Legal
Privacy Policy
Privacy Policy
Effective date: 24 July 2026 Last updated: 24 July 2026
This Privacy Policy explains how QOPTERVZN INFOCOM PRIVATE LIMITED, operating the GrowthMate service, collects, uses, stores, shares, protects and deletes personal data.
GrowthMate is operated by:
QOPTERVZN INFOCOM PRIVATE LIMITED Plot No. 19, At – Khokarla Balaji Nagar, Behind Bhaiyaji Nagar Bhupali Duplex Bhandara, Maharashtra India – 441904
In this Privacy Policy:
- “GrowthMate,” “we,” “our” or “us” means QOPTERVZN INFOCOM PRIVATE LIMITED.
- “Services” means the GrowthMate website, application, dashboards, integrations, reports, recommendations, communications and related services.
- “Website” means
growthmate.net. - “Application” means
app.growthmate.net. - “User,” “you” or “your” means a visitor, account holder, workspace member, customer, report recipient or other person interacting with GrowthMate.
- “Customer Data” means data that a business customer connects, uploads, submits or generates through GrowthMate.
- “Connected Platform Data” means data retrieved from services such as Google Analytics, Google Search Console, Google Ads or Umami at a user’s direction.
- “Personal Data” means information relating to an identified or reasonably identifiable individual.
This Privacy Policy applies to people in India and other countries where GrowthMate is offered.
1. About GrowthMate
GrowthMate is a marketing performance and business-insight platform primarily designed for website founders, business owners and their teams.
GrowthMate may connect to:
- Google Analytics;
- Google Search Console;
- Google Ads;
- Umami;
- website analytics tools;
- advertising services;
- payment services;
- email and messaging services; and
- other integrations selected by the user.
GrowthMate uses connected information to help users:
- understand website and marketing performance;
- identify important issues and opportunities;
- detect changes affecting traffic, leads, conversions, sales, revenue or marketing efficiency;
- identify potential advertising waste;
- prioritize recommended actions;
- create implementation briefs for developers, SEO managers, Google Ads managers and other specialists;
- assign, share and monitor actions;
- generate business reports and summaries; and
- measure whether completed actions were followed by an improvement.
GrowthMate provides decision-support information. It does not guarantee increased traffic, leads, rankings, sales, revenue, advertising performance or profit.
Unless expressly introduced as a separate feature and specifically authorized by the user, GrowthMate does not automatically modify websites, SEO settings, advertising campaigns, bids, advertisements, keywords or budgets.
2. Who controls your personal data
For information relating to GrowthMate’s own website, accounts, billing, communications, product analytics and marketing activities, QOPTERVZN INFOCOM PRIVATE LIMITED generally acts as the Data Fiduciary, controller or business responsible for determining why and how personal data is processed.
When a customer connects its own website, analytics property or advertising account, GrowthMate may process Customer Data on the customer’s instructions. In those situations:
- the customer may act as the Data Fiduciary, controller or business; and
- GrowthMate may act as the Data Processor, processor or service provider.
The applicable role depends on the relevant data, purpose, contract and processing activity.
Eligible business customers may request a Data Processing Agreement.
3. Scope of this Privacy Policy
This Privacy Policy applies to:
growthmate.net;app.growthmate.net;- GrowthMate account registration and authentication;
- GrowthMate dashboards and reports;
- data-source integrations;
- recommendations and implementation briefs;
- action assignment and monitoring;
- subscriptions and payments;
- email and WhatsApp communications;
- product analytics;
- advertising and remarketing conducted by GrowthMate; and
- support and grievance communications.
This policy does not govern the independent privacy practices of Google, Meta, Razorpay, PostHog, Brevo, MilesWeb, Umami providers or other third parties.
Those providers may process information under their own privacy policies and contractual terms.
4. Personal data we collect
The information collected depends on how you use GrowthMate.
4.1 Account and profile data
We may collect:
- name;
- business email address;
- telephone number, if provided;
- account identifier;
- encrypted or hashed authentication credentials;
- profile image;
- job title;
- user role;
- preferred language;
- timezone;
- authentication provider;
- login and logout history;
- account creation date;
- account security settings; and
- communication preferences.
We do not store plaintext passwords.
4.2 Business and workspace data
We may collect:
- business or workspace name;
- website address;
- industry;
- business type;
- products and services;
- target market;
- important geographical locations;
- business goals;
- primary conversion goals;
- lead, customer or order-value information;
- important website pages;
- marketing channels;
- connected integrations;
- team members;
- developer, SEO manager, advertising manager and agency relationships;
- report preferences;
- billing plan; and
- workspace configuration.
4.3 Google Analytics data
When authorized by the user, GrowthMate may process Google Analytics information including:
- accounts, properties and data streams;
- website and application traffic;
- users and sessions;
- page views;
- landing pages;
- acquisition channels;
- source and medium;
- campaigns;
- events;
- engagement data;
- conversions or key events;
- ecommerce activity;
- transaction and revenue values;
- device, browser and approximate geographical dimensions;
- report dates and timezones;
- property metadata; and
- data-quality and synchronization information.
GrowthMate processes only the information required to provide the user-requested analytics and reporting features.
4.4 Google Search Console data
When authorized, GrowthMate may process:
- Search Console properties;
- pages and canonical URLs;
- search queries;
- clicks;
- impressions;
- click-through rate;
- average position;
- device;
- country;
- search appearance;
- search type;
- sitemaps;
- indexing information;
- crawl and coverage information;
- URL inspection information; and
- synchronization metadata.
