Privacy policy
Last updated 8 October 2026
What we collect, why we collect it, who sees it and what you can do about it, in plain language.
1.Who we are
WickLabs is a brand of Growvia Solutions, an education and software business based in Sri Lanka. Growvia Solutions decides how and why your personal data is used, which makes it the “controller” of that data. This policy explains what we collect and what we do with it.
2.What we collect
- Account details: your name, email address and a one-way hash of your password (we cannot read your password). If you sign in with Google, we receive your name, email and profile picture from Google.
- Journal data: the trades, notes, accounts, playbooks and files you put into the journal. It is yours, and it is stored so that only your account can reach it.
- Consultation and contact requests: what you type into our forms, such as your name, email, Discord name, experience, markets, goals and time zone.
- Purchases: what you bought and when. Card and payment details are collected and held by our payment provider, not by us.
- Technical data: your IP address and browser details when you log in, kept with your session, and counters used to limit abuse such as repeated login attempts.
We do not knowingly collect data from anyone under 18.
3.How we use it, and why
- To create and run your account, and deliver what you bought (contract).
- To book and run consultations and mentorship, and to reply to your requests (contract and legitimate interests).
- To take payments, prevent fraud and meet tax and accounting duties (contract and legal obligation).
- To email you about your account, purchases and password resets (contract).
- To keep the service secure and working, and to fix problems (legitimate interests).
- To send you news or offers, only if you ask us to, and you can stop at any time (consent).
We do not sell your personal data, and we do not use your journal data for advertising.
6.Where your data is processed
Our providers may process data in countries other than yours, including the United States and the European Union. Where we transfer personal data internationally we rely on the safeguards our providers offer, such as standard contractual clauses.
7.How long we keep it
- Account and journal data: until you delete your account. Deleting it erases your profile and journal data.
- After a journal subscription ends: your journal is read-only for 90 days so you can export it, then it may be deleted.
- Consultation requests: for as long as needed to follow up, then deleted or anonymised.
- Purchase and payment records: for as long as tax and accounting rules require.
- Backups: copies roll off within a short, fixed period after deletion.
8.How we protect it
Passwords are stored only as one-way hashes. Each journal record is locked to its owner inside the database itself, and our own code cannot read another person’s journal data in normal operation. Traffic is encrypted in transit. No system is perfectly secure, so please use a strong, unique password.
9.Your rights
Depending on where you live, you can ask us to:
- give you a copy of your personal data;
- correct anything that is wrong;
- delete your data (you can also delete your account yourself on the Account page);
- limit or object to how we use it, or move it to another service;
- withdraw consent you gave us, at any time.
Contact us through support.growvia@gmail.com and we will reply within a reasonable time, normally within 30 days. If you are unhappy with our answer you may complain to your local data protection authority.
10.Changes
We may update this policy as the service grows. The date at the top shows the latest version, and we will tell you about important changes. See also our Terms of service.
11.Contact
Privacy questions or requests: support.growvia@gmail.com.