Customer Data Privacy
Customer data privacy lets you control which personal data GrowPanel stores about your customers. If your customers are private individuals — or your data protection policy calls for data minimization — you can run GrowPanel without storing their names and emails at all.
You'll find the setting under Settings → General → Customer data privacy (admin and owner roles only).
The three levels
| Level | What GrowPanel stores |
|---|---|
| Name and email (default) | Customer name and email, as provided by your billing source |
| Name only | Customer name, but no email address |
| Customer IDs only | Neither name nor email — customers appear as their billing-system ID (e.g. cus_NffrFeUfNV2Hib) everywhere |
With Customer IDs only, every surface — reports, customer lists, exports, email reports, the AI analyst, the API and the MCP server — shows the billing system's customer ID instead of a name. You can always cross-reference the ID in your billing platform, where the full customer record lives.
Tip: if you want a friendlier label than the raw ID without storing personal data, put a pseudonymous label in your billing system's customer metadata (for example an internal user number) — metadata is imported as custom variables and can be used for filtering and segmentation.
Changing the level requires a resync
The setting takes effect as customers are imported. When you change it, GrowPanel automatically starts a full resync of all your connected data sources, rewriting every stored customer according to the new level. Depending on account size this can take from minutes to a few hours; your reports stay available while it runs.
The change works in both directions: your customer data still lives in your billing source, so switching back to Name and email restores names and emails on the next resync — nothing is lost.
Good to know
- HubSpot sync is incompatible with reduced levels, because it matches contacts by customer email. You'll be asked to disconnect HubSpot before reducing the level, and reduced accounts can't connect HubSpot.
- MRR numbers are unaffected. The setting only concerns name and email; subscriptions, invoices, movements and metrics are calculated exactly as before.
- Raw source events: movement detail views can show the raw webhook payload from your billing source, which may contain customer details. If this matters for your setup, contact us.
- This is data minimization, not anonymization. Billing-system customer IDs are still pseudonymous personal data under GDPR — GrowPanel remains a processor of your customer data, just with a substantially reduced footprint. See our DPA for the full picture.