Groot.
PrivacySecurityTermsCompanySign in
Sign in
Menu
PrivacySecurityTermsCompanyBlogSolo

Privacy Policy

Last updated July 28, 2026

This Privacy Notice for GROOTIFY LLP (UEN: T25LL0686L) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our website at https://www.hellogroot.com or any website of ours that links to this Privacy Notice
  • Use the Groot Solo Bookkeeping Health Check or register interest in Groot Solo
  • Use the Groot platform for expense management, financial record-keeping, invoicing, or related business functions
  • Engage with us in other related ways, including any marketing or events

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at admin@hellogroot.com.

Prefer this without the legal vocabulary? We wrote Security and privacy. It explains what "sharing with third parties" actually means, who processes your data and what each one can see, what we never do, and what we do not claim. This Privacy Notice remains the binding document.

Summary of Key Points

This summary provides key points from our Privacy Notice. More detail is available in the numbered sections below.

  • What personal information do we process? We collect personal identifiers (names, emails, phone numbers), Groot Solo health-check and product-research responses, campaign attribution, business data (company registration numbers), financial records (expense claims, invoices, accounting entries), receipt images, leave and attendance records, AI chat conversation history, push notification tokens, and audit trail data.
  • Do we process any sensitive personal information? Yes. We process financial data, business registration numbers, and employment records which may be considered sensitive in certain jurisdictions.
  • Do we use artificial intelligence? Yes. We use Google Gemini AI and Qwen3-8B for receipt OCR, expense categorization, AI chat, e-invoice processing, and form auto-fill. Your data is not used to train AI models.
  • Do we share your data with third parties? Yes. We use the providers listed in Section 4 for authentication, storage, AI processing, payments, monitoring, email delivery, hosting, and optional analytics and advertising measurement. We do not sell your data. Google Analytics and Meta Pixel load on Groot Solo pages only after you choose Accept all, and they do not receive your contact details or detailed health-check and pricing answers.
  • Where is your data stored? All data is stored and processed in the United States. We have safeguards in place for cross-border transfers from Malaysia and Singapore.
  • How long do we keep your data? Retention depends on the record and the market. Malaysia financial and tax records are generally kept for 7 years. Singapore financial and tax records are generally kept for at least 5 years. Other personal data is deleted or anonymized when it is no longer needed, unless a legal hold or another legal requirement applies.
  • What are your rights? Depending on your location, you have rights under the Malaysia Personal Data Protection Act 2010 and/or the Singapore Personal Data Protection Act 2012, including the right to access, correct, and request deletion of your data.
  • How do you exercise your rights? Contact us at admin@hellogroot.com.

1. What Information Do We Collect?

Personal information you disclose to us

In Short: We collect personal information that you provide to us, including personal identifiers, business data, financial records, and data generated through your use of our AI-powered features.

We collect personal information that you voluntarily provide to us when you register on the Services, use our platform features, express an interest in obtaining information about us or our products and Services, or otherwise when you contact us.

Personal Identifiers. Names, email addresses, phone numbers, and job titles.

Business Data. Company names and business registration numbers, including Business Registration Numbers (BRN), Tax Identification Numbers (TIN), and Unique Entity Numbers (UEN).

Financial Records. Expense claims, invoices, accounting entries, and related financial transaction data.

Document Data. Receipt images and other uploaded financial documents that you submit for processing.

Employment Data. Leave records and attendance records submitted through the platform.

AI Interaction Data. Chat conversation history with our AI assistant, inputs and outputs from receipt OCR processing, and expense categorization results.

Technical Data. Push notification tokens and device identifiers used to deliver notifications.

Audit Trail Data. A complete record of user actions, approval workflows, and data modifications within the platform, maintained for security and compliance purposes.

Groot Solo Data. If you use the Groot Solo Bookkeeping Health Check or register for early access, we may collect your email address, optional name and WhatsApp number, selected persona, health-check answers and score, current bookkeeping method, fair-price response, optional free-text product feedback, founding-interest choice, decline reason, requested market, and whether you separately opted in to ongoing product marketing. These detailed research responses remain in Groot's first-party lead storage and are not sent to Google Analytics or Meta Pixel.

