Skip to main content

Privacy Policy

Last updated: 9 July 2026

Growpins ("Growpins", "we", "us", or "our") operates Growpins Ledger, an invoicing, document management, and bookkeeping platform for small and medium businesses (the "Service"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service at ledger.growpins.ai.

1. Information We Collect

1.1 Information you provide

  • Account information: your name and email address (used for magic-link sign-in), and, if you sign in with Google, the basic profile information Google shares with us (name, email address, profile photo).
  • Company information: your business name, address, logo, Tax Identification Number (TIN), bank details you choose to display on documents, and document customisation settings.
  • Business records you create: clients and their contact details, products, invoices, proformas, waybills, receipts, letterheads, expenses, and bookkeeping entries.
  • Communications: messages, feedback, and support requests you send us.

1.2 Information collected automatically

  • Usage data: pages visited, features used, and navigation paths, collected through privacy-friendly analytics.
  • Device and log data: IP address, browser type, operating system, server logs, and error reports.

2. Your Clients' Data

When you store information about your own clients in the Service (such as their names, addresses, phone numbers, emails, or TINs), you are the controller of that data and we process it on your behalf solely to provide the Service. You are responsible for ensuring you have a lawful basis to store and use your clients' information. We never use your clients' data for marketing, never sell it, and never share it with other users. Strict user-level data isolation means your business records are visible only to your account.

3. How We Use Your Information

  • Provide, operate, maintain, and improve the Service
  • Create and manage your account and authenticate sign-ins
  • Generate the documents and reports you request
  • Process subscription payments and send receipts
  • Respond to enquiries and provide customer support
  • Send service updates and, with your consent where required, product news (you can unsubscribe at any time)
  • Monitor for and prevent fraud, abuse, and security incidents
  • Comply with legal and tax obligations

4. How We Share Information

We do not sell your personal information. We share it only with:

  • Service providers that help us run the Service - cloud hosting, database hosting, email delivery, and analytics - under agreements that restrict their use of your data.
  • Recipients you choose: when you email a document or share a client-portal link, the contents of that document are visible to whoever you send it to.
  • Legal requirements: where required by law, court order, or a competent authority.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.

5. Data Retention

  • Active account data is retained for the life of the account.
  • If you delete your account, your data is purged within 90 days, except where retention is legally required.
  • Records connected to financial transactions may be retained for up to 7 years to meet tax and accounting obligations.
  • Backup copies may persist for up to 30 additional days.

6. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent.

Nigeria (NDPA 2023)

Nigerian users have the rights set out in the Nigeria Data Protection Act, 2023, including the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

EU/UK (GDPR) and California (CCPA)

Users in these regions have the corresponding rights under the GDPR and CCPA, including data portability (GDPR) and the right to know and delete (CCPA). We do not sell personal information as defined by the CCPA.

To exercise any right, email support@engagegrowth.com. We respond within 30 days. You can also export your clients, products, and documents as CSV or PDF from within the app at any time.

7. Security

We protect your information with encryption in transit (HTTPS/TLS), encryption of sensitive data at rest, token-based authentication, access controls, and strict per-user data isolation. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security - please keep your sign-in email account secure, since it is used for magic-link authentication.

8. Cookies and Local Storage

We use strictly necessary cookies and browser storage to keep you signed in and remember your preferences, plus privacy-friendly analytics to understand aggregate usage. We do not use advertising or cross-site tracking cookies.

9. International Transfers

Our infrastructure providers may process data in data centres outside your country. Where data is transferred internationally, we rely on appropriate safeguards consistent with applicable data protection laws.

10. Children's Privacy

The Service is a business tool and is not directed at children under 18. We do not knowingly collect personal information from children; if we learn that we have, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or an in-app notice, and the "Last updated" date above will reflect the latest revision.

12. Contact Us

For privacy questions, requests, or complaints, contact us at support@engagegrowth.com or via the contact page.