Search-query information and connected website-performance data are treated as Customer Data.
GrowthMate does not use connected Search Console data to advertise GrowthMate or build advertising audiences.
4.5 Google Ads integration data
When authorized, GrowthMate may process:
- Google Ads customer and manager-account identifiers;
- accessible advertising accounts;
- account name;
- account currency;
- account timezone;
- campaigns;
- campaign status and type;
- ad groups;
- keywords;
- search terms, where made available by Google;
- advertising networks;
- device segments;
- campaign budgets;
- bidding information;
- impressions;
- clicks;
- interactions;
- advertising cost;
- conversions;
- conversion actions;
- conversion value;
- cost per conversion;
- return on advertising spend;
- impression-share metrics;
- landing-page data;
- account permissions;
- API and synchronization status; and
- data-quality information.
Connected Google Ads data is used only to provide and improve GrowthMate’s customer-facing advertising-analysis, reporting, recommendation and monitoring features.
GrowthMate does not use a customer’s connected Google Ads data to advertise GrowthMate.
GrowthMate does not sell connected Google Ads data.
4.6 Umami and other analytics data
When authorized, GrowthMate may process:
- website identifiers;
- page views;
- visits;
- sessions;
- events;
- referrers;
- campaign parameters;
- device and browser categories;
- operating system;
- approximate country;
- conversion information; and
- associated analytics metadata.
4.7 OAuth and authorization data
When you connect a third-party service, we may process:
- OAuth access tokens;
- OAuth refresh tokens;
- authorization scopes;
- authorization dates;
- connected account identifiers;
- property identifiers;
- manager-account identifiers;
- token-expiry information;
- permission status;
- reconnection status;
- revocation status; and
- authorization errors.
OAuth tokens are confidential credentials. We use them only to provide the integration authorized by you.
We do not sell OAuth credentials, use them for GrowthMate advertising, or disclose them to advertising providers.
4.8 Reports, recommendations and action data
GrowthMate may create or process:
- generated reports;
- verified metrics;
- analytical findings;
- recommendations;
- recommendation categories;
- business-impact assessments;
- confidence and priority classifications;
- possible explanations;
- supporting evidence;
- implementation briefs;
- assigned roles;
- action owners;
- action status;
- notes supplied by users;
- completion dates;
- metrics selected for monitoring;
- expected success conditions; and
- verified or inconclusive outcomes.
This information may contain confidential Customer Data.
4.9 Payment and subscription data
GrowthMate uses Razorpay to process payments.
We or Razorpay may process:
- billing name;
- billing email;
- billing address;
- business name;
- GST or tax information;
- subscription plan;
- transaction identifier;
- invoice information;
- payment status;
- renewal status;
- cancellation status;
- payment-method type;
- card brand;
- last four digits of a card, where supplied by Razorpay; and
- fraud-prevention information.
Complete card numbers, CVV codes and equivalent sensitive payment credentials are processed by Razorpay and are not intended to be stored by GrowthMate.
4.10 Product-usage and analytics data
We may collect information about use of the Website and Application, including:
- pages and screens viewed;
- navigation paths;
- signup progress;
- onboarding progress;
- integrations started and completed;
- synchronization outcomes;
- reports opened;
- recommendations viewed;
- evidence sections expanded;
- briefs created, copied or shared;
- actions assigned or completed;
- feature usage;
- application version;
- plan type;
- device type;
- browser;
- operating system;
- approximate geographical location;
- IP address;
- referring source;
- session duration;
- error category;
- feature flags; and
- product-performance information.
We use Google Analytics and PostHog for relevant analytics purposes.
We do not intentionally send connected customer report contents, raw Google Ads search terms, Search Console query contents, OAuth credentials, passwords or complete customer datasets to product-analytics providers.
4.11 Session-replay data
PostHog session replay may be enabled on the public GrowthMate landing page at growthmate.net.
Session replay is not enabled inside the authenticated web application at app.growthmate.net.
Where session replay is enabled, it may capture:
- page navigation;
- clicks;
- scrolling;
- viewport size;
- device and browser information;
- interface interactions; and
- technical errors.
We configure session replay to mask or exclude sensitive content, including:
- passwords;
- payment information;
- authentication credentials;
- form contents where appropriate;
- email addresses entered into forms;
- private account information;
- OAuth parameters; and
- other sensitive fields.
Session replay operates only after the required analytics consent has been obtained.
4.12 Communications and support data
When you communicate with us, we may collect:
- name;
- email address;
- contact information;
- support requests;
- feedback;
- complaint information;
- grievance details;
- attachments;
- survey responses;
- correspondence history; and
- call or meeting notes.
4.13 Security and log data
We may process:
- IP address;
- timestamps;
- login attempts;
- authentication events;
- session identifiers;
- API requests;
- synchronization activity;
- device information;
- access-control events;
- audit records;
- security alerts;
- suspicious activity;
- error codes; and
- processing logs.
We use this information to secure GrowthMate, investigate incidents and maintain reliable services.
5. How we collect data
We collect information:
- directly from you;
- from your organization or workspace administrator;
- when you create an account;
- when you connect an integration;
- through third-party APIs at your direction;
- when you make a payment;
- automatically through cookies and similar technologies;
- through product-analytics tools;
- when you contact support;
- from marketing and referral partners; and
- from service providers acting on our behalf.
