Webby Reach
Privacy PolicyTerms of ServiceData Deletion

Privacy Policy

Last updated 2026-07-22

Webby Reach ("we", "us") operates Webby Reach, a marketing analytics dashboard that lets businesses connect their own marketing accounts and view their performance in one place. This policy explains what we collect, how we use it, and the choices you have.

1. Who this policy covers

It covers people who use the Webby Reach application ("customers" and their invited users) and the data that flows through it from the third-party accounts a customer chooses to connect.

2. Information we collect

Account information

  • Your name, email address, and a securely hashed password.
  • The business/client profile you set up (business name, website, industry, contact details, logo).
  • Basic activity logs (sign-ins, configuration changes) used for security and troubleshooting.

Connected platform data

When you connect an account, we access — using tokens you explicitly authorize — only the data needed to show your analytics:

  • Google Analytics & Search Console: traffic, engagement, and search metrics for the properties you select (read-only).
  • Google Business Profile: your business locations and profile performance (where you enable it).
  • Instagram & Facebook (via Meta): your Instagram Business/Creator account and linked Facebook Page — profile details, media, and insights such as reach and interactions.
  • Pinterest: your account, boards, and pin performance.

We request read/insights permissions to display analytics and, where you enable publishing, the permissions needed to post content you create. We do not collect your social media login credentials — authentication happens on the provider's own site via OAuth.

Authentication tokens

We store the access/refresh tokens the providers issue so your dashboards stay current. Tokens are encrypted at rest and are never displayed, exported, or shared.

3. How we use information

  • To display your marketing analytics and generate reports.
  • To publish content to your connected accounts when you ask us to.
  • To operate, secure, and support the service (authentication, troubleshooting, abuse prevention).
  • To communicate with you about your account (for example, password resets and invitations).

We do not sell your personal information or your connected platform data, and we do not use it for advertising.

4. How information is shared

Access is isolated per customer: one customer can never see another customer's data. We share data only with:

  • Infrastructure sub-processors (hosting and database) that store the data on our behalf.
  • The originating platforms (Google, Meta, Pinterest) when we call their APIs on your behalf.
  • Authorities where required by law, or to protect rights and safety.

5. Data retention

We keep account and analytics data for as long as your account is active. When you disconnect a provider we stop syncing and remove its stored tokens. When you close your account, or on a valid deletion request, we delete or de-identify your personal data and connected-platform data within a reasonable period, except where retention is required by law.

6. Your choices and rights

  • Disconnect any provider at any time from the Integrations page; this revokes our stored token.
  • Access or delete your data — see the Data Deletion page or email us.
  • Depending on your region, you may have rights to access, correct, port, or restrict processing of your data.

7. Meta Platform data

Our use of information received from the Meta APIs follows Meta's Platform Terms and Developer Policies. We use Instagram/Facebook data only to provide the analytics and publishing features you request, retain it only as needed for those features, and delete it on request or when you disconnect. To remove Meta-sourced data, use the Data Deletion instructions.

8. Google API data

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google data solely to provide and improve the analytics features you enable, and we never transfer it for advertising or sell it.

9. Security

We protect data with encryption of tokens at rest, encrypted transport (HTTPS), hashed passwords, per-customer isolation, CSRF protection, and access controls. No system is perfectly secure, but we work to safeguard your information.

10. Children

Webby Reach is a business tool not directed to children under 16, and we do not knowingly collect their data.

11. Changes

We may update this policy; material changes will be reflected by the "Last updated" date above and, where appropriate, an in-app notice.

12. Contact

Questions or requests: areyes@webbyreach.com.

Webby Reach operates the Webby Reach platform. Questions about this page? Contact areyes@webbyreach.com.