Who is responsible for your data
Agencies sign up for Accessello and are responsible for their account information; for that, we are the controller.
Clients are invited by an agency to complete an onboarding. The agency decides what to ask for and what to do with the answers, so for onboarding content the agency is the controller and we process it on the agency's behalf. Questions about how an agency uses your information are best sent to that agency; we'll help where we can.
What we collect
Agency accounts
- Name, work email and password (passwords are stored hashed by our auth provider).
- Workspace details: agency name, portal address, branding (logo, colours).
- Team members you invite, and their roles.
- Access settings: the Google account email clients share access with and, if you connect it, your Google Ads manager account ID.
Client accounts and advertising reports
Clients may create a password account with their name and email. Our authentication provider stores password hashes. A verified email links the account to primary-client onboarding records across agencies. When an agency enables reporting, we read campaign names, IDs, available statuses, spend, impressions and clicks for eligible recorded ad accounts using the agency's Google Ads or Meta connection. Reports include account currency and timezone and may be privately cached for up to five minutes.
Client onboardings
- Your name, email, company and website, as entered by the agency or by you.
- Answers to the agency's questions, and files you upload (logos, images, videos).
- Which platforms you've granted the agency access to, and at what level. We never ask for or store passwords to those platforms.
Automatically
- Activity needed to run the service: sign-ins, onboarding progress, timestamps, and a log of access changes.
- Technical data such as IP address and browser, used for security and rate limiting.
- Essential cookies only: a sign-in session for agency and client accounts and a session cookie for client portal links. We don't use advertising or tracking cookies.
Google user data
Accessello offers Connect Google, which lets a client grant their agency access to Google Analytics, Google Tag Manager and Google Ads by signing in once, instead of doing it by hand. This section describes exactly what Accessello does with data from Google.
What we access, and why
- Your Google account email (
openid,userinfo.email): to show you which account you signed in with. - Google Analytics (
analytics.readonly,analytics.manage.users): to list the properties you can manage so you can choose, and to add the agency's Google account to the ones you choose, at the level the agency requested. - Google Tag Manager (
tagmanager.readonly,tagmanager.manage.users): to list your containers and add the agency's account to the ones you choose. - Google Ads (
adwords): to list the Google Ads accounts you can access (name, ID, status) and link the ones you choose to the agency's manager account. For an agency connecting its manager account, to confirm the account and send link requests to the clients who ask for one.
With agency-enabled client reporting, we read Google Ads campaign performance and spend for the recorded client accounts. We do not read Analytics reports or Tag Manager tag contents for this feature. Reporting is read-only and does not edit campaigns.
How long we keep it
- Client sign-ins: the access token Google gives us is kept encrypted for at most 10 minutes while you choose what to share, never written to our database, and revoked at Google as soon as the share finishes (or when you pick a different account). We ask Google for no long-term access.
- Agency Google Ads connection: the agency's refresh token is kept encrypted in a secrets vault until the agency disconnects it in Accessello or revokes it in its Google account; disconnecting deletes it and revokes it at Google.
- What was shared: we keep a record of what was shared, with whom and at what level (for example “GA4 property ‘Web’, Editor”), so the agency can see it. It contains no tokens.
Limited Use
Accessello's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide the access-management and client-reporting features described above; it is not used for advertising, not sold, not used to train AI or machine-learning models, and not read by people except with your permission, for security, or where the law requires.
You can remove Accessello's access at any time from your Google Account at myaccount.google.com/permissions. Access you granted the agency stays in place until you remove it in the product itself or complete an eligible, verified removal through Accessello.
How we use information
- To run Accessello: portals, onboardings, uploads, checks, reminders and dashboards.
- To check uploaded files automatically (format, size, quality) and, when enabled, scan them for malware.
- To pre-fill your brand details from your public website. We read the public page and may send its text to an AI service (Google Gemini) to write a short business summary. No Google user data is sent to it.
- To send service emails: onboarding links, reminders and account notices.
- To keep Accessello secure, prevent abuse and fix problems.
We don't sell personal information or use it for advertising.
Who we share it with
- The agency you're onboarding with sees your answers, files and access status.
- Service providers who host and run Accessello for us under contract: Supabase (database, authentication and file storage, India region), DigitalOcean (application servers, India region), our email delivery provider, and Google (Gemini, for website summaries).
- Authorities, when the law requires it, or to protect the rights and safety of users and the public.
Retention and deletion
Agencies control their onboardings. Deleting an onboarding removes its answers and files. Agency accounts and their data are kept while the account is active and deleted on request. Clients can ask their agency, or us, to delete their information. Backups roll off within 30 days.
Security
Data is encrypted in transit (HTTPS) and at rest. Each agency's data is isolated by row-level security in the database. Client portal links use long random tokens that expire, uploaded files are served through short-lived signed links, and every access change is logged. No system is perfectly secure, but we work to protect your information and will notify affected users of a breach as the law requires.
Your rights
Depending on where you live (including under India's Digital Personal Data Protection Act and the EU/UK GDPR), you may have the right to access, correct, delete or export your personal data, to withdraw consent, and to complain to a data protection authority. To use these rights, email siddharthjagtap1@gmail.com. If your request is about an agency's onboarding, we may pass it to that agency.
Children
Accessello is a business tool and isn't meant for anyone under 18.
Changes to this policy
We'll update this page when our practices change and revise the date at the top. For significant changes, we'll tell agencies by email before they take effect.
Contact
SamantarLabs, India. Email: siddharthjagtap1@gmail.com.