Privacy Policy
This policy explains what personal data we handle, why we handle it, who we share it with, and the choices and rights you have. It covers our website, our platform, and the data our customers process through us.
Last updated August 28, 2026 · GrowOutly, Inc.
1. Two different roles
It matters which hat we are wearing, because your rights differ depending on the situation.
- We are a controller for data about our website visitors, prospects, and the people who administer customer accounts. We decide why and how that data is used.
- We are a processor for the contact data our customers upload or collect and then call, text, or email through GrowOutly. Our customer decides why and how that data is used; we act on their instructions under our Data Processing Addendum.
If you were contacted by a business using GrowOutly and want your data removed, contact that business directly. If you cannot reach them, write to privacy@growoutly.com and we will forward your request to the customer responsible.
2. Data we collect as a controller
Information you give us
- Account details: name, work email, company, phone number, and role.
- Demo and enquiry details you submit through our contact form.
- Billing details. Card data is handled by our payment processor, not stored by us.
- Support correspondence and any information you include in it.
Information collected automatically
- Device and browser type, operating system, and approximate location from IP address.
- Pages viewed, referring URLs, and interactions with the site and product.
- Log data such as timestamps and error reports.
See our Cookie Policy for the cookies and similar technologies involved.
3. Data we process on behalf of customers
When a customer uses GrowOutly, we process the data they put into the platform. This typically includes:
- Contact records: names, phone numbers, email addresses, company details, and notes.
- Business listing data collected from public Google Maps results, such as business name, category, address, phone, website, rating, and review count.
- Communications content: call recordings and transcripts where the customer has enabled recording, SMS message content, and email content.
- Calendar events created through the customer’s connected Google account.
- Metadata such as call times, durations, dispositions, and delivery status.
We do not sell this data, use it to build our own marketing lists, or share it with other customers.
4. Why we use data, and our legal bases
| Purpose | Examples | Legal basis (UK/EU) |
|---|---|---|
| Providing the service | Routing calls, sending messages, storing CRM records, syncing calendars | Performance of a contract |
| Billing and account management | Charging subscriptions, invoicing, collecting overage | Performance of a contract |
| Support and communication | Answering tickets, sending service notices | Contract and legitimate interests |
| Security and abuse prevention | Fraud detection, spam and traffic-quality monitoring, audit logs | Legitimate interests and legal obligation |
| Product improvement | Aggregated, de-identified usage analytics | Legitimate interests |
| Marketing to businesses | Product updates and offers to account contacts | Consent or legitimate interests, with opt-out in every message |
5. Who we share data with
We share personal data only with parties that help us run the service:
- Cloud infrastructure and storage providers that host the platform.
- Telecommunications carriers and messaging providers that actually deliver your calls and texts. They receive the numbers and message content necessary for delivery.
- Email and calendar providers you connect, such as Google Workspace or Microsoft 365.
- Payment processors for subscription billing.
- Analytics and support tooling used to operate the website and help desk.
- Professional advisers, acquirers, and authorities where required by law or in connection with a merger or acquisition.
We require every processor to protect data under contract and to process it only on our instructions. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
We are based in the United States and use providers in several countries. Where data is transferred out of the UK, EEA, or another region with transfer restrictions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical measures such as encryption in transit and at rest.
7. How long we keep data
- Account and billing records: for the life of the account and then up to seven years where tax or accounting law requires it.
- Customer Data in the platform: for as long as the customer keeps it. After an account closes it is available for export for 30 days, then deleted.
- Call recordings and transcripts: retained under the retention setting the customer chooses, and deleted on request.
- Website and security logs: typically 12 months.
8. Security
We apply administrative, technical, and physical safeguards, including:
- TLS encryption in transit and encryption at rest for stored data;
- Role-based access control and least-privilege internal access;
- Audit logging of privileged actions;
- Regular backups and tested restore procedures;
- Vendor security review before we introduce a new subprocessor.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and get a copy;
- Correct inaccurate or incomplete data;
- Delete data, subject to legal retention requirements;
- Restrict or object to certain processing, including direct marketing;
- Receive your data in a portable format;
- Withdraw consent where processing relies on consent;
- Lodge a complaint with your data protection authority.
California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.
To exercise any right, email privacy@growoutly.com. We respond within 30 days and may need to verify your identity first.
10. Call recording
Recording is a setting our customers control. Where a customer enables it, they are responsible for providing any notice or obtaining any consent required by the laws of the jurisdictions involved — including all-party consent states and countries. GrowOutly provides controls to disable recording per number, per team, or per region.
11. Children
GrowOutly is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product and the law change. Material changes will be announced by email or in-product notice at least 30 days before they take effect. The date at the top of this page always shows the current version.
13. Contact us
Privacy questions and requests: privacy@growoutly.com.
Postal address: GrowOutly, Inc., 1209 Orange Street, Wilmington, DE 19801, United States.