← Back to home

Privacy Policy

Version 2026-08-20 · Last updated 20 August 2026

This policy explains what personal data GrowOpsHQ (“we”, “us”) collects through this website, why we collect it, how long we keep it, and the rights you have over it. It is written to satisfy the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (“CCPA”).

1. Who is responsible for your data

GrowOpsHQ is the data controller for personal data collected through this website. For any privacy question or to exercise the rights described in section 7, contact us at privacy@growopshq.com. We respond to all requests within 30 days.

2. Cookies and tracking

This website sets no cookies of any kind. It runs no advertising or remarketing pixels, no session recording, no A/B testing tools and no social media widgets. It loads no third-party resources — no external fonts, no hosted scripts, no embedded media — so no third party receives your IP address by virtue of your visiting this page.

We do measure page views, using Vercel Web Analytics. It is served from our own domain rather than a third-party host, sets no cookies, and stores nothing on your device. It records aggregate figures only: the page visited, the referring site, and coarse country and device type. To recognise a repeat visit within the same day it derives a temporary, non-reversible hash from your IP address and browser, which is discarded within 24 hours and is never retained as an identifier or linked to anything you submit through the form. It does not build a profile of you and cannot follow you across other websites.

Because we place no non-essential cookies or similar tracking technologies, no cookie consent banner is required under the ePrivacy Directive or GDPR, and there is no sale or sharing of personal information to opt out of under the CCPA. We do not track you across other websites, so we do not respond to Global Privacy Control or Do Not Track signals — there is nothing for them to switch off.

3. What we collect

We collect personal data only when you choose to submit the Review Presence Scorecard form. The aggregate page-view measurement described in section 2 is the only other data collection on this site, and it does not identify you.

DataSourceWhy we hold it
Business nameYou, via the formTo personalise your scorecard and any follow-up
Email addressYou, via the formTo send your scorecard and contact you about the beta programme
Your five scorecard answers and resulting scoreYou, via the formTo generate your scorecard and prepare a relevant onboarding call
Consent record: the wording you agreed to, and the timestampGenerated on submissionTo evidence lawful consent, as GDPR Article 7(1) requires
Referring URL and campaign parameters in the link you arrived byYour browserTo understand which outreach produced an enquiry
Browser language and timezone nameYour browserTo contact you at a reasonable hour and in the right language
Timestamps for starting and submitting the scorecardGenerated on submissionService quality and abuse prevention

We do not collect payment details, government identifiers, precise geolocation, or any special category data (health, biometrics, race, religion, political opinions, sexual orientation, trade union membership). Please do not include such information in the form.

4. Our lawful basis (GDPR)

5. Who else sees your data

We do not sell, rent or trade personal data. We never have, and we do not share it for cross-context behavioural advertising. Under the CCPA, this means we do not “sell” or “share” personal information as those terms are defined.

Your form submission is transmitted to the following processors, which act only on our instructions:

ProcessorPurposeRegion
Make.com (Celonis SE)Receives the form submission and routes it into our workflowEU
Vercel Inc.Website hosting and delivery, and aggregate page-view analyticsGlobal edge network
Calendly LLCOnly if you choose to book a callUnited States

Where a processor is outside the EEA or UK, transfers are covered by the European Commission's Standard Contractual Clauses. We may also disclose data where legally compelled to do so, and will notify you unless prohibited from doing so by law.

6. How long we keep it

7. Your rights

To exercise any of these, email privacy@growopshq.com. We will not charge you, and we will not treat you differently for asking.

If GDPR applies to you (EU, EEA or UK)

If the CCPA applies to you (California)

An authorised agent may submit a request on your behalf with written proof of authorisation. We may ask you to verify your identity before acting, by confirming control of the email address in our records.

8. Security

The site is served over HTTPS with HSTS enforced. Form submissions are transmitted over encrypted connections. Access to submitted data is limited to personnel who need it to respond to your enquiry. No system is perfectly secure, but we hold only minimal business contact data and no payment or identity information, which keeps the impact of any incident low. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.

9. Children

This is a business-to-business service, not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data, contact us and we will delete it.

10. Changes to this policy

If we make a material change we will update the version number and date at the top of this page. Where the change affects processing you previously consented to, we will seek fresh consent rather than relying on the old one.

11. Contact

Privacy enquiries: privacy@growopshq.com
General enquiries: hello@growopshq.com