Skip To Content

Privacy Policy

1. Overview

This Privacy Policy explains how GrowCap, Inc. (“GrowCap,” “we,” “us,” or “our”) collects, uses, and protects information when you visit https://growcap.io, use our client portal at portal.growcap.io or our API at api.growcap.io, or otherwise use our services (together, the “Services”).

GrowCap provides user-acquisition finance, media buying, and analytics services to mobile app and game companies. This policy covers both personal information about individuals and the performance data belonging to our business clients (“Client Data”). Section 4 explains how Client Data is used, including for aggregated reporting, industry benchmarking, and model development.

For Client Data, GrowCap acts as a processor on the client’s instructions. Where a client agreement or data processing addendum exists, it governs Client Data and controls over this policy in the event of a conflict.

2. Information We Collect

You provide: name, business email, company name, job title, account credentials, billing contact details, and the content of forms and communications. Payment card data is handled by our payment processor, not stored by us.

Collected automatically: IP address, browser and device information, log data, and usage analytics including pages viewed and time spent while signed in.

Client Data from platforms and integrations. With client authorization we receive data from ad networks, mobile measurement partners (MMPs), app stores, and analytics platforms — campaign and creative identifiers, spend, impressions, clicks, installs, cohort metrics (retention, revenue, ARPU, LTV, ROAS), app/studio/geo/platform registry information, and pseudonymous device or user identifiers where the integration provides them.

We do not seek out, and ask clients not to send us, special category data, government identifiers, payment card numbers, or precise end-user geolocation.

3. How We Use Information

  • Provide, operate, secure, and improve the Services
  • Deliver reporting, dashboards, and analysis to clients
  • Manage accounts, authenticate users, and enforce API access limits
  • Communicate about the Services
  • Evaluate eligibility, underwrite, and manage financing and media-buying arrangements
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal, tax, audit, and regulatory obligations

4. Aggregated Data, Benchmarking, and Model Development

In addition to delivering each client’s own reporting, GrowCap may combine Client Data across clients and use the combined data in aggregated or de-identified form to improve the Services, to produce industry benchmarks and market analysis, and to develop, train, and improve the models and algorithms used in the Services. Insights, benchmarks, and models derived this way may be used to serve all clients, and are GrowCap property.

We treat client information as confidential. We do not disclose one client’s identifiable data to another client, a competitor, or any other third party, and we do not publish or share benchmarks or analysis in a form that identifies a client, app, or studio without that client’s prior written consent.

5. Information Sharing

We share information with service providers who host, store, secure, or process data on our behalf (bound by contract to use it only to provide services to us); client-authorized platform integrations; professional advisors under confidentiality; capital and financing partners where a client has entered a financing arrangement, limited to what that arrangement requires; regulatory authorities and law enforcement where legally required; and an acquirer in connection with a merger, financing, or sale of assets, subject to comparable protections. We also share aggregated and de-identified data as described in Section 4.

We do not sell personal information.

6. Data Retention

Personal information is retained only as long as necessary for legitimate business and legal purposes. Client Data is retained for the term of the client agreement and for a reasonable period afterwards to allow export, then deleted or de-identified, unless a longer period is required by law or agreement. Aggregated and de-identified datasets and trained models are retained indefinitely, as they are no longer linked to any identifiable client or individual. Clients may request earlier deletion at privacy@growcap.io.

7. Cookies

We use cookies and similar technologies for authentication, session management, security, and product analytics. We do not use third-party advertising cookies. You can control cookies through your browser settings; disabling them may break parts of the portal.

8. Data Security

We maintain safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based and least-privilege access controls, audit logging, and authenticated, rate-limited API access with scopes restricting which datasets a credential can reach. No method of transmission or storage is completely secure. If we become aware of a breach affecting personal information or Client Data, we will notify affected clients and, where required, regulators and individuals without undue delay.

9. International Transfers

GrowCap is based in the United States and processes data there. Information may be transferred to and processed outside your jurisdiction. Where required, we apply appropriate transfer safeguards, including Standard Contractual Clauses; copies are available on request.

10. Your Rights

Depending on your location, you may request access to, correction of, or deletion of your personal information, object to or restrict certain processing, withdraw consent, or opt out of the sale or sharing of personal information (we do not sell or share it). Email privacy@growcap.io; we will verify your identity and respond within the timeframe required by applicable law.

If you are an end user of a client’s app, GrowCap processes your data on that client’s behalf — please direct your request to that company. If you contact us, we will forward it to the relevant client and assist them in responding.

11. Children’s Privacy

The Services are business tools and are not directed to children. GrowCap does not knowingly collect personal information from individuals under 18. Clients whose apps are directed to children are responsible for ensuring any data they connect to GrowCap complies with COPPA, applicable children’s data rules, and platform policies, and for not transmitting children’s personal information to us.

12. Changes

We may update this Privacy Policy from time to time. We will update the “Last updated” date above, and will notify account administrators by email before material changes to how we use Client Data take effect. Continued use of the Services indicates acceptance.

13. Contact

GrowCap, Inc. Email: privacy@growcap.io