This Privacy Policy explains how GrowBro AI Solutions Private Limited (operating as “GrowBro”, “we”, “us”, “our”) collects, uses, shares, and protects personal information when you use our website, the GrowBro CRM, chat widgets, AI assistants, and integrations with third-party platforms — including the WhatsApp Business Cloud API, Instagram Messaging, Facebook Messenger, Google Workspace (Sheets and Calendar), HubSpot, and Razorpay (collectively, the “Services”).
We process personal data in two distinct capacities:
- As a controller / Data Fiduciary — for information about our website visitors, prospects, and account holders (“Customers”). We decide why and how this information is processed.
- As a processor / Data Processor — for information about our Customers’ own end users (e.g., people who chat with a Customer’s WhatsApp business number powered by GrowBro). We process this data only on the Customer’s documented instructions, subject to a Data Processing Agreement.
1. Who we are
- Legal entity: GrowBro AI Solutions Private Limited (CIN U70200DC2026PTC471127)
- Registered office: A-3/135, First Floor, Rohini Sector-8, A3/138, Rohini Sector 5, New Delhi 110085, Delhi, India
- General contact: conversation@growbro.ai
- Privacy contact: privacy@growbro.ai
- Grievance Officer (DPDPA / IT Rules 2011): Aakash Roy (Founder), reachable at grievance@growbro.ai. We acknowledge grievances within 48 hours and resolve them within 30 days.
2. Information we collect
2.1 Information you give us
- Account & contact: name, business email, phone number, company name, role, and login credentials.
- Billing: billing name, GST number, billing address, payment instrument metadata. Card, UPI, and netbanking details are collected and stored by our payment processor (Razorpay) — GrowBro does not store full payment card numbers.
- Customer Content: chat transcripts, lead records, AI prompts and configurations, and any files or content you upload to the Services.
- Support communications: the content of emails, tickets, and recordings of calls you initiate with us.
2.2 Information collected from integrations you connect
- WhatsApp Business Cloud API (Meta): WhatsApp Business Account ID (WABA ID), phone number ID, display name, access tokens, message content, message status webhooks, and end-user phone numbers contacting your number.
- Instagram Messaging & Facebook Messenger (Meta): Page ID, IG Business Account ID, access tokens, message content, sender PSID/IGSID, and basic profile data permitted by the user.
- Google Calendar (OAuth scopes
calendar,calendar.events): calendar event metadata (title, description, start/end, attendees, location) for events the AI assistant creates or reads on your behalf, and the OAuth refresh and access tokens. - Google Sheets (OAuth scope
spreadsheets): spreadsheet IDs you explicitly designate, sheet and worksheet names, header rows, and the lead/row values we read or write under your configuration. We do not list, browse, or index your Google Drive — we access only the specific spreadsheet ID you provide. - HubSpot: portal ID, access tokens, contact and lead records you sync.
- Razorpay: merchant ID, order IDs, payment IDs, payment statuses, and refund metadata.
2.3 Information collected automatically
- Device & usage: IP address, browser type and version, operating system, referring URLs, pages viewed, features used, and timestamps.
- Cookies: session cookies (required), preference cookies, and limited analytics cookies. See Section 11.
- Marketing pixels: on marketing pages we use the Meta Pixel (
fbq) to measure ad performance. Loaded only when consent is given in jurisdictions that require it.
3. How we use information
- To provide, operate, secure, and maintain the Services.
- To execute the messaging, lead-sync, calendar, and CRM features you configure.
- To deliver AI assistant responses based on the context, knowledge base, and prompts you supply.
- To detect and prevent fraud, abuse, security incidents, and platform-policy violations (Meta, Google, Razorpay).
- To bill you and process payments via Razorpay.
- To respond to support requests and communicate service notices.
- To send marketing emails — only with your opt-in where required. Every marketing email contains an unsubscribe link.
- To comply with applicable laws and enforce our agreements.
We do not sell personal information. We do not share personal information with third parties for their independent marketing purposes. We do not use your data to train GrowBro’s own AI models, and we do not permit our LLM provider (currently OpenAI) to use your data to train its models — OpenAI’s API terms confirm that API inputs and outputs are not used to train OpenAI’s models by default.
4. Legal bases (EEA, UK, Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Services to account holders.
- Legitimate interests — to secure and improve the Services, prevent fraud, and conduct limited analytics. Where we rely on legitimate interests we balance these against your rights.
- Consent — for non-essential cookies, marketing communications where required, and granular permissions you grant through integrations.
- Legal obligation — to comply with tax, accounting, and regulatory requirements.
5. Use of Google user data — Limited Use compliance
GrowBro’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide the user-facing features you have explicitly connected — Google Calendar event lookup and creation by the AI assistant, and Google Sheets read/write for lead sync.
- We do not transfer Google user data to third parties except as necessary to provide and improve these user-facing features, comply with applicable law, or as part of a merger or acquisition where users are notified.
- No human at GrowBro reads your Google data except: (i) for security investigations, (ii) to comply with law, or (iii) with your explicit consent for a specific support request.
