This Privacy Policy ("Policy") applies to users of HelloGrowthCRM and related services operated by Soor LLC("HelloGrowthCRM," "we," "us," "our"), including:
- The HelloGrowthCRM website and all related public pages and subdomains
- The HelloGrowthCRM web application and mobile experiences (where available)
- Any CRM features, AI functionality, integrations, and support tools made available through our Service
By accessing or using HelloGrowthCRM, you agree to this Policy. If you do not agree, please discontinue use of the Service.
1. Who We Are
- Company: Soor LLC
- Product: HelloGrowthCRM
- Address: 16192 Coastal Hwy, Lewes, DE 19958, USA
- Email: sales@hellogrowthcrm.com
2. Information We Collect
We collect information in three ways: (A) information you provide, (B) information collected automatically, and (C) permission-based data.
2.1 Information You Provide
- Account and profile data: name, email, phone number, password (stored as secure hashes), company/workspace details, and role
- CRM data you enter: leads, contacts, accounts, deals, activities, notes, tasks, pipeline details, and workflow configurations
- Communications data: messages, chat transcripts, support tickets, call recordings/transcripts where enabled, and attachments you submit
- Billing and subscription data: plan details, billing profile, invoices, and transaction metadata
- Imported data: CSV imports, migration files, and connector data you choose to sync from third-party systems
2.2 Information Collected Automatically
- IP address, browser type, operating system, device identifiers, and app/session metadata
- Feature usage events, page/screen interactions, performance data, and diagnostic logs
- Error reports, crash diagnostics, and system health telemetry
- Approximate region inferred from IP for localization and compliance defaults
- Push notification tokens (if notifications are enabled)
2.3 Cookies and Similar Technologies
We use cookies and similar technologies to keep sessions active, remember preferences, improve security, analyze usage, and enhance product performance. You can control cookies in browser settings and consent tools. Disabling certain cookies may affect functionality.
2.4 Device Permissions (Where Applicable)
Depending on the features you use, we may request access to camera, microphone, files/photos, or notifications for workflows such as document upload, QR scanning, voice-assisted input, and alerts. You can revoke these permissions in your device settings, but related features may not work.
3. AI Features and Data Processing
HelloGrowthCRM includes AI capabilities for CRM assistance, content generation, summarization, and workflow recommendations. To fulfill AI requests, relevant prompts and selected CRM context may be processed by AI infrastructure providers (including OpenAI and other configured providers).
- We send only data needed to complete your requested AI action
- AI output should be reviewed by users before business use
- You can avoid AI processing by not using AI-specific features
4. How We Use Information
- Create and manage user accounts, workspaces, and permissions
- Provide CRM functionality, automations, communications, and reporting
- Deliver support, service notifications, transactional messages, and product updates
- Process billing, invoices, and subscription operations
- Protect users and the Service through monitoring, fraud prevention, and abuse detection
- Improve reliability, performance, and feature quality through analytics and diagnostics
- Comply with legal obligations and enforce contractual rights
We do not sell your personal information for money. When you consent to marketing cookies, we use advertising and retargeting technologies that may qualify as a "sale" or "sharing" for cross-context behavioral advertising under California law. You can opt out at any time — see our California Privacy Notice (Section 21) and the Do Not Sell or Share My Personal Information page.
5. Legal Bases for Processing
Where applicable, we rely on legal bases such as performance of contract, legitimate interests, consent, and legal obligations. You may withdraw consent for consent-based processing where available.
6. How We Share Information
We share information only as needed for service delivery and legal compliance.
- Service providers and subprocessors: hosting, AI processing, communications, analytics, monitoring, and payment services
- Legal and safety disclosures: where required by law or necessary to protect rights, security, and users
- Business transfers: merger, acquisition, financing, restructuring, or sale of assets
7. Third-Party Services
Providers we use may include infrastructure, AI, analytics, communications, and billing partners, such as:
- AWS (infrastructure and storage)
- OpenAI and other configured AI providers (AI request processing)
- Stripe (payments and billing)
- Twilio/WhatsApp channels where enabled (communications workflows)
- Google Analytics and Microsoft Clarity (usage analytics)
- Resend and related email tooling (service emails)
- Error/performance monitoring tooling used for reliability and diagnostics
7.1 Meta (Facebook & Instagram) Integrations
When you connect a Facebook Page or Instagram Business account to HelloGrowthCRM (for Lead Ads sync, post publishing, Messenger, or Instagram Direct message management), you sign in through Meta's standard OAuth dialog. Meta automatically grants the public_profile permission to every Facebook Login flow; we use it solely to confirm the dialog completed successfully. We do not read, store, or transmit your Facebook public profile fields (Facebook user ID, name, profile picture, email, first/last name) to any database, log, or third party.
What we store is limited to the business assets you explicitly connect:
- Facebook Page ID, name, category, and Page access token — needed to publish posts, retrieve leads, and reply to Messenger conversations on that Page.
- Instagram Business account ID, username, display name, profile picture URL, and account type — needed to publish posts and moderate comments on that account.
