Privacy Policy
Effective Date: January 2025
Last Updated: January 2025
1. Introduction
HookedGrowth Pty Ltd (ACN 668 898 191) (“HookedGrowth”, “we”, “our”, or “us”) is committed to protecting your privacy and handling your personal information responsibly.
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the HookedGrowth platform, website, and related services (the “Service”).
By using the Service, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.
Our Contact Details:
HookedGrowth Pty Ltd
Suite 110 / Level 1
55 Collins Street
Melbourne, VIC 3000
Australia
Email: [email protected]
2. Definitions
In this Privacy Policy:
- “Personal Information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. This has the meaning given in the Privacy Act 1988 (Cth).
- “Sensitive Information” means personal information about racial or ethnic origin, political opinions, religious beliefs, health information, sexual orientation, criminal record, or biometric data.
- “Service” means the HookedGrowth platform, website, applications, and all related features.
- “Organisation” means a business entity or team using the Service.
- “User” means any individual who accesses or uses the Service.
3. Information We Collect
3.1 Account Information
When you create an account or use the Service, we collect:
- Identity Information: Name, email address, username, profile photo
- Professional Information: Job title, department/function, years of experience
- Contact Information: Email address, phone number (optional)
- Authentication Data: Login credentials (stored securely by our authentication provider)
3.2 Organisation Information
If you create or join an Organisation, we collect:
- Organisation name, logo, and branding assets
- Team member information and roles
- Business profile data you provide
- Other organisational information you provide
3.3 Usage Information
We automatically collect information about how you use the Service:
- Activity Data: Features used, actions taken, content created
- AI Interaction Data: Prompts submitted, outputs generated, feature usage
- Session Data: Login times, session duration, navigation patterns
- Performance Data: Error logs, load times, service performance metrics
3.4 Technical Information
We collect technical data from your devices:
- Device Information: Device type, operating system, browser type and version
- Network Information: IP address, approximate location (country/region)
- Identifiers: Device identifiers, session identifiers
3.5 Payment Information
If you subscribe to a paid plan, we collect:
- Billing name and address
- Payment method details (processed and stored securely by Stripe)
Note: We do not store credit card numbers on our servers. Payment processing is handled by Stripe.
3.6 Communications
We may collect information from your communications with us:
- Support requests and inquiries
- Feedback and survey responses
- Marketing preferences and consent
4. How We Collect Information
4.1 Information You Provide
We collect information that you directly provide when you:
- Create an account or update your profile
- Set up or manage an Organisation
- Use Service features and create content
- Make payments or manage subscriptions
- Contact us for support or inquiries
- Respond to surveys or provide feedback
4.2 Information Collected Automatically
We automatically collect certain information when you use the Service through:
- Cookies and Similar Technologies: See Section 9 for details
- Analytics Tools: Usage tracking and performance monitoring
- Server Logs: Technical data about your interactions with our servers
4.3 Information from Third Parties
We may receive information from:
- Authentication Providers: When you sign in using social login
- Payment Processors: Transaction and billing information from Stripe
- Marketing Partners: Information from referral or marketing sources (with your consent)
5. How We Use Your Information
5.1 Providing the Service
We use your information to:
- Create and manage your account
- Provide access to Service features
- Process AI requests and generate outputs
- Manage subscriptions and process payments
- Provide customer support
- Send service-related notifications
5.2 Improving the Service
We use your information to:
- Analyse usage patterns and trends
- Identify and fix bugs and issues
- Develop new features and improvements
- Conduct research and analytics
- Create anonymised, aggregated insights
5.3 Communications
We use your information to:
- Send important service updates and announcements
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
- Notify you of changes to our terms or policies
5.4 Security and Compliance
We use your information to:
- Protect against fraud, abuse, and security threats
- Verify identity and authenticate users
- Comply with legal obligations
- Enforce our Terms of Use
6. AI and Machine Learning
6.1 How We Use AI
The Service incorporates artificial intelligence to provide features such as:
- Growth Assistant for AI Chat
- Brand voice and content generation
- Image generation and recommendations
- Market analysis and insights
- Other features that require AI input
6.2 AI Service Providers
We use the following third-party AI providers to power our features:
| Provider | Purpose |
|---|---|
| OpenAI | Language models for content and analysis |
| Anthropic | Language models for content and analysis |
| Google AI (Gemini) | Language models and multimodal AI |
| DeepSeek | Language models for specialised tasks |
| xAI (Grok) | Language models for analysis |
6.3 Data Sent to AI Providers
When you use AI features, we may send to our AI providers:
- Your prompts and inputs
- Relevant context from your Organisation data
- Metadata necessary for processing
6.4 AI Training Policy
We do not use your data to train AI models.