6. Purposes for which we use personal data
6.1 Providing GrowthMate
We process data to:
- create accounts and workspaces;
- authenticate users;
- manage user permissions;
- connect authorized third-party services;
- retrieve and synchronize authorized data;
- normalize marketing and website data;
- display dashboards;
- generate reports;
- create recommendations;
- produce implementation briefs;
- assign and track actions;
- monitor selected metrics;
- deliver reports and notifications;
- manage subscriptions; and
- provide customer support.
6.2 Generating business insights
We use connected information to:
- detect performance changes;
- compare reporting periods;
- identify meaningful trends;
- identify potential advertising waste;
- identify possible website or conversion issues;
- identify SEO opportunities;
- evaluate advertising efficiency;
- compare website, search and advertising performance;
- prioritize actions;
- identify data-quality problems;
- monitor implementation outcomes; and
- explain findings in non-technical language.
GrowthMate may distinguish verified facts from possible explanations. Possible explanations should not be treated as proven causes.
6.3 Artificial intelligence
GrowthMate may use an approved third-party AI provider to:
- summarize structured findings;
- simplify technical explanations;
- create draft business summaries;
- prepare role-specific implementation briefs;
- categorize recommendations;
- improve report presentation; and
- support customer service.
Before publication, the current AI provider must be identified in GrowthMate’s Subprocessor List.
Where reasonably possible:
- calculations are performed before information is submitted to an AI provider;
- only the minimum structured information necessary is submitted;
- OAuth credentials are excluded;
- passwords and payment information are excluded;
- complete raw Google datasets are not submitted;
- Customer Data is not used to train public or generalized AI models unless expressly disclosed, contractually permitted and lawfully authorized; and
- AI providers are subject to confidentiality and data-protection obligations.
AI-generated explanations may be inaccurate or incomplete. Users remain responsible for reviewing and implementing recommendations.
6.4 Product improvement
We may use information to:
- understand onboarding and feature adoption;
- improve report quality;
- improve recommendation prioritization;
- test new features;
- detect errors;
- improve performance;
- improve security;
- measure customer satisfaction;
- create aggregated usage statistics; and
- develop new GrowthMate services.
Where practical, product-development analysis uses aggregated or de-identified information.
6.5 Billing and administration
We use information to:
- process subscriptions;
- receive payments;
- issue invoices;
- calculate applicable taxes;
- manage renewals;
- process cancellations;
- prevent payment fraud; and
- maintain accounting records.
6.6 Communications
We may send:
- account messages;
- authentication messages;
- security notices;
- integration alerts;
- synchronization notices;
- reports;
- billing communications;
- customer-support responses;
- service announcements;
- product updates; and
- marketing communications where lawfully permitted.
You can unsubscribe from promotional email messages at any time.
Unsubscribing from marketing does not prevent essential account, billing, security or service messages.
6.7 Security and legal compliance
We may process data to:
- protect user accounts;
- prevent unauthorized access;
- detect fraud and abuse;
- investigate security events;
- enforce our agreements;
- comply with legal requirements;
- respond to lawful governmental requests;
- establish or defend legal claims; and
- protect GrowthMate, its users and third parties.
7. Legal bases for processing
Depending on the jurisdiction and processing activity, we may rely on:
- consent;
- performance of a contract;
- steps requested before entering a contract;
- compliance with legal obligations;
- legitimate interests where permitted;
- prevention of fraud and security incidents;
- protection of legal rights;
- compliance with a user’s instructions; and
- other lawful grounds available under applicable law.
Where consent is used, you may withdraw it at any time through:
- Cookie Preferences;
- account settings;
- integration settings;
- unsubscribe controls;
- advertising opt-out controls; or
- a request to
[email protected].
Withdrawal does not affect processing that was lawful before consent was withdrawn.
8. Google API Services User Data
8.1 Google API compliance
GrowthMate’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the applicable Limited Use requirements.
GrowthMate will request only the Google permissions reasonably necessary to provide the user-requested feature.
8.2 How Google API data is used
Google API data may be used to:
- display the user’s connected account information;
- synchronize website, search and advertising data;
- generate analytics reports;
- generate recommendations;
- identify data-quality or tracking problems;
- compare connected sources;
- create user-requested implementation briefs;
- monitor selected outcomes; and
- provide support for the connected integration.
8.3 Prohibited uses of connected Google data
GrowthMate does not use connected Google API data to:
- sell personal data;
- build unrelated advertising profiles;
- advertise GrowthMate;
- create GrowthMate remarketing audiences;
- create GrowthMate Customer Match audiences;
- provide data to data brokers;
- determine creditworthiness;
- perform unauthorized surveillance;
- infer sensitive personal characteristics for advertising;
- train generalized public AI models without appropriate authorization;
- target advertisements unrelated to the user-requested GrowthMate service; or
- provide unrelated services without additional authorization.
Connected customer Google data is kept separate from GrowthMate’s own advertising and audience-building activities.
8.4 Human access to Google API data
Authorized GrowthMate personnel may access limited connected Google data only where reasonably necessary to:
- provide support requested by the customer;
- investigate a security incident;
- resolve an integration problem;
- comply with law;
- maintain or improve a user-facing feature; or
- protect GrowthMate and its users.
Access is limited according to role and business need.
8.5 Sharing Google API data
We may disclose limited Google API data to approved service providers only where necessary to operate the user-requested GrowthMate service.