Campaign and Referrer Data. On Groot Solo pages, we may record bounded campaign labels such as utm_source, utm_medium, utm_campaign, utm_content, and utm_term, together with the referring site's hostname. We use this information to understand which campaigns brought visitors to the Singapore or Malaysia experience. We do not retain arbitrary full referrer URLs or oversized query strings for this purpose.

Privacy Choice Data. We store your versioned Accept all or Necessary only choice in first-party browser storage for up to 180 days so the Solo pages can remember it. If you have not chosen, or if the stored choice is missing, malformed, inaccessible, or expired, optional analytics and advertising tracking remains off.

Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice here: https://stripe.com/privacy.

Social Login Data. We use Clerk for authentication. You may register and log in using your email address or through supported third-party identity providers (such as Google). When you use a third-party provider, we receive profile information including your name, email address, and profile picture.

Google API

Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

2. How Do We Process Your Information?

In Short: We process your information to provide, improve, and administer our Services, including AI-powered features, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts. We process your information through Clerk so you can create and log in to your account, as well as keep your account in working order.
  • To deliver and facilitate delivery of services to the user. We process your information to provide you with expense management, financial record-keeping, invoicing, and related business services.
  • To provide AI-powered features. We process your uploaded documents and data through AI services (Google Gemini AI and Qwen3-8B) to provide receipt OCR, expense categorization, AI chat assistance, e-invoice processing, and form auto-fill.
  • To respond to user inquiries/offer support to users. We process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
  • To provide the Groot Solo health check and requested early-access messages. We process the contact details and research responses you submit to save your progress, show your result, and send the result or early-access notification you requested.
  • To understand Groot Solo campaigns after consent. If you choose Accept all, we use Google Analytics and, when configured, Meta Pixel to measure page and funnel outcomes using bounded, non-identifying event properties. We do not send those providers your email address, name, WhatsApp number, exact score, individual answers, current bookkeeping method, fair-price selection, free-text note, or decline reason.
  • To send optional ongoing marketing. We use your email address or WhatsApp number for occasional Groot Solo product updates only when you select the separate, unchecked marketing permission. Accepting analytics cookies does not grant marketing permission. A requested health-check result or early-access notification does not by itself enrol you in ongoing promotional messaging.
  • To maintain audit trails and comply with legal obligations. We record user actions and data modifications for security, compliance, and regulatory purposes.

Your Groot Solo privacy choices

Before you choose Accept all, the Groot Solo pages do not load Google Analytics or Meta Pixel and do not create their analytics or advertising cookies. Necessary only keeps the complete landing page, health check, lead forms, requested emails, and optional interview text working without those providers.

You can reopen Privacy choices from the footer of either Solo page. If you change from Accept all to Necessary only, we immediately block further application analytics events, make a best-effort attempt to remove known first-party Google Analytics and Meta cookies, and reload the page without the optional scripts. Your change does not affect processing that already occurred while consent was active.

3. AI-Powered Features & Third-Party Data Processing

Groot Finance includes an AI assistant that helps users with financial queries, expense analysis, and business insights. When you use the AI assistant:

  • Data shared: Your chat messages and relevant business context (such as expense summaries, invoice data, and vendor information) are transmitted to process your request.
  • Third-party processor: This data is processed by Google Gemini AI through Google's enterprise API.
  • No training use: Under our enterprise agreement with Google, your data is not used to train, improve, or develop AI models.
  • Data retention: Chat messages are stored in our database for your conversation history. Data sent to Google Gemini is processed in real-time and not retained by Google beyond the API request.
  • User consent: You are asked to provide explicit consent before your first interaction with the AI assistant. You may decline, in which case no data is sent to the AI service.
  • OCR document processing: When you upload receipts or invoices, document images are processed by Google Gemini AI for text extraction (OCR). The same data protection terms apply — images are processed in real-time and not retained by Google or used for training.

