Legal
Privacy Policy
Last updated: 3 October 2026
This Privacy Policy describes how Metric Mage (“Metric Mage”, “we”, “us”) collects, uses, stores, and shares information when you use our website and application at ghost-core-two.vercel.app (the “Service”).
1. Who we are
Metric Mage is a multi-tenant operations and integrations platform. Organisation owners and members connect third-party business tools so activity can be normalised into an organisation-scoped timeline, insights, and workflows.
Contact for privacy requests: use the email address associated with your Metric Mage account owner profile, or the contact method published on the Service homepage once a support address is configured.
2. Information we collect
2.1 Account information
- Email address and authentication identifiers (via Supabase Auth)
- Optional profile name and avatar
- Organisation name, membership role, and invitation records
2.2 Integration and provider data
When an organisation administrator connects a provider (for example Meta, Google, Stripe, Shopify, GitHub, Slack, Notion), we receive only what that provider returns under the scopes the admin approved. Depending on the connector, that may include:
- Account or Page identifiers and display names
- Aggregate performance metrics (for example followers, reach, impressions, video views, spend, orders)
- Operational events translated into our universal event model
- Encrypted OAuth access and refresh tokens used only to sync on your behalf
Social connectors are read-only. We do not post, message, boost ads, or download private message bodies through organic social integrations.
2.3 Technical data
- Session cookies required for authentication and workspace selection
- Server logs needed to operate and secure the Service
- Background job run metadata for reliability
- Google Analytics on our public pages (home, sign-in, sign-up and policy pages) only, and only if you click Allow on the cookie banner. It measures visits to those pages; it is never used inside the app. .
3. How we use information
- Provide authentication, multi-organisation workspaces, and role-based access
- Import, normalise, and display provider activity for the connecting organisation
- Generate deterministic insights, correlations, notifications, and workflows
- Maintain security, prevent abuse, and debug failures
- Comply with legal obligations
We do not sell personal data.
4. Legal bases (where applicable)
Where GDPR or similar laws apply, we process data to perform our contract with you, with your consent (for example when connecting a provider), and for legitimate interests such as securing and improving the Service.
5. Sharing
We share data only as needed to run the Service:
- Infrastructure processors such as hosting (for example Vercel) and database/auth (Supabase)
- Connected providers you choose to authorise (Meta, Google, etc.), only via their OAuth/API flows
- Authorities if required by law
Organisation data is isolated by tenant policies. Other organisations cannot access your workspace data through normal application flows.
6. Retention
- Account and organisation data: while the account/organisation is active
- Integration tokens: until the admin disconnects the integration or the token expires
- Imported events and insights: retained for the organisation until deleted by an authorised process or account closure
7. Security
- TLS in transit for production traffic
- Provider tokens encrypted at rest with server-side keys
- Organisation-scoped access control and database row-level security
- Least-privilege, read-only OAuth scopes for social connectors where possible
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to withdraw consent for a connected provider by disconnecting it in Connections (and optionally revoking access in the provider’s security settings). See how to delete your data.
9. Meta (Facebook / Instagram) specific notes
When you connect Meta Social or Meta Ads, Metric Mage requests only the permissions shown on the Meta consent screen. Organic social access is used to import Page and Instagram professional aggregate insights for the organisation that connected the account. Metric Mage does not post or message on Facebook or Instagram.
You can disconnect these integrations at any time in Metric Mage. You should also remove Metric Mage from your Meta Business / Facebook settings if you want tokens revoked at the provider.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use of the Service after changes means you accept the updated policy.
12. Contact
Privacy questions: contact the organisation that invited you, or the Metric Mage operator via the support channel listed on the Service.