Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and what you can ask us to do about it. Written to be read rather than skimmed past.

Last updated 3 September 2026

Please have a lawyer review this before you publish it. It was drafted by a non-lawyer to reflect how this site and dashboard actually work, with the Digital Personal Data Protection Act, 2023 in mind. It is not legal advice. Anything below that no longer matches what you actually do must be corrected — an inaccurate privacy policy is worse than none.

Who this covers

This policy covers personal data ScaGrow handles as the organisation deciding why and how it is used — visitors to this website, people who book a call with us, and clients using our dashboard.

It does not cover data belonging to your own customers that we handle on your instructions while running your campaigns. That is dealt with separately in Your customers' data below, and in your services agreement.

What we collect

WhatWhenWhy
Name, email, phone, business name When you book a call or enquire To hold the meeting and follow up
Anything you tell us about your business During a call or in messages To prepare a proposal and do the work
Account email and password hash When we create your dashboard login To let you sign in. We never store your password itself — only a hash, held by Google Firebase
Your business results — revenue, sales, enquiries, ad spend Throughout our work together To report on performance in your dashboard
Billing and payment references When invoicing To raise invoices and match payments

We do not sell personal data, and we do not buy contact lists. We do not collect sensitive personal data, and please do not send us any.

Why we collect it

We rely on one of the following, depending on what the data is for:

  • To perform our contract with you — running your campaigns, giving you dashboard access, invoicing.
  • With your consent — when you fill in a form to book a call, or agree to receive updates from us.
  • Our legitimate interests — keeping our systems secure, and following up on an enquiry you started.
  • Legal obligation — keeping tax and accounting records.

Where we rely on consent, you can withdraw it at any time. That does not undo anything done before you withdrew it.

Your customers' data

Running campaigns for a client means we sometimes handle personal data belonging to that client's customers — enquiry names, phone numbers, and messages sent through WhatsApp or Instagram.

For that data we act on the client's instructions and only to provide the services. We do not use it for our own purposes, we do not sell or share it, and we delete or return it within thirty days of an agreement ending if the client asks.

Clients are responsible for having the consents required under the Digital Personal Data Protection Act, 2023 for the customer data they pass to us and for the advertising audiences built from it.

Who else sees it

We use a small number of service providers, each for a specific job:

ProviderWhat forWhere
Google FirebaseSign-in and the database behind your dashboardGoogle Cloud
NetlifyHosting this websiteGlobal CDN
Cal.comBooking callsEU / US
Meta, GoogleRunning your advertisingGlobal

Some of these store data outside India. We share only what each provider needs to do its job. We may also disclose data where the law requires it.

How long we keep it

  • Enquiries that did not become clients — up to two years, then deleted.
  • Client accounts and reporting data — for as long as we work together, and then as long as we need it for tax and accounting records.
  • Invoices and financial records — as long as Indian tax law requires.

Ask us to delete something sooner and we will, unless the law says we must keep it.

How we protect it

Dashboard access is protected by an account you control. What each account can read is enforced on the server by security rules, not merely hidden in the interface — one client cannot reach another client's data by tampering with the page.

Passwords are stored only as hashes, by Google Firebase. Where a client connects an advertising or messaging account to us, the access token is held server-side and is never exposed to the browser.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the Data Protection Board as required.

Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us to:

  • tell you what personal data of yours we hold and who we have shared it with;
  • correct anything inaccurate, or complete anything missing;
  • delete data we no longer need;
  • stop processing where you had given consent and have withdrawn it;
  • nominate someone to exercise these rights if you are unable to.

Write to us using the details below and we will respond within a reasonable period. If you are not satisfied, you may complain to the Data Protection Board of India.

Children

Our services are for businesses. We do not knowingly collect personal data of anyone under 18. If you believe we have, tell us and we will delete it.

Changes

We may update this policy. The version on this page is the current one, and the date at the top says when it last changed. Where a change matters to you, we will tell clients directly rather than rely on you noticing.

Contact

For anything about this policy or your data, contact:

Hrishikesh S Gireesh — ScaGrow

Kerala, India

Book a call · Our founder