This Privacy Policy explains how Grovr LLC (“Grovr,” “we,” “us,” or “our”), a Delaware limited liability company and a wholly-owned subsidiary of Dominion Labs Inc., collects, uses, discloses, and protects personal information in connection with grovr.co, the Grovr applications, and our related products and services (together, the “Services”). Grovr LLC is the controller of the personal information processed through the Services.
Grovr is used by three kinds of people, and what we collect depends on which one you are:
By using the Services you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.
This Privacy Policy explains how Grovr LLC, a Delaware limited liability company and a wholly-owned subsidiary of Dominion Labs Inc. (“Grovr,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with grovr.co, the Grovr applications, and our related products and services (together, the “Services”).
It applies to Residents who report and follow maintenance, Property Teams (the property managers and owners who run maintenance), and Grovr Pros (the independent contractors who perform it). Where a Property Team gives us information about its residents or units, we act as a service provider / processor to that Property Team for that information, and this Policy describes our own practices. Dominion Labs Inc. operates separate services under its own privacy policy; this Policy governs the Grovr Services only.
By using the Services you acknowledge that you have read this Policy. If you do not agree with it, do not use the Services.
At or before the point of collection, this section summarizes the categories of personal information we collect, why, and how long we keep it. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under California and other state laws.
| Category | Collected | Purpose | Retained |
|---|---|---|---|
| Identifiers (name, email, phone, account & device IDs, IP) | Yes | Operate the Services, accounts, security | Life of account + legal minimums |
| Commercial information (requests, invoices, transactions) | Yes | Deliver, schedule, bill, and record jobs | Job/warranty/tax period |
| Government identifiers & identity documents (pro ID/passport) | Pros only | Verify identity to accept work | Kept only to complete/evidence verification |
| Biometric information (face scan, faceprint) | Pros only | Liveness & face-match verification | Destroyed promptly, typically ≤ 30 days |
| Geolocation (single arrival point) | Pros only | Confirm on-site attendance | With the job record |
| Internet/usage activity (pages, actions, logs) | Yes | Security, support, service improvement | Rolling operational period |
| Audio/visual (photos you attach) | Yes | Document the issue and the completed work | With the job record |
| Professional/licensing & background-check results | Pros only | Eligibility and compliance | While active + evidence period |
| Communications (support messages, chat with Gro) | Yes | Provide support | Support/audit period |
“Sensitive personal information” (government-ID, biometric data, and precise geolocation) is used only for the verification and attendance purposes above and never to infer characteristics about you. See Sensitive and Biometric Information.
We capture a Grovr Pro’s device location only at the single moment they mark themselves arrived at a job, to confirm the visit took place at the property. We do not track a pro continuously, do not record location off the clock, and do not build a movement history. Residents and Property Teams are never shown a pro’s location. If you do not want your location captured, you cannot be verified on site and should not accept jobs.
To verify Grovr Pros before they can accept work, we collect and process identity documents (an image of a government-issued photo ID or passport and the details read from it) and biometric information — a short live face scan and the facial-geometry template (“faceprint”) derived from it.
We collect these only after you are informed and give consent at the time of verification, and we use them solely to confirm the document is authentic, that the live scan is a real person (a “liveness” check), and that the face on the ID matches you. This is performed for us by our identity-verification provider under contract. We do not sell, lease, trade, or otherwise profit from your biometric identifiers, we do not use them for any other purpose, and we do not disclose them except to that provider or as required by law.
We protect this data using the reasonable standard of care in our industry and retain and destroy it on the schedule in Data Retention. This notice supports residents of Illinois under the Biometric Information Privacy Act (BIPA) and residents of other states with biometric-privacy laws. Government identifiers, biometric data, and precise geolocation are “sensitive personal information” under California and similar laws, and we limit their use to the purposes described here.
We use personal information to: operate the Services (take a request, match it to a pro, schedule the visit, record what was done); show each party what they need (see What Each Party Can See); verify that a pro is licensed, insured, identity-verified, and arrived on site; process payments and produce invoices; send transactional messages; provide support and investigate disputes; maintain safety, prevent fraud and abuse, and enforce our Terms; keep records we are required to keep and establish or defend legal claims; and understand and improve how the Services are used.
We do not use your personal information to serve you third-party advertising, and we do not use the contents of your service requests or photos to train advertising models.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract (operating the Services and completing a job), legitimate interests (security, fraud prevention, service improvement, confirming a pro attended), legal obligation (records we must keep), and consent where we ask for it (including biometric verification).
We use automated logic to match a request to a suitable pro (by trade, coverage area, and availability) and to pause a pro’s availability when offers go repeatedly unanswered. These are operational tools; they do not produce legal or similarly significant effects about you, and a person is involved in disputes and account actions. You can contact us at [email protected] to question a decision.
Our “Gro” support assistant is powered by an AI service provider. When you chat with Gro, your messages are processed to answer your question and, if you ask for a person, to open a support ticket. Your chat content is not used to serve advertising, and our provider does not use it to train models for its other customers.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Grovr works only if certain information moves between the people in a job. We disclose personal information to the following categories of recipients:
Each processes only the information it needs for its role, under contract, and may not use it for its own purposes:
We keep this list current and will update it as our providers change.
