Privacy Policy for Grow365.io

Last updated: 08.04.2026

1. Introduction

At Grow365.io, we take the protection of your personal data seriously. This privacy policy explains what information we collect, how we use it, who we share it with, and what rights you have under GDPR and Danish law. By creating an account or using our platform, you accept this policy.

2. Data Controller

Grow365.io is owned and operated by:
Grow365.io ApS
CVR no.: 45494659
Stokagervej 5, 8240 Risskov, Denmark
Contact: hello@grow365.io

3. What information do we collect?

When you visit our website or use our platform, we may collect the following information:

  • Account information: Name, email address, and password (encrypted with bcrypt) when you create a user profile
  • Payment information: Card details are processed directly by Stripe and are never stored on our servers
  • Authentication data: If you sign in via Google or Microsoft, we receive your name and email address from the provider
  • Usage data: How you use the platform, including searches, actions, and feature usage
  • Technical information: IP address, browser, device type, and Cloudflare Turnstile security validation

4. Purpose of collection

We use your information to:

  • Create and manage your account and subscription
  • Deliver, maintain, and improve our platform and features
  • Process payments and manage trial periods via Stripe
  • Send transactional emails (account verification, password reset, welcome emails)
  • Provide support and technical assistance
  • Protect the platform against abuse via security validation (Cloudflare Turnstile)

5. Use of third-party data and liability

Our system provides access to external and publicly available data sources for lead generation and data analysis. It is the user's own responsibility to assess and use this data in accordance with applicable legislation, including GDPR and marketing laws.

Grow365.io disclaims all liability for:

  • How the collected data is used by the customer
  • Any consequences of incorrect use, misuse, or violations regarding data processing or use
  • The accuracy and update frequency of the content in external data sources

We encourage all users to make their own legal assessment before using data in a business context.

6. Third-party services and data processors

To deliver our platform, we use the following third-party services that may process your personal data as data processors on our behalf:

  • Neon (neon.tech) — Database hosting (PostgreSQL). Your account data is stored securely in Neon's cloud infrastructure with encrypted connections (SSL)
  • Vercel (vercel.com) — Web hosting and serving of our application
  • Stripe (stripe.com) — Payment processing, subscription management, and invoicing. Stripe is PCI DSS Level 1 certified
  • Google OAuth (accounts.google.com) — Optional sign-in via Google account
  • Microsoft Azure AD (login.microsoftonline.com) — Optional sign-in via Microsoft account
  • Gmail SMTP (smtp.gmail.com) — Sending transactional emails (verification and welcome emails)
  • Cloudflare Turnstile (cloudflare.com) — Security validation to protect against bots

We do not share your personal information with third parties beyond those listed above, unless we are legally obliged to do so. All data processors are selected with regard to security and GDPR compliance.

7. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you (right of access)
  • Have incorrect personal data corrected (right to rectification)
  • Have your personal data deleted (right to erasure / right to be forgotten)
  • Object to our processing of your data
  • Have your data transferred to another service (data portability)
  • Withdraw your consent at any time

Contact us at hello@grow365.io if you wish to exercise your rights. We will respond within 30 days.

8. Storage period

We store your account information for as long as your account is active. If you cancel your subscription or request deletion, we will delete your personal data within 30 days, unless legislation requires longer retention (e.g., bookkeeping laws). Payment history at Stripe is retained according to Stripe's own retention policies.

9. Cookies and sessions

We use session cookies to keep you signed in to the platform. These cookies are necessary for the platform to function and do not require separate consent. We also use Cloudflare Turnstile, which may set technical cookies for security purposes. We do not use third-party cookies for marketing or tracking.

10. Security measures

We implement appropriate technical and organizational measures to protect your data, including: encrypted database connections (SSL/TLS), encrypted password storage (bcrypt hashing), secure payment processing via Stripe (PCI DSS Level 1), HTTPS on all pages and API endpoints, and access control for administrative functions.

11. Transfer to third countries

Some of our data processors (Vercel, Stripe, Google, Microsoft, Cloudflare) may process data outside the EU/EEA. In such cases, we ensure that appropriate transfer mechanisms are in place in accordance with GDPR, such as the European Commission's Standard Contractual Clauses (SCCs) or the provider's certification under the EU-U.S. Data Privacy Framework.

12. Right to complain

If you believe that we are processing your personal data in violation of the law, you may file a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

13. Changes

We reserve the right to update this privacy policy. Significant changes will be communicated via the platform or email. Continued use of the platform after changes constitutes acceptance of the updated policy.

14. Chrome Extension – Grow365 LinkedIn Sync

When you install and use our Chrome extension, we collect the following data to provide the service:

  • LinkedIn session cookies (li_at, li_a) to maintain your LinkedIn session and enable automated campaigns on the platform

Handling: Cookies are transmitted encrypted to the Grow365 server via HTTPS solely to operate your LinkedIn account on our platform.

Storage: Session cookies are stored on our server (Render) and are automatically deleted when your account is deactivated or you uninstall the extension.

Sharing: We do not share this data with third parties. Cookie data is used exclusively internally to power the Grow365 platform.