Growie legal

Privacy Policy

Last updated July 10, 2026

The short version

Growie exists to help business owners get found and chosen. To do that we collect very little, and we are specific about what.

We set three cookies — one keeps you signed in, and two remember the language and market you picked. We run no advertising trackers and no third-party analytics pixels. We never sell personal information, and we never share it for marketing. If someone contacts a business through a site we power, their details go to that business — and nowhere else except the infrastructure that delivers them.

The rest of this page spells that out.

Who we are

Growie is operated by Techizta Services Private Limited, C119, Eastern Business District, Bhandup West, Mumbai 400078, Maharashtra, India. We run growie.ai, techizta.com and app.techizta.com, and the websites we build and host for verified business owners.

Questions about this policy or your data: [email protected] or +91 84338 73580.

Two kinds of people use Growie

Business owners create accounts, claim their business, and use our software and service.

Customers of those businesses may fill in a contact form on a site we power. If that is you, the section below about contacting a business through one of our sites is the one that matters most.

What we collect from business owners

When you create an account, we collect your email address and — only if you choose to give them — your name and phone number.

If you sign in with Google, Google sends us your email address, your name, and your Google account identifier. We request only the standard sign-in scopes (openid, email, profile) — nothing else from your Google account.

When you claim a business, we record the listing's Google place ID, the business name, and a verification record: where we sent your ownership code, whether it passed, and when. Login and ownership codes are stored only as cryptographic hashes — we never store the codes themselves — and they expire quickly: login codes in 10 minutes, ownership codes in 15 minutes.

If you contact a business through a site we power

When you submit a contact form on a business's site, we collect what you type — your name, phone number, email address, and message — together with the exact consent wording you agreed to and the time you agreed to it. The form only submits if you give that consent.

Your details are stored in a separate, consent-gated store, kept apart from our analytics, and they are passed to the business you asked to contact so that business can get back to you. We do not use your details for anything else: no marketing, no profiling, no sale, ever.

We keep lead details for up to 24 months and then delete them — sooner if you or the business asks (see Retention and deletion below).

Anonymous analytics

We count things server-side: a preview was generated, a claim was started, an enquiry was captured. These events carry a random anonymous identifier only. We do not record your IP address or your browser's user-agent in them, and they contain no names, emails, or phone numbers. Contact-form details never enter this analytics store.

Cookies: exactly three

We set three cookies, and here is each one.

tz_sess is a signed session cookie that keeps you logged in. It is HttpOnly (scripts on the page cannot read it), Secure (sent only over HTTPS), and it expires after 30 days.

tz_market and tz_lang remember the market and language you chose, so the page opens the same way next time. They are set when you pick a language or market (or arrive through a link that sets one), they last 1 year, and they hold nothing but those two settings — no identifier, nothing personal.

That is the complete list. No advertising cookies, no analytics trackers, no third-party pixels, no fingerprinting.

Google content on previews and sites

The reviews, photos, hours, and ratings you see on a preview come from the business's own public Google Business Profile. We fetch that content live from Google each time the page renders, in line with Google's terms, and we do not store it. The only thing we keep is the listing's place ID — a reference code, not content. Google attribution is shown wherever Google content appears.

If you connect your Instagram account

Connecting Instagram is entirely optional and nothing happens until you choose it. When you do, Instagram shows you its own permission screen, and it is worth reading — depending on which parts of Growie are switched on for you, we ask for permission to read your business profile and recent posts (so your photos can appear on your site), to send and read direct messages sent to your business account (so Growie can answer an enquiry that arrives there), and to publish posts to your account (so you can approve a post from your console instead of switching apps).

What we do with it: we store your Instagram business account id, the connection token (encrypted), and the posts we pull to show on your site. Direct messages are handled the same way as WhatsApp messages — the customer's message and the recent back-and-forth of that conversation are sent to our AI provider so a reply can be drafted, and the sender's Instagram-scoped id is stored only as a one-way hash, never in the clear. We never post anything to your account that you have not approved, and we never message anyone on your behalf without you.

You can disconnect Instagram at any time from Settings → Channels, which deletes the connection and the stored token. You can also revoke Growie's access from Instagram's own settings; if you do, Meta notifies us and we delete the connection and the associated data.

What we use information for

To run the service: signing you in, building and hosting your site, verifying ownership, routing enquiries to the verified owner, and counting results honestly in your console. To keep the service safe: preventing fraudulent claims and abuse. And to meet legal obligations where they genuinely apply.

We do not use your information for advertising, we do not build marketing profiles, and we do not sell it.