Your data is only sent to AI providers for real-time processing to deliver the features you request. We do not contribute your data to training datasets for any AI models.
6.5 AI Provider Terms
Our AI providers have their own privacy policies and terms. While we select providers with strong privacy practices, please be aware that your data is processed according to their policies when using AI features.
7. Information Sharing and Disclosure
7.1 Service Providers
We share your information with trusted service providers who help us operate the Service:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | User authentication | Email, name, profile data |
| Stripe | Payment processing | Billing and payment information |
| Convex | Database hosting | All Service data (encrypted) |
| PostHog | Product analytics | Usage data, anonymised interactions |
| HubSpot | Customer relationship management | Contact and organisation information |
| Loops | Transactional email | Email address, name |
| Axiom | System logging | Anonymised system logs |
| Cloudflare | CDN, security, AI gateway | Request data, AI prompts |
| Unsplash | Image library | Search queries |
Our service providers are contractually obligated to protect your information and use it only for the purposes we specify.
7.2 Within Your Organisation
If you are part of an Organisation:
- Organisation administrators can view and manage user accounts
- Content created within the Organisation is accessible to authorised members
- Usage and billing information may be visible to administrators
7.3 Legal Requirements
We may disclose your information if required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from government authorities
- Protect our rights, privacy, safety, or property
- Investigate or prevent fraud, security issues, or violations
7.4 Business Transfers
If HookedGrowth is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
7.5 With Your Consent
We may share your information in other circumstances with your explicit consent.
7.6 No Sale of Personal Information
We do not sell your personal information to third parties.
8. Third-Party Services
8.1 Third-Party Integrations
The Service may integrate with third-party services that you choose to connect. When you connect a third-party service:
- You may be subject to that service’s terms and privacy policy
- We may receive information from that service
- We may share information with that service as necessary for the integration
8.2 Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to review their privacy policies.
9. Cookies and Tracking Technologies
9.1 What We Use
We use the following technologies:
- Cookies: Small text files stored on your device
- Local Storage: Data stored in your browser
- Analytics Tools: Usage tracking and performance monitoring
9.2 Types of Cookies
| Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, basic functionality | Session/Persistent |
| Functional | User preferences, country detection | Up to 30 days |
| Analytics | Usage patterns, performance metrics | Up to 2 years |
9.3 Session Recording
We use PostHog for product analytics, which may include session recording. Session recordings help us understand how users interact with the Service to improve the experience.
Privacy Protections:
- Input fields containing passwords, emails, and phone numbers are automatically masked
- Recordings are used only for product improvement
- Recordings are not shared with third parties except our analytics provider
9.4 Managing Cookies
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Service functionality.
10. Data Storage and Security
10.1 Where We Store Data
Your data is stored on secure servers provided by our infrastructure partners:
- Primary Database: Convex (cloud infrastructure)
- Authentication: Clerk (US-based)
- Payments: Stripe (US-based)
- Analytics: PostHog (cloud infrastructure)
10.2 Security Measures
We implement industry-standard security measures, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- Employee access restrictions and training
10.3 Your Responsibilities
You are responsible for:
- Keeping your login credentials secure
- Logging out of shared devices
- Notifying us of any suspected security breaches
10.4 Security Incidents
If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.
11. International Data Transfers
11.1 Cross-Border Transfers
Your information may be transferred to and processed in countries other than Australia, including the United States, where our service providers are located.
11.2 Safeguards
When we transfer data internationally, we implement appropriate safeguards, including:
- Contractual protections with service providers
- Data processing agreements that ensure adequate protection
- Compliance with applicable data transfer requirements
11.3 Disclosure
By using the Service, you acknowledge that your information may be transferred to and processed in countries with different privacy laws than your country of residence.