Grovr is deliberate about what each role is shown, and we enforce those limits when the data is assembled — not by hiding fields in the page.
We use cookies and similar technologies to keep you signed in, remember preferences, keep the Services secure, and understand usage. We do not use advertising cookies and do not permit third-party ad tracking on the Services. You can control cookies through your browser; blocking some will stop parts of the Services from working.
| Type | Purpose | Duration |
|---|---|---|
| Strictly necessary | Sign-in, security, load balancing, fraud prevention | Session / short-lived |
| Preferences | Remember settings and choices | Up to 12 months |
| Analytics (first-party) | Understand usage to improve the Services | Up to 24 months |
Because we do not sell or share personal information or serve targeted ads, a browser Global Privacy Control or “Do Not Track” signal does not change what we collect; we honour it as an opt-out of sale/share to the extent one is legally required.
We keep personal information only as long as needed for the purposes in this Policy, then delete or de-identify it, unless a longer period is required by law or needed to establish or defend a legal claim.
| Data | Retention |
|---|---|
| Job records (report, photos, notes, assigned pro) | Life of the Property Team’s account, then as needed for warranty, dispute, tax, and audit purposes |
| Arrival location points | Kept with the job record they belong to |
| Pro compliance records (licence, insurance) | While the pro is active and a period afterward to evidence checks |
| Identity documents | Kept only as long as needed to complete and evidence verification |
| Biometric face scan & faceprint | Destroyed promptly after verification — typically within 30 days, and no later than one year after your last interaction with the Services |
| A record that verification occurred, and when | May be kept longer to evidence the check |
| Account information | Deleted or de-identified after the account is closed, unless we must keep it |
| Support communications | Support and audit period |
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and role-based limits on what each account can retrieve. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a security breach affecting your personal information occurs, we will notify affected users and the appropriate authorities as required by, and within the timeframes set by, applicable law.
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, to opt out of certain processing, to limit the use of sensitive information, and to appeal a refusal.
If your account was created for you by a Property Team, that team may also hold information about you independently; you may need to contact them for records they control. You can turn off non-essential notifications in your account; transactional messages about a live job cannot be turned off while the job is in progress.
When a Property Team uploads resident and unit information so work can be requested and performed, Grovr acts as a service provider (California) / processor (GDPR) and handles that information only on the Property Team’s documented instructions and for the purposes of providing the Services. We do not sell it, do not use it for our own purposes, and return or delete it on request, subject to legal retention.
Property Teams that require a signed Data Processing Addendum (including EU Standard Contractual Clauses where relevant) may request one at [email protected], and it will supplement this Policy for that relationship.
The Services are not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
Grovr is operated from the United States and information is processed there. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from your country’s. Where required, we use appropriate safeguards for those transfers, including the European Commission’s Standard Contractual Clauses and the UK Addendum.
We may update this Policy. If we make material changes we will update the “Last updated” date above and, where appropriate, give additional notice. Continuing to use the Services after a change takes effect constitutes acceptance of the revised Policy.
Privacy questions and rights requests: [email protected]
General support: [email protected]
Grovr LLC, a Delaware limited liability company and a wholly-owned subsidiary of Dominion Labs Inc. If you are in the EEA or UK and cannot resolve a concern with us, you may contact your local supervisory authority.
In the past 12 months we collected the categories of personal information listed in Notice at Collection and disclosed them to the categories of recipients in How We Disclose for the business purposes described. We did not sell or share (for cross-context behavioural advertising) personal information, and we do not do so. We do not knowingly sell or share the personal information of consumers under 16.
California residents have the rights to know/access, delete, correct, opt out of sale/sharing (nothing to opt out of on that basis), and limit the use of sensitive personal information. Because we already use sensitive information only for the permitted verification and attendance purposes, exercising the limit right does not change our handling. Exercise any right at [email protected]; you may use an authorized agent and may appeal a refusal. Under California’s “Shine the Light” law (§1798.83), we do not disclose personal information to third parties for their own direct-marketing.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights described in Your Privacy Rights, including access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising or sell personal information, and we obtain consent before processing sensitive data. Exercise any right at [email protected], and appeal a refusal by replying to our decision.
As described in Sensitive and Biometric Information, we collect a face scan and faceprint to verify Grovr Pros, only after informing you and obtaining consent, and use them solely for identity verification. We do not sell, lease, trade, or profit from biometric identifiers, disclose them only to our verification provider or as required by law, protect them with the reasonable standard of care in our industry, and destroy them on the schedule in Data Retention — and in any case within the timeframe BIPA requires.
Our legal bases are set out in How We Use Personal Information. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may object to processing based on legitimate interests and may lodge a complaint with your supervisory authority. International transfers are covered in International Data Transfers. Contact [email protected] for GDPR matters, including our EU/UK representative where one is required.