Email we send

We send transactional email only: login codes (valid for 10 minutes), ownership verification codes (valid for 15 minutes), and new-enquiry alerts to the verified owner of a business. We do not send marketing email, and we do not add anyone to mailing lists.

Who we share information with

Contact-form details are shared with exactly two kinds of parties: the business the person asked to contact, and the infrastructure providers that run our service — Amazon Web Services (hosting, and email delivery via SES), Cloudflare (network and security), and Google (the APIs that power search and previews). These providers process data on our behalf to deliver the service, not for their own marketing.

Growie also uses AI providers, and we would rather name them than leave you guessing. When Growie answers a customer on WhatsApp or on a website chat, the message they typed — and the recent back-and-forth of that conversation, which can include a name or a phone number if they typed one — is sent to Anthropic's Claude models running on Amazon Bedrock so a reply can be drafted. The same applies when you ask Growie to draft a reply to a review: the review text you paste is sent there too. Separately, to show you how AI assistants describe your business, we ask OpenAI, Perplexity and Google Gemini questions about it — those questions contain your business name and area, which for a sole practitioner is a personal name. We do not send them your customer list, your enquiries or your conversations. Each of these providers handles what we send under its own terms, and we send them the least we can — never your customer book, and never more of a conversation than is needed to answer the message in front of us.

We never sell personal information. We never share it for advertising or cross-context behavioral advertising. We would disclose information if the law genuinely compelled us to, and we would tell you where the law allows.

When you subscribe to a paid plan, your payment is processed by one of two providers, depending on where your business is listed: Paddle.com (our Merchant of Record for businesses listed outside India — Paddle subscriptions auto-renew until you cancel) or Razorpay (Razorpay Software Private Limited, India — recurring UPI-Autopay subscriptions for businesses listed in India, auto-debited monthly until you cancel). You enter your card or payment details in the provider's secure checkout under its own privacy policy — we never see or store your card number. We receive only confirmation that payment succeeded, the amount, and a payment reference, which we keep as the billing record.

Where your data is processed

Our servers, your database and your files run on Amazon Web Services in the ap-south-1 (Mumbai, India) region. That is where your account, your business data and your customer book live.

AI processing is the exception, and it leaves India. When Growie drafts a reply — to a customer's message or to a review — that text is sent to Amazon Bedrock in the us-east-1 (N. Virginia, United States) region, because the models we use are not available to us in Mumbai. The AI-visibility checks that ask how assistants describe your business go to OpenAI, Perplexity and Google, whose services run outside India as well. So a customer's message can be processed in the United States even though it is stored in Mumbai.

We say this plainly because a policy that mentions only Mumbai would be telling you something that is not true of every part of the product. We apply the protections described in this policy wherever the data is processed, and we do not currently promise storage or processing in any particular country or region.

Retention and deletion

Account data is kept while your account exists. Contact-form details are kept for up to 24 months, then deleted — earlier if deletion is requested. Ownership verification records are kept as an audit trail (with codes only ever stored as hashes).

There is no self-serve delete button yet — we are being honest about that. To delete your account, your business data, or an enquiry you submitted, email [email protected] from the relevant address. We will verify it is really you and complete the deletion within 45 days.

California notice at collection (CCPA/CPRA)

For California residents — and, as a matter of good faith, for everyone, whether or not a given law technically applies to us:

Categories we collect: identifiers (name, email address, phone number, Google account identifier), professional information (the business you claim and its Google place ID), and the content of messages submitted through contact forms. We collect them directly from you, for the purposes described in this policy, and retain them for the periods described above.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. Because we do neither, there is nothing to opt out of — but you can still tell us your preference and we will record and honor it.

Your rights: to know what we hold about you, to have it deleted, to have it corrected, and to opt out of sale or sharing (which we do not do). Exercise any of these by emailing [email protected]. We will never treat you worse for exercising a privacy right.

Children

Growie is not directed at anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.

Security

Verification codes are stored only as hashes. Sessions are signed and carried in an HttpOnly, Secure cookie. Contact-form details live in a store separate from analytics, and only the verified owner of a business can see its enquiries. All traffic runs over HTTPS.

No system is perfectly secure, so we also rely on the best protection there is: collecting less. The less we hold, the less there is to lose.

Changes to this policy

If we change this policy, we will update the effective date at the top and, for meaningful changes, note them plainly on this page. We will not quietly weaken your protections.

Contact

Techizta Services Private Limited

C119, Eastern Business District, Bhandup West, Mumbai 400078, Maharashtra, India

Email: [email protected]

Phone: +91 84338 73580