1. INTRODUCTION
Welcome to GrowingLoop ("we," "us," "our"). This Privacy Policy explains how we collect, use, store, share, and protect information when you access or use:
- Our website at https://growingloop.com (the "Site")
- Our marketing intelligence platform and applications (the "Platform")
- Our API integrations with LinkedIn, Facebook, TikTok, and Google
- Any related services, features, and content (collectively, the "Services")
By using our Services, you consent to the data practices described in this policy.
If you do not agree with this policy, please do not use our Services.
This policy is incorporated into and subject to our Terms of Service.
Who We Are
The Automatic Office, Corp. dba GrowingLoop, Inc.
8400 NW 33rd Street, Suite 310 PMB 2477
Doral, FL 33122
Email: privacy@growingloop.com
Website: https://growingloop.com
2. INFORMATION WE COLLECT
We collect information in three ways: information you provide directly, information collected automatically, and information from third-party platforms.
2.1 Information You Provide Directly
Account Registration:
- Full name
- Email address
- Password (stored encrypted)
- Company/organization name (optional)
- Phone number (optional)
- Billing information (processed by third-party payment processors)
Content You Create:
- Product descriptions and URLs
- Brand positioning and messaging
- Target audience definitions
- Campaign objectives and budgets
- Marketing hypotheses (if manually created)
- Communications with support
Creative Assets:
- Images, videos, and documents you upload
- File metadata (filename, size, upload date)
- Storage location (AWS S3 URLs)
2.2 Information Collected Automatically
When you use our Services, we automatically collect:
Usage Data:
- Pages viewed and features accessed
- Actions taken within the Platform
- Campaign creation and management activities
- Time spent on pages
- Navigation paths
Technical Data:
- IP address
- Device type, model, and operating system
- Browser type and version
- Screen resolution
- Referring/exit pages
- Date and time stamps
- Clickstream data
Performance Data:
- Campaign metrics (impressions, clicks, conversions)
- A/B test results
- Asset performance data
- Hypothesis validation outcomes
2.3 Information from Third-Party Platforms
When you authenticate via LinkedIn, Facebook, TikTok, or Google, we collect:
From LinkedIn:
- Profile information: Name, headline, profile URL, profile photo, user ID
- OAuth access token (encrypted, expires every 60 days)
- Posting permissions scope:
w_member_social,r_liteprofile - Post engagement metrics (only for content you publish through our Platform)
- Organization data (only if you grant
r_organization_socialpermission)
From Facebook:
- Profile information: Name, email, user ID, profile photo
- OAuth access token (encrypted, expires every 60 days)
- Page management permissions (if managing business pages)
- Ad account access (for campaign publishing)
- Post engagement metrics (only for your content)
From TikTok:
- Profile information: Username, user ID, profile photo
- OAuth access token (encrypted)
- Video posting permissions
- Engagement metrics (only for your content)
From Google:
- Profile information: Name, email, user ID, profile photo
- OAuth access token (encrypted)
- Google Ads account access (for campaign management)
- YouTube channel access (if applicable)
Important: We only request the minimum permissions necessary to perform the functions you've requested. We do NOT access your contacts, private messages, or any data unrelated to our Services.
3. LEGAL BASIS FOR PROCESSING (EEA Users)
If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on the following legal grounds:
Consent:
- When you grant permissions via third-party OAuth (LinkedIn, Facebook, etc.)
- When you upload creative assets
- When you opt-in to marketing communications
Contract Performance:
- To provide the Services you've signed up for
- To process your campaigns and experiments
- To generate AI-powered insights and recommendations
Legitimate Interests:
- To improve and optimize our Services
- To prevent fraud and ensure security
- To analyze usage patterns (anonymized where possible)
- To send service-related communications
Legal Compliance:
- To comply with applicable laws and regulations
- To respond to lawful requests from authorities
- To enforce our Terms of Service
You have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
18. CONTACT INFORMATION
We're here to answer your privacy questions and concerns.
18.1 Privacy Inquiries
General Privacy Questions:
Email: privacy@growingloop.com
Response time: 3 business days
Data Deletion Requests:
Email: deletemydata@growingloop.com
Response time: 48 hours
Security Concerns:
Email: security@growingloop.com
Response time: 24 hours
18.2 Mailing Address
The Automatic Office, Corp. dba GrowingLoop, Inc.
Attn: Privacy Department
8400 NW 33rd Street, Suite 310 PMB 2477
Doral, FL 33122
United States
Response Commitment: We commit to acknowledge all privacy inquiries within 3 business days and provide substantive responses within timelines specified in this policy.
SUMMARY OF KEY POINTS
Your privacy matters to us. Here are the essentials:
- We never sell your data - Your information is not for sale, ever.
- Minimal third-party data retention - LinkedIn, Facebook, TikTok, Google data kept maximum 30 days after last use.
- You control your data - Access, correct, delete, or export anytime.
- AI transparency - We explain exactly how AI processes your information.
- Strong security - Encryption, access controls, regular audits.
- Prompt breach notification - 72 hours or less if your data is compromised.
- GDPR & CCPA compliant - Full compliance with major privacy regulations.