Privacy Policy
Effective date: 25 July 2026
Last updated: 2 August 2026
Version: 1.4
1. Introduction
Your privacy matters to us. This Privacy Policy explains how AVENIX LTD (trading as GrowApp; “GrowApp”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you access or use growapp.nowand related services (collectively, the “Service”).
AVENIX LTD is a company registered in the United Kingdom. Our registered office is at 8 Stoney Lane, London SE19 3BD, United Kingdom. We are the data controller for personal data processed through the Service, unless stated otherwise in this policy.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and, where applicable, the EU GDPR for users in the European Economic Area (EEA).
This Privacy Policy is provided to explain our processing activities and does not mean that all processing is based on your consent. It should be read together with our Terms of Use.
Links on our site may lead to third-party websites (for example, Substack). Those sites have their own privacy policies, which govern your activity after you leave our Service.
2. Personal data we collect
We collect information in the following categories:
- Information you provide — for example, when you request a sign-in link or contact us.
- Information collected automatically — for example, when you browse the Service.
- Information from Substack — subscriber data we import to verify paid access (see Section 2.1).
Account and access data
- Email address (required to send magic sign-in links and verify subscription access)
- Magic-link token records (including the token, expiry time and usage status)
- Session identifiers (hashed session tokens associated with your authenticated visit)
2.1 Data received from Substack
Paid subscriptions are managed on Substack. From time to time our administrators import a Substack subscriber export into our database so we can grant and manage access to GrowApp. This import may occur before you first visit growapp.now, and may be repeated when we refresh subscriber lists.
We import only the fields needed to verify and administer GrowApp access: your email address, subscription status/type, subscription tier (Stripe plan), subscription start date and, where applicable, cancellation or expiry date. We do not import engagement metrics, revenue figures, location data, or other Substack analytics columns. We do not receive your payment card details.
After cancellation or expiry, we retain former subscriber records only for the period described in Section 8, then delete or anonymise them.
2.2 Information provided before you visit GrowApp (Article 14)
Because subscriber data may be obtained from Substack before you first visit growapp.now, we provide privacy information through:
- this Privacy Policy;
- notices in Substack checkout, welcome emails or newsletter/footer communications where available, stating that subscriber information is shared with AVENIX LTD / GrowApp to administer access; and
- the Privacy Policy link on the GrowApp sign-in page.
We aim to ensure that individuals are informed within one month of our obtaining the data, typically via Substack subscription communications and/or when they first interact with GrowApp.
Communications
If you contact us by email, we may retain the content of your message and our response for support and record-keeping purposes.
Log and technical data
When you visit the Service, our servers and infrastructure providers may automatically record standard technical data, including IP address, browser type and version, operating system and device type, pages viewed, referring URL, date and time of access, and error or diagnostic data if something fails.
We use this logging for security and operational purposes under legitimate interests. We do not treat this as a substitute for Google Analytics. Non-essential usage analytics via Google Analytics run only with your consent (see Section 5).
Analytics data
If you accept analytics cookies, Google receives and processes analytics identifiers and usage information in accordance with our configuration and Google's applicable data-processing terms. We configure Google Analytics without advertising personalisation and with IP anonymisation enabled. We do not intentionally enable Google Signals or User-ID for GrowApp. See Section 5 for cookie details and retention.
Payment and billing data
Card payments are processed by Substack and its payment processors under their own terms and privacy notices. AVENIX LTD does not process payment card details on GrowApp.
Cookie consent preference
We store your cookie choice in your browser local storage so we can remember and honour your preference on that browser.
3. Purposes, lawful bases and retention overview
Under the UK GDPR (and, where applicable, the EU GDPR), we process personal data only where we have a valid lawful basis. The following summary maps our main processing activities:
| Purpose | Data | Lawful basis | Retention |
|---|---|---|---|
| Authenticate users (magic link) | Email, magic-link token records | Contract | Until used or 24 hours, whichever is earlier |
| Maintain signed-in session | Session cookie / hashed session token | Contract | Up to 24 hours |
| Verify subscriptions and grant access | Email, subscription status/type, subscription tier (Stripe plan), subscription start date, and cancellation or expiry date where applicable | Contract | While the subscription is active; former subscriber records up to 12 months after end, then delete or anonymise |
| Secure and operate the Service | IP address, device/browser data, server logs | Legitimate interests (security, abuse prevention, reliability) | Security and operational logs typically 30–90 days |
| Website analytics (Google Analytics) | Cookie IDs, usage/event data | Consent | Only after consent; GA event retention per our GA4 property setting (currently configured for up to 14 months) |
| Customer support | Email, message content | Contract and/or legitimate interests | Up to 24 months after the enquiry is closed |
| Remember and honour cookie choices | Consent preference in browser local storage | Legitimate interests | Until you clear site data for that browser or change your choice |
| Legal, tax and accounting records | Transaction/subscriber metadata as required | Legal obligation | As required by applicable UK law (often up to 6 years for certain records) |
| Admin preview mode (authorised staff only) | Admin preview cookie | Legitimate interests (service testing) | Up to 7 days |
We rely on consent for Google Analytics and other non-essential cookies. We rely on legitimate interests for limited security and operational logging necessary to maintain the Service — not for Google Analytics. You may withdraw consent at any time via Cookie settings in the footer.
4. How we use personal data
We use personal data to:
- Provide, operate, and maintain the Service
- Send magic sign-in links and important service/account notices
- Verify subscription access and enforce content entitlements
- Respond to support requests
- Detect, prevent, and address security incidents, fraud, and abuse
- Comply with legal obligations and enforce our Terms of Use
- Measure site usage with Google Analytics only where you have given cookie consent
Marketing newsletters and subscription communications are sent and managed through Substack. Substack provides the unsubscribe mechanism included in each marketing email. GrowApp service emails (such as magic links and important account notices) are separate from marketing communications and are not used for advertising.