For questions about AI data handling, contact us at admin@hellogroot.com.

4. When and With Whom Do We Share Your Personal Information?

In Short: We use the providers listed below to deliver our Services and, after consent on Groot Solo pages, to measure analytics and advertising performance.

The role and permitted use of data differ by provider and service. Our operational service providers process data to perform the purpose listed. Google Analytics and Meta Pixel are optional measurement technologies on Groot Solo pages and load only after Accept all. We do not sell personal information. For a plain-language walkthrough, read Security and privacy.

We use the following third-party providers:

ProviderCountryPurposeData Categories
ClerkUnited StatesAuthentication and user identity managementUser identity, email, profile data, authentication tokens
ConvexUnited StatesDocument database and application data storageApplication data, documents, user records
AWS (us-west-2)United StatesFile storage, serverless compute, email sendingReceipt images, files, email content
Google Gemini AIUnited StatesReceipt OCR, expense categorization, e-invoice processing, form auto-fillDocument content, receipt data, chat inputs
Qwen3-8B on ModalUnited StatesAI chat assistantChat messages, conversation context
StripeUnited StatesPayment processing, billing, subscription managementPayment details, billing information, subscription data
SentryUnited StatesApplication error and performance monitoringError data, performance metrics, stack traces
ResendUnited StatesTransactional email deliveryEmail addresses, email content
VercelUnited StatesWebsite and application hostingWeb traffic data, deployment artifacts
Google AnalyticsUnited StatesOptional Groot Solo traffic and funnel measurement after consentPage URL, campaign labels, market, persona, sanitized funnel outcomes
Meta PixelUnited StatesOptional Groot Solo advertising measurement after consent, when configuredPage URL, campaign labels, market, persona, sanitized funnel outcomes

We may also need to share your personal information in the following situations:

  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

5. Artificial Intelligence and Automated Processing

In Short: We use specific AI services to process your data for defined purposes. Your data is not used to train AI models.

As part of our Services, we use the following AI-powered functions:

Our AI Functions

  1. Receipt OCR and Data Extraction (Google Gemini AI) — Scans uploaded receipt images to extract transaction details such as merchant name, amount, date, and line items.
  2. Expense Categorization (Google Gemini AI) — Automatically categorizes expenses based on extracted receipt data and transaction descriptions.
  3. AI Chat Assistant (Qwen3-8B hosted on Modal, and/or Google Gemini AI) — Provides conversational assistance for financial queries, report generation, and platform guidance.
  4. E-Invoice Processing (Google Gemini AI) — Processes electronic invoices to extract structured data for accounting records.
  5. Form Auto-Fill (Google Gemini AI) — Pre-populates form fields using data extracted from uploaded documents.

AI Data Training Commitment

Groot uses the Google Gemini API exclusively under a paid-tier billing account. Under this arrangement:

  • Your prompts and responses are not used for AI model training and are governed by Google's Cloud Data Processing Addendum (DPA).
  • Prompts and responses are logged by Google for a maximum of 30 days solely for abuse detection and prohibited use policy enforcement.
  • Modal (hosting Qwen3-8B) deletes function inputs and outputs within a maximum of 7 days.

Grounding Features

Certain AI features may use Google Search grounding or Google Maps grounding to provide enhanced, contextually relevant results. When grounding is used, prompts and contextual information are retained by Google for 30 days for feature creation and debugging purposes. This 30-day retention applies regardless of billing tier and cannot be opted out of.

Groot commits to using only paid-tier AI services for production workloads. No user data is processed through free-tier AI services where data may be used for model improvement.

You must not use the AI features in any way that violates the terms or policies of any AI service provider.

6. How Do We Handle Your Social Logins?

In Short: If you choose to register or log in to our Services using a third-party identity provider, we may have access to certain information about you.

Our Services use Clerk for authentication. You may register and log in using your email address or through supported third-party identity providers (such as Google). When you use a third-party provider, we receive profile information including your name, email address, and profile picture, as well as other information you choose to make available.

