed, corrected, or deleted, please contact that business directly -- they decide what happens to it. You can also write to us at [email protected] and we will pass the request on and help them action it.
7. Text Messages
Where you use text messaging, texts are sent and received through Twilio from a business phone number. Phone numbers, message content, and delivery status pass through and are stored by Twilio as well as by us.
- A marketing text is refused rather than sent to anyone without recorded consent for text messaging, and to any number on the opt-out list
- STOP (also STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT or REVOKE) unsubscribes that number immediately and adds it to the business's opt-out list. HELP returns an automatic reply naming the business with opt-out instructions. Both are handled automatically and cannot be switched off
- Opt-outs are held per business, and are kept indefinitely -- an opt-out has to outlive the contact record that carried it
- Message and data rates may apply. Carriers may delay, filter, or refuse messages, and delivery is not guaranteed
Text messaging also requires carrier registration (A2P 10DLC) before any message can be sent. Until a number is registered and texting is enabled on the account, sends are refused rather than delivered.
8. Cookies
We use cookies and similar technologies for:
- Session management -- keeping you logged in and maintaining your preferences
- Analytics -- understanding how people use our platform so we can improve it
- Optional advertising measurement -- only after you opt in, measuring GrowLocal signups, preview requests, and purchases through Meta Pixel and Google Ads
Meta and Google marketing tags are disabled by default. If you choose “Allow marketing,” Meta may set _fbp and related cookies, and we may send matching conversion events from our server. We use these only on GrowLocal-owned pre-purchase surfaces, never on a customer's purchased website or custom domain.
You can allow or reject marketing cookies from the consent prompt and change that choice at any time through Cookie settings. Essential login and security cookies cannot be disabled. Browser privacy controls that signal Global Privacy Control are treated as a rejection.
9. Data Retention
We retain your data according to the following schedule:
- Account data -- retained for the duration of your subscription plus 120 days after cancellation
- Content (logos, photos, text) -- deleted 120 days after subscription ends (you may request a copy before deletion)
- Payment records -- retained for 7 years as required by tax law
- Automated backups -- automatically deleted after 30 days via lifecycle policy
- Customer and contact records -- your business's contacts, their consent history, and their message history: kept while your business keeps them, deleted on request, and no later than 120 days after your subscription ends
- Unsubscribes and opt-outs -- kept indefinitely. A suppression has to outlive the contact record that carried it, or a deleted contact could be re-added and messaged again
- Connected-account access tokens -- deleted when you disconnect the account
10. Your Rights
You have the right to:
- Access -- request a copy of the personal information we hold about you
- Correct -- update or correct inaccurate information
- Delete -- request deletion of your personal information (subject to legal retention requirements)
- Object -- object to certain uses of your information
- Portability -- request your data in a portable format
California residents (CCPA): Under the California Consumer Privacy Act, you have additional rights:
- The right to know what personal information is collected and how it is used
- The right to delete your personal information
- The right to opt out of sale or sharing of personal information. We do not sell personal information for money. Optional advertising measurement is off until you opt in, and you can withdraw that choice through Cookie settings
- The right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within 30 days.
These rights cover the information we hold about you. If you are a customer of a business that uses GrowLocal, see Section 6 -- that business controls your information and we act on its instructions.
11. Security
We take the security of your data seriously. Our measures include:
- HTTPS encryption on all connections
- Encrypted storage for sensitive data
- Access controls limiting who can access your information internally
- Regular automated backups to prevent data loss
No system is 100% secure. While we implement commercially reasonable safeguards, we cannot guarantee absolute security. We encourage you to use a strong, unique password for your account.
12. Google User Data
Some GrowLocal features let you connect your Google account — for example, syncing your Google Calendar with your GrowLocal calendar, or connecting Google Search and Business Profile data to your dashboard. When you connect, Google asks for your permission first, and we only receive the data you approve.
- What we access: only the Google data needed for the feature you connected — calendar events for calendar sync; search performance and business listing data for the marketing dashboard.
- How we use it: solely to provide that feature to you inside your GrowLocal dashboard — for example, showing your Google Calendar events on your business calendar and keeping the two in sync. We do not use Google user data for advertising, and we never sell it.
- How we store it: access tokens and synced data are stored encrypted, and access is limited to the systems that run the feature.
- Who sees it: no one else. We do not share Google user data with third parties except the subprocessors that host our infrastructure, and no human reads it except with your permission, when needed for security, or where required by law.
- Disconnecting: you can disconnect at any time inside your dashboard, or revoke GrowLocal's access from your Google account permissions. When you disconnect, we stop syncing and delete the stored tokens.
GrowLocal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
13. Other Connected Accounts
Beyond Google, some features work by connecting an account you already own. In each case you authorize the connection on the provider's own screen and we receive only what you approve there.
- Social accounts -- connecting Instagram, Facebook, X, LinkedIn, TikTok, Pinterest, Bluesky, Threads, or YouTube runs through PostForMe, our publishing partner, which holds the platform authorization. We store a reference to the connected account plus the account name and picture we display, and we send PostForMe the caption, images, target accounts, and scheduled time for each post you publish
- Etsy -- product listings and images imported from your shop, plus the access token needed to read them
- Stripe -- your store's own Stripe account, connected through Stripe's onboarding (see our Terms of Service)
You can disconnect a social or Etsy account from your dashboard, which stops the feature and deletes the access we had stored. Where the provider offers its own permissions screen, you can withdraw our access there as well, and we recommend doing both. Your store's Stripe connection is managed in Stripe itself.
14. Children's Privacy
GrowLocal is a business service and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us immediately and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide at least 30 days' notice via email to the address associated with your account.
We encourage you to review this policy periodically. Continued use of the service after the notice period constitutes acceptance of the updated policy.
16. Contact
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us at:
See also our Terms of Service and Disclaimers for additional information.

