Privacy Policy
OpsForge("we", "our", "us") respects your privacy. This policy explains what we collect, how we use it, and the choices you have. It applies to the OpsForge web application and the services you use to connect and manage your clients.
What we collect
- Account information. Email, name, and profile image you provide at sign-up (or that your Google account provides on OAuth sign-in).
- Authentication token. After you sign in, we issue a short-lived session token so you stay signed in across sessions without logging in twice. The token is sent to our API only to authenticate your requests.
- Client connections and access tokens. When you invite a client and they grant access, we store the read-level OAuth tokens needed to connect their marketing platforms (Google Analytics 4, Search Console, Google Tag Manager, and Google Ads, with more on the way), along with the connection metadata you and your client provide. These tokens are used only to maintain the connections you set up.
- Usage metadata. Per-account client connection counts (used to enforce plan limits), timestamps, the platforms connected, and your plan tier.
- Billing. Handled by Stripe on our web app. We do not see or store your card details.
- Login activity. When you sign in or sign out, we record the timestamp, IP address, browser user-agent, and approximate country. This helps you detect unauthorised access to your account and lets us understand product engagement in aggregate. We do not sell or share this data.
How we use it
We use the access your clients grant to connect their marketing platforms to your OpsForgeworkspace, keep those connections live, and show you the status of each one. We use aggregate usage numbers (clients connected, platforms linked) to improve the product.
We do not sell, rent, or share your data with third parties for advertising or profiling.
Client access and OAuth tokens
OpsForge is an access collector for agencies. When you send a client a branded connection link and they approve it, the client authorises read-level access to the platforms they choose. Here is exactly how we handle that access.
- Least-privilege access.We request the minimum scopes needed to read reporting data from the assets your client connects. Google Analytics 4, Search Console, Tag Manager, and YouTube use Google's read-only scopes. Google Ads has no read-only scope variant, so we use the standard Google Ads scope but only ever read reporting data - we never create, edit, pause, or delete campaigns or any other resource in a connected account.
- Encrypted token storage. OAuth access and refresh tokens are stored encrypted and used only to maintain the connections you and your client set up. They are never exposed in API responses and never used for any other account.
- Revocable at any time. You can disconnect a client from your workspace, and a client can revoke access from their own platform settings. Revoking access deletes the stored tokens for that connection.
- No content selling or profiling. We do not use connected data for advertising, profiling, creditworthiness scoring, or any purpose unrelated to running the connections you create.
We do not sell or transfer user data to third parties outside of approved use cases (Stripe for payments, Google APIs for the connections themselves, a managed PostgreSQL database for data storage, and Resend for transactional email).
Google user data and Limited Use
This section describes, in the terms Google's API Services User Data Policy requires, how OpsForge accesses, uses, shares, protects, retains, and deletes Google user data.
- Data we access. When your client grants access, we access read-only reporting data from the Google APIs for the assets they select: Google Analytics 4, Search Console, Google Tag Manager, Google Ads, and YouTube (channel statistics such as views, watch time, and subscribers). We also read basic account, property, site, container, customer, and channel identifiers so you can choose which specific assets to connect.
- How we use it.We use this data solely to display reporting and connection status inside the agency's OpsForge workspace and to keep the connections you set up working. We never use it for advertising, profiling, credit scoring, or any purpose unrelated to the features you use.
- How we share it.We do not sell Google user data or transfer it to data brokers, advertisers, or any other third party. It is processed only by the sub-processors that run the service (our hosting and managed database, and Google's own APIs to fetch it) and shown only to the agency that owns the workspace and, where applicable, their client.
- How we protect it.OAuth access and refresh tokens are encrypted at rest, transmitted only over TLS, and never exposed in API responses. Database access is protected with row-level security so one account can never read another account's connections.
