← Back to myAgency
LEGAL

Privacy Policy

Effective Date: September 7, 2026 · Last Updated: September 28, 2026

1. Introduction

This Privacy Policy describes how myAgency ("we," "us," "our") collects, uses, stores, discloses, and protects information when you use the website at meetmyagency.com and the related Google Ads automation platform (the "Service"). The Service also includes landing pages we build and host for our customers, which may be served on our customers' own domains. This Policy applies to all users of the Service, including customers, affiliates, prospective users who interact with our marketing pages, and people who submit an inquiry form on a page we host. This Policy is incorporated into our Terms of Service by reference.

If you have questions about anything in this Policy, contact support@meetmyagency.com.

2. Definitions

The following definitions are used consistently with our Terms of Service, Section 13:

  • Customer Data means data you submit to the Service, plus data we receive from your connected Google Ads accounts through OAuth, including campaign, ad group, keyword, search term, ad creative, conversion, and performance data, keyword ideas and search-volume estimates we request from Google on your behalf, and the click identifiers Google's own click log reports for your account. You own all Customer Data; we process it only to operate the Service for you.
  • Service Data means metadata, telemetry, and feedback signals generated by your use of the Service — which recommendations you approve, reject, dismiss, or roll back; configuration choices; navigation patterns; feature usage; error logs; and performance metrics.
  • Aggregated Data means data that has been aggregated across multiple customers and de-identified such that it cannot reasonably be linked, directly or indirectly, to you, your business, or any individual.
  • Lead Data means the information a member of the public submits through an inquiry form on a landing page we host for you: their name, phone number, email address, whatever they write in the message box, the answers to any form fields you added yourself, and the technical details described in Section 3. Lead Data is your data about your prospective customer. You are its controller and we process it only on your instructions, to deliver it to you and to record the resulting conversion.
  • Personal Information means information that identifies, relates to, or could reasonably be linked with a particular individual.

3. Information We Collect

We collect the following categories of information:

  • Account information. Email address, name, password (stored as a bcrypt hash — we cannot read it), and (if you sign in with Google) your Google account profile picture and unique Google user ID.
  • Google Ads data. When you connect a Google Ads account, we access campaign data, ad group structure, keywords, search term reports, ad creative, conversion data, bid information, and related performance metrics through the Google Ads API. We store this data only to provide the Service to you.
  • OAuth refresh tokens. The refresh token issued by Google when you authorize access, encrypted at rest using MultiFernet symmetric authenticated encryption, which lets us rotate the encryption key without losing access to tokens encrypted under the previous one. We never see your Google account password.
  • Service Data. Telemetry about your use of the Service: actions taken in the dashboard (approve, reject, roll back, etc.), feature usage, configuration choices, performance metrics, and error logs. See Section 5 for how this is used.
  • Billing information. If you subscribe, we store your Stripe customer ID, subscription status, and the last four digits and expiry of your card on file. We never store full credit-card numbers or bank-account details — those live exclusively in Stripe.
  • Affiliate information. If you participate in the Affiliate Program: your referral activity (link clicks, signups, conversions), commission and payout history, and milestone progress. Payout processing is handled by Stripe Connect Express; the information you provide to Stripe during Connect onboarding (bank-account details, identity verification documents) is governed by Stripe's Privacy Policy.
  • Security data. IP addresses, browser user-agent, and approximate geolocation derived from IP, recorded with login attempts, password changes, OAuth events, and other security-significant events.
  • Acceptance records. When you accept our Terms of Service or this Privacy Policy, we record the timestamp, IP address, browser user-agent, and the version of the document accepted. See Section 14.
  • Lead Data from the pages we host for you. If we host a landing page for you and someone submits its inquiry form, we store what they typed: name, phone number, email address, the message, and the answers to any extra fields you added to the form. We also store, for that submission, the page they arrived on, the referring URL, their IP address, their browser user-agent, and a spam score we compute from those. If the visit came from a Google Ads click we store the click identifier so the resulting conversion can be reported back to your account. A spam score never rejects an inquiry; it only flags the row so you can judge it. Retention for all of this is in Section 8, and it is shorter than for your own account data.
  • The content of the website you advertise. We fetch and read the public pages of the website you point your ads at, so the engine knows what you actually sell and in what words. The crawler identifies itself as JSREngineBot, obeys your robots.txt and your noindex and nofollow directives, and reads at most 30 pages per site. We store the retrieved page text and the facts extracted from it. We do not submit your forms and we do not log in to anything.
  • Images you upload. Photos and logos you add to a landing page. We convert every upload to WebP at up to 1200 by 1200 pixels and store only our own converted copy. The file you uploaded is not kept.
  • Conversion tracking data. If you install our tracking tag on your own website, we record the calls and form submissions it reports, together with the Google Ads click identifier for that visit. We accept these only from web addresses you have registered with us, and we check that again before anything is sent to Google.
  • Landing page traffic counts. For each page we host we keep a daily count of visits and unique visitors, per page. That is a running total and nothing else: there is no per-visitor record, and no IP address, in this data.
  • The free campaign builder. If you use the free campaign builder, we read the public pages of the website you type in, exactly as described above for the website you advertise, and we build a Google Ads campaign from what we find. We store that campaign, the business name and service area we derived from your site, and the email address you give us to open it. For that visit we also record your IP address and the approximate location it maps to (country, region, city, postal code and coordinates), your browser and device, the page you arrived from and any ad or campaign identifiers on the link you clicked (UTM parameters, click IDs), the screens you moved through, when, and what you clicked or scrolled on each, and each time the campaign's link is opened. We use this to show you the campaign, to send you the link and reminders about it until it expires, and to market myAgency to businesses like yours. When the campaign expires we keep this record; you can ask us to delete it at any time by emailing support@meetmyagency.com, and every email we send has an unsubscribe link. Our emails tell us whether they were delivered, opened, and which link was clicked.
  • Team members. If you invite someone to work in your account, we store their email address, the access level and the accounts you gave them, and when they accepted and were last active. A team member signs in with their own login. We record the changes a team member makes in your account in a change log that you can see.
  • Help assistant questions. If you ask the in-app help assistant a question, we store the question, the answer it gave, the screen you asked it from, whether you rated the answer or sent it on to support, and a summary of your account's setup at the time. Section 5.2 describes what the summary contains and where it is sent.
  • Online status and live support. While you use the signed-in application or the free campaign builder, your browser tells us every few seconds that it is open, which page it is on (the page address without its query string), and whether the tab is in view, so our support staff can see who is online. A member of our support staff can also watch your screen live, as Section 6 describes. Nothing is recorded until they start watching.
  • Communications. If you email support or use the contact form, we retain the content of those messages.

