Privacy policy
What we hold, why we hold it, and the difference between the data that is ours and the data that belongs to an operator.
Who we are, and which role we are in
GrowthMessenger is the trading name of GrowthMessenger Ltd, registered in the Isle of Man under company number 134827C, at Third Floor, St George's Court, Upper Church Street, Douglas IM1 1EE, Isle of Man. This policy covers growthmessenger.com and the campaign work we run for licensed operators. Bryn Ashworth is accountable for it. There is no privacy department to be routed through.
Two roles, and they are not interchangeable.
- Controller for this website and for the people who contact us. If you filled in the quote form, emailed us or signed a contract with us, we decided what to collect and why. Your questions come to us.
- Processor for the player records an operator instructs us to message, and for the deposit events we take back to attribute those messages. The operator decides who is contacted and on what basis. We run the send and the measurement on its written instruction, under its licence, on its sender identity.
In plain terms: if you got a message from a brand you play with, we may have sent it, but we did not decide to send it to you.
What we hold as controller
- Enquiry details. Name, work email, the brand or group, the markets you hold a licence for, the rough size of your contactable base, the platform you run, and the offer you describe on the quote form.
- Correspondence. Email threads, call notes, and the briefs and reports that pass between us during an engagement.
- Billing records. Entity details, invoices, purchase orders and the bank references needed for us to be paid.
- Technical logs. Truncated IP address, browser string, pages requested and timestamps, kept to spot abuse and to see which pages produce enquiries. Nothing here profiles you for advertising. What the site sets in your browser is on the cookies page.
What we process on an operator's instruction
We get a narrow slice of an operator's player records. The scope is fixed in the contract and it is deliberately small.
- Mobile number in international format, and the market it belongs to.
- A player reference from the operator platform, used to split a segment and to match a deposit back.
- Segment membership: value tier, recency band, and the last product the player used.
- Consent state and the date it was captured, plus opt-out, cool-off and self-exclusion flags. These are checked at send time, every send, not at the moment a file was handed over.
- The send record: which variant, which wave, what time, and whether it reached the handset.
- Deposit events returned by the operator platform, used only for attribution.
We do not receive real names, addresses, identity documents, card details, game history or source-of-funds material. A campaign does not need it. If it arrives anyway we delete it and say so.
The attribution data, specifically
Attribution is the reason we hold anything about a player once a send is over, so it gets its own section.
- Each message carries a signed identifier unique to that player and that variant, on a short domain the operator owns. When the link is followed we record the identifier, the timestamp and a coarse device reading. Nothing beyond the click itself is tracked.
- The operator platform returns deposit events as they settle: player reference, amount, currency, timestamp. We match those to the signed identifier inside a stated attribution window, 72 hours by default, agreed in writing rather than assumed.
- It is reconciled daily against the operator's own reporting, so both sides hold the same records while a reconciliation is open.
What we will not do with it: build our own profile of a player, sell or share it, or match one operator's file against another's. Each engagement sits in its own environment. Somebody who appears in two clients' files is two unrelated records to us, and stays that way.
Lawful basis
As controller: legitimate interests for enquiries, correspondence and security logging, the contract for anything needed to deliver an engagement, legal obligation for accounting records.
As processor we rely on nothing of our own. The operator sets the basis for contacting a player, normally consent captured at registration or in the account. We enforce it rather than assert it: if the consent record does not carry a basis and a date, the number is not queued, whatever the brief says.
How long we keep things
- Enquiries that do not become work: 12 months from the last message, then deleted.
- Client correspondence and briefs: the term of the engagement plus 24 months.
- Billing and accounting records: 6 years from the end of the financial year.
- Website server logs: 30 days, then discarded. Only aggregate counts survive.
- Send records, click records and deposit events: 13 months from the send, then reduced to campaign totals with no player reference attached.
- Suppression records: held for as long as we work with that operator. An opt-out has to outlive the campaign it came from, otherwise it is not an opt-out.
When an engagement ends we return or destroy the operator's data within 30 days of written instruction, keeping only the suppression list and what accounting law requires. We confirm in writing when it is done.
Who else touches it
All under written contract, all bound to the terms we owe our clients.
- An infrastructure provider hosting the campaign system, in data centres in London and Dublin.
- The mobile networks in each market, and the partners they require traffic to be handed to. A number has to reach them or the message cannot be delivered.
- A mail and document provider used for correspondence and reports.
- An accounting provider used for invoicing.
Clients get 30 days' notice before we add one, and can object. The current list goes out on request to growth@growthmessenger.com.
Data crossing a border
The Isle of Man holds an adequacy decision from the European Commission and is recognised by the United Kingdom, so data moves between here, the EEA and the UK with no further instrument needed. That is one reason the company is registered where it is.
Player files are stored inside that footprint and are not moved out of it. The one exception is delivery: to reach a handset, the number has to pass to the networks serving that market. Where those sit outside the EEA the transfer runs on standard contractual clauses.
Your rights, and who to ask
If you are a client contact or made an enquiry, come straight to us. Ask for a copy of what we hold, have it corrected or erased, restrict or object to it, or ask for it in a portable form. We answer inside 30 days and we do not charge.
If you are a player who received a message, ask the operator whose name is on the sender. They hold your account, they decided you should be contacted, and they are the controller of that data. We cannot identify you from a phone number without them and we will not go looking. If you write to us anyway we pass it to that operator within 3 working days and tell you we have done it. To stop messages now, reply STOP to the message. That suppression takes effect within minutes and does not expire.
If you think we have handled something badly, tell us first. If that goes nowhere, complain to the Information Commissioner in the Isle of Man or to the authority where you live.
Security
Player data is encrypted in transit and at rest. Access is limited to the people running your campaigns, behind two-factor authentication, reviewed quarterly. Files stay inside the campaign system: never downloaded to a laptop, never passed around as spreadsheets. Each client sits in a separate environment with separate credentials.
If something goes wrong we tell the affected operator inside 24 hours of becoming aware, with what we know then rather than a tidied version a week later. There has been no reportable incident since we began trading.
Changes, and how to reach us
We do not rewrite this quietly. The date at the top is the date it last changed, and clients get 30 days' notice of anything material. Questions, requests and complaints go to growth@growthmessenger.com, or by post to GrowthMessenger Ltd, Third Floor, St George's Court, Upper Church Street, Douglas IM1 1EE, Isle of Man. A person reads it.