Privacy Policy
Last updated: August 18, 2026
GRWN, LLC ("GRWN," "we," "us") respects your privacy. This policy explains what information we collect and how we use it.
1. What we collect. We collect information you provide directly, such as your name, email, phone number, company name, and project details, and information generated through your use of the Client Portal, including files you upload, messages you send, and onboarding task status. We do not collect sensitive categories of personal information, such as health or financial account data, unless you choose to share it with us as part of a project.
2. How we use it. We use this information to deliver the services you've engaged us for, communicate with you about your engagement, process payments, improve our own internal processes, and meet our legal and accounting obligations.
3. Cookies and tracking. Our website does not use advertising or tracking cookies. It loads fonts from Google Fonts, which may process your IP address as part of that request. Our Client Portal uses only the minimum session technology needed to keep you securely signed in, and this is never shared with any third party for advertising purposes.
4. What we don't do. GRWN does not sell your personal information to third parties, and we do not use your information for advertising. We do not ask for or store your account passwords for other services. See our Access Authorization Notice for how access is actually granted and handled.
5. Sharing. We share information only with service providers who help us operate, such as our payment processor and email provider, and only as needed for them to perform that function on our behalf. We may also disclose information when required by law, such as in response to a valid subpoena.
6. Data retention. We retain your information for as long as needed to provide services and meet our legal, accounting, and business record-keeping requirements, after which it is deleted or anonymized in the ordinary course of business.
7. Security. We take reasonable technical and organizational measures to protect your information, including encrypting sensitive credentials at rest and using revocable, expiring login links rather than passwords for the Client Portal. No system is completely secure, and we cannot guarantee absolute security.
8. Children's privacy. Our services are intended for businesses and individuals over the age of 18. We do not knowingly collect personal information from children, and if we learn that we have, we will delete it.
9. International users. We are based in the United States and primarily store and process information there. If you contact us from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your home country.
10. Your choices. You can ask us to correct or delete your information, or ask what information we hold about you, by contacting [email protected], subject to our legitimate business and legal record-keeping needs. If you are a California resident, you have additional rights under California law, including the right to know what personal information we hold and to request its deletion.
11. Changes. We may update this policy from time to time to reflect changes in our practices or the law. Material changes will be communicated to active clients, and the date at the top of this policy will always reflect the current version.
12. Contact. Questions about this policy can be sent to [email protected].