We do not knowingly collect any other categories of Personal Information.

4. How We Use Information

We use the information we collect to:

  • Provide and operate the Service — fetch your Google Ads data, generate recommendations, apply approved changes, render the dashboard, send cycle and digest emails.
  • Authenticate you and protect your account against unauthorized access.
  • Process subscription payments and affiliate payouts via Stripe.
  • Build, publish, and host the landing pages you ask us to build, and serve them to the public on your behalf.
  • Deliver Lead Data to you, by email to the address you nominate and in your inquiry inbox, and report the resulting conversion to your Google Ads account.
  • Maintain audit logs of recommendations, approvals, and account changes, and show you the changes your team members make.
  • Answer your questions about the Service, in the help assistant and through live support.
  • Detect and prevent fraud, abuse, and policy violations — including referral fraud (IP-matching and behavioral analysis) and account abuse.
  • Improve the Service and our machine-learning models (see Section 5).
  • Communicate with you about the Service — transactional notifications, billing receipts, security alerts, and (only if you have not opted out) the weekly performance digest.
  • Comply with legal obligations, respond to lawful requests, and protect our rights and the rights of others.

We do not use your information for cross-context behavioral advertising, do not sell your information, and do not share your information with data brokers.

5. Artificial Intelligence & Machine Learning

The Service uses two different kinds of automated intelligence, and we describe them separately because they treat your data differently.

5.1 Our own machine-learning models

Most of the Service runs on conventional machine-learning models that we build and run on our own servers: our V2 confidence calibration system, our n-gram waste-detection engine, our search-term discovery engine, and our bid curve engine. These are statistical models such as isotonic-regression calibrators, logistic-regression quality classifiers, and robust regression curves. They are not generative AI and they do not produce free-form text.

Service Data and feedback signals. When you approve, reject, or roll back a recommendation, that signal becomes part of Service Data. We use Service Data to operate, maintain, secure, monitor, improve, and develop the Service, including to train, evaluate, and deploy the machine-learning models used in the Service.

5.2 Third-party generative AI

A number of features send data to Anthropic PBC, the provider of the Claude family of large language models, and use the model's response to make a better decision. This happens at the moment the feature runs. Anthropic is the only generative-AI provider we use, and it is listed as a sub-processor in Section 9.

