Customer Data Privacy
Customer data privacy lets you control which personal data GrowPanel stores about your customers. If your customers are private individuals – or your data protection policy calls for data minimization – you can run GrowPanel without storing their names and emails at all.
You'll find the setting under Settings → General → Customer data privacy (admin and owner roles only).

The three levels
| Level | What GrowPanel stores |
|---|---|
| Name and email (default) | Customer name and email, as provided by your billing source |
| Name only | Customer name, but no email address |
| Customer IDs only | Neither name nor email – customers appear as their billing-system ID (e.g. cus_NffrFeUfNV2Hib) everywhere |
With Customer IDs only, every surface – reports, customer lists, exports, email reports, the AI analyst, the API and the MCP server – shows the billing system's customer ID instead of a name. You can always cross-reference the ID in your billing platform, where the full customer record lives.
Tip: if you want a friendlier label than the raw ID without storing personal data, put a pseudonymous label in your billing system's customer metadata (for example an internal user number) – metadata is imported as custom variables and can be used for filtering and segmentation.
How changes take effect
Reducing the level (removing email, or removing both) takes effect immediately: the stored details are scrubbed from already-imported data the moment you save, and future imports follow the new level. No resync is needed.
Restoring a level (bringing names or emails back) triggers a full resync of your connected data sources, because the data can only come back from your billing source. Depending on account size this can take from minutes to a while; your reports stay available while it runs.
One permanent effect worth knowing: customers that have been deleted in your billing source are scrubbed like everyone else when you reduce the level, but they stay scrubbed even if you later restore – their details no longer exist at the source to re-import. For a privacy setting, that is usually exactly what you want.
Good to know
- HubSpot sync is incompatible with reduced levels, because it matches contacts by customer email. You'll be asked to disconnect HubSpot before reducing the level, and reduced accounts can't connect HubSpot.
- MRR numbers are unaffected. The setting only concerns name and email; subscriptions, invoices, movements and metrics are calculated exactly as before.
- Raw source events: movement detail views can show the raw webhook payload from your billing source, which may contain customer details. If this matters for your setup, contact us.
- This is data minimization, not anonymization. Billing-system customer IDs are still pseudonymous personal data under GDPR – GrowPanel remains a processor of your customer data, just with a substantially reduced footprint. See our DPA for the full picture.