- Retention and deletion.We store OAuth tokens and connection metadata only for as long as the connection is active. We do not warehouse the underlying Google reporting data - it is fetched from Google's APIs on demand and used transiently to render your dashboards. When a client revokes access, an agency disconnects a client, or an account is deleted, the associated tokens and connection records are permanently deleted.
Limited Use. OpsForge's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalized AI or ML models, and we do not transfer it to any third party for that purpose.
YouTube API Services
When your client connects a YouTube channel, OpsForge uses YouTube API Services to read that channel's statistics (such as views, watch time, and subscribers) and display them in the agency's reporting dashboard. We do not read, upload, modify, or delete videos, comments, or any other channel content.
- By connecting YouTube, you agree to the YouTube Terms of Service.
- Google's Privacy Policy also governs Google's handling of your data.
- You can revoke OpsForge's access to your YouTube and other Google data at any time from the Google security settings page, and stored YouTube data is deleted when you do.
Your data, your control
- You can disconnect any client or platform from your workspace at any time.
- You can export your account data from Settings.
- You can delete your account from Settings. This removes all stored client connections, access tokens, and account data.
Security
Data is stored in a managed PostgreSQL database with row-level security so only you can read your own records. Traffic is encrypted with TLS. Authentication uses short-lived session tokens.
AI provider API keys
If you add your own AI provider API key (Anthropic, OpenAI, Google, or xAI) via Settings › AI Providers, here is exactly how we handle it:
- Encrypted at rest. Your API key is encrypted with AES-256 before being written to our database. The plaintext key is never stored. We hold only the encrypted ciphertext plus the last four characters of the key so you can identify which key you saved.
- Used only for your requests. The key is decrypted in memory only at the moment your AI request is processed, and only to call the AI provider on your behalf. It is never logged, never exposed in API responses, and never used for any other account.
- Never shared or sold.Your key is not shared with third parties beyond the provider it belongs to (e.g. your Anthropic key is sent only to Anthropic's API endpoint during your AI request).
- You control deletion.You can remove your API key at any time from Settings › AI Providers. Deletion permanently removes the encrypted ciphertext from our database.
Cookies
We use essential cookies for authentication and your preferences (such as theme). Optional analytics and marketing cookies are only set after you accept them in our cookie banner, and no non-essential cookie loads before you consent. You can change or withdraw your choice at any time from our Cookie Policy page, and we honour the Global Privacy Control (GPC) browser signal. That page also lists every cookie, its purpose, and its duration.
Sub-processors
We share data with a small set of vetted sub-processors that help us run the service (hosting, database, payments, transactional email, error monitoring, and AI processing). The current list, including each vendor's purpose and data location, is published on our Security page. We do not sell your personal information.
Data Processing Agreement
Business customers can request a GDPR Art. 28 Data Processing Agreement. See how to request a DPA.
Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect. Identifiers (name, email, account ID); commercial information (subscription plan and billing handled by Stripe); internet and network activity (login activity: timestamp, IP address, user-agent, approximate country; usage metadata); and the content you submit for processing. We collect these to provide and secure the service, as described above. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect data from children.
We do not sell your personal information,and we do not "share" it for cross-context behavioural advertising. Analytics and marketing cookies run only with your consent. You can opt out at any time using the Do Not Sell or Share My Personal Information control on our Cookie Policy page, and we treat a Global Privacy Control signal as a valid opt-out.
Your rights. You have the right to know what personal information we hold and how we use it, the right to delete it, the right to correct it, and the right to opt out of any sale or sharing. You can exercise the rights to know and delete directly: download a copy of your data or permanently delete your account from Settings. You may also email us (see Contact below) and we will respond within the timeframes the law requires.
Non-discrimination. We will never deny you service, charge a different price, or provide a different quality of service because you exercised any of these privacy rights.
Changes to this policy
If we make material changes, we will update the date above and, for signed-in users, show a notice on your next visit.
Contact
Questions? Email hello@opsforge.agency or see our Terms of Service.