Service providers must be subject to appropriate confidentiality, security and data-processing obligations.
We do not sell Google API data.
We do not disclose connected Google API data to Google Ads, Meta or another advertising platform for GrowthMate’s own advertising.
8.6 Revoking Google access
You may stop GrowthMate’s access by:
- disconnecting the integration within GrowthMate;
- deleting the applicable workspace;
- deleting your account; or
- revoking GrowthMate through your Google Account’s third-party access settings.
After revocation or disconnection:
- GrowthMate will stop requesting new data;
- active OAuth credentials will be revoked or deleted;
- imported data will be deleted according to the retention schedule below; and
- legally required records may be retained where applicable.
9. GrowthMate’s own Google Ads advertising
This section concerns advertising GrowthMate itself. It does not concern the Google Ads data customers connect for analysis.
GrowthMate may use:
- Google Ads conversion tracking;
- Google Ads remarketing;
- enhanced conversions, where lawfully configured;
- Google Customer Match;
- campaign attribution;
- advertising cookies; and
- related Google advertising services.
These tools may process:
- page visits;
- interactions with GrowthMate;
- signup events;
- checkout events;
- subscription events;
- advertising identifiers;
- cookie identifiers;
- IP address;
- browser and device information;
- campaign identifiers;
- consent signals; and
- contact information supplied directly to GrowthMate, where Customer Match is used.
9.1 Google Customer Match
GrowthMate may use Google Customer Match to reach existing GrowthMate users or prospective customers who directly provided their contact information to GrowthMate.
For Customer Match:
- only first-party contact information collected directly by GrowthMate will be used;
- users will be informed that information may be shared with advertising service providers;
- consent will be obtained where required;
- only Google-approved upload interfaces or APIs will be used;
- contact information will be normalized and hashed where required;
- connected customer Google Analytics, Search Console or Google Ads data will not be uploaded;
- children’s data will not be uploaded;
- sensitive personal data will not be uploaded;
- withdrawn or opted-out contacts will be removed from active audience uploads;
- upload staging files will be deleted within seven days after successful processing or failed-upload resolution; and
- audience membership will not be refreshed unless a valid legal basis and marketing permission remain.
Google Customer Match membership will not be maintained beyond Google’s applicable platform duration without a lawful and valid refresh. At the date of this policy, Google states that unrefreshed Customer Match membership is limited to 540 days.
9.2 Google Ads remarketing
Where consent is required, GrowthMate remarketing tags will operate only after advertising consent is granted.
GrowthMate may place users into website-visitor advertising audiences for up to 180 days, unless:
- the user withdraws consent;
- the user opts out;
- a shorter period is configured;
- the advertising purpose ends; or
- applicable law requires earlier removal.
Remarketing is not based on connected customer analytics, search-query or campaign data.
9.3 Enhanced conversions
Where enhanced conversions are used:
- only eligible first-party information will be used;
- information will be hashed or otherwise protected as required;
- appropriate notice and consent will be provided;
- consent signals will be passed to Google as required; and
- users who opt out will not be included in new enhanced-conversion advertising uses.
10. Meta, WhatsApp and Meta advertising tools
10.1 WhatsApp communications
GrowthMate may use Meta’s WhatsApp services to send:
- requested reports;
- account notifications;
- integration alerts;
- support responses;
- reminders;
- transactional messages; and
- marketing messages where consent has been obtained.
Meta and its service providers may process telephone numbers, message-routing information, delivery information and message content according to their applicable terms and privacy practices.
Users may opt out of non-essential WhatsApp marketing messages.
10.2 Meta Business Tools
GrowthMate may use Meta Business Tools, including where enabled:
- Meta Pixel;
- Meta Conversions API;
- advertising conversion measurement;
- website custom audiences;
- customer-list custom audiences; and
- campaign attribution.
These tools may process:
- page visits;
- browser and device information;
- IP address;
- cookie or advertising identifiers;
- signup events;
- checkout or subscription events;
- campaign information;
- consent information; and
- first-party contact information where a customer-list audience is used.
Meta advertising technologies will operate only where GrowthMate has an appropriate legal basis and has obtained consent where required.
10.3 Meta customer-list audiences
If GrowthMate uses a customer-list custom audience:
- only first-party information directly provided to GrowthMate will be used;
- GrowthMate will have the required permission or lawful basis;
- contact information will be hashed or protected as required by Meta;
- connected customer analytics or advertising data will not be uploaded;
- data relating to children will not be intentionally uploaded;
- sensitive personal information will not be intentionally uploaded;
- opted-out contacts will be removed from new uploads;
- upload staging files will be deleted within seven days after successful upload or failure resolution; and
- audiences will be reviewed regularly and removed when no longer necessary.
10.4 What is not shared with Meta for GrowthMate advertising
GrowthMate does not intentionally share the following with Meta for GrowthMate advertising:
- connected Google Analytics reports;
- connected Search Console queries;
- connected Google Ads account data;
- customer campaign names;
- customer search terms;
- customer website-performance rows;
- generated customer reports;
- recommendation contents;
- specialist briefs;
- OAuth credentials;
- passwords;
- payment-card data; or
- confidential customer business information.
11. Other advertising providers
GrowthMate may use other advertising, attribution or audience providers in the future.