These are the features, and what each one sends:

  • Website context extraction. When we crawl your advertised website (see Section 3), we send the text of those public pages to Anthropic to work out what services you actually offer, the vocabulary your industry uses, and which industry you are in. We use the result so the engine does not treat a service you genuinely sell as irrelevant.
  • Non-English search term review. Our waste-detection engine sometimes flags a search term it does not recognize. Before we act on that, if the term looks non-English we send the flagged phrase, the Google Ads search queries that produced it, and a list of your business's own keywords to Anthropic, and ask whether the phrase is actually relevant to your business. This exists to protect you: it stops the engine from blocking a legitimate customer searching for your service in Spanish, Portuguese, or French. The answer can only ever spare a keyword from being blocked, never cause one to be blocked.
  • Campaign creation. When the Service builds a campaign for you, we send the facts extracted from your website, the answers you gave during setup, your ad group names, and the keywords under consideration. The model helps group and name the ad groups, expand and select keywords, and propose the opening list of searches to block. One of the questions we ask it is the one the data cannot answer: whether an ad group name is the name of a service or the name of a town.
  • Ad copy and sitelinks. The extracted facts, your own words that support each claim, and the ad group's keywords, to draft headlines, descriptions, and the short link descriptions that sit under an ad. You see and can edit every line before it runs.
  • Hosted landing page copy. The same extracted facts, plus your business name, address, and phone number, to draft the text of a page we build for you. Every claim on the finished page has to trace back to something we actually found on your site, or it is removed before the page can be published.
  • Help assistant. When you ask the in-app help assistant a question, we send your question, your recent questions and answers in the same conversation, the screen you are on, and a summary of your account's setup: the names of your connected accounts, your campaigns' names, types, and status, your automation settings, how many recommendations are waiting for you, your conversion tracking setup, your landing pages' titles and status, your plan status, and which features are switched on for you. The model answers from that summary and from our own help articles. It cannot change anything in your account.

What this means for your data. We want to be precise about the boundary here:

  • We send data to the model to get an answer back. We do not send it so that anyone can train on it.
  • Anthropic is contractually prohibited from training its models on the data we send. Under Anthropic's Commercial Terms of Service, the content we submit is our confidential information, and Anthropic may not train models on it.
  • We do not train generative-AI foundation models or large language models on Customer Data, and we will not do so without your separate written consent.
  • No human at Anthropic or at myAgency reviews this data as part of the feature. It is an automated request and an automated response. The help assistant is the one exception on our side: our team reads the questions people ask it and the answers it gave, so we can improve its answers and our help articles, and if you send an answer on to support, we read it to help you.
  • We cache the result of the non-English review so we do not re-send the same phrase repeatedly. The cache holds the phrase and the verdict, and is deleted when your account is deleted.
  • Lead Data is never sent to the model. Not the name, the phone number, the email address, or the message a person typed into one of your forms. No feature above reads your inquiries, and when we crawl a website we strip its forms and input fields out of the text before the request is made, so that a form's own contents cannot travel with the page.
  • Every one of these features fails safe. If the model is unavailable or returns something we cannot use, the feature falls back to its ordinary behavior rather than guessing, and where the fallback would be a published page that we cannot substantiate, we do not publish it at all.
  • You can opt out of the two analysis features. Website context extraction and non-English search term review are the two that run on their own, in the background, without you asking for them. Email support@meetmyagency.com and we will switch both off for your account, enforced by an automatic check on every call, and without otherwise degrading your Service. The engine keeps working; it is just less good at recognizing your services and at sparing non-English searches. The same opt-out also applies to the help assistant: a question asked while an opted-out account is selected is not sent to the provider, and the assistant offers to pass it to our support team instead.
  • Three more run only when you ask for them. Campaign creation, ad copy and sitelinks, and hosted landing page copy send data at the moment you request that work. Opting out of the two analysis features does not switch these three off, because they are the work itself rather than a background process. If you do not use campaign creation, ad copy, or a hosted landing page, no data is sent to the provider for those purposes, and declining to use them costs you nothing else.

Section 6 explains how this is consistent with the commitments we make to Google about data received from the Google Ads API.

5.3 Aggregated Data

We may use Aggregated Data for any lawful purpose, including benchmarking, analytics, research, marketing materials, industry reports, and model training. We will not attempt to re-identify Aggregated Data, and we contractually require any third party that receives Aggregated Data from us to be similarly bound. This commitment is intended to satisfy the de-identification standards in California Civil Code §1798.140 and similar state-law provisions, so that Aggregated Data falls outside the scope of those laws.

5.4 Recommendations are not automated decisions about consumers

Recommendations generated by the Service relate to your management of advertising campaigns. They are not "significant decisions" about consumers within the meaning of California CPRA Automated Decision-making Technology regulations, and they are not automated decisions producing legal or similarly significant effects on natural persons under Article 22 of the GDPR.

