Privacy Policy

MarketingLeague · Effective date: 11 July 2026

Who we are

MarketingLeague is an advertising operations platform for agencies, operated at ops.marketingleague.ai. It helps authorized agency teams connect, diagnose, report on, monitor, plan, and manage advertising accounts. This policy describes the data the platform accesses, how it is used, where it is stored, when it is shared, and the controls available to users.

Data we process

How we use Google user data

Google user data is used only to provide visible, user-facing advertising operations features: account discovery, diagnostics, complete reporting, monitoring, planning, validation, and explicitly approved account changes. Offline access supports monitoring and resumable report generation after a user has connected an account. We do not use Google user data for our own advertising, audience profiling, or unrelated product development.

MarketingLeague's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use Meta data

Meta data is used only for visible, user-facing advertising operations features: Business Portfolio and account discovery, campaign diagnostics, reporting, monitoring, and derived findings. The ads_read permission supplies advertising structure and performance data. The business_management permission identifies the businesses and client advertising accounts the connected person is authorized to access. We do not use Meta data for our own advertising, audience profiling, or unrelated product development, and the current connector does not request ads_management.

Storage and security

OAuth credentials are encrypted at rest using organization-bound envelope encryption and are not exposed in the dashboard, reports, logs, or public links. Core application compute and report-artifact storage run in Google Cloud's EU region; application state is stored in Neon Postgres in Frankfurt, Germany. Cloudflare provides the public edge and traffic protection layer, and WorkOS provides application identity services. Authorized users can access their organization's data. Personnel do not read connected-provider data unless the user has affirmatively agreed to have specific data viewed for support, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for internal service operations. Audit records are kept to make account access and changes reviewable.

Sharing and user-selected AI clients

We do not sell Google or Meta user data and do not share one customer's data with another customer. Data is processed by Google Cloud, Neon, Cloudflare, and WorkOS only as needed to operate, store, secure, and authenticate the service. When a user directs a connected agent client such as ChatGPT, Claude, or Codex to run a MarketingLeague workflow, the relevant account data or derived result may be returned to that user-selected client to fulfill the request. We do not use Google or Meta user data to create, train, or improve generalized or foundational AI models.

Reports are private by default. If an authorized user deliberately enables a public report link, a sanitized report can be viewed by anyone who has that bearer link. The user can disable the link immediately. Public report views omit connection credentials and internal identity fields.

Retention, disconnection, and deletion

Disconnecting a Google connection immediately removes the stored OAuth credential and connected account inventory from active MarketingLeague state. If MarketingLeague can confirm it is the last stored connection for that Google identity, MarketingLeague also asks Google to revoke the project grant. When another stored connection shares that Google identity, or MarketingLeague cannot safely identify the grant, the project grant remains active. If Google cannot complete a revocation attempt, the local credential is still deleted. In either case, the user can revoke the project grant directly from Google Account permissions.

Reports, snapshots, monitoring runs, plans, and limited audit metadata are not automatically deleted merely because a connection is disconnected; they remain available to the organization for continuity and accountability. An authorized user can request deletion of retained account data at any time. We remove requested customer data from active systems after verification of the request, subject only to limited security, legal, and fraud- prevention records. Residual backup copies age out under the applicable backup schedule and are not used for normal processing. See the deletion instructions.

Disconnecting Meta removes the encrypted access token and account inventory from active MarketingLeague state. A person can also remove MarketingLeague from Facebook's Business Integrations settings. Meta sends MarketingLeague a signed deauthorization request when the integration is removed and a signed deletion request when the person uses Meta's data- deletion control; after signature verification, MarketingLeague removes the matching Meta connection and starts deletion of retained data associated with that Meta user ID.

Your controls

Changes and contact

We update this policy when our data practices materially change. If a change introduces a new use of Google or Meta user data, we will provide notice and obtain any consent required before applying that use. For privacy questions, access requests, or deletion requests, contact privacy@marketingleague.ai.