Customer Data Privacy


Customer data privacy lets you control which personal data GrowPanel stores about your customers. If your customers are private individuals — or your data protection policy calls for data minimization — you can run GrowPanel without storing their names and emails at all.

You'll find the setting under Settings → General → Customer data privacy (admin and owner roles only).


The three levels

LevelWhat GrowPanel stores
Name and email (default)Customer name and email, as provided by your billing source
Name onlyCustomer name, but no email address
Customer IDs onlyNeither name nor email — customers appear as their billing-system ID (e.g. cus_NffrFeUfNV2Hib) everywhere

With Customer IDs only, every surface — reports, customer lists, exports, email reports, the AI analyst, the API and the MCP server — shows the billing system's customer ID instead of a name. You can always cross-reference the ID in your billing platform, where the full customer record lives.

Tip: if you want a friendlier label than the raw ID without storing personal data, put a pseudonymous label in your billing system's customer metadata (for example an internal user number) — metadata is imported as custom variables and can be used for filtering and segmentation.

Changing the level requires a resync

The setting takes effect as customers are imported. When you change it, GrowPanel automatically starts a full resync of all your connected data sources, rewriting every stored customer according to the new level. Depending on account size this can take from minutes to a few hours; your reports stay available while it runs.

The change works in both directions: your customer data still lives in your billing source, so switching back to Name and email restores names and emails on the next resync — nothing is lost.

Good to know

  • HubSpot sync is incompatible with reduced levels, because it matches contacts by customer email. You'll be asked to disconnect HubSpot before reducing the level, and reduced accounts can't connect HubSpot.
  • MRR numbers are unaffected. The setting only concerns name and email; subscriptions, invoices, movements and metrics are calculated exactly as before.
  • Raw source events: movement detail views can show the raw webhook payload from your billing source, which may contain customer details. If this matters for your setup, contact us.
  • This is data minimization, not anonymization. Billing-system customer IDs are still pseudonymous personal data under GDPR — GrowPanel remains a processor of your customer data, just with a substantially reduced footprint. See our DPA for the full picture.