Privacy Policy
Who we are
MarketingLeague is an advertising operations platform for agencies, operated at
ops.marketingleague.ai. It helps authorized agency teams connect, diagnose,
report on, monitor, plan, and manage advertising accounts. This policy describes the data
the platform accesses, how it is used, where it is stored, when it is shared, and the
controls available to users.
Data we process
- Application identity data — name, email address, organization, role, and authentication records used to sign users in and enforce access controls.
- Google connection data — the connected Google identity, OAuth scopes granted, encrypted refresh token, connection status, and accessible account inventory.
- Meta connection data — the connected Meta user ID, OAuth scopes granted, encrypted access token, token and data-access expiry, connection status, accessible Business Portfolio inventory, and accessible advertising-account inventory.
- Google Ads data — account and campaign structure, targeting, budgets, bidding, ads, assets, search terms, placements, conversion configuration, recommendations, change history, policy state, and performance metrics. When a user has enabled edit access, MarketingLeague may also perform only the changes that the user has deliberately requested and approved.
- Search Console data — only when separately enabled: accessible properties, search queries and pages, clicks, impressions, click-through rate, position, sitemaps, and URL inspection status. MarketingLeague uses the read-only scope and does not modify Search Console data.
- Meta Ads data — advertising-account, campaign, ad-set, and ad structure; delivery status; spend; results and conversions; cost-per-result; and return-on-ad-spend metrics. The current Meta connector is read-only and does not create, edit, publish, pause, or delete Meta advertising objects.
- Derived platform data — snapshots, monitoring results, reports, plans, findings, approvals, and audit records produced from connected account data.
How we use Google user data
Google user data is used only to provide visible, user-facing advertising operations features: account discovery, diagnostics, complete reporting, monitoring, planning, validation, and explicitly approved account changes. Offline access supports monitoring and resumable report generation after a user has connected an account. We do not use Google user data for our own advertising, audience profiling, or unrelated product development.
How we use Meta data
Meta data is used only for visible, user-facing advertising operations features: Business
Portfolio and account discovery, campaign diagnostics, reporting, monitoring, and derived
findings. The ads_read permission supplies advertising structure and
performance data. The business_management permission identifies the businesses
and client advertising accounts the connected person is authorized to access. We do not use
Meta data for our own advertising, audience profiling, or unrelated product development,
and the current connector does not request ads_management.
Storage and security
OAuth credentials are encrypted at rest using organization-bound envelope encryption and are not exposed in the dashboard, reports, logs, or public links. Core application compute and report-artifact storage run in Google Cloud's EU region; application state is stored in Neon Postgres in Frankfurt, Germany. Cloudflare provides the public edge and traffic protection layer, and WorkOS provides application identity services. Authorized users can access their organization's data. Personnel do not read connected-provider data unless the user has affirmatively agreed to have specific data viewed for support, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for internal service operations. Audit records are kept to make account access and changes reviewable.
Sharing and user-selected AI clients
We do not sell Google or Meta user data and do not share one customer's data with another customer. Data is processed by Google Cloud, Neon, Cloudflare, and WorkOS only as needed to operate, store, secure, and authenticate the service. When a user directs a connected agent client such as ChatGPT, Claude, or Codex to run a MarketingLeague workflow, the relevant account data or derived result may be returned to that user-selected client to fulfill the request. We do not use Google or Meta user data to create, train, or improve generalized or foundational AI models.
Reports are private by default. If an authorized user deliberately enables a public report link, a sanitized report can be viewed by anyone who has that bearer link. The user can disable the link immediately. Public report views omit connection credentials and internal identity fields.
Retention, disconnection, and deletion
Disconnecting a Google connection immediately removes the stored OAuth credential and connected account inventory from active MarketingLeague state. If MarketingLeague can confirm it is the last stored connection for that Google identity, MarketingLeague also asks Google to revoke the project grant. When another stored connection shares that Google identity, or MarketingLeague cannot safely identify the grant, the project grant remains active. If Google cannot complete a revocation attempt, the local credential is still deleted. In either case, the user can revoke the project grant directly from Google Account permissions.
Reports, snapshots, monitoring runs, plans, and limited audit metadata are not automatically deleted merely because a connection is disconnected; they remain available to the organization for continuity and accountability. An authorized user can request deletion of retained account data at any time. We remove requested customer data from active systems after verification of the request, subject only to limited security, legal, and fraud- prevention records. Residual backup copies age out under the applicable backup schedule and are not used for normal processing. See the deletion instructions.
Disconnecting Meta removes the encrypted access token and account inventory from active MarketingLeague state. A person can also remove MarketingLeague from Facebook's Business Integrations settings. Meta sends MarketingLeague a signed deauthorization request when the integration is removed and a signed deletion request when the person uses Meta's data- deletion control; after signature verification, MarketingLeague removes the matching Meta connection and starts deletion of retained data associated with that Meta user ID.
Your controls
- Choose which Google identity and advertising accounts to connect.
- Choose which Meta identity, Business Portfolio, and advertising accounts to connect.
- Grant optional Search Console access separately and only when needed.
- Keep Google read-only or deliberately enable approval-controlled Google edit access; the Meta connection remains read-only.
- Disconnect a connection, revoke Google or Meta access, disable public report links, or request deletion of retained data.
Changes and contact
We update this policy when our data practices materially change. If a change introduces a new use of Google or Meta user data, we will provide notice and obtain any consent required before applying that use. For privacy questions, access requests, or deletion requests, contact privacy@marketingleague.ai.