Effective date: July 19, 2026 Last updated: July 19, 2026
In short
SimpleGrowHQ uses personal and business data to provide and secure its wireless retail sales platform. Customers control their reps’ operational data; SimpleGrowHQ processes it for them. We do not sell personal information or use it for cross-context behavioral advertising.
- Product
- SimpleGrowHQ
- Founder / operator
- Ashkan Alasvand
- Privacy and legal contact
- privacy@simplegrowhq.com
1. Who we are and our role
SimpleGrowHQ is a United States-focused B2B software service for commission-based telecom and wireless retail teams. For subscriber account, billing, website, and direct-support information, SimpleGrowHQ acts as a business or data controller. For rep, sales, RGU, goal, location, commission, and other operational data a Customer supplies, the Customer is the controller and SimpleGrowHQ processes that data on the Customer’s documented instructions.
If you are a sales representative, direct privacy requests about employer-provided data to your employer. We will assist the Customer with an appropriate response.
2. Information we collect
- Account data: name, work email, role, company name, and authentication information. Passwords are hashed by the authentication provider.
- Customer operational data: rep names, sales records, RGU counts, team and location assignments, goals, commission rates, and commission amounts.
- Billing data: Stripe customer reference, plan, and subscription status. SimpleGrowHQ does not store full payment-card numbers.
- Technical data: IP address, browser and device information, logs, security events, and authentication tokens needed to operate and protect the Service.
- AI inputs: prompts and files submitted to the AI Assistant or Smart Import, including spreadsheets, PDFs, Word documents, and descriptions supplied for extraction or analysis.
The public leaderboard displays rank, name, RGUs, and goal percentage. It does not display commission dollar amounts. We do not intentionally collect special-category data. Employment-performance data is treated as sensitive and access-controlled.
3. How we collect information
We receive information directly from Customers and users, automatically from browsers and devices, from a rep’s employer or account administrator, and from service providers that support authentication, billing, hosting, security, email, and AI functions.
4. How and why we use information
| Purpose | Examples | GDPR/UK basis, if applicable |
|---|---|---|
| Provide the Service | Accounts, dashboards, imports, reports, goals, commissions, and support | Contract; legitimate interests |
| Authenticate and secure | Login, access control, fraud prevention, rate limits, and logs | Contract; legitimate interests; legal obligation |
| Billing | Subscriptions, payments, taxes, and accounting records | Contract; legal obligation |
| Communicate | Service notices, support replies, and material policy changes | Contract; legitimate interests; consent where required |
| Improve the Service | Troubleshooting, reliability, and aggregated or de-identified analysis | Legitimate interests; consent where required |
5. AI Assistant and Smart Import
The AI Assistant and Smart Import transmit submitted content to Anthropic’s Claude API to generate the requested result. Customers must have the right to upload and process that content. AI output can be inaccurate and must be reviewed by a person before use. Commission and payroll figures require independent verification. Anthropic states that commercial/API inputs are not used for model training by default unless a customer opts in or provides feedback. See Anthropic’s current commercial privacy terms for details.
6. Service providers and disclosures
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, row-level security, and application-data hosting |
| Cloudflare | Edge Workers, routing, proxying, security, KV, and rate limiting |
| Hostinger | Website and application hosting |
| Stripe | Payment processing and subscription billing; Stripe handles payment-card data under its own terms |
| Anthropic (Claude API) | AI Assistant and Smart Import processing |
| Titan Email and Resend | Transactional and notification email |
| Google Analytics / Google Site Kit | Marketing-site measurement, subject to applicable consent requirements |
We may also disclose information when required by law, to protect rights and safety, or in connection with a merger, financing, acquisition, or sale of assets. We may update subprocessors and will provide reasonable notice of a material change by email, in-product notice, or an update to this page.
SimpleGrowHQ does not sell personal information and does not use personal information for cross-context behavioral advertising.
7. International transfers
International-transfer terms apply when legally required. If EU/UK data is processed outside the applicable region, SimpleGrowHQ and its Customers will use an available transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or the UK Addendum, as applicable. Representative details will be published if legally required.
8. Retention and deletion
Active-account data is retained for the subscription term. After cancellation, Customer data will be available for export for the period available under the applicable plan or agreement and deleted within the period established by the applicable retention policy, unless law, security, dispute resolution, or accounting duties require limited records to be retained longer. Billing and transaction records may be kept for the period required by tax and accounting law.
9. Security practices
SimpleGrowHQ uses company-scoped row-level security, authentication, MFA for privileged actions, HTTPS/TLS in transit, provider-managed encryption at rest, secret storage for privileged server keys, least-privilege operator access, and API/AI rate limiting. No security program eliminates all risk. SimpleGrowHQ does not claim SOC 2, ISO 27001, HIPAA, or PCI-DSS certification. Stripe’s own compliance status does not make SimpleGrowHQ certified.
10. Your privacy rights
Depending on location and applicable law, people may have rights to access, know, correct, delete, restrict, or receive a portable copy of personal data; object to processing; withdraw consent; and complain to a regulator. California residents may also have rights under the CCPA/CPRA to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory service. We do not sell or share personal information for cross-context behavioral advertising.
Reps should normally submit requests through their employer. Account holders may use the Contact Us page while the dedicated privacy email remains privacy@simplegrowhq.com. We may verify identity and authority before acting.
11. Children
The Service is for business use and is not directed to children under 18. We do not knowingly collect personal information from children.
12. Third-party links
Third-party websites and services have their own privacy practices. Review their notices before providing information.
13. Changes and notice
We may revise this Policy as the Service or law changes. We will update the date above and provide additional notice for material changes when appropriate.
14. Contact
Privacy and legal inquiries: privacy@simplegrowhq.com. You may also use our Contact Us page.
