FerrGrowth-specific privacy addendum. The canonical FerrLabs privacy policy covers shared account data and infrastructure.
Customer Data stored by FerrGrowth
- Sites — name, slug, custom domain, theme, members and roles.
- Pages and blocks — every page version (drafts and published) including text, structured blocks, image references, A/B variants.
- Form submissions — every submission to a form on a customer site (field values, submission timestamp, source page, IP fingerprint). Retained per the form configuration; default 12 months.
- Analytics events — pageviews and conversion events for customer sites. Visitor identifiers are derived from a salted, daily-rotated HMAC of the IP and user-agent (no cookie, no cross-day tracking).
Data of your end-users (visitors of your sites)
When a visitor browses a marketing site you publish through FerrGrowth, you are the data controller for that visitor's personal data, and FerrLabs is your processor. The processing terms are governed by the FerrLabs DPA.
You are responsible for displaying any required cookie banner / privacy notice to your visitors. FerrGrowth provides a built-in privacy-respecting analytics pipeline that does not require a cookie banner under the ePrivacy directive interpretation followed by the CNIL (no cross-site tracking, no persistent identifier).
Retention
- Sites and pages — for the lifetime of the workspace; deleted on workspace deletion.
- Form submissions — per form configuration; default 12 months.
- Analytics raw events — 13 months. Aggregated metrics — indefinitely.
Subprocessors and rights
Same subprocessors as the rest of FerrLabs: subprocessors. GDPR rights and how to exercise them: canonical privacy policy.
French version: Confidentialité.