Privacy Policy
Last updated: August 2026
1. Controller
The controller responsible for data processing under the GDPR is:
Grow Inside LLC
30 N Gould St
Sheridan, WY 82801
USA
Email: info@grow-inside.de
Represented by: Stefanie Lackas. Offered under the brand Grow Fit Academy.
2. Data we collect
We collect the following personal data:
- Name and email address (on registration / magic link)
- Payment data (processed by Stripe; we do not store full credit card details)
- Learning progress and quiz/exam results
- Technical data (IP address, browser, device type)
3. Purpose of processing
We process data to provide the e-learning platform, process payments, improve learning content, and communicate with users.
4. Legal basis
Processing is based on Art. 6(1)(b) GDPR (performance of a contract), (c) (legal obligation), and (f) (legitimate interest in secure operations and abuse prevention).
5. Retention
We store personal data only as long as needed to perform the contract or as required by statutory retention rules (depending on document type, up to 10 years).
6. Your rights
Users have the right to access, rectification, erasure, restriction of processing, data portability, and objection. Contact info@grow-inside.de.
7. Cookies & tracking
We use cookies and similar technologies. Necessary cookies are required for operation, login, and security (Art. 6(1)(b)/(f) GDPR). Analytics and marketing cookies (e.g. Google Analytics / Google Ads tag and Meta / Facebook Pixel) are used only with your consent (Art. 6(1)(a) GDPR). Without consent these services are not loaded.
You can change or withdraw your choice anytime via “Cookie settings” in the footer. After withdrawal, future loads of the respective tags are blocked.
8. Third parties
We use, among others: Supabase (auth, database), Stripe (payments), Vercel (hosting). Additionally – only with consent – Google (analytics / ads) and Meta Platforms (Facebook Pixel) may be used. Each provider processes data under its own privacy terms and, where required, with appropriate safeguards (e.g. DPAs / Standard Contractual Clauses).
9. International transfers
The controller is based in the USA. Personal data may therefore be transferred to the USA and possibly other third countries. Where the GDPR applies, transfers only take place with an appropriate legal basis (e.g. Standard Contractual Clauses, adequacy decision, or explicit consent).
