Legal
Privacy policy
Last updated September 17, 2026
This Privacy Notice for Stopa Development (“we,” “us,” or “our”) describes how and why we process personal information when you:
- Visit our website at growthrecord.app
- Sign up for a Growth Record workspace, or sign in with Google or Microsoft
- Contact us for support, or as the billing contact for a workspace’s subscription
What this notice does not cover. If your employer uses Growth Record to run performance reviews, the data your employer holds about you there — your assessments, evidence, development plans and check-ins — is processed by us on your employer’s behalf, as a data processor, under our Data Processing Agreement with them. This notice does not cover that processing; your employer's workspace administrators do, and they are your point of contact for requests about that data.
Questions or concerns? If you do not agree with this notice, please do not use our Services. If you have any questions, contact us at [email protected].
Table of contents
1. What information do we collect?
Account information. When you sign up, we collect your name, email address, and — unless you sign in with Google or Microsoft — a password. If you enable two-factor authentication or a passkey, we store the credential needed to verify it, not the underlying device secret.
Billing information. If your workspace subscribes to a paid plan, payment is handled by Stripe. We do not receive or store your card number; we hold the subscription and invoice records Stripe gives us. See Stripe’s privacy notice.
Sign-in data. We record the IP address and browser of your active sessions, so you can see and revoke them, and to detect suspicious sign-ins.
Support requests. If you email us, we keep that correspondence to answer you and to have a record of the request.
Information from Google or Microsoft. If you sign in with one of them, they share your name, email address and profile picture with us. See section 6.
We do not process sensitive personal information (such as health, religious belief, or sexual orientation data), and we do not knowingly collect information from anyone under 18.
2. How do we use your information?
- To provide the Services. To create and secure your account, run your workspace’s subscription, and operate the product.
- To communicate with you. To send invitations, review reminders, security notices (such as a new sign-in), and billing receipts. These are service messages, not marketing, and are not optional while you have an account.
- To keep the Services secure. To detect and prevent fraud, abuse, and unauthorized access.
- To understand product usage. Through Plausible, described in section 5, to see which pages and features are used so we can improve the product.
- To comply with the law. Such as tax and accounting obligations, and to respond to lawful requests from authorities.
We do not use your information for advertising, and we do not sell or share it with data brokers.
3. What legal bases do we rely on?
Stopa Development is established in Denmark, so the GDPR governs our processing wherever you are located. We rely on the following legal bases:
- Performance of a contract. To create your account, run your subscription, and provide the Services you signed up for.
- Legitimate interests. To keep the Services secure (sign-in logging, fraud prevention), and to understand product usage through cookie-free analytics, in each case balanced against your right to privacy.
- Legal obligation. To keep the records Danish tax and accounting law require, such as invoices.
- Consent. Where we ask for it specifically, which you can withdraw at any time by contacting us.
4. Who do we share your information with?
We do not sell or rent your information. We share it only with the service providers who help us run Growth Record, each bound by a data processing agreement, and only for the purpose described:
- Laravel Cloud (on Amazon Web Services, EU region) — hosting, storage and backups.
- Cloudflare — sending the service’s emails.
- Plausible — cookie-free product usage analytics, described in section 5.
- Stripe — billing, for workspaces on a paid plan.
If a workspace’s data — the reviews, evidence and development plans it holds about its people — is processed by any of the above, that use is authorised under our Data Processing Agreement with the workspace, not this notice.
We may also disclose information if required by law, or in connection with a merger, acquisition, or sale of the business, in which case we would tell you.
5. Do we use cookies and other tracking technologies?
In short: We use a small number of strictly necessary cookies to operate the Services, and a cookie-free analytics service to understand how the Services are used. We do not use cookies, tracking pixels, or similar technologies for advertising.
We use strictly necessary cookies to operate the Services, such as keeping you signed in and protecting forms against forgery. These cookies do not require consent because the Services cannot function without them.
For analytics, we use Plausible, a privacy-focused analytics service. It does not set cookies or any other persistent identifier on your device, does not track you across other websites, and does not collect or store your IP address. Because it does not track you, it does not require consent under EU law, and there is no cookie banner on this site.
We do not permit third parties to use tracking technologies on our Services for advertising, and we do not sell or share your information for cross-context behavioral advertising.
6. Signing in with Google or Microsoft
You can create an account and sign in using a Google account, or a Microsoft work or school account, instead of a password. If you choose to, the provider shares your name, email address and profile picture with us — we do not request access to your email, files, or anything beyond your basic profile.
An account created this way has no password: the provider is what lets you in, so review its own security settings too. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. How long do we keep your information?
We keep your account information for as long as your workspace exists. If a workspace’s subscription ends, we keep its data for a reasonable period in case it is reactivated, then delete it, except where we must keep records for longer — invoices, for example, are kept as long as Danish accounting law requires.
This mirrors the erasure terms in our Data Processing Agreement.
8. How do we keep your information safe?
All traffic to and from the Services is encrypted with TLS. Passwords are stored only as salted hashes, and two-factor secrets and recovery codes are stored encrypted. Access to the production environment is limited, protected by two-factor authentication, and data is stored encrypted at rest in our hosting provider’s EU region.
The full set of technical and organisational measures we apply is set out in our Data Processing Agreement, which every workspace is bound by.
No method of transmission or storage is 100% secure, so we cannot guarantee absolute security, but we design and operate the Services to keep it as safe as we reasonably can.
9. Children’s privacy
Growth Record is a workplace tool for businesses, intended for people 18 and over acting in a professional capacity. We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Your privacy rights
Wherever you are located, you can ask us to:
- give you access to, or a copy of, the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- delete your information, subject to the retention needs described above;
- restrict or object to certain processing, such as processing based on legitimate interests; and
- receive your information in a portable format.
To exercise any of these, email [email protected]. We may need to verify your identity first. We will respond within one month, as the GDPR requires.
If your request concerns data your employer holds about you in a Growth Record workspace, we will forward it to your workspace’s administrators — as the data controller for that data, they are best placed to act on it, and we assist them as our Data Processing Agreement requires.
If you are not satisfied with our response, you can complain to Datatilsynet, our supervisory authority in Denmark, or to the data protection authority in your own EU or EEA country, or in the UK, to the Information Commissioner’s Office.
11. Do-not-track signals
Some browsers send a “Do Not Track” signal. Because we do not use cookies or technologies for advertising or cross-site tracking in the first place, as described in section 5, there is nothing for such a signal to opt you out of, and we do not respond to it separately.
12. Do we make updates to this notice?
We may update this notice as our practices change. We will update the “Last updated” date above, and if a change is material, we will let workspace administrators know by email.
13. How can you contact us?
Email us at [email protected], or write to us at:
Stopa Development
Ramsøbakken 10
4621 Gadstrup
Denmark