Privacy Policy

Last updated: 8 September 2026

1. Who we are

GrowthCore Suite ("GrowthCore Suite", "we", "us" or "our") is a trading name of Marcus Johnson, a sole trader. GrowthCore Suite is the umbrella brand for our software ecosystem, which includes PresenceScan AI, ReachPilot AI and NetBizz. GrowthCore Suite is not a limited company.

2. Data controller

Marcus Johnson, trading as GrowthCore Suite, is the data controller for personal data processed through this platform.

3. Contact details

Privacy enquiries: privacy@growthcoresuite.com. General support: support@growthcoresuite.com.

4. Personal data we collect

  • Account data — email address and account identifier held in our authentication system, sign-up and last sign-in timestamps, and any role assigned to your account.
  • Enquiry / lead data — the name, email address, business details and message you submit through our forms.
  • Subscription & billing data — subscription and entitlement records, plan, status, trial state, and payment-provider references (such as customer and subscription identifiers). We do not store card numbers.
  • Usage & product activity data — pages viewed, feature and call-to-action interactions, session identifiers, device/browser information, cross-platform ecosystem activity, health scores, streaks, milestones and onboarding progress generated as you use the platform.
  • Support data — support tickets and replies, including messages forwarded from other platforms in our ecosystem.
  • Email data — send logs, delivery state, unsubscribe tokens and suppression records.
  • Notification data — in-app notifications and, if you opt in, web push subscription details for your browser/device.
  • AI-assisted content — the business and activity information used to generate summaries, forecasts and recommendations in your dashboard, together with the generated output.
  • Rights request data — the details you provide when you make a data protection request.

5. How we collect personal data

Directly from you (account creation, forms, support messages, billing), automatically as you use the platform (usage events, device and session information, storage technologies described in section 14), and from services connected to your account, including our payment provider and other GrowthCore Suite platforms you use.

6. Why we use personal data, and 7. our lawful bases

  • Creating and running your account, and giving access to the platforms you subscribe to — contract.
  • Taking payment, managing subscriptions, trials, renewals and cancellations — contract; keeping business and transaction records — legal obligation.
  • Sending service and transactional messages (sign-in, email changes, trial and billing notices, support replies) — contract.
  • Responding to enquiries submitted through our forms — legitimate interests: replying to someone who has contacted us about our services.
  • Providing dashboards, recommendations and AI-assisted summaries of your own activity — contract, and legitimate interests in improving and securing the product.
  • Keeping the platform secure, preventing abuse, and investigating faults — legitimate interests: protecting our service and our users.
  • Optional analytics via Google Analytics 4 — consent, given through our cookie banner.
  • Marketing messages and broadcasts — consent where consent is required, otherwise legitimate interests for messages to existing customers about our own similar services; you can opt out at any time.
  • Web push notifications — consent, given in your browser.
  • Handling data protection requests and complying with applicable law — legal obligation.

8. AI and automated functionality

Parts of the platform use an AI model service to generate written summaries, forecasts and recommendations. Where this happens, business and activity information from your account (for example platform activity, scores and trends) is sent to the AI provider to produce that output. Please do not enter sensitive or confidential information into free-text fields that feed these features. These outputs are there to assist you — they are guidance, and no decision with a legal or similarly significant effect on you is made solely by automated means. We do not make claims about whether the AI provider retains or trains on data; that is governed by the provider's own terms.

9. Who we share personal data with, and 10. our service providers

We share personal data with the service providers our platform actually uses, so they can perform services on our behalf:
  • Supabase — database, authentication and file storage. Receives account, subscription, usage, support and content data.
  • Lovable (hosting and platform services) — application hosting, transactional email delivery and the AI gateway used for the features above.
  • Stripe — payment processing and subscription billing. Receives your email address, payment details you enter with them, and subscription information.
  • Google Analytics 4 — optional usage analytics, loaded only with your consent.
  • Web push services — where you enable notifications, the push service operated by your browser vendor delivers the message.
We may also disclose personal data where we are required to do so by law or to establish, exercise or defend legal claims.

11. International transfers

Some of these providers are based outside the UK or may process data outside the UK (for example Stripe and Google operate globally). Where that happens, the transfer is made under the safeguards those providers put in place in their own data protection terms. We have not independently verified the specific transfer mechanism used by each provider and do not claim that all data stays in the UK. If you need details for a specific provider, contact us and we will tell you what we know.

12. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including providing the service, maintaining appropriate business and transaction records, resolving disputes, enforcing agreements and meeting applicable legal, accounting or regulatory requirements. In practice:
  • Account, subscription and usage records — kept while your account exists, and afterwards only where we still need them for records, disputes or legal reasons.
  • Enquiry and support records — kept while needed to handle your enquiry and for a reasonable period afterwards for reference and dispute handling.
  • Billing and transaction records — kept for the period required by applicable accounting and tax law.
  • Email suppression / unsubscribe records — kept for as long as needed to keep honouring your opt-out.
  • Consent records — your cookie choice is stored in your browser until you change or clear it, or until our consent version changes.
We do not currently run automatic deletion on a fixed schedule for every category of data. If you want to know what we hold about you, or want it deleted, use the options in section 17.

13. Security

We use appropriate technical and organisational measures, including encryption in transit, database row-level security, restricted administrative access, scoped service credentials, signed webhooks and audit logging of administrative actions. No online service can be guaranteed to be free from risk. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office and, where required, affected users.

14. Cookies and storage technologies

We use a small number of cookies and browser storage items — for authentication and session security, to remember your cookie choice, to identify a device for notifications, to hold a short-lived session identifier for usage measurement, and for form and interface preferences. Optional analytics and any marketing technologies load only if you allow them. Full detail and controls are in our Cookie Policy.

15. Marketing communications

We send service and transactional emails as part of running your account; these are not marketing. Separately, we may send product news or offers by email, in-app notification or web push. You can opt out at any time using the unsubscribe link in any marketing email, by turning off notifications in your browser, or by contacting us. Opting out of marketing does not stop essential service messages.

16. Your rights

Depending on the processing concerned, you have the right to ask for access to your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive certain data in a portable form, and to withdraw consent where we rely on consent. These rights do not apply in the same way to every activity — for example, we may need to keep certain billing records even after an erasure request.

17. How to exercise your rights

Use our data request form, or — if you have an account — your privacy dashboard, where you can download your data, manage cookie consent and request deletion of your account. You can also email privacy@growthcoresuite.com. When you request account deletion, we record and action the request, remove your account and associated personal data, and retain only what we still need for records, security or legal reasons. Copies may persist briefly in routine backups before they expire.

18. Complaints

If you have a concern about how we handle your personal data, please contact us first so we have the chance to put it right. You can also complain at any time to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. You do not need to contact us before approaching the ICO.

19. Children

Our platform is intended for people running or working in a business and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will look into it.

20. Changes to this policy

We may update this policy as our service or legal obligations change. We will update the date above and, where the change affects what you have consented to, ask for your consent again.