Recommendations are also probabilistic. They can be wrong. Where you have enabled automatic application for an automation type, the Service will apply a change to your Google Ads account without asking you first, subject to the confidence thresholds described in your dashboard. You can review every change in the activity log, roll most of them back, and switch any automation to approve-and-deny at any time in Settings.

6. Google API Services User Data Policy

myAgency's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only access Google user data necessary to provide and improve user-facing features of the Service.
  • We do not sell Google user data.
  • We do not use Google user data for advertising or for retargeting.
  • We do not allow humans to read Google user data except (a) with your explicit consent, (b) as necessary for security purposes, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations consistent with the User Data Policy.

The permissions we ask for

We request the narrowest set that makes each part of the Service work, and we ask for the sensitive ones only at the point you turn the relevant feature on:

  • openid, userinfo.email and userinfo.profile, to identify you and create your account. At a routine sign-in this is all we ask for.
  • https://www.googleapis.com/auth/adwords, to read your Google Ads data and apply the changes you approve. Requested when a Google Ads connection is actually needed. If you sign up only as an affiliate, we never request it.
  • https://www.googleapis.com/auth/datamanager, to report conversions back to your account. Requested separately, and only if you switch conversion tracking on. An account that never enables tracking never grants it.

You can see exactly what you granted, and withdraw any of it, at the Google permissions page linked at the end of this section.

When a person at myAgency can see your account

We want to be straight about the exception above rather than leave it abstract. Our support tooling lets an administrator open your dashboard as you, so we can reproduce a problem you have reported or investigate a fault. This is how we debug, and it falls within the exception for security and troubleshooting purposes.

  • Access is limited to administrators. It is read-only by default, and switching a session to one that can make changes is a separate, deliberate step.
  • Every time such a session starts, ends, or is escalated, we write a security event recording who did it and when. Those records are retained for 90 days as described in Section 8.
  • We use it to operate and support the Service. We do not use it to browse your data for any other purpose.

Our support staff can also watch your screen live while you use the signed-in application or the free campaign builder, including when you work in someone else's account as a team member. We use this to see a problem as it happens and help you with it.

  • Only administrators can watch, and only when one of them chooses to. Nothing is recorded until an administrator starts watching. While they watch, your browser sends what is on your screen and how you move through it (clicks, scrolling, and pointer movement), and they see it within a second or two. When they stop, recording stops.
  • Anything you type into a form field is masked in your browser before it is sent, so the administrator can see that you typed but not what you typed. Card details are entered in Stripe's own secure frame, which we cannot see.
  • The administrator sees your screen as you see it. That can include Customer Data, such as your campaigns and their performance, and Lead Data shown in your inquiry inbox.
  • We do not keep recordings. What your browser sends is held in a short-lived cache only long enough to show it, is deleted when the administrator ends the watch, and in any case expires 60 seconds after the last update. It is never saved to our database.
  • The online status described in Section 3 holds only the page, whether the tab is in view, and a random identifier for the browser tab, and it expires 20 seconds after your browser last sends it.
  • Each watch is recorded as a security event naming the administrator, whose session it was, and when it started. Those records are retained for 90 days as described in Section 8.
  • We use it only to support you and to find and fix problems in the Service.

How this applies to our use of AI

Section 5.2 describes the features that send data to Anthropic, our AI sub-processor. Several of them send data that came from a Google API: the search queries behind a flagged search term, the keywords under consideration for an ad group, the name of an ad group, and, for the help assistant, the names, types, and status of your campaigns. We treat every one of those transfers as governed by the commitments above, and we hold them inside them:

  • The transfer happens only to provide a feature you can see and use in the Service, and only for accounts where the feature is active. It is not a bulk export.
  • Anthropic acts as our service provider on our instructions. It may not use the data for its own purposes and, under its Commercial Terms of Service, may not train its models on it.
  • The data is not sold, and is never used for advertising or retargeting.
  • No human reads it. The request and the response are automated. For the help assistant, our team reads the questions asked and the answers given, as Section 5.2 describes; the account summary sent with them is not part of that review.
  • By accepting our Terms of Service, which incorporate this Policy, you consent to this processing. You may withdraw that consent for your account at any time by emailing support@meetmyagency.com, and we will disable the feature without otherwise affecting your Service.

If Google notifies us that this processing is inconsistent with any policy applicable to our API access, we will disable it rather than continue.

You can review and revoke myAgency's access to your Google account at any time at myaccount.google.com/permissions.

