About this policy
This Privacy Policy explains how Garage Growth Labs collects, uses, shares, and protects information about you when you visit our website, fill in a form, sign up for an account, buy a service, or otherwise interact with us.
It applies to all four of our operating regions β US, UK, Canada, and Australia β and we've called out region-specific rights where they differ.
Who's responsible (data controller)
The "data controller" (the entity responsible for your data) is the Garage Growth Labs entity in your country. The header at the top of this page shows the entity for your current region. For specific data subject requests, contact hello@garagegrowthlab.com and we'll route you to the right entity.
What we collect
Information you give us
- Contact details β your name, email, phone, business name, and the content of any message you send us.
- Project information β the kickoff brief, assets you upload (logo, photos, copy), domain and platform credentials you share for project work, and any feedback you submit.
- Account details β if you create a dashboard account, the data Clerk stores on our behalf (email, name, hashed password, optional avatar).
- Billing information β handled by Stripe. We don't store full card numbers; we receive a token plus the last four digits, card brand, and billing region.
Information we collect automatically
- Site usage β pages visited, time on page, referrer, screen size, browser, approximate location (country / region only) via Google Analytics 4 and optionally PostHog.
- Cookies β see Β§5 below.
- Server logs β IP address, request timestamps, user agent. We use these for security, debugging, and abuse prevention.
Information from third parties
- Ad platforms β when you click an ad of ours, the ad network may pass us a click identifier so we can attribute the conversion.
Why we collect it (lawful bases)
Under GDPR (UK + applicable to EU traffic) and equivalent regimes, we need a lawful basis for each use. Ours are:
- Contract performance β to deliver the services you bought from us (build your site, run your retainer, host your account).
- Legitimate interests β to operate, secure, and improve the studio; understand which marketing channels work; prevent fraud.
- Consent β for non-essential cookies, marketing email, and any optional features that require explicit opt-in.
- Legal obligation β for tax records, accounting, and responding to valid government requests.
Where we rely on consent (e.g., marketing email), you can withdraw it any time via the unsubscribe link in any email, or by emailing us.
International transfers
Because we operate in four countries and use global vendors, your data may be processed outside your home country. Where it leaves the UK or EU, we rely on Standard Contractual Clauses (SCCs) or equivalent approved mechanisms.
How long we keep it
- Project files and account data β for the life of your account, plus up to 24 months after closure (so we can restore on request).
- Billing and tax records β 7 years (or as required by local tax law).
- Analytics β 14 months by default.
- Server logs β 90 days.
- Marketing email lists β until you unsubscribe.
You can request earlier deletion at any time, subject to legal retention requirements.
Security
We use industry-standard security: TLS everywhere, hashed passwords (via Clerk), least- privilege access controls, encrypted backups, and quarterly security reviews. Payments go through Stripe, which is PCI-DSS Level 1 certified β we never see your full card number.
No system is bulletproof. If we ever experience a breach affecting your data, we'll notify you and the relevant regulator without undue delay, in line with our legal obligations.
Your rights
Wherever you live, you have the right to:
- Access the personal data we hold about you;
- Correct data that's inaccurate or out of date;
- Delete data, subject to retention requirements;
- Export your data in a portable format;
- Object to certain processing (notably marketing); and
- Withdraw consent at any time for processing based on consent.
UK / EU residents (GDPR / UK GDPR): You can complain to the Information Commissioner's Office (ICO) in the UK or your local supervisory authority in the EU.
California residents (CCPA / CPRA): You have additional rights to know, delete, correct, opt out of "sale" or "sharing" (we don't sell), and limit use of sensitive personal information.
Canada residents (PIPEDA / provincial laws): You can complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.
Australia residents (Privacy Act 1988): You can complain to the Office of the Australian Information Commissioner (OAIC).
To exercise any right, email hello@garagegrowthlab.com. We'll respond within 30 days (and free of charge, except for clearly excessive or repeated requests).
Children
Our services are not directed at children. We don't knowingly collect personal data from anyone under 16. If you believe we have, contact us and we'll delete it.
Changes to this policy
We may update this policy from time to time. The "Last reviewed" date at the top reflects the most recent change. For material changes, we'll email retainer clients and show a notice at the top of this page for at least 30 days.
How to contact us
Privacy questions and data-subject requests: hello@garagegrowthlab.com (subject line: "Privacy request"). We aim to respond within one business day and resolve within 30.