Privacy Policy
Last updated July 17, 2026 · Alpha release
This policy describes what granvl (“we”, “us”) collects, why, and how it’s handled — both for you as an account holder and for visitors to pages our customers publish.
1. Account data
When you sign up we collect your name and email address (via our authentication provider, WorkOS) and the workspace data you create: funnels, pages, analytics, integration configuration, and team membership. We use this to operate the Service and to contact you about your account (approval, invitations, product alerts). You can unsubscribe from non-essential product email at any time.
2. Product analytics
We use PostHog to understand how the dashboard is used and to capture errors, so we can fix what breaks. This includes session replay: recordings of your dashboard screens with text inputs masked. It covers your activity in our product, not your visitors’ personal data.
3. Visitors to published pages (zero-PII posture)
- —Analytics on published pages are first-party and aggregate: page views, clicks, form submits, session flow. Visitor identifiers are salted hashes; we do not store visitor names, emails, or other personal form contents.
- —Form submissions are never stored on our servers. Forms deliver directly from the visitor’s browser to the destination our customer chose (their CRM, webhook, or lead platform). We record only that a submission happened, not what it contained.
- —Customers may add their own tracking pixels (Meta, Google, TikTok, etc.) to their pages; those are governed by the customer’s own privacy disclosures.
For visitor data we process on our customers’ behalf, the customer is the controller and granvl is a processor under our Data Processing Agreement at granvl.com/dpa.
4. Connected integrations
When you connect an ad platform, CRM, or lead distributor, we store the access credentials encrypted at rest and use them only to perform the actions you configure (syncing performance data, creating campaigns you request, delivering leads). We never sell or share this data.
5. Google user data
When you connect a Google account (Google Ads):
- —What we access: your Google account email address (to label the connection) and your Google Ads data — accounts, campaigns, ad groups, ads, keywords, and performance metrics such as spend, clicks, and conversions.
- —How we use it: only to provide the features you use — showing your campaigns and performance in your workspace, and creating or updating campaigns you explicitly request. granvl’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- —Transfer: we do not sell, share, or transfer Google user data to third parties, except to the infrastructure providers in Section 7 as needed to run the Service.
- —AI/ML: we do not use Google user data to develop, improve, or train AI or machine-learning models.
- —Protection: OAuth tokens are encrypted at rest and all data moves over TLS.
- —Retention and deletion: disconnect Google Ads in Settings to revoke access; we delete the stored tokens immediately. To delete synced ads data, use granvl.com/delete-my-data or email support@granvl.com. Deleting your account removes everything.
6. Meta platform data
When you connect a Meta ad account:
- —What we access: your ad accounts, campaigns, ad sets, ads, creative metadata, and performance metrics such as spend, impressions, clicks, and conversions, via the Meta Marketing API under the permissions you approve. Where you configure it, we also send server-side conversion events to Meta using your own pixel and access token.
- —How we use it: only to provide the features you use — showing performance in your workspace, joining it with conversions measured on your granvl pages, and taking actions in your account that you explicitly request. Data received from Meta (“Platform Data”) is processed in accordance with the Meta Platform Terms and Developer Policies.
- —We do not sell Platform Data, use it to build advertising profiles of individuals, or share it with third parties except the infrastructure providers in Section 7 as needed to run the Service.
- —Retention and deletion: disconnect Meta in Settings (or in Meta Business Settings → Integrations) to revoke access; we delete the stored tokens immediately, and delete synced data on request via granvl.com/delete-my-data. Deleting your account removes everything.
7. Service providers
We rely on a small set of infrastructure providers to run the Service: Vercel (hosting), Supabase (database and storage), WorkOS (authentication), PostHog (product analytics, session replay, and error tracking), Better Stack (server logs and uptime monitoring), Resend (transactional email), and Upstash (rate limiting). Each processes data only as needed to provide their function. These providers process data in the United States. The full, current list — with what each touches — is maintained at granvl.com/subprocessors.
8. Cookies
The dashboard uses cookies for sign-in (essential), your theme preference, and PostHog analytics. Pages our customers publish set only a first-party cookie that keeps a visitor on the same page variant; it identifies no one. More detail is in our Cookie Policy at granvl.com/cookies.
9. Your rights
Depending on where you live, you have rights to access, correct, delete, and receive a copy of your personal information, and to object to or restrict certain processing. To exercise them, email support@granvl.com or use granvl.com/delete-my-data — we respond within 30 days.
- —Canada: we comply with PIPEDA and BC’s PIPA. You may withdraw consent, and you may complain to the Office of the Privacy Commissioner of Canada or the OIPC for British Columbia.
- —EEA / UK / Switzerland: where the GDPR or UK GDPR applies, our legal bases are performance of a contract (operating your account), legitimate interests (securing and improving the Service), and consent where required. You may complain to your supervisory authority. International transfers to the US rely on Standard Contractual Clauses, incorporated through our DPA.
- —California and other US states: we do not sell personal information for money. Where analytics could constitute “sharing” under state law, you can opt out by emailing support@granvl.com; we also honor Global Privacy Control signals.
10. Children
The Service is for business use and not directed to children. We do not knowingly collect personal information from anyone under 16; if you believe we have, contact support@granvl.com and we will delete it.
11. Security
All traffic is encrypted in transit (TLS); credentials and integration tokens are encrypted at rest. Workspaces are isolated with default-deny, role-based access, and security-relevant actions are logged. Nightly encrypted backups are retained for 30 days with automated restore verification. No system is perfectly secure, but we design for minimal data held and least access.
12. Retention and deletion
Workspace data is retained while your account is active. To delete your account and its data — or specific data such as synced ads data — use the form at granvl.com/delete-my-data or email support@granvl.com. We verify the request, act on it within 30 days, and confirm when deletion is complete, except for records we are legally required to retain (which remain protected until deleted).
13. Changes
We may update this policy as the product evolves; material changes will be reflected here with an updated date.
14. Contact
Privacy questions: support@granvl.com.
granvl · British Columbia, Canada