π Privacy Policy
Your Privacy Matters to Us
Learn how Grove Web Digital collects, uses, protects, and manages your personal information when you visit our website or work with our team.
This Privacy Policy is provided for general informational purposes for visitors and clients of Grove Web Digital. Laws vary by jurisdiction; have qualified legal counsel review this policy before relying on it for compliance in your region.
Introduction
Grove Web Digital ("Grove Web Digital", "we", "us", or "our"), founded by Ahoshan Hasan Ratul and led by Chief Executive Officer Mohan Khan, provides website development, digital marketing, SEO, AI engineering, and related professional services. This Privacy Policy describes how we handle personal information when you visit our website, submit inquiries, subscribe to communications, book consultations, or engage us for services.
By using our website or providing information to us, you acknowledge this policy. Where local law requires consent for specific processing activities, we will request it separately. If you do not agree with this policy, please do not use our website or submit personal information to us.
Information We Collect
We collect information that you provide directly, that is generated through your use of our website, and that we receive from service providers acting on our behalf. The categories below are illustrative and may vary depending on how you interact with us.
Personal Information
Personal information may include your name, email address, phone number, job title, and any other identifiers you choose to provide when contacting us, booking a consultation, subscribing to a newsletter, or completing forms on our website.
Business Information
When you inquire about services, we may collect company name, industry, website URL, project scope, budget range, timeline preferences, and descriptions of business goals. This helps us assess fit and prepare appropriate recommendations.
Technical Information
When you access our website, we may automatically collect device and usage information such as browser type, operating system, referring URLs, pages viewed, and approximate location derived from IP address. This data supports security, performance, and analytics.
Cookies
We use cookies and similar technologies to operate the site, remember preferences (such as theme selection), andβwhere permittedβunderstand usage patterns. For more detail, see the Cookies Policy and Cookie Notice below.
Analytics
Where enabled, analytics tools help us understand aggregated traffic, navigation paths, and engagement. Analytics data is generally used in de-identified or aggregated form to improve content, usability, and marketing effectiveness.
Log Files
Our servers and infrastructure providers may record log files containing IP addresses, timestamps, request paths, status codes, and user agent strings. Logs are retained for security monitoring, troubleshooting, and abuse prevention for a limited period.
How We Use Information
We use personal information for legitimate business purposes, including:
- Responding to contact forms, quote requests, and consultation bookings
- Delivering contracted services and managing client relationships
- Operating, maintaining, and improving our website and internal systems
- Securing our platform, detecting fraud, and preventing abuse
- Complying with legal obligations and enforcing our terms
- Sending service-related communications and, where permitted, marketing you have opted into
- Preparing aggregated analytics to understand audience needs and site performance
We do not use personal information in ways that are incompatible with the purposes described at the time of collection without providing notice or obtaining consent where required.
Legal Basis for Processing
Where applicable law requires a legal basisβsuch as the UK GDPR or EU GDPRβwe may rely on one or more of the following:
- Consent β for optional cookies, newsletters, or marketing where consent is required
- Contract β to respond to pre-contractual requests and perform services you engage us to deliver
- Legitimate interests β to secure our website, improve services, and communicate with prospects in a proportionate way
- Legal obligation β to comply with applicable laws, regulations, or valid legal requests
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Retention periods depend on the type of data and our relationship with you.
- Inquiry records β typically retained while an active discussion is ongoing and for a reasonable period afterward for follow-up
- Client project data β governed by contract terms and applicable professional obligations
- Marketing subscriptions β until you unsubscribe or request deletion, subject to suppression records
- Server logs β retained for a limited window for security and diagnostics
When data is no longer needed, we delete or anonymize it using reasonable technical and organizational measures.
Third-Party Services
We use trusted third-party providers to operate our website and business. These providers process data on our behalf or as independent controllers depending on the service. We encourage you to review their privacy policies.
Google Analytics
Where implemented, Google Analytics may help us understand website traffic and usage in aggregated form. Google may process technical and usage data according to its own policies. You may use browser controls or industry opt-out tools where available.
Cloudflare
We may use Cloudflare or similar content delivery and security services to improve performance, mitigate attacks, and protect our infrastructure. These services may process IP addresses and request metadata.
Payment Providers
If you make payments for services, payment processors may collect billing details, transaction identifiers, and fraud-prevention data directly. Grove Web Digital does not store full payment card numbers on its own servers when processing is handled by a certified provider.
Email Services
We use email and transactional messaging providers to deliver inquiry confirmations, consultation notifications, and service communications. These providers process recipient addresses, message content, and delivery metadata.
Security Measures
We implement reasonable technical and organizational safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Measures are proportionate to the nature of the data and our business operations.