Before using another provider, GrowthMate will:
- evaluate its privacy and security terms;
- update this Privacy Policy or Cookie Policy where necessary;
- disclose the provider in the Cookie Preferences interface or Subprocessor List;
- obtain consent where required;
- limit the data shared;
- avoid using connected Customer Data for GrowthMate advertising; and
- provide applicable opt-out controls.
12. Cookies and similar technologies
GrowthMate uses cookies, local storage, pixels, tags, SDKs and similar technologies.
12.1 Cookie categories
Strictly necessary
These technologies support:
- authentication;
- security;
- fraud prevention;
- session continuity;
- network management;
- load balancing;
- privacy preferences;
- payment security; and
- essential website or application functionality.
Strictly necessary technologies cannot normally be disabled through the cookie banner because the service cannot function securely without them.
Preferences
These remember:
- language;
- timezone;
- interface settings;
- report preferences;
- saved choices; and
- accessibility preferences.
Analytics
These help us understand:
- landing-page usage;
- product adoption;
- onboarding;
- feature performance;
- errors;
- report engagement; and
- conversion journeys.
Analytics providers include Google Analytics and PostHog.
Advertising
These support:
- Google Ads conversion measurement;
- Google Ads remarketing;
- Google Customer Match-related measurement;
- Meta advertising measurement;
- custom audiences;
- campaign attribution;
- frequency control; and
- personalized advertising where permitted.
12.2 Consent configuration
GrowthMate’s cookie interface provides:
- Accept all;
- Reject all non-essential cookies; and
- Granular category controls.
Where prior consent is required:
- optional analytics and advertising technologies are disabled by default;
- no advertising personalization occurs before consent;
- users can make separate analytics and advertising choices;
- consent is recorded;
- the consent notice identifies relevant third parties;
- withdrawal is intended to be as easy as giving consent; and
- preferences can be changed through the “Cookie Preferences” link.
Rejecting optional cookies will not prevent access to essential privacy settings or core account functions, although some optional features may be unavailable.
12.3 Google Consent Mode
GrowthMate may use Google Consent Mode to communicate consent choices to Google.
Depending on the user’s selection, the following signals may be set to granted or denied:
analytics_storage;ad_storage;ad_user_data; andad_personalization.
A denied choice will not be silently changed to granted.
12.4 Consent records
We may retain:
- consent choice;
- selected categories;
- consent timestamp;
- policy or banner version;
- country or region;
- withdrawal date; and
- a pseudonymous device or consent identifier.
Consent records are retained according to the retention schedule below to demonstrate compliance and honour preferences.
12.5 Changing cookie choices
Users may change their choices at any time through:
- the Cookie Preferences link;
- browser settings;
- Google advertising settings;
- Meta advertising settings;
- device privacy controls; or
- an applicable opt-out mechanism.
Deleting cookies may remove stored preferences, in which case GrowthMate may ask for a new selection.
13. Do Not Sell or Share and targeted-advertising choices
GrowthMate does not sell personal data for money.
Some US privacy laws may define the use of advertising cookies, audience matching or personalized advertising as:
- sharing;
- targeted advertising;
- cross-context behavioural advertising; or
- a sale under a broad statutory definition.
Where applicable, users may opt out through:
- “Cookie Preferences”;
- “Do Not Sell or Share My Personal Information”;
- a privacy-settings page;
[email protected]; or- a legally recognized browser signal.
Where required, GrowthMate will process a valid Global Privacy Control signal as an opt-out of sale or sharing for the applicable browser or device.
GrowthMate will not discriminate against users for exercising applicable privacy rights.
14. Email communications
GrowthMate uses Brevo for email delivery and communication management.
Brevo may process:
- recipient email address;
- recipient name, where provided;
- message content;
- delivery status;
- bounce information;
- unsubscribe status;
- email opens, where enabled and permitted;
- link interactions, where enabled and permitted; and
- technical delivery information.
Promotional emails include an unsubscribe method.
GrowthMate may retain a minimal suppression record after an unsubscribe so that the address is not accidentally added back to promotional mailing lists.
15. Payment processing
Payments are processed through Razorpay.
When you make a payment, Razorpay may independently process personal and payment information under its own privacy policy and terms.
GrowthMate receives only the information required to:
- confirm payment;
- activate or renew a subscription;
- issue invoices;
- handle refunds;
- manage billing; and
- prevent fraud.
GrowthMate does not intentionally store complete payment-card credentials.
16. Service providers and subprocessors
GrowthMate uses service providers to operate the Services.
Current providers include:
| Provider | Purpose | | -------------------- | -------------------------------------------------------------------------------------------------------- | | MilesWeb | Cloud hosting, application infrastructure and database hosting | | Razorpay | Payment processing, subscriptions, billing and fraud prevention | | Brevo | Transactional and marketing email delivery | | Meta / WhatsApp | WhatsApp messaging and related communication delivery | | Google Analytics | Website and product analytics | | PostHog | Product analytics, feature measurement, error monitoring and landing-page session replay | | Google | Google APIs, Google Analytics integrations, Search Console, Google Ads, advertising and related services | | Approved AI provider | Report explanation, structured summaries and implementation-brief generation |
GrowthMate may replace or add providers.
Material changes will be reflected in an updated Subprocessor List or Privacy Policy.
Service providers are expected to:
- process data only for authorized purposes;
- maintain confidentiality;
- implement appropriate safeguards;
- assist with applicable privacy obligations; and
- delete or return data as contractually required.
