Privacy Policy
Allmetrics, an internal reporting tool
Last updated: 25 September 2026
1. Who is responsible
Allmetrics is an internal reporting tool at https://allmetrics.integratedcmo.com, operated by [Company legal name], [Country] ("we", "us"). It is used only by our own staff to review the performance of the advertising and sales accounts we manage for our clients. It is not sold or offered to the public, and there is no public sign-up.
Contact for anything in this policy: [Contact email].
2. What data we read
We connect to a platform only after the owner of the account, or someone they authorize, grants access on that platform's own authorization screen. Our access to advertising platforms is read-only: we never create, edit, pause or delete ads, campaigns, audiences or budgets.
- Google Ads (Google Ads API): account, campaign, ad group and ad names and IDs, and daily performance metrics such as cost, impressions, clicks, conversions and conversion value.
- Google Analytics 4 (read-only access): property names and aggregate reports such as sessions, users and conversions.
- Google Drive (only the files Allmetrics itself creates): we upload ad creative files to a Drive folder our staff choose and keep track of them. We cannot see any other file in the Drive.
- TikTok (TikTok API for Business, read-only permissions): ad account ID, name, currency and time zone; campaign, ad group and ad names, IDs and status; daily performance metrics; and the IDs and thumbnails of creatives used in ads.
- Meta (Facebook and Instagram), through our reporting provider Reportei: aggregate advertising performance metrics and account metrics such as follower counts. We do not connect to Meta directly.
- Hotmart: sales of our clients' products, including product, price, currency, commissions, fees, status, dates and tracking parameters, and the buyer's name and email address and Hotmart buyer code, which we store with each sale.
- Kiwify: sales of our clients' products, including product, amounts, status, dates and tracking parameters. We do not store any customer fields from Kiwify, such as name, email, document or address.
From the advertising platforms we receive only aggregate counts. We do not receive names, emails, phone numbers or user IDs of the people who saw or clicked the ads.
For our own staff we store the minimum needed to sign in: their work email and name.
3. How we use it
We use this data only to:
- show our staff the performance of the accounts we manage;
- prepare reports for the client who owns each account, shared as a private link or a WhatsApp message.
We do not use it for advertising, profiling, reselling or any other purpose, and we never show one client's data to another client.
4. Google user data
Allmetrics' use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular, we use Google data only to provide the reporting features described above, we do not transfer it to anyone except as described in section 8, we do not sell it, and we do not use it to serve advertising or to train generalized AI or machine-learning models.
5. Where it is stored
- Data is stored in a PostgreSQL database hosted by Supabase. The application runs on Vercel.
- The database is reached only from the server side of the application. Browsers never query it directly.
- All traffic uses HTTPS.
6. Access tokens and keys
The access tokens and API keys a platform issues when an account is connected are encrypted at rest with AES-256-GCM under a dedicated secret key. They are never sent to a browser and never written to logs.
7. Retention, disconnection and deletion
- We keep performance and sales data for as long as we manage the client's account, and delete it earlier if the client asks.
- When an account is disconnected in Allmetrics, we delete our stored copy of its token or key immediately, and no further data is read. Data already collected is kept until it is deleted as described here.
- An account owner can also revoke our access at any time in the platform's own settings, for example at myaccount.google.com/permissions for Google. The token then stops working.
- To have the data we hold for an account deleted, write to [Contact email]. We will delete it and confirm when it is done.
8. Sharing
We do not sell, rent, license or share this data with third parties. It is shown only to our staff and, in reports, to the client who owns the account. The service providers below process it on our behalf and for no other purpose:
- Supabase (database) and Vercel (hosting);
- Reportei, which supplies the Meta metrics;
- our WhatsApp sending service, which delivers a client's report to that client;
- an AI model provider (through OpenRouter), only when a staff member uses the optional in-app assistant to ask a question about an account; it receives the figures needed to answer that question.
9. Security
- tokens and keys are encrypted at rest;
- database access is server-only;
- the tool is internal and every page except the client report links requires sign-in;
- platform permissions are read-only and limited to what reporting needs.
10. Your rights
Depending on where you are, you may have the right to access, correct or delete data about you, including a buyer's name and email from a sale. To use these rights, write to [Contact email].
11. Changes
We may update this policy. The date at the top shows the latest version.
12. Contact
[Company legal name], [Country]: [Contact email]