groflo

Legal

Privacy Policy

Groflo collects the minimum it needs to answer your questions, book your calls, and run the growth programs clients hire it for. It does not sell personal information.

Last updated: September 1, 2026

Who this policy covers

This policy applies to Groflo ("Groflo," "we," "us"), a sole-proprietor growth consultancy operated by Garett McDonald in the United States. It covers the groflo.ai website, email and scheduling with us, our client engagements, and the Groflo applications that connect to third-party platform APIs, including LinkedIn and Google.

Questions, requests, or complaints go to g@groflo.ai. Groflo is the data controller for the information described here, except where we process client data as a service provider (see "Client data" below).

Information we collect

Information you give us

  • Contact and inquiry details. Your name, email address, company, and anything you choose to write when you email us or reach out on LinkedIn.
  • Booking details. When you book a strategy call, our scheduler (Cal.com) collects your name, email address, time zone, meeting time, and any notes you add. Cal.com creates the calendar invite and sends the confirmation.

Information collected automatically

  • Privacy-friendly site analytics. We use Vercel Web Analytics and Vercel Speed Insights to count page views and measure page performance. These are cookieless and aggregated: they do not use persistent identifiers to track you across sites and they do not build a profile of you.
  • Server logs. Our host (Vercel) records standard request data such as IP address, user agent, referrer, and timestamp, for security, abuse prevention, and reliability.

LinkedIn Marketing API data

Groflo operates LinkedIn advertising programs for its clients through the LinkedIn Marketing API Program. A Groflo application connects to a LinkedIn advertising account only after a member who holds a valid role on that account authorizes it through LinkedIn's OAuth consent screen, and only for the scopes that member grants. Groflo does not share credentials, does not use one profile to administer accounts it has not been granted a role on, and does not create profiles for the purpose of managing accounts.

What we access. Depending on the permissions you grant, we may access: your basic profile information as the authenticating member (r_basicprofile); the advertising accounts you administer and their campaign structure, settings, and reporting (r_ads, rw_ads, r_ads_reporting); the LinkedIn Pages you administer and their reporting (r_organization_admin); responses to your lead generation forms (r_marketing_leadgen_automation); your matched audience segments (rw_dmp_segments); and your conversion tracking data (rw_conversions).

What we do with it. We use it only to run the advertising programs you engaged us for: authenticating you, building and optimizing campaigns in your accounts, delivering the leads your forms collect into your own CRM, maintaining the audience segments you asked us to build, recording conversions, and reporting on performance to you.

What we never do with LinkedIn member data. LinkedIn member data is walled off from every other part of our business. We do not export, distribute, or transfer it outside the application; we do not combine it with client CRM records, prospect lists, or any other data to create, supplement, verify, or append to profiles or leads; we do not use it to identify sales or marketing prospects, to build outbound target lists, or for account-based marketing; and we do not sell it or share it with third parties for their own purposes. Where a client separately provides us their own contact data, that data stays separate from anything retrieved through the LinkedIn APIs.

How long we hold it. We retain LinkedIn data no longer than the LinkedIn Marketing API Program Data Storage Requirements allow, and delete or refresh it on that schedule regardless of any longer period stated elsewhere in this policy. Where a field falls under more than one limit, we apply the shortest. In practice:

  • Profile data for members other than the person who authenticated is cached for no more than 24 hours and is not stored.
  • Member social activity data is held for no more than 48 hours.
  • Advertising account and LinkedIn Page administration and reporting data, which contains no individual member-level data, is held for up to one year.
  • Lead generation form responses are delivered into the client's own system and are thereafter retained by that client under their own policy.
  • Access and refresh tokens are stored encrypted and are deleted when you disconnect the application or ask us to.

Matched audiences and conversion data.Where a client asks us to build a matched audience, we upload contact identifiers from data the client provides, in the hashed form LinkedIn requires, solely to match against LinkedIn members for that client's campaigns. Where a client uses conversion tracking, we send conversion event data from the client's systems to LinkedIn for attribution. In both cases the client represents that it has the lawful basis and any required consent to use that data for advertising, and we act only on the client's instructions. We do not upload data obtained from the LinkedIn APIs into audience segments.

How to revoke.You can remove Groflo's access at any time from LinkedIn's Settings under Data privacy, "Permitted services," by removing our role from your ad account in Campaign Manager, or by emailing g@groflo.ai. You may also ask us to delete data we hold about you, and we will do so.

Our use of LinkedIn data is governed by the LinkedIn API Terms of Use, the LinkedIn Marketing API Program Terms, and LinkedIn's own privacy policy in addition to this one. Where those terms are more restrictive or more protective of the data than this policy, those terms apply.

Google API Services data

Groflo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access.Where you authorize a Groflo application through Google's OAuth consent screen, we may access: your name and email address for the account you authenticate with; the Google Ads accounts and manager accounts you administer, and their campaign structure, settings, and performance reporting; and, where you connect them, analytics and conversion measurement properties associated with those accounts. We request the narrowest scopes that let us do the work, and no more.

What we do with it. We use Google user data only to provide the user-facing features you engaged us for: building, managing, and optimizing campaigns inside your own accounts, measuring their performance, and reporting the results to you. We do not use it to provide or improve any product other than the service delivered to the account owner.