17. How we share data
We may share information with:
17.1 Service providers
We share limited data with the providers described above where necessary to operate GrowthMate.
17.2 Workspace administrators
Workspace administrators may:
- access workspace reports;
- manage integrations;
- invite or remove users;
- assign roles;
- view action status;
- manage billing; and
- control workspace data.
17.3 Team members and recipients
When a user shares or assigns a report, recommendation or brief, the selected recipient may access the information shared.
Users are responsible for confirming that recipients are authorized.
17.4 Connected platforms
Data may be exchanged with a connected platform when necessary to complete a user-authorized request.
17.5 Professional advisers
Information may be disclosed to lawyers, accountants, auditors, insurers, security advisers and consultants where reasonably necessary.
17.6 Legal and safety purposes
We may disclose data to:
- comply with applicable law;
- respond to valid legal processes;
- investigate fraud;
- enforce agreements;
- protect rights and safety;
- address security incidents; or
- respond to regulatory authorities.
17.7 Corporate transactions
If GrowthMate is involved in a merger, acquisition, financing, restructuring, investment or sale of assets, information may be transferred as part of the transaction subject to applicable safeguards.
17.8 Aggregated or de-identified data
We may disclose aggregated or de-identified statistics that do not reasonably identify a person or customer.
18. International data transfers
GrowthMate is operated from India and actively offers services to users in other countries.
Some service providers may process information outside India or outside the user’s country.
Where required, GrowthMate will use appropriate transfer safeguards, such as:
- contractual data-protection clauses;
- standard contractual clauses;
- data-processing agreements;
- transfer assessments;
- encryption;
- access controls;
- regional hosting options; and
- other lawful transfer mechanisms.
Transfers from the European Economic Area, United Kingdom or Switzerland may be subject to applicable adequacy decisions, standard contractual clauses or equivalent safeguards.
Transfers from India are subject to restrictions or requirements issued under applicable Indian law.
19. Data retention schedule
GrowthMate retains data only as long as reasonably necessary for the relevant purpose, legal obligations, platform rules, security and dispute resolution.
Unless a longer period is legally required or a shorter period is requested and permitted, the following schedule applies.
| Data category | Normal retention | | -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | | Active account and workspace profile | For the duration of the active account | | Account data after verified deletion request | Deleted or de-identified from active systems within 30 days | | Connected analytics, Search Console, Google Ads and Umami data | While the connection or workspace remains active | | Connected data after disconnection or account deletion | Deleted from active systems within 30 days | | OAuth access and refresh tokens | Revoked and deleted within 7 days after confirmed disconnection or account deletion | | Generated reports, recommendations, briefs and action records | While the workspace is active; deleted within 30 days after verified workspace deletion unless retention is requested or legally required | | Google Customer Match upload staging files | Deleted within 7 days after successful upload or resolution of a failed upload | | Google Customer Match audience membership | Maintained only while lawful permission remains; not left unrefreshed beyond the applicable Google platform limit, currently 540 days | | Meta customer-audience upload staging files | Deleted within 7 days after successful upload or resolution of a failed upload | | Website remarketing audience membership | Up to 180 days, unless consent is withdrawn or a shorter period applies | | Landing-page session replay | 30 days | | Google Analytics and PostHog raw product-analytics data | Up to 14 months | | Aggregated or de-identified analytics | May be retained longer where reidentification is not reasonably possible | | Security, access, processing and relevant traffic logs | At least 1 year, and longer where required for security or law | | Customer-support correspondence | 24 months after resolution or account closure | | Consent records | 5 years after the relevant consent or withdrawal, unless another period is required | | Marketing unsubscribe or suppression record | As long as needed to honour the opt-out | | Billing, invoice, tax and accounting records | Up to 8 years, or longer where legally required | | Failed-payment and fraud-prevention records | Up to 5 years, subject to legal and risk requirements | | Legal claims and dispute records | Until the claim expires or is finally resolved | | Deleted-data backups | Removed through normal backup rotation within 90 days |
When a deletion request is received:
- deletion from active systems will normally occur first;
- backup copies may remain inaccessible until overwritten;
- the deleted data will not be restored to active use except for disaster recovery or legal necessity; and
- legally required records may be retained in restricted form.
GrowthMate may shorten these periods as systems and legal requirements evolve.
20. Data security
GrowthMate uses reasonable administrative, technical and organizational measures designed to protect personal data.
Measures may include:
- HTTPS and encryption in transit;
- encryption or equivalent protection for sensitive credentials;
- OAuth token protection;
- password hashing;
- role-based access;
- tenant isolation;
- least-privilege access;
- secure OAuth state handling;
- environment separation;
- audit logging;
- monitoring;
- backups;
- vulnerability management;
- secure software-development practices;
- access reviews;
- contractual confidentiality; and
- incident-response procedures.
No method of transmission or storage is completely secure. GrowthMate cannot guarantee absolute security.
Users are responsible for:
- safeguarding login credentials;
- using secure passwords;
- enabling available security protections;
- controlling workspace access;
- removing former team members;
- reviewing shared links; and
- reporting suspected unauthorized access.
21. Personal-data breaches
If GrowthMate becomes aware of a personal-data breach, it will investigate, contain and mitigate the incident.
Where legally required, GrowthMate will notify:
- affected users;
- business customers;
- the Data Protection Board of India;
- other regulators; or
- law-enforcement authorities.