7. Data Storage and Security

Your data is stored on access-controlled servers operated by DigitalOcean in the United States. We use industry-standard administrative, technical, and physical safeguards to protect it, including:

  • TLS 1.2+ encryption for all data in transit.
  • MultiFernet symmetric authenticated encryption (AES-128-CBC + HMAC-SHA256) for OAuth refresh tokens at rest, which lets us rotate the encryption key without losing access to tokens encrypted under the previous one.
  • Bcrypt password hashing.
  • HTTP-only, Secure, SameSite=Lax cookies for authentication; JWT-based session tokens with version-based revocation.
  • PostgreSQL instance not exposed to the public internet — accessible only from the application server.
  • Rate limiting and CSRF protection at the application layer.
  • A Content-Security-Policy on every landing page we host. It starts closed, and widens only to the specific providers you have chosen to enable on your own page.
  • A nightly database backup to DigitalOcean Spaces object storage, taken at 02:00 UTC. Every night at 03:10 UTC we restore the most recent backup into a temporary database and check that it is usable, so a backup that would have failed when we needed it is found the next morning instead of during an incident.

We comply with the New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, N.Y. Gen. Bus. Law §899-bb), including maintaining a designated security coordinator, conducting risk assessments, contractually obligating vendors to maintain appropriate safeguards, training employees on security practices, and adhering to a written breach-notification procedure that targets disclosure within 30 days of discovery.

No system is perfectly secure. We disclaim any warranty of absolute security in our Terms of Service, Section 17. If we become aware of a breach affecting your Personal Information, we will notify you as required by applicable law.

8. Data Retention

We retain different categories of data for different periods, generally aligned with the purposes for which we collected the data:

  • Customer Data and account information: retained for the duration of your account. When you cancel or close your account, your account and its data are kept, so that you can reopen it later without starting over. If you would rather have it deleted, ask us (Section 10) and we delete it within 30 days. Our backups run on a rolling 30-day cycle, so residual copies are gone within 30 days of that deletion, except where retention is required by law.
  • Recommendations: expired recommendations are automatically purged after 7 days. Applied and failed recommendations are purged after 30 days. Recommendations you rejected or rolled back are kept for as long as your account is open, because they are how the engine remembers not to suggest the same thing to you again. They are deleted when your account is deleted.
  • Search term data from the Google Ads API: 30 days, then automatically deleted. Thirty days is the minimum retention Google's Required Minimum Functionality policy expects of a tool like ours.
  • Action log (the audit trail of changes applied to your Google Ads account): 90 days, then automatically deleted. We keep this longer than other operational data so there is a durable record of what the Service did on your behalf.
  • Security event logs (login attempts, IP addresses, geolocation): 90 days, then automatically deleted.
  • Lead Data from a page we host: deleted after 395 days, about 13 months. That window is set by Google Ads' own horizon for conversion data, so an inquiry outlives every period in which its conversion could still be reported or withdrawn, and no longer. Separately, at 90 days we erase the technical details we only ever needed in order to score it for spam, meaning the IP address, the browser user-agent, and the referring URL. What the person actually wrote to you, and their contact details, stay available to you until the 395 days are up.
  • Website crawl content and the facts extracted from it: 90 days, then automatically deleted. The next scheduled crawl re-fetches your site.
  • Landing page traffic counts: the daily visit and unique-visitor totals per page, kept while the page exists. These are counts, not records of people.
  • Free campaign builder records: the campaign, what we derived from your site, your email address, and the visit record described in Section 3 are kept after the campaign expires, until the campaign's data is purged or until you ask us to delete them.
  • Free campaign builder event log: the free campaign builder's detailed event log is deleted after 180 days.
  • Help assistant: your questions and the answers are deleted after 30 days, and a conversation you have not used for 30 days is deleted with them. The account summary stored with each question is deleted after 7 days. We keep at most your 50 most recent conversations.
  • Live support: not retained. What your browser sends while an administrator is watching is deleted when the watch ends and expires 60 seconds after the last update at the latest, and online status expires after 20 seconds (Section 6). The security event recording each watch is kept for 90 days, as above.
  • AI review cache (Section 5.2): the flagged phrase and the model's verdict, kept while your account is open so we do not re-send the same phrase, and deleted with your account.
  • Billing records: retained for a period consistent with tax and accounting obligations (generally 7 years), independent of account status.
  • Acceptance records for Terms of Service and Privacy Policy: retained for at least three (3) years following the conclusion of the account relationship, per our commitment in Terms of Service, Section 22.
  • Affiliate records: referral activity, commission, and payout history are retained for the duration of the Affiliate's account and a reasonable period after termination for tax and legal compliance.
  • Aggregated Data: retained indefinitely as it is no longer linked to any individual or account.