- Long-lived user access token (~60 days, encrypted at rest) — refreshed automatically while the connection is active.
For Lead Ads specifically, we use the leads_retrieval permission to fetch the data a prospect submitted through your Facebook or Instagram lead form (name, email, phone, and any custom questions you configured) and store it as a CRM lead record, subject to the retention terms in Section 9.
The internal identifier of the HelloGrowthCRM user who initiated the connection is recorded against the integration for audit purposes; this is not your Facebook ID. Disconnecting the integration from Settings → Integrations revokes our tokens and deletes the stored Page / Instagram metadata within thirty (30) days.
8. Payment Information
Payments are processed by third-party payment processors. We do not store full payment card numbers on our servers.
9. Data Retention
We retain information only for as long as needed for business, contractual, security, legal, and compliance reasons. Retention varies by data type and your account status. When no longer needed, data is deleted or anonymized.
10. Account Deletion
You may request account deletion on our account deletion page, or by contacting us at sales@hellogrowthcrm.com. Upon deletion request, we remove or anonymize data according to operational and legal retention requirements.
11. Security
We maintain technical and organizational safeguards, including:
- TLS encryption in transit
- Encryption at rest
- Role-based access controls and authentication controls
- Audit logging, monitoring, and incident response practices
- SOC 2 Type II controls referenced in our trust materials
No system is 100% secure. Please use strong credentials and good security practices.
12. Incident and Breach Notification
If we identify unauthorized access to personal data, we investigate, contain, and remediate the incident, and provide required notifications under applicable law and contractual commitments.
- Customer notification: We will notify affected customers without undue delay, and in any event no later than 72 hours after we become aware of a confirmed personal-data breach.
- Regulator notification (India): We will notify the Data Protection Board of India in the form and manner prescribed by the DPDPA Rules as soon as practicable after confirmation.
- Regulator notification (EEA / UK): Where required, we will notify the relevant supervisory authority within 72 hours, in line with Article 33 GDPR.
- Status updates: While an incident is open, we will share updates and the eventual post-incident review with affected customers.
13. Children's Privacy
HelloGrowthCRM is a B2B CRM intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18.
India — DPDPA Section 9 (verifiable parental consent for minors):Under the Digital Personal Data Protection Act, processing of personal data of a child (under 18) requires verifiable consent of the parent or lawful guardian, and we may not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Because our Service is offered to businesses for adult workforce use, we do not seek such consent. If we discover that personal data of a child has been collected without verifiable parental consent, we will delete it promptly. To request deletion of a minor's data, contact privacy@hellogrowthcrm.com.
Persons with disability: Where a Data Principal is a person with disability who has a lawful guardian, we will process such personal data only with the verifiable consent of that lawful guardian, in line with Section 9(1) of the DPDPA.
14. International Transfers
Data may be processed in the United States and other jurisdictions where our providers operate. Where applicable, we use contractual and legal safeguards for cross-border transfers.
15. Your Privacy Rights
Depending on your location, your rights may include:
- Access to personal data we hold about you
- Correction of inaccurate or incomplete data
- Deletion of personal data (subject to legal exceptions)
- Restriction or objection to certain processing activities
- Data portability where applicable
- Withdrawal of consent where processing is consent-based
- Right to lodge a complaint with your local data protection authority
16. Region-Specific Notices
We support applicable rights frameworks including GDPR/UK GDPR, California privacy laws (CCPA/CPRA), India's DPDPA, and other local laws where relevant. For a concise rights guide, see Privacy rights (DPDPA, GDPR & CCPA). California residents: see the California Privacy Notice (Section 21) below and the Do Not Sell or Share My Personal Information opt-out.
17. Third-Party Links
Our Services may include links to third-party websites or products. Their privacy practices are governed by their own policies, not this one.
18. Policy Updates
We may update this Policy from time to time. We will update the "Last updated" date and provide additional notice for material changes when appropriate.
19. Contact Us
If you have privacy questions or requests, contact the entity that operates HelloGrowthCRM in your region:
- Soor LLC (HelloGrowthCRM)
- 16192 Coastal Hwy
- Lewes, DE 19958, USA
- Email: privacy@hellogrowthcrm.com
20. India — Digital Personal Data Protection Act (DPDPA) 2023
If you are located in India, the following additional rights and obligations apply under the Digital Personal Data Protection Act, 2023 ("DPDPA") and its implementing rules.
20.1 Data Fiduciary
Meru Technosoft Pvt. Ltd. (operating HelloGrowthCRM in India) is the Data Fiduciary as defined under Section 2(i) of the DPDPA. It determines the purpose and means of processing your personal data.
20.2 Consent
We process your personal data only for the purposes for which you have given free, specific, informed, unconditional, and unambiguous consent, or as otherwise permitted under the DPDPA (e.g., legitimate uses under Section 7). Consent is obtained via our in-app consent notice before data collection begins. You may withdraw consent at any time by emailing privacy@hellogrowthcrm.com.