We will use the information we receive only for the purposes that are described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party identity provider. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information.

7. How Long Do We Keep Your Information?

In Short: We keep each category only for its stated purpose and any applicable legal period. The period is not the same for every record or market.

Financial record-keeping rules apply to the relevant business records and their supporting documents. They do not make every chat message, profile field, or technical log a financial record. The following table sets out our retention schedule:

Data CategoryRetention PeriodLegal Basis
Financial and tax-related records (expense claims, invoices, accounting entries)Malaysia: 7 years from the end of the relevant year, or 7 years after completion of the relevant transaction where the Companies Act applies. Singapore: at least 5 years from the relevant year of assessment or GST accounting period.MY Income Tax Act 1967 s.82 and Companies Act 2016 s.245; SG Income Tax Act s.67 and GST record-keeping requirements
Receipt images and other source documents linked to a financial recordThe same period as the financial or tax record they supportSupporting documentation for the linked record
AI chat conversation historyWhile needed to provide conversation history. Content that becomes part of a retained financial or audit record follows the period for that record.Service delivery and, where applicable, the requirement applying to the linked record
Audit trail recordsThe same period as a linked financial record where needed to show its history. Other security audit data is kept only while needed for security, legal, or business purposes.Record integrity, security, and legal obligations
Leave and attendance recordsMalaysia: at least 6 years after the information is recorded. Singapore: the latest 2 years for current employees; for former employees, the last 2 years kept for 1 year after employment ends. A longer financial or tax period may apply where the same record supports payroll or tax reporting.MY Employment Act 1955 s.61; SG Employment Act record-keeping requirements; applicable tax rules
Account and profile data linked to a retained recordOnly the minimum identifiers needed to keep the retained record accurate and intelligible, for the same period as that recordIntegrity of records retained under legal or business requirements
Account and profile data (non-essential)30 days after account terminationDeleted when no longer needed for any purpose
Error and performance monitoring logs1 year (minimum 90 days immediately accessible)Groot security and incident investigation policy
Push notification tokens30 days after account terminationPurpose-limited; no statutory retention requirement
Groot Solo lead and research dataWhile the Solo research or early-access programme remains active, then deleted or anonymized when no longer neededProduct research, requested service, and consented marketing purposes
Groot Solo browser privacy choiceUp to 180 days, unless changed or cleared earlierRemembering the visitor's tracking preference

Primary references include Malaysia's Companies Act 2016, Employment Act 1955, and Personal Data Protection Standard 2015, together with Singapore's IRAS record-keeping requirements, MOM employment-record requirements, and PDPA retention obligation.

We may retain a record for longer where a legal hold, dispute, investigation, or another specific legal requirement applies. We limit that extension to the data and period needed for that purpose.

When we have no ongoing legitimate business or legal need to retain your personal information, we will either delete or anonymize such information. If this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

8. International Data Transfers

In Short: All your data is stored and processed in the United States. We have safeguards in place for cross-border transfers from Malaysia and Singapore.

All personal data processed by Groot is stored and processed in the United States through our third-party service providers listed in Section 4. This means your data is transferred from your location to the United States.

For users in Malaysia

We transfer your data to the United States on the basis of (1) your explicit consent, provided after being informed of the nature of cross-border transfer, and (2) contractual necessity for the performance of our services to you, in accordance with the Personal Data Protection Act 2010 (as amended by Act A1703, 2024). We exercise reasonable diligence to ensure that our service providers maintain protections consistent with the Malaysian PDPA, including entering into data processing agreements that require comparable levels of protection.

For users in Singapore

We transfer your data to the United States pursuant to binding contractual arrangements with each service provider that require them to provide a standard of protection to your personal data that is at least comparable to the protection under the Singapore Personal Data Protection Act 2012, in compliance with the Transfer Limitation Obligation under Section 26 of the PDPA. By using our Services after being informed of this transfer, you consent to the transfer of your data overseas.

