Legal

Privacy Policy

Last updated: August 14, 2026

This Privacy Policy explains how Project GRVE (operated by GRVE LLC)(“we”, “us”, or “our”) collects, uses, shares, and protects personal information when you visit this website, submit a form, or use our platform and services. It also explains the choices and rights available to you, including rights under the Indiana Consumer Data Protection Act (ICDPA).

When we build and operate websites or lead systems for our business clients, we generally process the personal information collected through those systems on the client’s behalf and under their instructions. Those websites carry their own privacy policies; this policy covers our own website and platform.

Information we collect

Information you give us

  • Contact details: name, email address, and phone number when you submit our Get Started form or otherwise contact us.
  • Business details: company name, trade or industry, and anything you include in a message to us.
  • Account information: if you become a client and receive platform access, your login email and role.

Information collected automatically

  • IP address: used to rate-limit form submissions and prevent abuse.
  • Server logs: standard technical records of requests to our site, kept on a short rolling window by our hosting provider.
  • Usage analytics: we use Google Analytics 4 to measure how many people visit, which pages they read, and roughly where they arrived from. It sets cookies containing a random identifier for your browser. We have not enabled Google’s advertising-personalization or remarketing features.
  • A theme preference stored on your device: kept in your browser’s local storage and never sent to us. For the full list of cookies and third-party tools this site loads, see our Cookie Policy.

Information we collect from other sources

  • Publicly listed business information: to find contractors who may be a fit for our service, we collect listing details from public sources such as business directories and companies’ own websites. This includes the company name, trade, address, phone, and website, and may include an owner or manager’s name and their work email address where the business publishes it — including a personal-format address such as a first name at the company domain. We record where we found it and how confident we are that it is correct.
  • What we do with it, and how to stop it: we use it only to decide whether to introduce ourselves, and to send that introduction. We do not sell it or share it with anyone else. Every email we send includes an unsubscribe link. If you unsubscribe or reply asking us to stop, that decision is permanent — we keep a record of it precisely so a later refresh of our prospect list cannot start contacting you again. You can also ask us to delete your listing entirely using the contact details below.

Information generated by our systems

  • AI-assisted lead notes and scores: when you submit an inquiry, we may use an AI service to help us prioritize and summarize it (for example, a fit score and a short summary). This is used only to decide how quickly and how best to follow up with you. It does not produce legal or similarly significant effects about you, and a person reviews inquiries before any business decision is made.

How we use information

  • Respond to your inquiry and communicate with you.
  • Provide, operate, and improve our website and platform.
  • Prioritize and qualify inbound inquiries (see above).
  • Protect against spam, abuse, and security threats.
  • Comply with legal obligations and enforce agreements.

We do not sell personal information, and we do not use your personal information for targeted advertising or profiling that produces legal or similarly significant effects.

Who we share information with

We share personal information only with service providers that help us run the business, under contracts that limit how they may use it:

  • Netlify: website hosting and delivery.
  • Supabase: our database, where inquiries and platform data are stored.
  • Resend: email delivery (for example, notifying us of your inquiry).
  • Anthropic: AI processing used for inquiry qualification.
  • Stripe: payment processing, if you become a paying client. We never see or store full card numbers.
  • Twilio: SMS and call features, where a client has enabled them.
  • Google: website analytics for this site; for clients, the Analytics, Search Console, Business Profile, and advertising data we report on from the client’s own Google accounts; Google Calendar, where a client connects it, to write booked appointments including the customer name and contact details; and Google Sheets and Drive, which we use as our own internal working records for bookkeeping and for the prospect list described above.
  • Cloudflare: bot and spam protection on our forms.
  • Cal.com: scheduling, if you book a call with us.
  • n8n: the automation service that runs our scheduled workflows.
  • SE Ranking: search ranking and competitor tracking for clients. It receives website addresses and keywords, not personal information.
  • Meta: for clients who run Facebook or Instagram ads, we read that campaign’s performance figures. This is spend and results data, not information about individual people.
  • GitHub: our scheduled jobs run on GitHub’s infrastructure, so information passes through it while those jobs run.
  • DocuSign: electronic signature, if you sign an agreement with us.

This list is current as of the date at the top of this page. If we add a provider that handles personal information, we update this list and, for clients, give notice under the client agreement.

We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a business transfer (such as a merger or sale), in which case this policy continues to apply to information collected before the transfer.

SMS consent: SMS opt-in data and consent are not shared with third parties for their marketing purposes.

How long we keep information

  • Inquiries: up to 24 months after our last interaction with you, unless you ask us to delete them sooner.
  • Client platform data: for the duration of the engagement, then deleted from our active systems within 90 days of termination, or within 30 days if the client asks us to do it sooner. Routine encrypted backups are not edited in place; they age out on their own cycle, within 180 days.
  • SMS and call records (where used): typically 90 days.
  • Server logs: short rolling windows set by our hosting provider.

We may keep information longer where required by law (for example, tax and accounting records) or to resolve disputes.

How we protect information

We use industry-standard safeguards: encryption in transit (TLS) and at rest, role-based access controls, database-level row security that isolates each client’s data, and verification of inbound webhooks. No system is perfectly secure, but we design for least privilege and defense in depth.

Your privacy rights

If you are an Indiana resident, the ICDPA gives you the right to:

  • Know and access: confirm whether we process your personal data and obtain a copy of it in a portable format.
  • Correct: inaccuracies in your personal data.
  • Delete: personal data you provided or that we obtained about you.
  • Opt out: of the sale of personal data, targeted advertising, and certain profiling. (We do none of these today.)

To exercise any right, email michael@projectgrve.com with your request. We will verify the request using the email address associated with your information, respond within 45 days (extendable once by 45 days with notice), and will not discriminate against you for exercising your rights.

Appeals: if we decline a request, you may appeal by replying to our decision; we will respond to appeals within 60 days. If your appeal is denied, you may contact the Indiana Attorney General.

Residents of other states may have similar rights under their own laws; we honor the same process for any verified request.

Children

Our website and services are for businesses and are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We will update this policy as our services evolve and will revise the “Last updated” date above. Material changes will be noted on this page.

Contact us

Privacy questions or requests: michael@projectgrve.com. Project GRVE (operated by GRVE LLC) is based in Indianapolis, Indiana, USA.