Closing your account from Settings keeps your data, as described above; deletion happens on request. You may request deletion at any time; see Section 10. Deletion is not limited to your login. In one transaction we remove your connected account records, your campaigns, keywords, search terms, performance history, recommendations and their quality statistics, your action log and automation state, the landing pages we host for you (which stop being served, and whose published files are torn down), and the Lead Data those pages collected, and then the user record itself. Billing records are the documented exception above.

9. Sub-Processors

We use the following service providers ("sub-processors") to operate the Service. Each is engaged under a data processing agreement that contractually obligates them to maintain appropriate safeguards and to process Personal Information only as needed to provide their service.

Sub-processorPurposeData categoryLocation
DigitalOceanCloud hosting, PostgreSQL database, object storage for backupsAll data at restUnited States
StripeSubscription payment processing, customer-balance credits, Affiliate Program Connect payoutsBilling identifiers, payment-method metadata; for Affiliates, identity verificationUnited States
Google (Google Ads API)Source of Customer Data; destination for approved campaign mutationsOAuth tokens, account identifiersUnited States / Global
Anthropic PBCGenerative AI for the features described in Section 5.2Text of your public website pages; flagged search terms and the Google Ads search queries behind them; your business keyword vocabulary; the setup answers, extracted facts, and keywords used to build campaigns, ad copy, and landing pages; questions you ask the help assistant, with a summary of your account's setup. Contractually may not be used to train Anthropic's models.United States
Google (Analytics 4 / Tag Manager)Anonymous traffic analytics on our public marketing pages only. Not present on the signed-in application.Pseudonymous usage and device data from marketing pagesUnited States / Global
ResendTransactional and digest email deliveryEmail address, message contentUnited States
Meta PlatformsMeasurement of our own advertising: which of our ads led to a signup. Present on our /lp/ marketing pages and in the signed-in application. See Section 15.Pixel events from a browser: page views, a click on a trial call to action, and a one-time signal that an account was created. No Customer Data, no Lead Data, and no Google Ads data.United States / Global
Microsoft Corporation (Clarity)Session analytics and recordings on our marketing pages, the free campaign builder, and the signed-in application. See Section 15.Page interactions, device and approximate location data, with typed input masked; your account id once you sign in, never your name or email address. Not loaded for a browser sending Global Privacy Control.United States
OpenStreetMap (Nominatim)Looking up the boundary or coordinates of a town, city, or county so location targeting matches the area you asked forPlace names only. No personal information, and nothing about your account, is sent.Global
MaxMind (GeoLite2)IP-to-approximate-location lookup for security event loggingIP addresses (processed locally, not transmitted)Local database; no live data sent

Tags you add to a page we host for you. If we host a landing page for you, you may choose to install your own third-party tracking on it: Google Analytics 4, Google Ads conversion tracking, Google Tag Manager, the Meta pixel, CallRail, Microsoft Advertising UET, LinkedIn, Hotjar, or Microsoft Clarity. We load only the ones you configure, and we tighten the page's Content-Security-Policy to the specific providers you chose. Those are your processors, engaged on your instruction and governed by your own arrangements with them, not sub-processors of ours. If you enable none, the page loads no third-party tracking at all.

We will notify you by email at the address associated with your account, or by posting an updated version of this Policy, before adding or replacing a sub-processor that materially affects how Personal Information is processed. We will not add sub-processors that do not satisfy our security and privacy standards.

10. Your Privacy Rights

Regardless of where you live, you may:

  • Access: request a copy of the Personal Information we hold about you.
  • Correct: request correction of inaccurate Personal Information.
  • Delete: close your account from Settings → Close Account (your data is kept so you can reopen it), or ask us to delete it. Deleting your account removes what Section 8 lists: your connected account records, campaigns, keywords, search terms, performance history, recommendations and their quality statistics, action log and automation state, the landing pages we host for you and the Lead Data they collected, and your user record. Billing records are kept as Section 8 describes. Ask us at support@meetmyagency.com to remove anything else.
  • Port: request a copy of your data in a structured, commonly-used, machine-readable format.
  • Object or restrict: object to or ask us to restrict certain processing.
  • Revoke Google API access: at any time, at myaccount.google.com/permissions.

To exercise any of these rights, email support@meetmyagency.com from the address associated with your account. We will respond within 45 days. We may request additional information to verify your identity before fulfilling a request, in order to protect against unauthorized disclosure.

We will not discriminate against you for exercising any of these rights.

