Privacy Policy
Last updated: [FILL IN DATE]
This Privacy Policy explains how [FILL IN LEGAL ENTITY NAME] (“Groager”, “we”, “us”), a company incorporated in India at [FILL IN REGISTERED ADDRESS], collects, uses, and protects information in connection with the Groager platform. It applies both to (a) you, if you hold a Groager account, and (b) visitors to websites that use Groager's tracking snippet, where we act as a data processor on behalf of our customer (the website owner). This policy describes what our systems actually collect today, not a generic template — see the sections below for specifics.
1. Information We Collect About You (Account Holders)
1.1 Account & profile data
- Full name and email address, provided at signup;
- Password (stored as a salted hash — we never store or can view your plaintext password), or, if you sign up with Google, your Google account's email/profile info via OAuth (no password stored);
- Organization/workspace name, and your role within it (owner, admin, member, or viewer);
- Content you create in the product: chat conversations with the AI assistant, business goals you define, alert configurations, API keys and webhook endpoints you create, and similar account configuration.
1.2 Billing data
Subscription payments are handled entirely by Paddle.com Market Limited as our payment processor and Merchant of Record. We do not receive or store your full card number or other sensitive payment details — Paddle collects and processes that directly. We receive from Paddle only what is necessary to manage your subscription (e.g. plan, status, and billing email).
1.3 Technical & usage data
When you use the Groager dashboard itself, our servers log standard request metadata (IP address, timestamp, endpoint accessed, response time) for security, rate-limiting, and debugging. If an unhandled error occurs, we log the error type, message, the page/endpoint involved, and — if you were logged in — your user and organization ID, to help us fix bugs. The Groager dashboard itself does not use cookies for authentication; your session is kept in your browser's local storage.
2. Information Collected From Your Website Visitors (If You Use the Tracking Snippet)
If you embed Groager's tracking snippet on your own website, it collects the following about your website's visitors, on your behalf, so we can generate your analytics dashboard:
2.1 Sessions
- A visitor identifier stored in a first-party browser cookie (
niq_vid) on your website's own domain, valid for 365 days, used to recognize returning visitors across sessions; - IP address (used transiently for approximate geolocation — see 2.3 — and abuse/bot filtering);
- Browser user agent, parsed into device type, browser, and operating system;
- Referring URL, and any UTM campaign parameters present in the landing URL;
- Landing page, exit page, session duration, and number of pages viewed;
- Whether the session is flagged as a bounce, a conversion, likely bot traffic, or internal traffic (e.g. from an IP you've allow-listed as your own office/team).
2.2 Events
The snippet can record individual visitor interactions, depending on what your site triggers:
- Page views, scroll depth, and outbound link clicks;
- Clicks on designated call-to-action elements, file downloads, and clicks on
tel:,mailto:, and WhatsApp links; - Form-related events;
- Custom events you define, which may include arbitrary properties you choose to send;
- Screen/viewport dimensions and page responsiveness (Core Web Vitals-style) metrics;
- The visitor's IP address and user agent (same as above), attached to each event for attribution.
2.3 IP-based geolocation
To show country/city/region-level location in your analytics, we send the visitor's IP address to a third-party geolocation lookup service, ip-api.com, which returns an approximate country, city, and region. Results are cached for 24 hours per IP to limit how often this lookup happens. We do not use this for precise (e.g. GPS-level) location.
2.4 Respecting Do Not Track / opt-out
The tracking snippet checks the visitor's browser navigator.doNotTrack signal (and equivalent vendor-prefixed signals) and does not collect data if it is enabled, unless the site owner has explicitly configured the snippet to require separate consent. Bot and known-internal traffic is flagged but is still recorded (marked as such) rather than silently dropped, so it can be excluded from your reports without losing the underlying record.
If you are a visitor to a website that uses Groager's tracking snippet and have questions about that site's data practices, please contact that website directly — they, not Groager, are the data controller for their own visitors and determine how their site uses this data (e.g. what consent notices they show). Groager processes this data as instructed by our customer.
3. Optional Third-Party Integrations You Connect
3.1 Google Search Console
If you choose to connect a website to Google Search Console, we request read-only access via Google OAuth and store your connection's access/refresh tokens (encrypted at rest) plus the Search Console performance data you've authorized us to read (queries, clicks, impressions, click-through rate, and average position for your site). You can disconnect this at any time from your dashboard, which revokes our access.