Limited Use commitments. Specifically, and in addition to everything else in this policy:

  • We limit our use of Google user data to providing or improving the user-facing features that account owner sees in our service.
  • We do not transfer Google user data except where necessary to provide those features with your consent, for security purposes such as investigating abuse, to comply with applicable law, or in connection with a merger, acquisition, or sale of assets.
  • We do not transfer or sell Google user data to advertising platforms, data brokers, or information resellers, and we do not use it for creditworthiness assessment or lending purposes.
  • We do not allow humans to read Google user data, except where you have given affirmative agreement for us to view specific data, where it is necessary for security purposes or to investigate a bug, where the law requires it, or where the data is aggregated and used for internal operations. In practice this means the operator delivering your engagement views your campaign and reporting data in order to do the work, and no one else does.

What we never do with Google user data.As with LinkedIn, Google user data is walled off from the rest of our business. We do not combine it with client CRM records, prospect lists, or other data to build or enrich profiles or leads; we do not use it to identify prospects or build outbound target lists; and we do not sell it or share it with third parties for their own purposes. Data from one client's Google account is never used for another client.

Retention and deletion.We keep Google user data only as long as needed to deliver the service, and delete it on request. OAuth tokens are stored encrypted and deleted when you disconnect. You can revoke Groflo's access at any time from your Google Account permissions page, by removing our access in Google Ads, or by emailing g@groflo.ai to ask us to delete what we hold.

Where we use the Google Ads API, our use is additionally governed by the Google Ads API Terms and Conditions and Google's own privacy policy. Where those terms are more protective of the data than this policy, those terms apply.

Other platform data

The same principles apply to any other platform account a client connects, such as HubSpot or an email sending tool: we connect only with the account owner's authorization, use the access only to deliver the engagement, and keep each platform's data separate.

Client data

During a client engagement we process business contact data belonging to our clients: prospect names, business email addresses, job titles, company details, and engagement history inside our clients' CRM, outbound, and advertising systems. This data is provided to us by the client or gathered from sources the client directs us to. None of it comes from the LinkedIn Marketing APIs, and we do not enrich it with anything retrieved from those APIs. In that work the client is the controller and Groflo acts as a processor or service provider under the engagement agreement. We use that data only to deliver the engagement, never for our own marketing, and we return or delete it when the engagement ends.

How we use information

  • To respond to inquiries and schedule and hold meetings.
  • To deliver, support, and improve the services clients hire us for.
  • To operate, secure, and improve the groflo.ai website.
  • To send occasional business communications to people who asked to hear from us or who are existing clients. Every marketing email includes an unsubscribe link.
  • To meet legal, tax, accounting, and contractual obligations, and to establish or defend legal claims.

We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law.

Legal bases (EEA and UK visitors)

Where the GDPR or UK GDPR applies, we rely on: contract to provide services you requested, including booking and holding calls; legitimate interests to run and secure the website, understand aggregate traffic, and conduct B2B outreach in proportion to those interests; consent where consent is required, such as certain marketing messages, which you can withdraw at any time; and legal obligation for tax and record-keeping.

Who we share information with

We share personal information only with service providers who need it to run our business, under contracts that limit their use of it:

  • Vercel for website hosting, analytics, and speed insights.
  • Cal.com for scheduling strategy calls.
  • Google Workspace for email, calendar, and document storage.
  • Platform providers such as LinkedIn, Google Ads, and the CRM and outbound tools used in a given engagement, only as directed by the account owner.

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will note the change here.

Cookies and tracking

The groflo.ai website does not set advertising or cross-site tracking cookies, and it does not run a LinkedIn Insight Tag or a Meta Pixel. Vercel Web Analytics is cookieless. Cal.com may set cookies necessary to operate the embedded scheduler when you interact with it. Because we do not run non-essential tracking, there is no cookie banner to click through.

How long we keep information

Inquiry and booking records are kept for up to 24 months after our last contact, unless you ask us to delete them sooner. Client engagement records are kept for the life of the engagement plus the period required by our agreement and by tax law, typically seven years for financial records. Platform API tokens are deleted as soon as the connection is revoked. Aggregated analytics that cannot identify you may be kept indefinitely.

These periods do not apply to data retrieved through the LinkedIn Marketing APIs. That data is held only for the periods set out under "LinkedIn Marketing API data" above, which are shorter and which override anything in this section.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to opt out of marketing. California residents may also request the categories of information collected and disclosed, and may not be discriminated against for exercising these rights.

To exercise any of these, email g@groflo.ai. We respond within 30 days and may need to verify your identity first. You may authorize an agent to act for you. EEA and UK residents may also complain to their local supervisory authority.

International transfers

Groflo operates in the United States, and our service providers may process data in the United States and elsewhere. Where we transfer personal information out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

Security

We use encryption in transit, access controls, multi-factor authentication on business accounts, encrypted credential storage, and least-privilege access to platform APIs. No system is perfectly secure, so we cannot guarantee absolute security, but we will notify affected people and regulators of a breach where the law requires it.

Children

Groflo sells to businesses. The website and our services are not directed to anyone under 18, and we do not knowingly collect their information. If you believe a child gave us information, email us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the "last updated" date above. Material changes will be highlighted at the top of the page for at least 30 days.

Contact

Groflo
Attn: Garett McDonald
400 SW 1st Ave
Fort Lauderdale, FL 33301
United States
g@groflo.ai
groflo.ai