Privacy Policy
Version 2026-08-20 · Last updated 20 August 2026
This policy explains what personal data GrowOpsHQ (“we”, “us”) collects through this website, why we collect it, how long we keep it, and the rights you have over it. It is written to satisfy the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
1. Who is responsible for your data
GrowOpsHQ is the data controller for personal data collected through this website. For any privacy question or to exercise the rights described in section 7, contact us at privacy@growopshq.com. We respond to all requests within 30 days.
Placeholder to complete before launch: GDPR Article 13 and the CCPA both require a controller's registered legal name and postal address to be published here. Replace this paragraph with your registered entity name and address. If you have no registered entity yet, use the address you are trading from.
2. Cookies and tracking — there are none
This website sets no cookies of any kind. It runs no analytics, no advertising or remarketing pixels, no session recording, no A/B testing tools and no social media widgets. It loads no third-party resources at all — no external fonts, no hosted scripts, no embedded media — so no third party receives your IP address by virtue of your visiting this page.
Because we place no non-essential cookies or similar tracking technologies, no cookie consent banner is required under the ePrivacy Directive or GDPR, and there is no sale or sharing of personal information to opt out of under the CCPA. We do not track you across other websites, so we do not respond to Global Privacy Control or Do Not Track signals — there is nothing for them to switch off.
3. What we collect
We collect personal data only when you choose to submit the Review Presence Scorecard form.
| Data | Source | Why we hold it |
|---|---|---|
| Business name | You, via the form | To personalise your scorecard and any follow-up |
| Email address | You, via the form | To send your scorecard and contact you about the beta programme |
| Your five scorecard answers and resulting score | You, via the form | To generate your scorecard and prepare a relevant onboarding call |
| Consent record: the wording you agreed to, and the timestamp | Generated on submission | To evidence lawful consent, as GDPR Article 7(1) requires |
| Referring URL and campaign parameters in the link you arrived by | Your browser | To understand which outreach produced an enquiry |
| Browser language and timezone name | Your browser | To contact you at a reasonable hour and in the right language |
| Timestamps for starting and submitting the scorecard | Generated on submission | Service quality and abuse prevention |
We do not collect payment details, government identifiers, precise geolocation, or any special category data (health, biometrics, race, religion, political opinions, sexual orientation, trade union membership). Please do not include such information in the form.
4. Our lawful basis (GDPR)
- Consent (Article 6(1)(a)) — you tick a mandatory, unticked-by-default box before submitting. This is our basis for sending you your scorecard and contacting you about the beta programme. You may withdraw consent at any time, and withdrawing it is as easy as giving it: email us, or use the unsubscribe link in any message.
- Legitimate interests (Article 6(1)(f)) — for keeping the consent record itself, and for basic security and abuse prevention. We have assessed that these do not override your rights, since the data involved is minimal and directly protective of you.
5. Who else sees your data
We do not sell, rent or trade personal data. We never have, and we do not share it for cross-context behavioural advertising. Under the CCPA, this means we do not “sell” or “share” personal information as those terms are defined.
Your form submission is transmitted to the following processors, which act only on our instructions:
| Processor | Purpose | Region |
|---|---|---|
| Make.com (Celonis SE) | Receives the form submission and routes it into our workflow | EU |
| Vercel Inc. | Website hosting and delivery | Global edge network |
| Calendly LLC | Only if you choose to book a call | United States |
Where a processor is outside the EEA or UK, transfers are covered by the European Commission's Standard Contractual Clauses. We may also disclose data where legally compelled to do so, and will notify you unless prohibited from doing so by law.
6. How long we keep it
- Scorecard submissions and answers: 24 months from submission, then deleted.
- Consent records: retained for the same period as the underlying data, plus 12 months, to evidence lawful basis if challenged.
- If you ask us to delete your data: deleted within 30 days, except for a minimal suppression record (your email address only) that stops us contacting you again.
7. Your rights
To exercise any of these, email privacy@growopshq.com. We will not charge you, and we will not treat you differently for asking.
If GDPR applies to you (EU, EEA or UK)
- Access — a copy of the personal data we hold about you
- Rectification — correction of anything inaccurate
- Erasure — deletion, where we have no overriding basis to retain it
- Restriction — pause our processing while a dispute is resolved
- Portability — your data in a structured, machine-readable format
- Objection — to processing based on legitimate interests
- Withdraw consent — at any time, without affecting processing already carried out
- Complain — to your national supervisory authority. You may do this without contacting us first, though we would prefer the chance to put things right.
If the CCPA applies to you (California)
- Right to know — the categories and specific pieces of personal information we have collected, the sources, our purposes, and any third parties involved
- Right to delete — subject to the statutory exceptions
- Right to correct — inaccurate personal information
- Right to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of; we state this explicitly rather than omitting it
- Right to limit use of sensitive personal information — we collect none
- Right to non-discrimination — exercising any right will never affect the price or quality of anything we provide you
An authorised agent may submit a request on your behalf with written proof of authorisation. We may ask you to verify your identity before acting, by confirming control of the email address in our records.
8. Security
The site is served over HTTPS with HSTS enforced. Form submissions are transmitted over encrypted connections. Access to submitted data is limited to personnel who need it to respond to your enquiry. No system is perfectly secure, but we hold only minimal business contact data and no payment or identity information, which keeps the impact of any incident low. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.
9. Children
This is a business-to-business service, not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data, contact us and we will delete it.
10. Changes to this policy
If we make a material change we will update the version number and date at the top of this page. Where the change affects processing you previously consented to, we will seek fresh consent rather than relying on the old one.
11. Contact
Privacy enquiries: privacy@growopshq.com
General enquiries: hello@growopshq.com