12. Data Retention
12.1 Retention Periods
We retain your personal information for as long as:
- Your account remains active
- Necessary to provide the Service
- Required for our legitimate business purposes
- Required by law or regulation
12.2 After Account Closure
When your account is closed:
- We will delete or anonymise your personal information within a reasonable period
- Some information may be retained for legal, compliance, or legitimate business purposes
- Anonymised data may be retained indefinitely for analytics
12.3 Backup and Archives
Information in backups and archives may be retained for longer periods for disaster recovery and legal compliance purposes.
13. Your Rights
13.1 Access and Correction
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Receive a copy of your personal information
13.2 Deletion
You may request deletion of your personal information. We will comply with your request unless we have a legal obligation or legitimate reason to retain it.
13.3 Data Portability
Where technically feasible, you may request your data in a portable format.
13.4 Marketing Opt-Out
You can opt out of marketing communications at any time by:
- Clicking the unsubscribe link in our emails
- Updating your preferences in your account settings
- Contacting us at [email protected]
13.5 Account Deletion
You can request account deletion by contacting us. Upon deletion:
- Your account will be deactivated
- Your personal information will be deleted or anonymised
- Content within Organisations may be retained by the Organisation
13.6 Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
14. Australian Privacy Principles
14.1 Our Commitment
We are committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
14.2 APP Compliance
In accordance with the APPs:
- APP 1 (Open and transparent management): We have this Privacy Policy describing our practices
- APP 2 (Anonymity and pseudonymity): Where practicable, you may deal with us anonymously
- APP 3 (Collection): We only collect personal information that is reasonably necessary
- APP 4 (Unsolicited information): We destroy or de-identify unsolicited information we cannot lawfully retain
- APP 5 (Notification): We notify you about collection at or before the time of collection
- APP 6 (Use and disclosure): We only use information for the purposes described in this policy
- APP 7 (Direct marketing): We only send marketing with your consent and provide opt-out options
- APP 8 (Cross-border disclosure): We ensure adequate protections for overseas transfers
- APP 9 (Government identifiers): We do not adopt government identifiers as our own
- APP 10 (Quality): We take reasonable steps to ensure information is accurate and up-to-date
- APP 11 (Security): We take reasonable steps to protect information from misuse and loss
- APP 12 (Access): You can access your personal information upon request
- APP 13 (Correction): You can request correction of your personal information
14.3 Sensitive Information
We do not intentionally collect sensitive information unless:
- You provide it voluntarily
- It is necessary for the Service
- We have your explicit consent
14.4 Complaints
If you believe we have breached the APPs, you may lodge a complaint with us. We will investigate and respond within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
15. GDPR Compliance (EU/UK Users)
15.1 Applicability
If you are located in the European Union (EU) or United Kingdom (UK), the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data.
15.2 Legal Basis for Processing
We process your personal data based on:
- Contract Performance: Processing necessary to provide the Service
- Legitimate Interests: Processing for our legitimate business interests (such as improving the Service)
- Consent: Processing based on your explicit consent (such as marketing)
- Legal Obligation: Processing required by law
15.3 Your GDPR Rights
In addition to the rights in Section 13, EU/UK users have the right to:
- Restrict Processing: Request restriction of processing in certain circumstances
- Object to Processing: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time (without affecting lawfulness of prior processing)
- Lodge a Complaint: Lodge a complaint with a supervisory authority
15.4 Data Protection Authority
You may lodge a complaint with your local data protection authority:
- EU: Your national data protection authority
- UK: The Information Commissioner’s Office (ICO)
15.5 Data Transfers
When we transfer your data outside the EU/UK, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
16. Children’s Privacy
16.1 Age Restriction
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
16.2 Parental Notice
If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
16.3 Reporting
If you believe we have collected information from a child under 18, please contact us immediately at [email protected].
17. Changes to This Policy
17.1 Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
17.2 Notification
We will notify you of material changes by:
- Posting the updated policy on the Service
- Sending notice to your registered email address
- Displaying a prominent notice within the Service
17.3 Review
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
17.4 Version History
The “Last Updated” date at the top of this policy indicates when it was last revised.
18. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
HookedGrowth Pty Ltd
Suite 110 / Level 1
55 Collins Street
Melbourne, VIC 3000
Australia
Email: [email protected]
Website: https://www.hookedgrowth.com
We will respond to your inquiry within a reasonable timeframe.
This Privacy Policy was last updated in January 2025.