Privacy Policy — Hetu Growth Engine

Effective date: 11 September 2026. Hetu Growth Engine is operated by Hetu Softworks. This policy explains how Hetu Growth Engine and the Hetu Softworks website access, use, store, share and delete personal information, including data received through Google APIs.

The Growth Engine is a business marketing-management service. A client keeps ownership of its Google assets and chooses whether to connect them. We request only the permissions needed for the features the client enables. Product-specific services operated by Hetu publish their own privacy notices on their own sites.

Information we collect

Website enquiries: when you send the contact form, we store the name and mobile number you enter, and any email address, organisation and message you choose to provide. We also record the consent choice and time, the network address used to submit the form, and limited anti-abuse request counts.

Growth Engine accounts: we store the account identity, organisation, assigned client and location access, settings, approval decisions and an audit history of authorised actions.

Connected Google data: depending on the permissions a client grants, the Growth Engine may access Google Ads account and campaign identifiers, settings, performance and conversion reports; Google Business Profile locations, hours, posts, photos, reviews and performance; and read-only Google Analytics and Search Console properties and reports. We also store granted scopes, connection status and revocation status. OAuth access and refresh tokens are credentials and are handled separately from report data.

How we use information

We use website enquiry data to respond to the conversation the visitor started and to protect the public form from abuse.

We use connected Google data only to provide or improve the Growth Engine features requested by the authorised client: show account health and performance, prepare reports and recommendations, connect enquiries and confirmed outcomes to campaigns, and carry out an account action that the client's configured authority permits. The Growth Engine does not transfer ownership of a client's Google assets.

We do not sell Google user data, use it to build advertising audiences, serve personalised or retargeted advertising, determine creditworthiness, or train general-purpose artificial-intelligence or machine-learning models. Customer admissions matching is a separate feature and remains disabled unless its own notice and stored consent evidence permit it.

Sharing and human access

We do not sell personal information or Google user data. We disclose it only to infrastructure and service processors needed to operate the requested feature, under confidentiality and security obligations; to the client users and authorised Hetu operators assigned to that client; when the user permits support access; to investigate abuse or a security incident; or when law requires disclosure.

We do not transfer Google user data to data brokers, information resellers, advertising-audience providers or unrelated third parties. A person may inspect non-aggregated Google user data only with the user's permission, for necessary security or abuse investigation, or to comply with law.

Security

We use encrypted network connections, access controls scoped to the assigned client and location, server-side permission checks, audit records and operational monitoring. OAuth access and refresh tokens are encrypted at rest, are never returned to a client application, and are never written to logs or audit entries. Credentials are scoped to the minimum permission needed and token refresh and revocation are handled centrally.

No internet service can guarantee absolute security. We review access and investigate suspected misuse or unauthorised disclosure.

Retention and deletion

Disconnecting or revoking a Google account stops new access immediately. Encrypted Google credentials are deleted within 30 days. Raw Google report records are deleted within 90 days after the connection or client engagement ends. Minimal security and action-audit evidence that contains no token, raw contact identifier or raw provider payload may be retained for up to 3 years to investigate misuse and account changes. A legal requirement may require a different period, in which case we keep only the required record.

Website contact messages are kept as the record of the conversation the visitor started and are currently removed on a verified deletion request rather than an automatic schedule. We delete or anonymise other information when it is no longer needed for the stated purpose, subject to security, fraud-prevention, contractual and legal record obligations.

Your choices and requests

A Google account owner can revoke access in the Growth Engine or in the Google account's security settings. The owner may also ask us to identify, correct, export or delete information associated with the connected client account. We verify the requester before acting. Revocation does not undo an action that the user previously authorised and Google already completed.

The Google connection is intended for authorised adult representatives of client businesses. Hetu does not knowingly invite children to connect Google business accounts. Customer records for people under 18, or whose age is unknown, are excluded from advertising conversion uploads unless a separate lawful process is approved.

Contact and policy updates

For privacy questions or requests to access, correct, delete or withdraw access to data, email founder@hetuhq.com. We will verify the request against the relevant website message or connected client account before acting.

We may update this policy when the Growth Engine's data practices or legal obligations change. Material changes to Google user-data handling will be published here and presented for consent before the new use begins. The effective date at the top identifies the current version.