3.2 “Sign in with Google”
If you sign in using Google, we receive your name, email address, and Google account ID via standard OpenID Connect scopes (openid, email, profile) — we do not request access to your Gmail, Drive, or other Google data through this login flow.
3.3 Other integrations
Additional optional integrations may be added to the platform over time; each will only access the specific data needed for that integration, and will be described here and/or at the point you connect it.
4. How We Use Information
- To provide, operate, and maintain the Service (e.g. generating your analytics dashboard, running SEO audits, powering the AI assistant);
- To send transactional emails: account verification, password reset, team invitations, and alerts you've configured (e.g. a website's Core Web Vitals crossing a threshold);
- To detect, investigate, and prevent fraud, abuse, and security incidents;
- To provide customer support and respond to your requests;
- To improve the Service, including debugging errors (see 1.3);
- To comply with legal obligations.
We do not sell your personal data, or your website visitors' data, to third parties.
5. AI Processing
The AI assistant and AI-generated explanations are powered by Anthropic's Claude API. When you use these features, relevant structured data already in your dashboard (e.g. your analytics figures, audit findings, or the text of your question) is sent to Anthropic to generate a response. Per our product design, the AI is used only to explain and summarize evidence already computed by our backend — it is not given blanket access to your full account and does not train on your data beyond what Anthropic's own API terms provide for. See Anthropic's Privacy Policy for how they handle API data.
6. Third-Party Sub-Processors
We share data with the following categories of third-party service providers, only as needed to run the Service:
- Paddle.com Market Limited — payment processing, billing, tax compliance (Merchant of Record for subscriptions);
- Google LLC — OAuth sign-in and, if you connect it, Search Console API access;
- Anthropic PBC — AI processing for the AI assistant and AI-generated explanations (see Section 5);
- ip-api.com — IP-to-location lookups for visitor geolocation in analytics (see 2.3);
- Our email delivery provider (currently Google/Gmail SMTP) — for sending transactional emails;
- Our cloud infrastructure and database backup storage providers, currently including Backblaze B2 for encrypted off-site database backups, and [FILL IN: hosting provider name] for our servers.
We do not have a Content Delivery Network (CDN) in front of the Service at this time; requests are served directly from our servers.
7. Data Retention
- Account data is retained for as long as your account is active, and for a limited period afterward to allow for reactivation or legally required record-keeping, after which it is deleted or anonymized upon request.
- Analytics data collected via the tracking snippet (sessions/events) is currently retained indefinitely by default for as long as the associated website remains connected to an active account, so historical reporting remains available; you can request deletion of this data at any time (see Section 9).
- Database backups are retained for 30 days on our servers and up to 90 days in off-site backup storage, after which they are permanently deleted, independent of when the underlying live data was deleted.
- Error logs are retained as needed for debugging and are not kept indefinitely.
8. Security
We use industry-standard measures to protect data, including encrypted connections (TLS/HTTPS) for all traffic, hashed password storage, role-based access control within workspaces, and rate limiting on sensitive endpoints. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you as required by applicable law.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these rights — for your account data, or on behalf of your website if you're requesting deletion of visitor analytics data you collected — contact us at digitekentails@gmail.com. We currently process deletion and access requests manually; we aim to respond within a reasonable time and in any event within the timeframe required by applicable law.
If you are located in the European Economic Area, United Kingdom, or a jurisdiction with a similar data protection authority, you also have the right to lodge a complaint with your local supervisory authority.
10. Cookies Summary
- The Groager dashboard itself (app.[FILL IN DOMAIN]) does not set authentication cookies — your session token is kept in your browser's local storage, not a cookie.
- The tracking snippet, when embedded on a customer's website, sets one first-party cookie (
niq_vid) on that website's own domain to recognize returning visitors, described in Section 2.1.
11. International Data Transfers
We are based in India; some of our sub-processors (Section 6) are based outside India, meaning your data may be transferred to and processed in other countries. Where required by applicable law, we rely on appropriate safeguards (such as those sub-processors' own standard contractual clauses or equivalent mechanisms) for such transfers.
12. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect account data from them. If you believe a child has provided us with personal data, contact us at digitekentails@gmail.com and we will take appropriate action.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice before they take effect.
14. Contact
Questions about this Privacy Policy, or requests relating to your data, can be sent to digitekentails@gmail.com.