Privacy Policy

Last updated: July 21, 2026

This Privacy Policy explains what information WebGrowthSignal collects, who processes it on our behalf, and how long we keep it. It covers both your data as a customer and the data we handle about visitors to the websites you connect.

Information we collect

Account information

You can sign in with Google, with an email address and password, or with a one-time email link. We store your email address, and your name and profile image when your sign-in method provides them. Passwords are never stored in readable form — only a salted, computationally expensive hash.

Sites and audit data

The website and competitor URLs you add, and everything we derive by fetching your public pages: scores, findings, titles, meta tags, headings, link structure, response times, and page screenshots used for heatmap overlays. We fetch only publicly reachable pages and never attempt to reach password-protected areas.

Visitor analytics from our pixel

If you install our pixel, we collect pageview events (page path, referrer or campaign source, and timestamp) and, where you enable heatmaps, interaction events (clicks, pointer movement and scroll depth as coordinates on the page). The pixel sets no cookies and does no cross-site tracking.

To count unique visitors we derive a keyed one-way hash from the visitor's IP address, browser, your pixel id and the current date. The key is a secret only we hold, and the hash changes every day — so it cannot be reversed into an IP address, and it cannot be used to follow anyone across days or across sites. Stored pageview records contain no IP address.

Visitor identification (business traffic)

If you enable Visitor Identification, a visitor's IP address is sent to our lookup provider to determine whether it belongs to a company or educational network. We keep the resulting organisation details and discard the IP address. Addresses identified as residential, mobile, VPN, proxy, Tor or datacenter traffic are dropped and no profile is created. Any IP address still held while a lookup is pending is deleted automatically within 9 days, whether or not the lookup ever completed.

Business contact details

For companies identified this way, we fetch that company's own public website (its homepage and up to three contact or about pages) and keep only generic role addresses on that company's own domain — such as info@ or sales@ — plus publicly listed phone numbers and social profiles. We deliberately do not keep addresses belonging to named individuals, even when they are published.

Contacts and outreach you create

Subscriber lists you upload or collect, sales leads built from your own traffic, and any outreach emails you draft or send through the service, including delivery results such as bounces, complaints and unsubscribes. You choose these recipients; we send on your behalf from a sending address you verify.

Website Builder

The prompts and chat messages you write, the application code generated from them, and any data you enter into a generated app while previewing it. Prompts are screened for abuse before generation, and generated code runs in an isolated sandbox — never on our own servers.

Billing information

Payments are processed by Razorpay. We never receive or store your full card number. We store your plan, subscription and order identifiers, credit-wallet history, and the payment metadata Razorpay reports back to us for each transaction — such as the amount, the method used, a payment reference, and the contact details you gave at checkout.

How we use your information

  • To run audits and compute your Growth Score and daily action plan.
  • To produce the analytics, heatmaps and lead intelligence you enable.
  • To generate AI recommendations, reports, ad copy and websites you request.
  • To send the alerts and digests you configure, and the outreach you initiate.
  • To take payment, apply your entitlements and meter usage.
  • To operate, secure, support and improve the service.

We do not sell your personal information, we do not use your analytics data for advertising, and we do not use your data to train AI models.

Service providers

We share data with a small set of processors, each only for the purpose listed:

  • Vercel — application hosting; also the isolated sandboxes and hosting used to build, preview and publish Website Builder apps.
  • Neon — database hosting, including the separate database provisioned for each generated app that stores data.
  • Google — sign-in, for accounts that use it; and PageSpeed Insights, which receives the page URLs we measure performance for.
  • Razorpay — payment processing for subscriptions and credit top-ups.
  • Resend — delivery of alerts, digests, sign-in links, and outreach you send.
  • OpenRouter — access to the AI models behind recommendations, reports, ad copy, outreach drafts and generated websites. It receives the minimum context needed for each task.
  • IPLocate — organisation lookup for Visitor Identification. It receives a visitor IP address and returns the organisation it belongs to.

We do not send visitor IP addresses, subscriber lists or contact details to AI providers.

How long we keep data

  • Account, site and audit data — for as long as your account is open.
  • Pending visitor IP addresses — deleted within 9 days, unconditionally, by a scheduled sweep. This does not depend on your audit schedule or on the lookup succeeding.
  • Organisation lookup cache — up to 30 days, after which the cached entry, including the IP address it was keyed on, is deleted.
  • Company contact profiles — up to 90 days, then deleted and re-fetched if still needed.
  • Billing records — retained after cancellation where we are required to keep them for tax and accounting purposes.

Deleting a site or your account deletes the associated data, including collected pageview and heatmap data. Deleting a generated app also destroys its sandbox, its hosting project and its database.

Data about your visitors and contacts

For the pixel, Visitor Identification, subscriber lists and outreach, you decide what is collected and who is contacted — you are the controller of that data and we process it on your instructions. You are responsible for having a lawful basis, for telling your visitors what you collect (for example in your own privacy notice), and for honouring their requests. We will assist you in doing so; contact us and we will action deletions on your behalf.

Your rights

You can access, correct, export, or delete your data from inside the app or by contacting us. To revoke WebGrowthSignal's access to your Google sign-in, use your Google account permissions. Depending on where you live, you may have additional rights under laws such as the GDPR, the DPDP Act or the CCPA, including the right to object to processing or to complain to your data protection authority.

International transfers

Our providers operate in several countries, so your data may be processed outside the country you live in. Where that happens we rely on the safeguards those providers offer for international transfers.

Security

We encrypt data in transit, restrict access on a least-privilege basis, and design for data minimisation. See our Security page for specifics.

Contact

Questions about this policy? Email privacy@webgrowthsignal.com. We may update this policy from time to time; we'll revise the “Last updated” date above when we do.