MarkGrid

MarkGrid · Legal

Privacy Policy

Last updated: September 21, 2026

MarkGrid is committed to protecting the privacy of our customers, prospects, and visitors. This Privacy Policy outlines how we collect, use, store, and share information across the MarkGrid platform and website.

What we collect

We collect information you provide directly (such as your name, work email, and company when you request a demo), data your team configures in the platform (brand guidelines, competitor lists, integration credentials stored as encrypted tokens), and standard telemetry from authenticated platform usage. We do not collect personal data from visitors to your owned channels.

How we use it

Customer data is used solely to operate the MarkGrid platform for the customer's authorized users. We do not train shared or third-party AI models on customer-private data. Aggregate, fully anonymized signals may inform platform improvements and benchmarks.

Where data is stored

Customer data is encrypted at rest (AES-256) and in transit (TLS). MarkGrid's primary database runs on Supabase's managed infrastructure on AWS in the Sydney, Australia region (ap-southeast-2), with a replica in the same region.

Your rights

Customers can request data export, deletion, or correction at any time through their account administrator. MarkGrid supports GDPR, India DPDP Act, and CCPA obligations through documented processes and a Data Processing Addendum available on request.

Google user data we access

If you connect a Google Ads account, MarkGrid asks for three Google permissions. The https://www.googleapis.com/auth/adwords permission lets us read the Google Ads accounts you choose to connect: account names, campaigns, ad groups, ads and creatives, and their performance metrics such as impressions, clicks, cost, conversions and impression share. We only read this data. MarkGrid does not create, edit, pause or delete anything in your Google Ads account, and does not change budgets or bids. The userinfo.email and openid permissions let us see the email address of the Google account that approved the connection, so your team can tell which login each connection uses. We do not access any other Google data, such as Gmail, Drive or Contacts.

How we use Google user data

We use Google user data only to provide the Ads Performance features you see in MarkGrid: importing up to 13 months of history when you connect, keeping it up to date, and showing reports to the authorized users of your brand workspace. We do not use Google user data to serve or target advertising, we do not sell it, we do not use it to decide creditworthiness or for lending, and we do not use it to develop, improve or train generalized or shared AI or machine learning models. Google user data is not included in the anonymized signals or benchmarks described above.

Limited Use

MarkGrid's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. MarkGrid staff do not read your Google user data unless you ask us to (for example, to troubleshoot a sync), it is needed for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

How Google user data is shared

Google user data is visible only to the authorized users of the brand workspace it was connected to. We do not transfer it to anyone else, except to the providers that host MarkGrid's infrastructure, solely so they can run the service for us; when required by law; or as part of a merger, acquisition or sale of assets, in which case we will notify you first.

How we protect Google user data

Google user data travels to and from MarkGrid over TLS, and is encrypted at rest with AES-256. The credential Google issues when you connect is protected more tightly still: it is sealed with AES-256-GCM before it reaches the database, using keys held outside the database in the application environment, and those keys are versioned so they can be rotated without re-encrypting stored history. That credential is never sent to your browser and is never written to our application logs; only MarkGrid's own backend services can use it, and they authenticate to one another with a separate shared secret. Each customer's Google data is kept separate by row-level security enforced in the database itself, not only in application code, so one brand workspace cannot read another's. Access to production systems is limited to a small number of authorized team members. MarkGrid never receives or stores your Google password: access is by an OAuth credential that you can revoke at any time at https://myaccount.google.com/connections.

Keeping, revoking and deleting Google user data

The credential Google issues when you connect is encrypted with AES-256 before we store it. Synced Google Ads data is kept for as long as your brand workspace uses MarkGrid, so your reporting history stays available. You can revoke MarkGrid's access at any time at https://myaccount.google.com/connections. Once you do, MarkGrid can no longer read data from your account. Revoking access does not delete data already synced. To delete it, follow the steps at https://markgrid.ai/data-deletion or email privacy@markgrid.ai. If your MarkGrid subscription ends, we delete your data as described in our Terms of Service.

Meta user data we access

If you connect a Meta advertising account (Facebook or Instagram ads), MarkGrid asks for the ads_read and ads_management permissions, and the business_management permission where your ad accounts belong to a business portfolio, through Facebook Login for Business. They let us read the ad accounts you choose to connect: account names, campaigns, ad sets, ads and creatives, and their performance insights such as impressions, reach, clicks, spend and conversions. We also receive the ID and name of the Facebook account that approved the connection, so your team can tell which login each connection uses. MarkGrid changes something in your Meta ad accounts, such as pausing or resuming an ad or adjusting a budget, only when an authorized person on your team chooses to make that change in MarkGrid. We never make changes on our own. We do not access your personal Facebook profile, friends, messages, Pages or posts.

How we use and share Meta user data

We use Meta user data only to provide the Ads Performance features you see in MarkGrid: importing your advertising history, keeping it up to date, showing reports to the authorized users of your brand workspace, and carrying out the campaign changes they ask for. We do not use it to serve or target advertising, we do not sell it or pass it to data brokers, we do not use it to build profiles of individuals, and we do not use it to develop, improve or train generalized or shared AI or machine learning models. It is visible only to the authorized users of the brand workspace it was connected to, and is shared only with the providers that host MarkGrid's infrastructure, solely so they can run the service for us; when required by law; or as part of a merger, acquisition or sale of assets, in which case we will notify you first. Our handling of this data follows the Meta Platform Terms (https://developers.facebook.com/terms).

How we protect Meta user data

Meta user data travels to and from MarkGrid over TLS, and is encrypted at rest with AES-256. The access token Meta issues when you connect is sealed with AES-256-GCM before it reaches the database, using versioned keys held outside the database in the application environment. That token is never sent to your browser and is never written to our application logs; only MarkGrid's own backend services can use it, and they authenticate to one another with a separate shared secret. Each customer's Meta data is kept separate by row-level security enforced in the database itself, not only in application code. Access to production systems is limited to a small number of authorized team members. MarkGrid never receives or stores your Facebook password.

Keeping, revoking and deleting Meta user data

The access token Meta issues when you connect is encrypted with AES-256 before we store it. Synced Meta ad data is kept for as long as your brand workspace uses MarkGrid. You can remove MarkGrid's access at any time from Facebook: Settings and privacy, then Settings, then Business integrations (https://www.facebook.com/settings/?tab=business_tools), and remove MarkGrid. Once you do, MarkGrid can no longer read data from or make changes to your ad accounts. Removing access does not delete data already synced. To delete it, follow the steps at https://markgrid.ai/data-deletion or email privacy@markgrid.ai.

Subprocessors

A full list of subprocessors used to deliver the MarkGrid platform is available on request as part of the security pack. We commit to advance notice of material changes to enterprise customers under contract.

Questions about how we handle data? Email privacy@markgrid.ai for a full Data Processing Addendum, security pack, or specific data inquiry.

This document is intended as a plain-language summary for prospective customers. Enterprise customers receive the full executed legal documentation as part of the contract pack. For any conflict between this summary and an executed agreement, the agreement controls.