If you submitted an inquiry on a page we host

If you filled in a form on a landing page and want your information corrected or deleted, the business named on that page is the one that holds it and decides what happens to it. We process it for them. The fastest route is to ask that business directly. You can also email support@meetmyagency.com and we will pass the request to them and act on their instruction. In any case the inquiry is deleted automatically on the schedule in Section 8.

11. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you the following specific rights:

  • Right to know. Request disclosure of the categories of Personal Information we collected, the sources, the purposes, and the categories of third parties with whom we shared it.
  • Right to access. Request a copy of the specific pieces of Personal Information we hold about you.
  • Right to delete. Request that we delete the Personal Information we collected from you, subject to applicable exceptions.
  • Right to correct. Request that we correct inaccurate Personal Information.
  • Right to limit use of sensitive personal information. We do not use sensitive personal information for any purpose other than what is necessary to provide the Service.
  • Right to opt out of sale or sharing. We do not sell Personal Information. We use the Meta pixel to measure our own advertising, which some state laws treat as "sharing." You can block it with a content blocker, or ask us at support@meetmyagency.com.
  • Right of non-discrimination. We will not deny service, charge different prices, or provide a different quality of service because you exercised any of these rights.

Categories of Personal Information collected (last 12 months)

Identifiers (name, email, IP address, Google user ID); commercial information (subscription status, billing identifiers, transaction history); internet/network activity (usage of the Service, dashboard navigation, recommendation approval/rejection, online status, and what support staff see while watching your screen live, which is not retained); geolocation (approximate, from IP); inferences drawn from the above (recommendation-quality and confidence-calibration scores).

Where we host a landing page for a customer, we also process, on that customer's behalf and not for our own purposes, the identifiers and commercial information a member of the public submits through its inquiry form: name, email address, phone number, the message, the IP address and browser user-agent of the submission, and the advertising click identifier that brought them to the page. For that data the customer is the business that decides how it is used, and Section 10 explains how to reach them.

We do not collect biometric information, precise geolocation, race or ethnicity, religious beliefs, philosophical beliefs, union membership, sexual orientation, gender identity, health or genetic information, or any other category of sensitive personal information.

How to submit a request

Email support@meetmyagency.com with subject line "CCPA REQUEST". We will respond within 45 days. You may also designate an authorized agent to make a request on your behalf — the agent must provide written authorization, and we may still contact you to verify identity.

If you believe we have not adequately responded to your request, you may contact the California Attorney General at oag.ca.gov.

12. EU and UK Residents

The Service is offered only to United States-based businesses and U.S. residents. We do not target users in the European Economic Area, the United Kingdom, or Switzerland, and our Terms of Service, Section 3 require you to represent that you are not located in those regions. If you nonetheless access the Service from one of those regions, you do so at your own initiative and we make no representations regarding compliance with GDPR, UK GDPR, the EU-U.S. Data Privacy Framework, or other regional data-protection laws. If you believe you have submitted Personal Information to us as an EU, UK, or Swiss resident, email support@meetmyagency.com and we will delete it.

13. Children

The Service is not directed to, and we do not knowingly collect Personal Information from, children under 18. If you believe a child has submitted Personal Information to us, email support@meetmyagency.com and we will delete it.

14. Acceptance Records

We retain a record of each user's acceptance of the Terms of Service and this Privacy Policy, including the version accepted, the timestamp of acceptance, and the IP address and browser user-agent from which acceptance was made. We use these records to demonstrate that you agreed to the version of our policies in effect at the relevant time — including the binding arbitration clause in Terms of Service, Section 19. These records are retained for at least three (3) years after the conclusion of your account relationship.

15. Cookies

Cookies set by the application

These are set on app.meetmyagency.com and are strictly necessary to operate the Service:

NamePurposeDurationAttributes
access_tokenAuthentication. Keeps you logged in.24 hoursHttpOnly, Secure, SameSite=Lax
oauth_stateCSRF protection during Google OAuth sign-in5 minutesHttpOnly, Secure, SameSite=Lax
oauth_scopesRecords which permissions were requested, so the sign-in can be completed correctly5 minutesHttpOnly, Secure, SameSite=Lax
affiliate_intentIdentifies the affiliate signup flow during OAuth5 minutesHttpOnly, Secure, SameSite=Lax
audit_intentIdentifies the free audit flow during OAuth5 minutesHttpOnly, Secure, SameSite=Lax
consent_retryPrevents an infinite loop when Google needs to ask for your consent a second time5 minutesHttpOnly, Secure, SameSite=Lax
tracker_intentIdentifies the conversion-tracking reconnect flow during OAuth, and carries the account you started it from so we can return you to the same page5 minutesHttpOnly, Secure, SameSite=Lax
mya_signupTells the browser, once, that the account it just landed in was created on that request, so our own signup measurement counts it a single time. Holds your account identifier and is deleted by the app as soon as it is read. See the note below on the Meta pixel.10 minutesSecure, SameSite=Lax. Readable by our own scripts.
mya_attributionRemembers which link or campaign brought you to us, so signups are attributed correctly. First-touch only; never overwritten.30 daysSecure, SameSite=Lax. Readable by our own scripts.

