Skip to main content
Legal

Global Privacy Policy

Last updated: August 2026

GrowthRail ("GrowthRail", "we", "us", or "our") respects your privacy. This Privacy Policy describes the information we collect when you visit www.growthrail.dev (our "Website") or use our referral-program infrastructure services (our "Service"), why we use it, how long we retain it, and the choices available to you. The contracting entity for a paid customer is the entity identified on that customer's order form or other written agreement.

When GrowthRail processes end-user data on a customer's instructions, GrowthRail generally acts as a processor or service provider and the customer acts as the controller or business. The applicable agreement and, where executed, Data Processing Addendum govern that processing. Contact contact@growthrail.dev to request the current DPA or identify the contracting entity for your account.

1. Information We Collect

We collect several types of information from and about users of our Website and Service, including:

  • Customer Account Information: Name, email address, company name, billing information, and account credentials required to provide the Service.
  • End-User Data (Processed on behalf of Customers): The IDs and attributes our customers send us via the SDK or API, plus event timestamps and device signals used for attribution (OS, OS version, timezone, locale, screen size, model, IP address). We process this data strictly under the instructions of our customers.
  • Usage Data & Telemetry: Details of your visits to our Website and use of the Service, including traffic data, location data, logs, and other communication data and the resources that you access and use.
  • Device and Security Data: Information about your computer and internet connection, including your IP address, operating system, authentication events, and browser type.

2. Prohibited Data (HIPAA & PCI-DSS)

GrowthRail is a referral infrastructure provider. We are not intended for the transmission, processing, or storage of Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA), nor are we a PCI-DSS compliant payment gateway. Customers are strictly prohibited from submitting PHI, full credit card numbers, government-issued IDs (like Social Security Numbers), or highly sensitive biometric data into our Service.

3. Cookies and Tracking Technologies

The Website uses essential storage for preferences and, only after you consent, optional analytics and advertising measurement from services such as PostHog, Microsoft Clarity, and Google Ads. You can accept or decline those tools in the consent panel and reopen it through “Cookie preferences” in the footer. The referral SDK uses first-party storage and the attribution inputs configured by the customer; it does not depend on a third-party advertising cookie.

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal identification information. We may disclose personal information that we collect or you provide as described in this privacy policy:

  • To Sub-Processors & Service Providers: We use infrastructure, authentication, billing, communications, analytics, and support providers to operate the Service. A current list of relevant sub-processors is available upon request.
  • For Legal Reasons: To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
  • Business Transfers: To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of GrowthRail's assets.

5. Global Data Protection Rights (GDPR, UK GDPR, LGPD)

If you are a resident of the European Economic Area (EEA), the United Kingdom (UK), or Brazil, you have specific data protection rights. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. Your rights include:

  • The right to access: To request copies of your personal data.
  • The right to rectification: To request correction of inaccurate data.
  • The right to erasure ("Right to be Forgotten"): To request deletion of your personal data under certain conditions.
  • The right to restrict processing: To request restriction of processing your personal data.
  • The right to object to processing: To object to our processing, particularly for direct marketing.
  • The right to data portability: To request transfer of your data to another organization.
  • The right to lodge a complaint: You have the right to complain to a Data Protection Authority (DPA) about our collection and use of your Personal Data.

Note for End-Users: If you are an end-user of one of our Customers, please direct your request directly to them (the Data Controller). GrowthRail acts as a processor and will assist our Customers in fulfilling these requests.

6. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the CCPA/CPRA may provide rights to know, delete, correct, and limit certain uses of personal information, and the right not to be discriminated against for exercising those rights. GrowthRail does not sell customer end-user data for money. Optional advertising measurement on the Website is disabled until consent; you can decline or withdraw that consent through “Cookie preferences.”

7. International Data Transfers

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. When transferring data from the EEA, UK, or Switzerland to jurisdictions without an adequacy decision, we rely on standard safeguards, such as the Standard Contractual Clauses (SCCs) approved by the European Commission or the UK Information Commissioner's Office.

8. Data Retention, Security & Breach Notification

GrowthRail applies technical and organisational safeguards intended to protect personal data. We retain data for the period needed to provide the Service, meet legal and accounting obligations, resolve disputes, and enforce agreements. Customer-specific deletion and backup-retention commitments are governed by the applicable agreement and DPA; contact us for the terms that apply to your account.

If a security incident affects customer personal data, GrowthRail will notify the affected customer without undue delay as required by the applicable agreement and data-protection law. Statutory notification duties and timelines vary by role and jurisdiction.

9. Changes to Our Privacy Policy

We will post any changes we make to our privacy policy on this page. If we make material changes to how we treat our users' personal information, we will notify you by email to the primary email address specified in your account.

10. Contact Information

To ask a question about this policy, exercise a privacy right, or identify the contracting entity for your account, email contact@growthrail.dev. We may need to verify your identity and relationship to an account before fulfilling a request.