A notice may include:
- the nature and timing of the breach;
- affected data categories;
- likely consequences;
- actions GrowthMate has taken;
- steps users should consider; and
- relevant contact information.
Where the Indian DPDP Rules apply, required detailed notifications to the Board will be made within the prescribed period, including the applicable 72-hour detailed-notification period unless an extension is permitted.
22. Your privacy rights
Rights vary by location and may include the right to:
- receive information about processing;
- access personal data;
- receive a summary of processing;
- correct inaccurate information;
- complete incomplete information;
- request deletion or erasure;
- withdraw consent;
- object to processing;
- restrict processing;
- receive portable data;
- opt out of marketing;
- opt out of targeted advertising;
- opt out of sale or sharing;
- limit certain sensitive-data uses;
- request information about recipients;
- nominate another person where permitted;
- lodge a grievance;
- appeal a privacy decision; and
- complain to a regulator.
Rights are subject to applicable exceptions, verification and legal limitations.
To exercise a right, email:
Include:
- your account email;
- workspace name or identifier;
- country or state of residence;
- the right you wish to exercise; and
- enough information for us to verify and process the request.
Do not send passwords, OAuth tokens or payment-card details.
23. Rights of users in India
Subject to the Digital Personal Data Protection Act, 2023 and applicable rules, Indian Data Principals may have rights to:
- obtain information about personal-data processing;
- request access to a summary of personal data;
- request correction;
- request completion;
- request updating;
- request erasure where retention is not required;
- withdraw consent;
- use grievance redressal;
- nominate another individual; and
- complain to the Data Protection Board of India after using the applicable grievance process.
GrowthMate intends to provide withdrawal methods that are reasonably comparable in ease to the method used to give consent.
24. EEA, UK and Switzerland rights
Where the GDPR, UK GDPR or equivalent law applies, users may have rights to:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection;
- withdrawal of consent; and
- lodge a complaint with the applicable supervisory authority.
Where legally required, GrowthMate will respond without undue delay and normally within one month. This period may be extended where permitted for complex or multiple requests.
Users also have the right to object to direct marketing at any time.
25. United States privacy rights
Depending on the user’s state and whether the relevant law applies to GrowthMate, users may have rights to:
- know the categories and specific items of personal information collected;
- know the sources, purposes and recipients;
- request deletion;
- request correction;
- request portability;
- opt out of sale;
- opt out of sharing;
- opt out of targeted advertising;
- limit certain sensitive-data uses;
- appeal a denied request; and
- receive equal service without unlawful discrimination.
Where applicable, GrowthMate will process valid requests within the legally required period.
California users may use the “Do Not Sell or Share My Personal Information” or Cookie Preferences control.
26. Categories disclosed for US privacy purposes
During the preceding 12 months, GrowthMate may have collected the following categories, depending on service usage:
| Category | Examples | Business purpose | Recipients | | --------------------------- | ---------------------------------------- | ---------------------------------------------------------- | --------------------------------------------------------------------- | | Identifiers | Name, email, IP address, account ID | Account, security, communications, advertising measurement | Hosting, analytics, email, payment and advertising providers | | Customer-record information | Contact and billing details | Subscription and support | Razorpay, Brevo and support providers | | Commercial information | Plan, invoices, payments | Billing and business administration | Razorpay and accounting advisers | | Internet activity | Page views, clicks, device and browser | Analytics, security and advertising | Google Analytics, PostHog, Google and Meta where consented | | Geolocation | Approximate country or region | Security, localization and analytics | Hosting and analytics providers | | Professional information | Job role, business and workspace role | Workspace management and recommendations | GrowthMate workspace members and hosting providers | | Inferences | Product-interest or lifecycle categories | Product improvement and marketing | GrowthMate, Google or Meta where lawfully enabled | | Sensitive information | Account credentials and OAuth tokens | Authentication and integrations | Restricted GrowthMate systems and authorized infrastructure providers |
GrowthMate does not sell these categories for money.
Some advertising disclosures may constitute sharing or targeted advertising under certain state laws and are subject to applicable opt-out rights.
27. Marketing choices
You may stop promotional communications through:
- the unsubscribe link in an email;
- replying STOP or using another opt-out method where available for WhatsApp;
- account notification settings;
- Cookie Preferences;
- “Do Not Sell or Share” controls;
- Google advertising settings;
- Meta advertising settings; or
[email protected].
GrowthMate may retain a minimal suppression record to honour the opt-out.
28. Account and integration deletion
Users may request account deletion through:
- the Application’s account settings, where available; or
[email protected].
Users may disconnect a Google or other integration through the Data Sources or integration-settings area.
After confirmed deletion or disconnection:
- new synchronization will stop;
- OAuth credentials will be revoked or deleted;
- connected data will be scheduled for deletion;
- active reports and briefs may become unavailable;
- backup deletion will follow the backup cycle; and
- legally required records may be retained in restricted form.
Where the workspace belongs to an organization, an individual user may need to contact the workspace administrator concerning organization-controlled Customer Data.
We may verify identity and authority before processing deletion.
29. Automated processing
GrowthMate uses automated systems to:
- calculate metrics;
- detect changes;
- classify findings;
- assess confidence;
- prioritize recommendations;
- select report content;
- identify responsible roles; and
- generate explanations.
These systems provide business decision support. They are not intended to make legal, employment, credit, insurance or similarly significant decisions about individuals.
Users can request human review of a material support issue by contacting [email protected].