- HTTPS encryption for data in transit where supported
- Role-based access controls for internal systems
- Secure hosting and storage practices with reputable providers
- Monitoring for suspicious activity and routine security reviews
No online service can guarantee absolute security. If you believe your interaction with us is no longer secure, please contact us promptly.
Data Security Practices
Encryption
We use industry-standard encryption for data transmitted between your browser and our website where TLS/HTTPS is enabled.
Access Control
Access to personal information is limited to personnel and contractors who need it for their role and are bound by confidentiality obligations.
Secure Storage
Data is stored on infrastructure with physical and logical safeguards provided by established cloud and hosting partners.
Monitoring
We monitor systems for anomalies, failed login patterns, and other indicators that may suggest unauthorized activity.
Your Privacy Rights
Depending on your location, you may have rights regarding your personal information. We will respond to valid requests in accordance with applicable law and may need to verify your identity before processing certain requests.
GDPR Rights (EEA, UK, and similar jurisdictions)
Where the GDPR or UK GDPR applies, you may have the right to access, rectify, erase, restrict processing, object to processing, and data portability in certain circumstances. You may also withdraw consent where processing is consent-based, without affecting the lawfulness of prior processing.
You may lodge a complaint with your local supervisory authority if you believe our processing violates applicable law.
CCPA / CPRA Rights (California residents)
California residents may have rights to know categories of personal information collected, request deletion subject to exceptions, correct inaccurate information, and opt out of certain sharing for cross-context behavioral advertising where applicable. Grove Web Digital does not sell personal information as defined under the CCPA.
User Rights Summary
- Access β request confirmation of whether we process your personal information and obtain a copy where applicable
- Correction β request correction of inaccurate or incomplete personal information
- Deletion β request deletion of personal information, subject to legal and contractual exceptions
- Export β request a portable copy of certain data you provided, where technically feasible
- Withdraw consent β withdraw consent for processing that relies on consent, where applicable
To exercise these rights, contact us using the details in the Contact Information section. We may need additional information to verify your request.
International Data Transfers
Grove Web Digital may process and store information in countries other than the country where you reside, including where our service providers maintain infrastructure. When we transfer personal information internationally, we take steps designed to provide appropriate safeguards consistent with applicable law, such as standard contractual clauses or equivalent mechanisms where required.
Children's Privacy
Our website and services are directed to businesses and adults. We do not knowingly collect personal information from children under 16 (or the age defined by local law). If you believe a child has provided personal information to us, please contact us and we will take reasonable steps to delete such information.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide additional notice. Continued use of the website after changes become effective constitutes acknowledgment of the updated policy, subject to applicable law.
Contact Information
For privacy-related questions, requests, or complaints, contact Grove Web Digital:
Privacy contact
Grove Web Digital β Privacy Team
Email: [email protected]
Privacy FAQ
What personal data does Grove Web Digital collect?
We may collect contact details (name, email, phone), business information you provide in forms, project inquiry content, and technical data such as IP address, browser type, and usage logs when you visit our website or use our services.
Does Grove Web Digital sell personal information?
No. Grove Web Digital does not sell your personal information. We use data to respond to inquiries, deliver services, secure our platform, and improve our website as described in this policy.
How can I request access to my data?
Contact us using the privacy contact details on this page. We will verify your request and respond within a reasonable timeframe, subject to applicable law and the nature of the request.
How long does Grove Web Digital keep my information?
We retain personal data only as long as necessary for the purposes described in this policy, including responding to inquiries, fulfilling contracts, meeting legal obligations, and resolving disputes. Retention periods vary by data type.
Does Grove Web Digital use cookies?
Yes. We use necessary cookies for core functionality and security. Analytics, marketing, and preference cookies may be used where applicable and, where required, only with your consent. See our Cookie Notice and Cookies Policy for details.
Is my data transferred internationally?
Grove Web Digital may process data in countries other than your own when we or our service providers operate globally. Where required, we implement appropriate safeguards for cross-border transfers.
How does Grove Web Digital protect personal data?
We apply technical and organizational measures including encryption in transit, access controls, secure storage practices, and monitoring. No method of transmission or storage is completely secure, but we work to protect data responsibly.
Can I opt out of marketing communications?
Yes. If you receive marketing emails from us, you may unsubscribe using the link in the message or contact us directly. Transactional messages related to active inquiries or services may still be sent where necessary.
Does this policy apply to client project data?
This policy primarily describes our website and general business operations. Specific client engagements may be governed by separate agreements, statements of work, or data processing terms that define roles and responsibilities.
Who should I contact about privacy concerns?
Use the privacy contact information at the bottom of this page. For general inquiries, you may also visit our Contact page or FAQ Center.