Privacy Policy

What we collect, why, who else sees it, and how to get it deleted.

TIKGROWTH LTD ("we", "us") runs the TikGrowth client portal at
tikgrowth-cc.com. We are the data controller for the
information described here.

  • Registered address: England and Wale
  • Company number: 16132227
  • Data protection contact: harun@tikgrowth-cc.com

This policy is written under the UK GDPR and the Data Protection Act 2018. If
you are in the EU, the EU GDPR gives you the same rights and you can exercise
them the same way.

The short version

You can read the whole thing, but the parts people actually want to know are:

  • We do not sell your data, and we do not run advertising on it.
  • Your tracker — your commission figures, your video ideas, your notes — is
    private to you. Your coaches can see it. Other members cannot.
  • The assistant sends your question and the relevant course material to an AI
    provider outside the UK to write the answer. Details in
    How the assistant uses your information.
  • Anything you post in the community Discord channels we have opted in may be
    quoted back to another member by the assistant. Treat those channels as
    public to the membership.
  • You can ask us to delete your account and everything in it, and we will.

What we collect

Information you give us

What Why Lawful basis
Email address It is your login. There is no password — we email you a code. Contract
Your name So the portal and your coach can address you properly. Optional. Contract
Discord username and account ID Only if you choose to connect Discord, so we can grant your access in the server automatically. Consent
Tracker entries — daily commission, videos posted, day rating, notes, product and video cards It is the accountability tool you joined for, and what your coach reviews with you. Contract
Questions you ask the assistant To answer them, and to see which questions the material fails to answer. Contract, and our legitimate interest in improving the programme
Anything you write in a support request To reply to it. Contract

Information we record automatically

What Why Lawful basis
IP address and browser user-agent Shown to you on your account page as "signed-in devices" so you can spot a login that isn't yours, and kept in a security log of sign-ins and permission changes. Legitimate interest in keeping accounts secure
Sign-in times and session records So you can sign out a device remotely and so we can end a session that has been compromised. Legitimate interest in security
Which lessons you have marked complete To show your progress. Contract

We do not use analytics or tracking pixels, we do not build advertising
profiles, and we do not do any automated decision-making that produces legal
effects for you.

Cookies

We set one cookie, called tg_session. It holds your signed session token
and nothing else — no tracking identifier, no advertising ID. It is strictly
necessary to keep you signed in, which is why there is no cookie banner: UK law
does not require consent for a cookie that only does the thing you asked for.

It is HttpOnly (JavaScript cannot read it), Secure (HTTPS only), and
SameSite=Lax. It lasts 30 days, or until you sign out.

Embedded video may set its own cookies once you press play. The walkthrough
video is embedded through youtube-nocookie.com, which does not set cookies
until playback starts. Course videos hosted on Bunny Stream are served from our
own CDN account with signed, expiring links.

Who else sees your information

We use a small number of suppliers. They only get what they need to do their
job, and none of them are allowed to use your data for their own purposes.

Supplier What they receive Where
DeepSeek (AI) Your question, the last few messages of that conversation, and excerpts of the course material that matched it. China. See the AI notice.
Discord Your Discord account ID, if you connect it. USA
Bunny.net (video) Your IP address when you play a course video. EU
YouTube / Google Your IP address if you play the walkthrough video. USA
Cal.com (booking) Your name and email when you book a call. USA
Gmail Your email address, to deliver your access code. USA
Hostinger Everything, as the server the portal runs on. LITHUANIA

Where a supplier is outside the UK, the transfer is covered by the UK
International Data Transfer Addendum to the EU Standard Contractual Clauses, or
by UK adequacy regulations where they apply. You can ask us for a copy of the
safeguards for any specific transfer.

We will also disclose information if we are legally required to — a court order,
a regulator, a police request we are obliged to answer.

We do not sell your personal data. We have never done so and have no plans to.

Your coaches can see your tracker

This is worth stating plainly because it surprises people.

Administrators of the portal — your coaches — can see your tracker: your logged
commission, how many videos you posted, your day ratings, your notes, your
product list and your video cards. They can also ask the assistant for a summary
of how you are getting on, and every time one of them does that, it is written
to a security log with their name against it.

That is the whole point of an accountability tracker — it is not a private
diary, it is a record you and your coach work from. But you should know it
before you write something in the notes field.

Other members cannot see any of it. The assistant refuses to answer
questions about another member's numbers unless the person asking is an
administrator, and it refuses in exactly the same words whether or not that
person exists, so nobody can fish for who is on the programme.

The community Discord

If your coaches have opted a Discord channel into the assistant's knowledge
base, messages in that channel — including yours, and the display name attached
to them — are copied into the portal's search index and may be quoted to another
member as the source of an answer, with a link back to the original message.

Only channels explicitly opted in are read. Direct messages are never read. But
please treat any opted-in channel as visible to the whole membership, because
in effect it is.

If you want your messages excluded, tell us and we will remove them from the
index.

Call recordings

Group calls are recorded so that people who could not attend can catch up. The
recordings live on Fathom and are linked from the Recordings page.

We generate a short written summary of each recording. Before any transcript is
sent to the AI provider for summarising, participant names are replaced with
"Coach" and "Member 1", "Member 2" and so on, and email addresses are stripped
out. The summaries are about the subject matter, not about who said what.

If you do not want to appear in a recording, keep your camera and microphone off
and do not type in the chat, or ask us and we will cut you out.

How long we keep it

What How long
Your account and tracker While you are a member, and for 6 months after you leave, so you can come back to your history. Then deleted.
Assistant transcripts 6 months, then deleted.
Security log (sign-ins, permission changes) 6 months.
Session records Until they expire or you sign them out.
Login codes 15 minutes.
Billing records Six years, because HMRC requires it.

Your rights

Under the UK GDPR you can ask us to:

  • give you a copy of everything we hold about you;
  • correct anything that is wrong;
  • delete your account and its contents ("right to erasure");
  • stop or limit what we do with it;
  • hand it over to you or someone else in a portable format;
  • object to anything we are doing on the basis of legitimate interest.

Where we rely on your consent — connecting Discord, for instance — you can
withdraw it at any time, and disconnecting Discord in your account settings does
exactly that.

Email harun@tikgrowth-cc.com and we will respond within one month. We will not
charge you and we will not make it difficult.

If you think we have handled your data badly, please tell us first so we can put
it right. You also have the right to complain to the Information Commissioner's
Office at ico.org.uk or on 0303 123 1113.

Children

The portal is not for under-18s. We do not knowingly hold data about children.
If you believe a child has an account, tell us and we will remove it.

Security

Sign-in is by one-time code, so there is no password of yours for us to lose.
Session tokens are signed and can be revoked instantly from your account page.
Login codes are stored only as hashes. Uploaded files are served only to
signed-in members and are never executable.

No system is perfectly secure. If we ever suffer a breach that puts your rights
at risk, we will tell the ICO within 72 hours and tell you without undue delay.

Changes

If we change this policy in a way that matters, we will tell you in the portal
before it takes effect. The date at the top is the last change.

Last updated: 4 August 2026.