LEGAL / PRIVACY
Privacy Policy
This policy explains what information getMetrics handles, why we handle it, and the choices available to you.
Effective July 28, 2026
1. About this policy
getMetrics provides a control plane and live-query connector service for advertising, analytics, and social platforms. This Privacy Policy applies when you visit our website, create an account, join an organization, connect a third-party platform, or use getMetrics through destinations such as Data Studio and Google Sheets.
In this policy, “getMetrics,” “we,” “us,” and “our” refer to the operator of the getMetrics service. “You” means the person using the service or the organization on whose behalf that person acts.
2. Information we collect
Account and profile information
We collect information such as your email address, name, profile image, authentication records, and account security events when you register or sign in.
Organization and subscription information
We process organization names, memberships, roles, invitations, plan entitlements, usage limits, subscription status, and related billing records. If payment processing is introduced, payment card details will be handled by the payment provider rather than stored directly by getMetrics.
Connected-platform information
When you authorize a platform, we may receive the connected identity, provider account identifiers, account names, granted permissions, selected advertising or analytics accounts, connection health, and access or refresh credentials. Provider credentials are encrypted at rest and are not exposed to browser clients or connector scripts.
Query, usage, and diagnostic information
We process query configuration such as selected accounts, requested fields, date ranges, filters, destination, response size, timing, cache state, safe provider error codes, and rate-limit observations. getMetrics is live-query first: customer performance results are not retained as a permanent reporting warehouse by default. Results may be held in a short-lived cache to improve reliability and reduce repeated provider requests.
Device and technical information
We may collect IP address, browser and device information, request identifiers, cookies, session information, security logs, and similar technical data needed to operate and protect the service.
3. How we use information
- Provide authentication, organization access, connectors, and live data queries.
- Store and apply your selected accounts, permissions, and connector configuration.
- Enforce plan limits, prevent abuse, and manage rate limits and request deduplication.
- Diagnose errors, monitor availability, improve performance, and support users.
- Protect accounts, investigate suspicious activity, and comply with legal obligations.
- Communicate service, security, policy, and account-related updates.
4. Google API Services user data
When you connect a Google service, getMetrics accesses Google user data only after you grant permission through Google OAuth. Depending on the features you choose, this may include your basic Google Account identity; Google Ads accounts and reporting data; Google Analytics properties and reports; Search Console verified sites and performance data; YouTube channels, videos, analytics, and monetary reports; and Google Sheets spreadsheets, ranges, and report output that you select.
How Google user data is used
We use Google user data only to provide user-facing getMetrics features. This includes identifying the Google Account that authorized a connection, listing resources the account can access, running the live reporting queries you request, writing results to the Data Studio or Google Sheets destination you choose, and performing scheduled spreadsheet refreshes that you configure. Apps Script permissions are used to display the Sheets sidebar, call the getMetrics backend, and create or manage user-authorized refresh triggers.
Storage and protection
Google OAuth access and refresh credentials are stored only in trusted server systems, encrypted at rest, and are not exposed to browser clients or connector scripts. We retain connected resource identifiers, names, granted scopes, query configuration, and operational records needed to provide and secure the service. Reporting results are not retained as a permanent analytics warehouse by default and may be held in a short-lived cache. Results sent to Google Sheets are written only to the spreadsheet and range selected by the user.
Sharing, transfer, and prohibited uses
We disclose Google user data only as necessary to provide the requested getMetrics feature: to authorized members of your organization, to the reporting destination you select, and to service providers that process data on our behalf under appropriate confidentiality and security obligations. We do not sell Google user data, use it for advertising or retargeting, provide it to data brokers or information resellers, use it to determine creditworthiness or for lending, or use it to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Retention, deletion, and revocation
You may disconnect a Google service in getMetrics or revoke access from your Google Account. Disconnecting removes or invalidates the associated OAuth credentials, subject to provider behavior and limited backup retention. Short-lived query caches expire automatically. You may also request deletion by following our User Data Deletion instructions.
Google API Services User Data Policy
getMetrics's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Legal bases
Where applicable law requires a legal basis, we process information to perform our agreement with you, pursue legitimate interests in operating and securing the service, comply with legal obligations, and act on consent where consent is required. You may withdraw consent, but doing so may prevent the relevant connection or feature from working.
6. How information is shared
We may share information only as needed with:
- Infrastructure and service providers that support hosting, authentication, databases, caching, monitoring, communications, and payment processing.
- Platforms you choose to connect, such as Meta, Google, TikTok, LINE, and other supported providers, in order to complete authorization and requested queries.
- Members of your organization according to their assigned role and the resources shared within that organization.
- Authorities or professional advisers when reasonably necessary to comply with law, protect rights, or address fraud and security threats.
- A successor in connection with a merger, acquisition, financing, reorganization, or sale of the service, subject to appropriate safeguards.
We do not sell personal information or connected-platform data.
7. Retention and deletion
We retain account, organization, and configuration information while your account or organization remains active and for a reasonable period afterward when required for security, dispute resolution, legal compliance, or backup recovery. OAuth credentials are removed or invalidated when the associated connection is deleted, subject to provider behavior and backup retention. Query caches expire automatically according to the applicable cache policy.
You can disconnect a platform from the Connections page. For account or organization deletion requests, follow our User Data Deletion instructions or contact us using the details below.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including tenant access controls, server-side authorization, encrypted provider credentials, restricted secret access, and operational monitoring. No online service can guarantee absolute security, so you should also protect your credentials and promptly report suspected unauthorized access.
9. International processing
The service and its providers may process information in countries other than your own. Where required, we use contractual, organizational, or other lawful safeguards for international transfers.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent or submit a complaint to a data protection authority. We may need to verify your identity and organization authority before completing a request.
You may manage connected accounts and selected resources inside getMetrics. You can also revoke provider access from the relevant third-party platform.
11. Children
getMetrics is a business service and is not directed to children under 18. We do not knowingly collect personal information from children.
12. Third-party services
Connected platforms and destinations operate under their own terms and privacy policies. Their handling of information is controlled by those policies, and getMetrics is not responsible for their independent practices.
13. Changes to this policy
We may update this policy to reflect changes to the service, law, or our practices. We will post the revised policy here, update the effective date, and provide additional notice when required.
14. Contact
For privacy questions or requests, email privacy@getmetrics.me.