- We do not use Google user data for advertising, ad personalisation, or to train generalised AI/ML models.
- You may revoke GrowBro’s Google access at any time at myaccount.google.com/permissions or by disconnecting from the GrowBro CRM Integrations page.
6. AI assistant & automated processing
- GrowBro’s AI assistants generate responses using large language models (currently OpenAI’s API). Inputs sent to the LLM include the prompt, conversation context, and knowledge-base content you configure.
- We do not use your data to train GrowBro’s own models, and our LLM provider does not use API inputs or outputs to train its models under its standard API terms.
- AI outputs may be inaccurate, incomplete, or biased. You are responsible for reviewing AI outputs before relying on them, and for telling your end users they may be communicating with an automated agent where required by law.
- If a decision produced by the AI assistant has significant effects on you (GDPR Article 22), you have the right to request human review by emailing privacy@growbro.ai.
8. International data transfers
We are based in India and our infrastructure may be hosted in India, the European Union, the United States, or another region depending on the sub-processor.
- For transfers of EEA or UK personal data outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses (Module Two, controller-to-processor) and the equivalent UK IDTA, supplemented by appropriate technical and organisational measures.
- For transfers from India, the Digital Personal Data Protection Act, 2023 permits cross-border transfers except to countries the Central Government may specifically restrict. We monitor that list and adjust accordingly.
9. Data retention
We retain personal information only as long as needed for the purposes described, with the following guideline periods:
- Active account data: for the duration of your subscription, then 90 days post-termination to allow account recovery, then deletion.
- Chat transcripts and lead records: for the duration of your subscription, or until you delete them via the CRM.
- OAuth tokens (Google, Meta, HubSpot): until you disconnect the integration; revoked on disconnect.
- Audit logs: 12 months for security investigation purposes.
- Backups: rolling backups are retained up to 30 days, after which deletions propagate to backups.
- Billing & tax records: 8 years, as required under the Indian Companies Act, 2013 and Income Tax Act.
- Marketing contact lists: until you unsubscribe.
10. Your rights
Depending on where you live, you have some or all of the following rights. Submit any request to privacy@growbro.ai.
10.1 Under India’s DPDPA, 2023
- Right to access information about your personal data and the processing thereof.
- Right to correction, completion, updating, and erasure of personal data.
- Right to nominate another individual to exercise rights in the event of death or incapacity.
- Right to grievance redressal via our Grievance Officer.
- Right to withdraw consent at any time where processing is based on consent.
10.2 Under the EU/UK GDPR
- Articles 15–22: access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.
- Right to lodge a complaint with a supervisory authority in your country of residence.
10.3 Under California’s CCPA / CPRA
- Right to know what categories of personal information we collect and disclose.
- Right to delete personal information.
- Right to correct inaccurate personal information.
- Right to opt out of “sale” or “sharing” of personal information — GrowBro does not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of.
- Right to limit use and disclosure of sensitive personal information.
- Right to non-discrimination for exercising any CCPA right.
- You may use an authorised agent to submit a request; we will verify both your and the agent’s identity.
12. Security
We implement administrative, technical, and physical safeguards designed to protect personal information from unauthorised access, alteration, disclosure, or destruction. See our Security page for details. No system is perfectly secure; you are responsible for protecting your account credentials.
13. Data breach notification
In the event of a personal data breach, we will (a) notify the Data Protection Board of India and other competent supervisory authorities (e.g., the lead GDPR supervisory authority) without undue delay and, where feasible, within 72 hours of becoming aware, and (b) notify affected individuals where the breach is likely to result in a high risk to their rights — as required by the DPDPA and GDPR Article 34.
14. Children
The Services are intended for business use and are not directed to children. Consistent with the DPDPA’s treatment of minors, we do not knowingly process the personal data of individuals under 18 without verifiable parental or guardian consent. Where the GDPR or CCPA applies, we do not knowingly collect personal data from individuals under 16. If you believe a minor has provided us data, please contact privacy@growbro.ai.
15. Third-party platforms
The Services integrate with third-party platforms (Meta, Google, HubSpot, Razorpay). Their handling of your data is governed by their own privacy policies. Notably:
- Meta Platform Terms and the WhatsApp Business Messaging Policy apply to your use of WhatsApp, Instagram, and Messenger.
- Google’s privacy and terms apply when you connect a Google account.
- Razorpay’s privacy policy applies to payment processing.
16. Data Processing Agreement
For Customers acting as controllers / data fiduciaries of their end users’ data, GrowBro acts as processor / data processor. Enterprise customers may request our standard Data Processing Agreement (incorporating GDPR Article 28 terms, Standard Contractual Clauses, and DPDPA processor obligations) by emailing privacy@growbro.ai.
17. Changes to this policy
We may update this Privacy Policy from time to time. The “Effective” date at the top of this page reflects the current revision. Where changes materially affect your rights or how we process personal data, we will provide advance notice via in-app banner, email, or other reasonable means.
Questions or requests?
Privacy questions: privacy@growbro.ai
Grievance Officer (Aakash Roy, Founder): grievance@growbro.ai