MorrowYour workspace
Back to MorrowCLEAR FROM THE START

Privacy policy

How we handle information, and the choices you have.

Last updated 11 September 2026

Morrow is operated by Aleksander Jørgensen and Maksim Polupanov.

Contact us at hello@morrowsocial.com.

What this policy covers

This policy covers hiremorrow.io, app.hiremorrow.io, Morrow-hosted booking pages, and the connections you enable for Morrow. We are responsible for information used to run Morrow, including account administration, demos, support, billing and service security. A business using Morrow remains responsible for its own leads, customers and marketing choices; we handle that business’s customer information on its instructions. If you contact a clinic through its booking page, its own privacy notice also applies.

Information we use

  • Accounts and demos: name, email, phone, business website, role, goals, preferences, demo requests, appointment details, subscription identifiers and support correspondence.
  • Your workspace: conversations, uploaded documents, business facts, research, creative assets, marketing methods, campaign proposals, review feedback, execution records and usage information.
  • Connected services: the account and business identifiers, permissions, access credentials and records needed for the features you authorize. This can include ad accounts, Pages, ads, spend and campaign metrics; CRM contacts, consent, appointments and calendars; and messages directed to Morrow in connected conversations.
  • Booking requests: the visitor’s supplied name, email or phone, selected communication consent, page and campaign identifiers, and available referral parameters such as UTMs or a Meta click identifier.
  • Technical records: IP address and request information handled by our hosting and security services, login/session information, errors, integration events and audit records.

Public market research may include business listings, websites, public offers, ads and reviews. Sources may be incomplete or outdated; a competitor’s visible ad does not establish its results.

Why we use it

We use this information to provide your account and requested demo; research and prepare marketing work; retrieve relevant business knowledge; carry out authorized actions; route booking requests; respond to conversations; manage subscriptions; prevent abuse; and investigate failures. Review feedback helps Morrow remember your preferences. It is kept distinct from measured campaign outcomes.

Where European data-protection law applies, account and requested-service processing relies on performing our agreement or taking steps you request before it; security and service administration rely on legitimate interests; required records rely on legal obligations; and optional marketing relies on the relevant consent. You can withdraw consent without changing the lawfulness of earlier processing.

AI and your instructions

Relevant messages, business information, selected documents, images and tool results may be sent to AI providers to generate answers, research and creative work. AI can make mistakes. Morrow prepares ad and campaign changes for review, and may adjust spend within the permissions and limits you configure. Do not upload patient medical records, diagnoses, treatment notes or other sensitive health information. Morrow is a marketing service, not a medical-record system.

Uploaded research and conversations become workspace context; they do not automatically retrain an AI model’s weights. We do not sell personal information or use one customer’s private workspace as another customer’s knowledge base.

Services that receive information

We use Cloudflare for hosting and security, Supabase for database, authentication and private file storage, OpenAI for AI processing, and Stripe for payment processing. Stripe collects payment details through its own payment interface; Morrow does not store full card numbers.

GoHighLevel handles our demo intake and calendar and, when connected, customer CRM and messaging workflows. Meta handles authorized Facebook and Instagram advertising; Slack and WhatsApp handle their connected conversations where supported. Outscraper supplies local-business research. Google Maps or Places may be used if enabled. Customer-configured tools and MCP services receive the information needed for the actions you authorize. Each service also processes information under its own applicable terms and privacy policy.

Information may be processed in the United States and other countries where these providers operate. Our application database is hosted in the United States. Where required, international transfers must use applicable safeguards, such as contractual protections. Contact us for information about safeguards for your account.

Storage and retention

Workspace records remain available while needed to provide the service, support recovery, explain decisions and meet contractual or legal duties. The relevant criteria include account activity, customer instructions, pending work or disputes, security needs and required financial records. Archiving a document removes it from active retrieval; it does not physically erase the original or historical records.

You can request deletion of specific information or an account. We will explain any information that must be retained and why. Copies in backups are handled through the backup lifecycle and must not be restored to active use after an approved deletion. Disconnecting a service revokes Morrow’s access but does not erase records already held by that service.

Cookies and browser storage

Morrow uses session and browser storage for sign-in, security, workspace preferences and conversation continuity. Cloudflare Turnstile checks for automated abuse during authentication. Opening a connected provider’s calendar, checkout or authorization page may allow that provider to use its own cookies. This policy does not authorize advertising trackers or optional cookies that require separate consent.

Your choices and rights

Contact hello@morrowsocial.com to request access, correction, export, deletion, restriction, or to object to processing. Your rights depend on the law and circumstances, and you can complain to your relevant data-protection authority. Workspace owners can export the business records available in Settings and disconnect integrations in Connections. For clinic-held data, contact the clinic; we can help route requests concerning a Morrow-hosted page.

We verify requests proportionately to protect your information. Where GDPR applies, we respond within one month, and tell you within that period if a lawful extension is necessary. See our data-deletion instructions for the information to include.

Changes to this policy

We update this page when our handling of information changes. Material changes affecting existing accounts will be communicated through an appropriate account or contact channel. The date above identifies this version.

Something unclear? We’re here at hello@morrowsocial.com.

PrivacyTermsData deletion