We regularly review the data protection practices of our service providers to ensure ongoing compliance with applicable data protection requirements in both jurisdictions.

9. How Do We Keep Your Information Safe?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

10. Do We Collect Information From Minors?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at admin@hellogroot.com.

11. Your Rights Under the Malaysia PDPA

In Short: If you are in Malaysia, you have specific rights under the Personal Data Protection Act 2010.

If you are located in Malaysia, the Personal Data Protection Act 2010 (as amended by Act A1703, 2024) provides you with the following rights:

  • Right of Access (Section 12): You may request access to your personal data that we hold and information about how it has been processed.
  • Right of Correction (Section 34): You may request that we correct any inaccurate, incomplete, misleading, or not up-to-date personal data.
  • Right to Withdraw Consent: You may withdraw your consent to the processing of your personal data at any time by contacting us.
  • Right to Data Portability: Under the Amendment Act (effective 1 June 2025), you may request your personal data in a structured, commonly used, and machine-readable format.
  • Right to Prevent Processing for Direct Marketing: You may instruct us to cease processing your personal data for direct marketing purposes.

We process your data in accordance with the seven Data Protection Principles under the Malaysian PDPA: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle, and the Access Principle.

Privacy inquiries: admin@hellogroot.com

Filing a Complaint: If you believe your personal data has been mishandled, you may lodge a complaint with the Department of Personal Data Protection (JPDP) at https://www.pdp.gov.my or by calling +603-8000 8000.

12. Your Rights Under the Singapore PDPA

In Short: GROOTIFY LLP is registered in Singapore and is subject to the Personal Data Protection Act 2012.

As a data subject under the Singapore PDPA, you have the following rights:

  • Right of Access (Section 21): You may request access to your personal data and information about how it has been used or disclosed within the past year.
  • Right of Correction (Section 22): You may request correction of any error or omission in your personal data that is in our possession or under our control.
  • Right to Data Portability (Section 26H): You may request that your data be transmitted to another organization in a commonly used machine-readable format.
  • Right to Withdraw Consent: You may withdraw consent for the collection, use, or disclosure of your personal data at any time, subject to legal or contractual restrictions and on reasonable notice.

We comply with the Retention Limitation Obligation under Section 25 of the PDPA: we will cease to retain personal data, or remove the means by which the personal data can be associated with particular individuals, when the purpose for which the personal data was collected is no longer being served by retention, unless retention is required by law.

Privacy inquiries: admin@hellogroot.com

Filing a Complaint: If you believe your personal data has been mishandled, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at https://www.pdpc.gov.sg or by calling +65 6377 3131.

13. General Privacy Rights

In Short: You may review, change, or terminate your account at any time.

Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us at admin@hellogroot.com.

However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.

Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account.

Account Information

If you would at any time like to review or change the information in your account or terminate your account, you can:

  • Contact us at admin@hellogroot.com

Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files as required by law (see our retention schedule in Section 7), to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms, and/or comply with applicable legal requirements.

14. Controls for Do-Not-Track Features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

Regardless of DNT support, optional Google Analytics and Meta Pixel tracking on Groot Solo pages remains off unless you choose Accept all. You can withdraw that choice through Privacy choices in the Solo page footer.

15. Do We Make Updates to This Notice?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

16. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may contact:

Privacy and general inquiries: admin@hellogroot.com

GROOTIFY LLP UEN: T25LL0686L Singapore

17. How Can You Review, Update, or Delete the Data We Collect From You?

Based on the applicable laws of your country (including the Malaysia PDPA 2010 and Singapore PDPA 2012), you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information, or to request your data in a portable format. These rights may be limited in some circumstances by applicable law.

To exercise any of these rights, please contact us at admin@hellogroot.com. We will respond to your request within the timeframe required by applicable law.

Groot.

© 2026 Grootify LLP

UEN T25LL0686L | Singapore

SoloBlogSecurityPrivacyTermsCompanyadmin@hellogroot.com