Privacy Policy
Last updated: July 2026
Notice at Collection. When you open a Grivn link we collect your IP address, browser user-agent and the device details we derive from it, your language preference, the referring page, and the campaign tags in the link, and we compute one-way device identifiers from your IP address, device type, and operating system. We use these to route you and to attribute the click to an app install for the developer whose link you opened. We keep the matching record for 48 hours and the click record for 90 days. We do not sell your personal information. See Your Privacy Choices to opt out of attribution.
1. Introduction
Grivn, LLC ("we", "our", or "us") operates the grivn.com website and the Grivn deep linking platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and authentication credentials. If you sign in via a third-party provider (Google, GitHub, Apple), we receive basic profile information from that provider.
Deep Link Click Data
When a user opens a Grivn link, our servers automatically receive and record: IP address (last segment zeroed after 48 hours - see Retention); User-Agent string and the device type, operating system, and browser derived from it; Referer URL; UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term); Accept-Language header; and technical quality flags such as whether the request appears to be an automated bot. We do not set cookies on the link-redirect page.
Device Identifiers (for deferred matching)
From the information above we compute two one-way SHA-256 hashes: a primary identifier from your full IP address together with your device type and operating system; and a network identifier from your network only (the first three segments of your IP address) together with your device type and operating system. These are one-way and cannot be reversed to recover your IP address. They are used solely to link a click to a subsequent app install (deferred deep linking), never for cross-site tracking or advertising. Because the network identifier is based on your network rather than your exact address, it may match a device to a link opened from the same network, which could be a different device.
Product analytics in the dashboard
When you are signed in to the Grivn dashboard, we use PostHog to understand how our customers use the product, which may include session replay of your activity within the dashboard. We use this only to operate and improve the product. We do not run this analytics on our public website or on link-redirect pages.
Cookies
We use cookies to maintain your signed-in session, remember your preferences in the dashboard, and remember your privacy choices (such as opting out of attribution). You can control cookies through your browser settings.
3. How We Use Your Information
- Provide, operate, and maintain our deep linking services
- Process your transactions and manage your account
- Provide analytics and reporting on deep link performance
- Send you service-related communications and updates
- Detect, prevent, and address technical issues or security threats
- Comply with legal obligations
4. Data Sharing and Disclosure
We report only aggregated results to the developer whose link you opened (for example, how many clicks led to installs) - not your individual click record. We do not sell your personal information, and we share it only with the infrastructure providers who operate our platform (cloud hosting, payment processing, email delivery), who are contractually bound to protect it. We may also disclose your information when required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS/HTTPS), encrypted storage, access controls, and regular security audits. While no method of transmission over the Internet is 100% secure, we strive to protect your data using commercially acceptable means.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services. When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
Analytics Data Retention
- IP addresses: Anonymized after 48 hours (last octet zeroed to x.x.x.0). Full IP is retained for 48 hours solely for deferred deep link matching.
- Raw click data (including anonymized IP, User-Agent, UTM parameters): Automatically deleted after 90 days.
- Aggregated statistics (click counts, device breakdown — no personal data): Retained for 365 days.
- Deferred deep link matching data: Expires after 48 hours, cleaned up within 1 additional day.
You may request deletion of your analytics data at any time through the dashboard or by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data
- Rectify inaccurate or incomplete data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
To exercise any of these rights, please contact us at support@grivn.com.
8. California Privacy Rights
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of its sale or sharing. Grivn does not sell your personal information. The categories we collect are: identifiers (IP address, device identifiers, account email); internet or network activity (link clicks, user-agent, referring page, campaign parameters); and commercial information (subscription and billing records). We collect these to route links, attribute installs for the developer whose link you opened, operate your account, and secure the service. To exercise any right, use Your Privacy Choices or contact support@grivn.com. We will not discriminate against you for exercising your rights.
9. SDK Data Collection
Our mobile SDKs (iOS and Android) are integrated by app developers to enable deep linking functionality.
Data Collected by the SDK
Our mobile SDKs collect the device's User-Agent (device model and OS version) and language, which are used for deferred deep link matching as described above.
Data NOT Collected by the SDK
- Advertising identifiers (IDFA/GAID)
- Contacts or address book
- GPS or precise location
- Photos, camera, or microphone data
Opt-Out
App developers can disable analytics data collection by calling setAnalyticsEnabled(false) in the SDK. When disabled, the SDK will not send deferred deep link requests or install confirmation data. Regular deep link handling (Universal Links / App Links) continues to work normally.
10. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will take steps to delete such information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at support@grivn.com.