Privacy Policy
Last Updated: July 10, 2026
At Grow Smart Online ("we", "our", or "us"), we respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable European data protection laws.
This Privacy Policy explains how we collect, use, store, and share your personal data when you use our onboarding portal, submit a project request, or contract our services.
1. Data Controller
Grow Smart Online is the data controller for the personal data collected through this website and onboarding portal. If you have any questions about this Privacy Policy or wish to exercise your data rights, you can contact us at support@getgso.com.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: Full name, business name, and job title.
- Contact Data: Email address, phone number, and physical billing address.
- Project Data: Information you provide in questionnaires, client brief submissions, asset uploads (including logos and brand documentation), and discussion logs.
- Transaction & Payment Data: Details about payments made to us and invoices, processed securely via Stripe. We do not store your credit card details directly on our servers.
- Technical Data: IP addresses, browser types, and access timestamps.
3. How and Why We Use Your Data
We only use your personal data when the law allows us to. Most commonly, we process your data on the following legal bases:
- Performance of a Contract (GDPR Art. 6(1)(b)): To manage your onboarding, deliver project deliverables, process payments, and facilitate support.
- Legitimate Interests (GDPR Art. 6(1)(f)): To notify you of critical project changes, respond to support messages, and prevent security breaches.
- Legal Obligation (GDPR Art. 6(1)(c)): To maintain tax, accounting, and business logs as required by European regulators.
4. Third-Party Data Processors
To deliver our services, we share necessary data with trusted third-party service providers who comply with GDPR safeguards:
- Stripe, Inc. (Payment Processing)
- Brevo (Transactional Notification Emails)
- Hostinger (Web Hosting and Database Storage)
5. Data Retention
We retain your personal data and project assets only for as long as necessary to fulfill the purposes we collected it for, including any legal, accounting, or reporting requirements. For tax compliance, payment records are kept for a minimum of 7 years.
6. Your Data Rights
Under GDPR, you have the following rights regarding your personal data:
- The right to access the data we hold about you.
- The right to request rectification of inaccurate data.
- The right to request the erasure of your personal data ("right to be forgotten").
- The right to object to or restrict processing under certain conditions.
- The right to data portability.
To exercise any of these rights, please email us at support@getgso.com.