Customer Data Privacy


Customer data privacy lets you control which personal data GrowPanel stores about your customers. If your customers are private individuals –  or your data protection policy calls for data minimization –  you can run GrowPanel without storing their names and emails at all.

You'll find the setting under Settings → General → Customer data privacy (admin and owner roles only).

Customer data privacy setting under Settings → General


The three levels

LevelWhat GrowPanel stores
Name and email (default)Customer name and email, as provided by your billing source
Name onlyCustomer name, but no email address
Customer IDs onlyNeither name nor email –  customers appear as their billing-system ID (e.g. cus_NffrFeUfNV2Hib) everywhere

With Customer IDs only, every surface –  reports, customer lists, exports, email reports, the AI analyst, the API and the MCP server –  shows the billing system's customer ID instead of a name. You can always cross-reference the ID in your billing platform, where the full customer record lives.

Tip: if you want a friendlier label than the raw ID without storing personal data, put a pseudonymous label in your billing system's customer metadata (for example an internal user number) –  metadata is imported as custom variables and can be used for filtering and segmentation.

How changes take effect

Reducing the level (removing email, or removing both) takes effect immediately: the stored details are scrubbed from already-imported data the moment you save, and future imports follow the new level. No resync is needed.

Restoring a level (bringing names or emails back) triggers a full resync of your connected data sources, because the data can only come back from your billing source. Depending on account size this can take from minutes to a while; your reports stay available while it runs.

One permanent effect worth knowing: customers that have been deleted in your billing source are scrubbed like everyone else when you reduce the level, but they stay scrubbed even if you later restore –  their details no longer exist at the source to re-import. For a privacy setting, that is usually exactly what you want.

Good to know

  • HubSpot sync is incompatible with reduced levels, because it matches contacts by customer email. You'll be asked to disconnect HubSpot before reducing the level, and reduced accounts can't connect HubSpot.
  • MRR numbers are unaffected. The setting only concerns name and email; subscriptions, invoices, movements and metrics are calculated exactly as before.
  • Raw source events: movement detail views can show the raw webhook payload from your billing source, which may contain customer details. If this matters for your setup, contact us.
  • This is data minimization, not anonymization. Billing-system customer IDs are still pseudonymous personal data under GDPR –  GrowPanel remains a processor of your customer data, just with a substantially reduced footprint. See our DPA for the full picture.