We do not sell your personal data. We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
5. Cookies and similar technologies
We use cookies and similar technologies in accordance with PECR and the UK GDPR. On your first visit we show a cookie banner so you can accept or reject non-essential cookies with equally available choices. Essential cookies may still be used for sign-in and security. You can change your choice at any time via Cookie settings in the site footer.
| Name | Provider | Purpose | Category | Expiry | Type |
|---|---|---|---|---|---|
| magic_access | GrowApp | Authenticated session after magic-link sign-in | Essential | 24 hours | First-party HttpOnly cookie |
| growapp_admin_preview | GrowApp | Authorised administrator access-view testing only | Essential (admin tooling) | 7 days | First-party HttpOnly cookie |
| growapp_cookie_consent | GrowApp | Remember and honour your analytics cookie preference on that browser | Essential (preference) | Until you clear site data for that browser or change your choice | First-party local storage key (not a cookie) |
| _ga | Google Analytics | Distinguish users for analytics | Analytics (consent required) | Up to 2 years | First-party cookie created by the Google Analytics script |
| _ga_* | Google Analytics | Persist GA4 session state | Analytics (consent required) | Up to 2 years | First-party cookie created by the Google Analytics script |
The cookie lifetime in your browser is separate from the retention period for event data in our Google Analytics property.
Google Analytics scripts and analytics cookies are loaded only after you choose “Accept all”. If you choose “Reject non-essential”, we do not load Google Analytics and do not set analytics cookies. We do not send analytics events before consent.
Most browsers also let you block or delete cookies; blocking essential cookies may prevent parts of the Service from working correctly.
6. How we share personal data
We share personal data only as described below:
- Service providers (processors) who help us run the Service:
- Database and authentication infrastructure: Supabase
- Object storage and content delivery: Cloudflare R2
- Hosting and application infrastructure: DigitalOcean
- Operational backups: Backblaze B2
- Transactional email delivery: Zoho Mail
- Website analytics: Google Analytics (only with your cookie consent)
- Substack — subscription billing, payment processing and subscriber management are handled by Substack as an independent controller for payment and newsletter data. We import limited subscriber data as described in Section 2.1 to operate access on GrowApp.
- Legal and safety disclosures — where required by law, court order, or regulatory request (including UK authorities), or where necessary to protect rights, safety, and security.
- Business transfers — if we undergo a merger, acquisition, or asset sale, personal data may transfer as part of that transaction, subject to this policy or notice to you.
We do not share personal data with third parties for their independent marketing.
7. International data transfers
We are established in the United Kingdom. Personal data may be processed in countries other than the UK, including outside the UK and EEA (for example, the United States), where our service providers maintain facilities.
Where we transfer personal data from the UK to a country that is not covered by a UK adequacy regulation, we put in place appropriate safeguards required by UK GDPR. These may include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer mechanisms.
Where EU GDPR applies to a transfer from the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision.
You may contact us to request further information about the safeguards used for a particular transfer.
8. Data retention
We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by UK law. The overview table in Section 3 sets out our current retention periods. Operational backups may retain deleted data for up to 30–90 days before being overwritten.
When data is no longer needed, we delete it or anonymise it so it can no longer identify you.
9. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration, as required under UK GDPR. These include access controls, encrypted connections (HTTPS), and restricted access to production systems.
No method of transmission or storage is completely secure. You are responsible for keeping access to your email account secure, since sign-in links are sent there.
10. Your rights (UK GDPR / GDPR)
Under the UK GDPR (and, where applicable, the EU GDPR), you have the following rights regarding your personal data:
- Access — request a copy of personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to legal exceptions.
- Restriction — request that we limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Data portability — where processing is automated and based on your consent or a contract, you may have the right to receive personal data that you provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint — with a supervisory authority (see Contact us).
To exercise these rights, contact us at [email protected]. We will request only information reasonably necessary to verify your identity and protect your personal data. We aim to respond within one month, as required by UK GDPR (extendable in complex cases as permitted by law).
11. Data breaches
If a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner’s Office (ICO)without undue delay and, where feasible, within 72 hours after becoming aware of it. If the breach is likely to result in a high risk to individuals' rights and freedoms, we will also notify affected individuals without undue delay, unless an applicable legal exception applies.
12. Children's privacy
The Service is intended for individuals aged 18 or over. We do not knowingly collect personal data from children under 18. If you believe that a person under 18 has provided us with personal data, please contact us and we will take steps to delete it.
13. Third-party app content and personal data
Screenshots and recordings in our research library are intended to show application interfaces rather than identify individual users. Where reasonably possible, we use demonstration data or remove, blur or anonymise names, account identifiers, profile images, messages and other personal data.
In limited cases, Third-Party App Content may incidentally contain publicly available or demonstration personal information. We process such material only where necessary for the research and commentary purposes of the Service and subject to applicable data-protection and intellectual-property laws.
If you believe that content in the Service contains your personal data and would like us to review or remove it, please contact [email protected] and identify the relevant content.
14. Changes to this policy
We may update this Privacy Policy from time to time. The effective date and version at the top indicate when it was last revised. Material changes will be posted on this page; where required by law, we will provide additional notice (for example, by email to registered users).
15. Contact us
For privacy questions, requests to exercise your rights, or complaints about our data practices, contact:
- AVENIX LTD (trading as GrowApp)
- Registration number: 16105497
- VAT number: Not VAT registered
- Email: [email protected]
- Registered office:
8 Stoney Lane
London SE19 3BD
United Kingdom
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection: https://ico.org.uk/. You can make a complaint at https://ico.org.uk/make-a-complaint/. If you are in the EEA, you may also contact your local data protection authority.