30. Children’s privacy
GrowthMate is intended for business users who are at least 18 years old.
GrowthMate does not knowingly offer accounts to children or process children’s information for advertising.
GrowthMate does not knowingly upload information relating to children to Google Customer Match, Meta customer audiences or similar advertising services.
If we learn that personal data belonging to a child has been collected without valid authorization, we will take reasonable steps to delete it.
31. Sensitive information and restricted advertising
GrowthMate does not intend to use sensitive personal information for advertising personalization or audience creation.
We do not intentionally create advertising audiences based on:
- health conditions;
- racial or ethnic origin;
- religion;
- political beliefs;
- trade-union membership;
- sexual orientation;
- criminal allegations;
- precise financial hardship;
- biometric information;
- children’s information; or
- other sensitive categories restricted by law or advertising-platform policy.
Users must not upload such information for Customer Match or custom-audience purposes.
32. Business-customer responsibilities
Customers connecting their own websites or advertising accounts are responsible for:
- having authority to connect the account;
- providing required privacy notices to their visitors;
- obtaining legally required cookie and advertising consent;
- ensuring analytics tags operate lawfully;
- respecting browser and user opt-outs;
- configuring Google Consent Mode or equivalent controls where required;
- not collecting prohibited or sensitive information unlawfully;
- responding to rights requests relating to Customer Data;
- managing team access;
- obtaining necessary employee, client or end-user permissions; and
- ensuring their use of GrowthMate complies with applicable platform policies.
If a customer uses GrowthMate in connection with its own Google advertising products, the customer remains responsible for compliance with Google’s applicable advertising and consent policies.
33. Third-party websites and services
GrowthMate may contain links to third-party websites and services.
GrowthMate does not control those parties’ independent privacy practices.
Users should review the privacy policy of a third party before supplying information or enabling an integration.
34. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- product changes;
- new integrations;
- changes in advertising technologies;
- changes in service providers;
- legal requirements;
- regulatory guidance;
- security practices; or
- business operations.
Material changes may be communicated through:
- the Website;
- the Application;
- email; or
- another appropriate method.
Where required, we will request new consent before applying a materially different processing purpose.
The “Last updated” date identifies the latest version.
35. Privacy and Grievance Officer
GrowthMate’s Privacy and Grievance Officer is:
Alok Diwate Designation: Director Company: QOPTERVZN INFOCOM PRIVATE LIMITED
Grievance email: [email protected] Privacy email: [email protected]
Registered address:
Plot No. 19, At – Khokarla Balaji Nagar, Behind Bhaiyaji Nagar Bhupali Duplex Bhandara, Maharashtra India – 441904
GrowthMate intends to respond to privacy grievances within a reasonable period and, where the Indian DPDP Rules apply, within a period not exceeding 90 days.
Please include:
- your name;
- account email;
- affected workspace;
- nature of the concern;
- relevant dates;
- supporting information; and
- requested resolution.
Users should first use GrowthMate’s grievance process before approaching the Data Protection Board of India where such prior grievance handling is required.
36. Contact information
For questions about this Privacy Policy or GrowthMate’s privacy practices, contact:
QOPTERVZN INFOCOM PRIVATE LIMITED
Plot No. 19, At – Khokarla Balaji Nagar, Behind Bhaiyaji Nagar Bhupali Duplex Bhandara, Maharashtra India – 441904
Privacy: [email protected] Grievance Officer: [email protected]
Website: https://growthmate.net Application: https://app.growthmate.net
Appendix A — Cookie Preference Categories
The Cookie Preferences interface should contain these categories:
Necessary — always active
Used for:
- authentication;
- security;
- consent storage;
- payment security;
- session management; and
- core application operation.
Preferences — optional
Used for:
- language;
- interface preferences;
- saved choices; and
- user-experience settings.
Analytics — optional
Providers may include:
- Google Analytics; and
- PostHog.
Used for:
- website usage;
- product adoption;
- error analysis;
- onboarding measurement; and
- service improvement.
Advertising — optional
Providers may include:
- Google Ads; and
- Meta Business Tools.
Used for:
- conversion measurement;
- remarketing;
- Customer Match;
- custom audiences;
- advertising attribution; and
- personalized advertising.
The interface must provide equally accessible Accept All and Reject All options and a clear method for granular selection.
Appendix B — Required implementation controls
To ensure actual practices remain consistent with this Privacy Policy, GrowthMate should implement:
1. A persistent Cookie Preferences link. 2. Accept All, Reject All and granular controls. 3. Optional cookies disabled by default where prior consent is required. 4. Google Consent Mode signals for:
* analytics storage; * advertising storage; * advertising user data; and * advertising personalization. 5. Consent records and version history. 6. Withdrawal controls as easy to use as the consent controls. 7. A “Do Not Sell or Share” control where applicable. 8. Recognition of Global Privacy Control where legally required. 9. Separation between connected Customer Data and GrowthMate advertising data. 10. Customer Match uploads limited to first-party GrowthMate contact data. 11. Suppression of opted-out contacts from new audience uploads. 12. OAuth token revocation and deletion workflows. 13. Account and connected-data deletion workflows. 14. PostHog replay restricted to the public landing page. 15. Masking of landing-page form fields in session replay. 16. No authenticated webapp session replay. 17. A current Subprocessor List. 18. An identified AI provider before production use. 19. Vendor data-processing agreements where required. 20. Regular review of Google Ads, Customer Match and Meta advertising policies.