Bounty Growth Pty Ltd
Privacy Policy
This policy explains how Bounty handles personal data, customer-authorized business data, and data received through Google APIs.
Last updated 20 August 2026
Who we are
Bounty Growth Pty Ltd (ABN 49 697 769 761) provides Bounty, a business-to-business marketing analytics and operations service. In this policy, “Bounty”, “we”, “us”, and “our” refer to Bounty Growth Pty Ltd.
Contact us about privacy at arran@bountygrowth.com.
Scope and roles
This policy covers our public websites, documentation, authenticated application, support communications, and customer-authorized integrations. It explains how we handle account, usage, integration, and customer data.
We generally act as a processor or service provider when a customer asks Bounty to process data from its systems. The customer remains responsible for its instructions, permissions, notices, and lawful basis. We act as controller for our own account administration, security, billing, website analytics, and business communications.
Data we collect
- Account and administration data, including name, business email, organization, role, workspace membership, and authentication details.
- Product and support data, including prompts, queries, files, outputs, actions, configuration, feedback, and support communications.
- Usage, device, network, security, and diagnostic data, including IP address, browser, operating system, product events, errors, and logs.
- Customer-authorized business data from advertising, analytics, CRM, messaging, warehouse, and other connected systems.
- Integration metadata, including provider, selected account or property identifiers, connection status, schema, and synchronization information.
Google API data
A Bounty user can choose to connect Google Ads, Google Analytics 4 (GA4), or Google Search Console. Bounty requests Google Ads access to discover and select authorized advertiser accounts, read-only Google Analytics access to discover and select authorized GA4 properties, and the https://www.googleapis.com/auth/webmasters.readonly scope to discover and read selected Search Console properties. Bounty cannot access an account or property the authorizing Google user cannot access.
Search Console access is read-only. Bounty lists the domain and URL-prefix properties available to the authorizing account, and the user chooses which properties belong to the current Bounty organization. Bounty reads finalized daily Search Analytics data for those properties, including date, query, canonical page URL, clicks, impressions, click-through rate, and average position. Google may omit privacy-protected or lower-volume query rows, so query-level data may not equal complete page totals. Bounty does not modify properties or submit indexing changes.
The native connections store the OAuth credential and selected accounts or properties for the customer's Bounty organization. Google credentials are encrypted in organization-specific Vault secrets, remain server-side, are not returned to the browser, and are not shared with another Bounty organization. When a customer activates a Bounty data workflow using a connection, Bounty processes the selected Google data only to provide the customer-visible reporting, analysis, recommendations, and workflows the customer requests.
See the detailed Google Ads, Google Analytics, and Google Search Console integration documentation. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
How we use data
- Provide, operate, secure, and support Bounty.
- Authenticate users and enforce organization and account permissions.
- Connect customer-authorized systems and deliver requested reporting, analysis, recommendations, and workflows.
- Monitor reliability, investigate errors, prevent misuse, and improve product performance.
- Administer customer relationships, billing, legal obligations, and business communications.
AI processing and customer-specific models
Bounty uses AI to return customer-visible analysis, summaries, recommendations, chat responses, and workflow outputs. Where needed to produce a requested feature, Bounty may send de-identified data, including de-identified Google-derived data, to OpenAI or Anthropic as contracted subprocessors. We do not allow these providers to use submitted customer data to train their general models.
A customer may choose features that personalize a model or model artifact for that customer’s Bounty organization. Google-derived data used for this purpose keeps its organization provenance, remains isolated to the authorizing organization, and is never pooled, commingled, or used to train a generalized, foundational, or cross-customer model.
How we share data
We share data only as needed to provide and protect Bounty, follow customer instructions, or meet legal obligations. Recipients may include hosting, database, monitoring, support, analytics, AI, and integration service providers under contractual confidentiality and data-protection obligations.
We do not sell personal data, Google user data, or OAuth credentials. We do not share Google-derived data for advertising, credit, insurance, employment, or unrelated profiling.
Security and access
Bounty uses organization-scoped authorization, encryption in transit, encrypted credential storage, restricted service access, logging, monitoring, and vendor controls appropriate to the service. OAuth access and refresh credentials remain server-side and are not returned to the browser after authorization.
No system is completely secure. Customers should grant only the access needed and remove access when it is no longer required.
Retention, disconnection, and deletion
We retain account and customer data while the customer relationship is active and as needed to provide the service, meet contractual instructions, resolve disputes, secure the service, and comply with law. Retention may differ by data type and customer agreement.
Disconnecting Google Ads, GA4, or Google Search Console in Bounty removes that organization's stored OAuth credential and native account or property selections and stops future access through that connection. Disconnecting Search Console also disables future synchronization for its Datasets. Synced Search Console data is retained by default so existing reporting remains readable, unless the user chooses the available option to delete synced data. A user can also revoke Bounty from their Google Account permissions. Disconnecting does not by itself delete data previously imported through another customer-configured data path.
A customer can request deletion of previously processed Google-derived data and associated customer-specific model artifacts by contacting us. We remove the requested data from active systems within 30 days unless a shorter contractual period applies or retention is legally required. Encrypted backup copies are isolated from ordinary use and expire through the normal backup lifecycle. Deleted Google-derived data is removed from future training inputs; an affected customer-specific model is deleted or rebuilt without that data.
Privacy rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data, or receive a portable copy. Contact us to make a request. If we process data only for a customer, we may refer the request to that customer.
International processing
Bounty and its service providers may process data in Australia, the United States, and other countries where they operate. Where required, we use contractual and organizational safeguards for international transfers.
Changes to this policy
We may update this policy as Bounty, our providers, or legal requirements change. We will publish the revised policy at https://www.bountygrowth.com/privacy and update the date above. We will provide additional notice where a material change requires it.