Privacy, clearly explained
Your data deserves
a clear answer.
What Growth Engine reads, what it stores, for how long, and how to withdraw it. Updated 30 September 2026.
1. Who is responsible
The controller is doop Osakeyhtiö, Kauppiaskatu 5, 20100 Turku, Finland, business ID 2058661-9. For privacy questions and requests write to [email protected].
Growth Engine is operated by this company for its own marketing projects. There is no public sign-up and no second customer, so there are two kinds of personal data in it and no others: the operator’s own Google data, and the visitor events the operator’s own sites send.
2. The operator’s Google data
Signing in to Google from the application grants it two read-only scopes: Search Console (webmasters.readonly) and Google Ads (adwords, used for reading campaigns, spend and clicks). The application stores the OAuth refresh token, encrypted, on its own server, and the figures it reads with it: impressions, clicks, queries, spend, campaign names.
It writes nothing back to Search Console. Any Google Ads change is made only when the operator explicitly asks for it in the application. None of this is sold, shared, sent to any third party, or used to train models. It is read for exactly one purpose: showing the operator what their own marketing did.
The grant can be withdrawn at any time at myaccount.google.com/permissions, which immediately stops all further reading. The stored figures are then deleted on request.
3. Visitors to the sites that use the tracker
The operator’s sites load a first-party tracking client from collect.grrow.online, which is operated by the operator and sends data to nobody else. It sets no cookies and does not fingerprint. It records page views and product events, such as a form sent or a signup, with the campaign parameters, ad click id, landing address and referrer that came with the visit. Each event also records the path of the page it happened on, such as /pricing, without anything after a ? or a # in the address.
With consent, and only with consent, it writes one first-party localStorage key, _ge: a random visitor id plus the first and last arrival (campaign parameters, click ids, landing address, referrer), so that a later signup can be attributed to the search or ad that started the visit, and so that a consenting visitor’s page views can be read as one journey through the site. It is kept for at most 13 months. A visitor who declines is counted with the attribution of the page they are on, and nothing is written to their device.
The key can be cleared at any time by withdrawing consent on the site, or by clearing the browser’s site data. Each site that uses the tracker has its own privacy notice naming it, and that notice is where the site’s own processing is described.
4. This website
grrow.online itself uses no analytics service, sets no cookies and stores nothing in your browser. The tracker described above is not loaded on this site.
If you use the contact form, what you write is delivered to our mailbox by Formspree, Inc., a service in the United States, which processes it on our behalf under the European Commission’s standard contractual clauses. If you email us directly, your message is held in our mailbox. Either way it is used to answer you and for nothing else.
The site is served by Cloudflare, Inc., which processes connection data such as your IP address to deliver the pages and to protect the site, and which acts as our processor.
5. Retention and deletion
- Google figures read by the application: for as long as the grant stands and the operator keeps the history; deleted on request.
- Visitor events sent by the operator’s sites: kept as marketing history; the identifier in a visitor’s browser for at most 13 months.
- Messages sent through the form or by email: for as long as the conversation needs, then deleted.
6. Your rights
Under the General Data Protection Regulation you may ask what personal data we hold about you, have it corrected or deleted, restrict or object to its processing, and receive it in a portable form. Write to [email protected]; we answer within a month. You may also complain to the supervisory authority, in Finland the Office of the Data Protection Ombudsman (tietosuoja.fi).
7. Updates to this notice
This notice was last updated on 30 September 2026. A change that matters to you is announced at the top of this page with its date.