20.3 Notice Requirements
Before or at the time of collecting personal data, we will provide a clear notice in English (and on request in any language listed in the Eighth Schedule to the Constitution of India) explaining:
- What personal data is being collected
- The purpose of processing
- How to exercise rights under the DPDPA
- How to make a complaint to the Data Protection Board of India
20.4 Your Rights under DPDPA
- Right to access: Request a summary of your personal data we hold and the processing activities.
- Right to correction & erasure: Request correction of inaccurate data or erasure of data no longer needed for its stated purpose.
- Right to grievance redressal: Lodge a complaint with our Grievance Officer (details below). If unresolved, escalate to the Data Protection Board of India.
- Right to nominate: Nominate a person to exercise rights on your behalf in the event of your death or incapacity.
20.5 Data Retention (India)
- Active accounts: Data retained for the lifetime of your account.
- Suspended / lapsed accounts: Personal data deleted within 90 days of account suspension.
- Deleted leads: Purged within 30 days of deletion request.
- Audit logs: Retained for 7 years as required under applicable law.
- Financial records: Retained for 8 years under Indian accounting rules.
20.6 Cross-border Data Transfers
Your personal data may be transferred to and processed in countries outside India (including the United States) by our sub-processors (see /subprocessors). We ensure that such transfers are made only to countries or entities that provide adequate protection as notified by the Central Government under Section 16 of the DPDPA, or under Standard Contractual Clauses or equivalent safeguards.
20.7 Security Safeguards
We implement reasonable security measures as required under Section 8(5) of the DPDPA, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, and periodic security audits.
20.8 Grievance Officer (India)
As required under Section 13 of the DPDPA, we have appointed a Grievance Officer for India:
- Name: Grievance Officer, HelloGrowthCRM
- Organisation: Meru Technosoft Pvt. Ltd.
- Email: grievance@hellogrowthcrm.com
- Response time: We acknowledge within 48 hours and resolve within 30 days.
If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India through the official government grievance and DPDPA complaint channels when they are publicly available.
21. California — CCPA / CPRA Privacy Notice
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides the following disclosures and rights. This section serves as our Notice at Collection and California privacy notice. Similar rights may apply to residents of other U.S. states with comprehensive privacy laws (e.g., Colorado, Connecticut, Virginia, Utah).
21.1 Notice at Collection — categories we collect
At or before the point of collection, we collect the following categories of personal information (as defined in Cal. Civ. Code §1798.140), for the business and commercial purposes described in Section 4 above:
- Identifiers: name, email address, phone number, IP address, and online/device identifiers.
- Customer records: account, billing, and subscription details.
- Commercial information: plan and transaction records, and CRM data you enter.
- Internet/network activity: usage events, page interactions, diagnostics, and cookie data.
- Geolocation: approximate (city/region) location inferred from IP address.
- Inferences: limited product-usage and marketing-audience inferences.
We do not collect or process sensitive personal information for the purpose of inferring characteristics, and we do not knowingly sell or share the personal information of consumers under 16 years of age.
21.2 Purposes, retention, and sources
We use each category for the purposes in Section 4 (providing and securing the Service, billing, support, analytics, and — with consent — marketing). We retain each category only as long as needed for those purposes and applicable legal, security, and accounting requirements (see Section 9), after which it is deleted or anonymized. We collect this information directly from you, automatically through your use of the Service, and from service providers acting on our behalf.
21.3 "Sale" and "sharing" of personal information
We do not sell your personal information for money. However, when you consent to marketing cookies, we use advertising and retargeting technologies (such as the Meta Pixel, LinkedIn Insight Tag, and Google Ads tags) that may disclose identifiers and internet activity(e.g., cookie IDs and device identifiers) to advertising partners. Under the broad CCPA/CPRA definitions, this activity may constitute a "sale" or "sharing" for cross-context behavioral advertising. We do not disclose any other categories for these purposes, and we do not sell or share sensitive personal information.
21.4 Your right to opt out of sale/sharing
You have the right to opt out of the sale or sharing of your personal information at any time. To exercise it:
- Use our Do Not Sell or Share My Personal Information control — it disables advertising and retargeting cookies for your browser immediately; or
- Enable Global Privacy Control (GPC) in a supported browser or extension. We honor GPC as a valid opt-out signal and will not load advertising/retargeting cookies for browsers that broadcast it.
21.5 Other California rights
- Right to know: the categories and specific pieces of personal information we have collected about you.
- Right to delete: deletion of personal information we collected, subject to legal exceptions.
- Right to correct: correction of inaccurate personal information.
- Right to limit: we do not use or disclose sensitive personal information beyond the purposes permitted under CPRA §1798.121, so no separate limitation control is required.
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
21.6 How to exercise your rights
Submit a request through our privacy request form or email privacy@hellogrowthcrm.com. We will verify your request to protect your account and respond within the timeframes required by law (generally 45 days, extendable once). You may use an authorized agent to submit a request; we may require proof of authorization. For an overview of all frameworks, see Privacy rights (DPDPA, GDPR & CCPA).