Privacy Policy
Last updated: August 14, 2026
This policy explains what information Capital Growth Media collects through this website, how it is used, and the choices you have. It is not a substitute for legal advice; if you need a policy tailored to specific regulatory obligations, have it reviewed by an attorney.
Information we collect
When you submit the contact form on this website, we collect the information you provide: your name, email address, company name, website (optional), marketing budget, the services you’re interested in, and a description of your goals. If you log in to the client portal or internal platform, we also store your account information (name, email, role) and any business records associated with your account, such as proposals and project details.
This site does not use analytics, advertising, or tracking cookies. It does not track your browsing activity across other websites.
How we use information
Contact form submissions are used solely to respond to your inquiry and evaluate a potential working relationship. Client portal data is used to deliver the services we’ve agreed to provide, including managing proposals, projects, and communications related to your account.
Data sharing and storage
Contact form submissions are delivered to us via Resend, an email delivery provider. Client portal and internal account data is stored with Supabase, our database and authentication provider, and the application is hosted on Vercel. Where a client engagement is connected to QuickBooks Online, billing data is also exchanged with Intuit’s QuickBooks Online API — see “QuickBooks Online integration” below. We do not sell your information, and we do not share it with third parties for their own marketing purposes. We may disclose information if required by law.
QuickBooks Online integration
Client accounts and internal staff accounts can optionally be connected to QuickBooks Online via Intuit’s OAuth 2.0 authorization flow, so that a client’s billing status shown in the platform reflects QuickBooks rather than manually entered figures. When a QuickBooks connection is authorized, we access Customer, Invoice, and Payment records from the connected QuickBooks company — only what’s needed to answer whether an invoice was sent, whether it was paid, and what’s still owed. We do not access QuickBooks payroll, tax, or banking-connection data, and we do not create, edit, delete, or send anything in QuickBooks through this integration.
OAuth access and refresh tokens issued by Intuit are stored server-side in our database, are never sent to the browser, and are not readable by client accounts. A staff member with QuickBooks administrator access can disconnect the integration at any time, either from inside QuickBooks (Apps → disconnect) or from this platform’s Finance settings; disconnecting revokes our access to your QuickBooks data going forward but does not delete QuickBooks data already synced into our database until a deletion is separately requested (see “Your rights” below).
Data retention
We keep account and business records for as long as your engagement with us is active, and for a reasonable period afterward for our own recordkeeping, unless you request earlier deletion. Contact-form submissions from people we don’t go on to work with are periodically deleted.
Security
The website and platform are served over HTTPS. Platform access is authenticated, and data access is scoped by account role — a client account can only see its own records. Sensitive credentials, including QuickBooks OAuth tokens, are stored as encrypted environment/database values on our hosting and database providers, not in application source code. We have not obtained third-party security certifications (such as SOC 2 or ISO 27001) and don’t claim to; if that’s a requirement for your organization, contact us to discuss it before connecting sensitive data.
Your rights
You can request access to, correction of, or deletion of your information at any time by contacting us at the email address below. If you have a client portal account, you can also request that we delete your account and associated records, including any QuickBooks-derived billing data we’ve synced. Disconnecting QuickBooks yourself only stops future syncing — email us if you also want previously synced QuickBooks data deleted from our database.
Contact
Questions about this policy, or requests regarding your data, can be sent to capitalgrowthdmv@gmail.com.