Your commercial data, handled like it matters
Spend, margin and customer behaviour are some of the most sensitive numbers a business has. Here is exactly how they are stored, who can reach them and how you get them removed.
Isolated per client
Every client workspace is scoped at the database level. A query that is not tied to a workspace you belong to returns nothing, and that rule is enforced server side rather than in the interface.
Least-privilege connections
Channel connections request the narrowest scope that supports the workspace. Read-only is the default, and any write scope is enabled deliberately with your sign-off.
Encrypted in transit and at rest
Traffic is served over TLS and stored data is encrypted at rest. Access tokens are held in managed secret storage, never in application code or client bundles.
Role-based access
Roles are stored separately from user profiles and checked server side on every request, so access cannot be escalated from the browser.
Auditable changes
Budget, bid and creative changes made through the platform are logged with who, when and why, and later measured against what actually happened.
Deletion on request
You can request removal of a connection, a client workspace or your whole account, and we remove the associated data rather than archiving it indefinitely.
Common questions
Who can see our data?
Your team, plus the named account manager assigned to your workspace. Access is granted per client, not across the platform, and is removed when an engagement ends.
Is our data used to train models?
No. Your commercial data is used to run your workspace. Benchmarks shown in the product are aggregated and anonymised, and never expose another business's figures.
What happens if we leave?
We export what you want to keep, disconnect the channels and delete the workspace data. Nothing stays connected to your ad accounts once the engagement ends.
Need to remove data now? Use the data deletion route.