The Meta pixel

We advertise myAgency, and we measure whether our own ads work. The Meta pixel is loaded in two places: on our /lp/ marketing pages, and in the signed-in application. We would rather tell you this plainly than describe the application as tracker-free when it is not.

  • On the /lp/ pages it records a page view, and a click on the trial call to action. The click carries the page's own name and industry, and nothing about you.
  • In the application it records a page view, and it records once, on the load right after your account is created, that a signup happened. That one event carries an identifier we derive from your account id so that the same signup is not counted twice. It does not carry your email address, your name, your business, or anything from your Google Ads account.
  • We do not send Customer Data, Lead Data, Google Ads data, or the contents of your dashboard to Meta. The pixel is measurement of our own marketing, not of your advertising.
  • Meta's script sets its own cookies on your browser, typically _fbp, and reads a click identifier if one is present in the URL. Their names and lifetimes are set by Meta, not by us.
  • Blocking it costs you nothing. Any tracker blocker, or a browser setting that refuses third-party scripts, stops it, and the Service works exactly the same. Nothing in the product depends on the pixel loading.

Apart from the pixel, the signed-in application uses Microsoft Clarity for session analytics, as described under Session recording below, and no advertising cookies. Google Analytics and Google Tag Manager are on our marketing pages only, and are not loaded in the application.

Cookies and analytics on our marketing pages

Our public marketing pages at meetmyagency.com load Google Tag Manager and Google Analytics 4. These set their own cookies, typically named _ga and _ga_<container>, which Google uses to distinguish one visitor from another and to measure traffic. We use this only for aggregate traffic analytics. We do not use it to build advertising audiences, we do not use it for retargeting, and it is not connected to your myAgency account or to any Google Ads data.

The same marketing pages store a first-touch attribution record in your browser's local storage under the key mya_attribution. It holds the campaign parameters from the URL you arrived on. It is written once and not overwritten.

Session recording (Microsoft Clarity)

We use Microsoft Clarity, a service from Microsoft, to understand how people use meetmyagency.com, our free campaign builder, and the signed-in myAgency application. On those pages Clarity records how you interact with the page: where you click and tap, how far you scroll, how you move between pages, and the page as it was shown to you, along with your browser, device type, screen size and approximate location. It sets its own first-party cookies to recognize a returning browser. Anything you type into a form field is masked in the recording before it leaves your browser, and we do not turn that masking off. On the free campaign builder we attach the build's reference to the recording so we can see where a build went wrong. Once you sign in, recordings are associated with your account id so we can review your own sessions with you; we never attach your name or email address. Microsoft keeps session recordings for 30 days. We use them only to find and fix problems on our pages and to improve them, and we do not use them for advertising. Microsoft processes this data under the Microsoft Privacy Statement. Browsers sending a Global Privacy Control signal are not recorded. You can also opt out by blocking cookies from clarity.ms, or scripts from clarity.ms, in your browser or with a content blocker; our pages work the same without it.

Landing pages we host for a customer

A landing page we host sets no cookie of ours. The only third-party tracking on it is whatever the business that owns the page chose to install, from the list in Section 9. If that business enabled nothing, the page loads no third-party tracking at all. The page also carries its own short privacy notice naming the business, what its form collects, and how long an inquiry is kept.

You can block or delete these at any time in your browser settings, or opt out of Google Analytics with Google's opt-out add-on. Blocking them does not affect the Service.

Global Privacy Control. We do not sell Personal Information. We use the Meta pixel to measure our own advertising, which some state laws treat as "sharing"; you can block it with a content blocker, or ask us at support@meetmyagency.com. A browser sending a Global Privacy Control signal is not recorded by Microsoft Clarity, as described under Session recording above.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a change that materially affects how we collect, use, or share your Personal Information, we will provide at least thirty (30) days' advance notice by email to your account address and by posting an updated version on this page. Non-material changes (clarifications, typographical fixes, formatting) are effective on posting. The "Last Updated" date at the top of this page reflects the most recent change.

17. Contact

If you have questions about this Privacy Policy, or to exercise any of the rights described above, contact us at support@meetmyagency.com. For California-specific requests, use subject line "CCPA REQUEST".

myAgency operates from New York, United States.