Privacy policy
Last updated 2 October 2026
Who we are
Agency Hub is a private performance reporting hub operated by Your Agency ("we"). It is used by Your Agency's team and the clients it works with. It is not open to public sign-up. This policy explains what data the hub accesses, why, and how it is protected.
What we access, and only with permission
The hub connects to advertising and e-commerce platforms only when an authorised person signs in to that platform and grants access, or provides an API key. Depending on what is connected, it reads:
- Ad platforms (Meta, Google Ads, TikTok, Pinterest, Snapchat): ad account names and IDs, campaign, ad set and ad names, ad creative (images, video thumbnails, headlines and copy), and aggregated performance figures such as spend, impressions, clicks, conversions and conversion value. Access is read-only; the hub never creates, edits or pauses ads.
- Klaviyo: account name and aggregated metrics (orders, revenue, email sends, opens, clicks). No individual subscriber or customer profiles are read.
- Shopify: store name and aggregated daily sales and order totals. No individual customer or order details are read.
- The connecting account: the name or email address and account ID of the person who connected each platform, so the team can see which login each connection uses.
- Public websites: for strategy research, the hub may read publicly available pages of a client's website and of competitors.
The hub does not collect personal data about the people who see or click ads (the advertisers' customers). Platform figures arrive already aggregated.
People who use the hub
For each login we store a name, email address, role, a securely hashed password (never the password itself) and the time of last sign-in. One essential cookie keeps you signed in; your browser also remembers display preferences such as dark mode. We use no advertising or analytics cookies and no third-party tracking.
How we use it
- To report advertising and store performance to Your Agency's team and to the client the data belongs to.
- To spot notable changes in performance and record them in the client's change log.
- To prepare strategy suggestions, such as creative and email ideas, for the client the data belongs to.
Each client's data is shown only to Your Agency's team and to that client. We do not sell data, use it for advertising, or share it with other clients.
AI features
Some features (strategy research and written performance summaries) send performance summaries, change log notes and public website content to Anthropic's Claude API to generate text. These features run only when a team member requests them. Under Anthropic's commercial terms, data sent through the API is not used to train its models.
Google user data
Your Agency's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Ads data is used only to provide the reporting described above.
Where it is stored and how it is protected
- The hub runs on Vercel and stores data in a Neon (PostgreSQL) database.
- Platform access tokens and API keys are encrypted at rest (AES-256-GCM). All traffic uses HTTPS.
- Access inside the hub is by role: team members see only the clients assigned to them, and clients see only their own data.
Service providers that process data for us: Vercel (hosting), Neon (database) and, for AI features, Anthropic. Exchange-rate services are used for currency conversion and receive no personal data.
How long we keep it
Data is kept while Your Agency works with the client. Disconnecting a platform deletes its stored access tokens straight away. When a client relationship ends, or on request, we delete that client's data from the hub.
Removing access and deleting your data
- Revoke access at any time from the platform itself: Facebook Settings → Business Integrations (Meta); your Google Account → Security → Third-party connections (Google); or the connected apps settings in TikTok, Pinterest and Snapchat. Klaviyo and Shopify keys can be deleted in those accounts.
- Ask us to delete your data by emailing the contact named in your agreement with Your Agency with the account or brand concerned. We confirm deletion within 30 days.
Your rights
You can ask to see, correct or delete personal data we hold about you, or object to how it is used, by contacting the contact named in your agreement with Your Agency. If you are not satisfied with our response, you can contact your local data protection authority.
Changes
If we change this policy, we update the date at the top of this page.