This policy explains what Agency Stack collects, why, how it is used, and the choices you have. It applies to the Agency Stack web application and the APIs that serve it.
1. Who we are, and our role
Agency Stack is an assumed name (DBA) of Shadyne LLC, a Utah limited liability company. “We”, “us” and “our” in this policy mean Shadyne LLC. We provide software that marketing agencies use to operate their client accounts. Our role depends on whose data is in question:
- For your own account data (the people who sign in to a workspace), we are the controller.
- For the client data you put into or connect to a workspace, we are a processor acting on your instructions. You are responsible for having a lawful basis to place that data with us, and for the authority to connect your clients’ third-party accounts.
2. What we collect
Data you give us
- Account data — name, email address, password hash, workspace name, role, and the terms/privacy versions you accepted.
- Workspace content — the client records, briefs, documents, tasks, notes, files and reports you create.
- Credentials for connected systems — API keys, OAuth tokens and CMS logins you add so the platform can act on your behalf. These are encrypted (see §7).
- Waitlist enquiries — if you ask for early access before launch, the email address and optional agency name you submit, used solely to contact you about availability.
Data we collect from connected accounts
When you connect a third-party marketing account, we retrieve only the data needed to run and report on that account — for example search performance, campaign and ad metrics, business-listing details, reviews, and site analytics. The specific providers and purposes are listed on our home page and in §4 and §5 below.
Data generated by use
- Operational logs — requests, errors, timestamps, IP address and user agent, used to keep the service running, diagnose faults and prevent abuse.
- Audit records — who changed what and when inside a workspace, so account owners can review activity.
- Usage and cost records — which external API calls a workspace made, so usage can be attributed and billed accurately.
3. How we use it
- To provide, operate and secure the service.
- To display, analyse and report on the accounts you connect.
- To authenticate you and enforce workspace permissions.
- To detect, prevent and investigate abuse, fraud and security incidents.
- To send service and lifecycle email about your account.
- To meet legal and accounting obligations.
We do not sell personal information. We do not use data from your connected accounts for advertising.
Where the service uses AI features, the content involved is sent to the AI model provider that processes it on our behalf, or to the provider whose API key you have supplied.
4. Google user data
Agency Stack’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You choose which Google services to connect, and we request only the permissions for those services. This is what each one is used for:
- Search Console — we read search performance (queries, pages, clicks, impressions) and site and sitemap status for reporting, and can submit sitemaps and URLs for inspection when you ask us to.
- Business Profile — we read locations, reviews, posts, media and performance insights, and publish the edits, posts and review replies you create or approve.
- Google Ads — we read account structure and campaign, ad group, ad and keyword performance, and apply the campaign changes you create or approve.
- Google Analytics — we read traffic, engagement and conversion reporting, and can change property configuration, such as conversion events, when you ask us to.
- Google Tag Manager — we read accounts, containers and tags, and create, edit and publish tags and container versions when you ask us to. We do not delete containers or manage who has access to your Tag Manager account.
- Google Calendar (your agency’s own calendar, read only) — we read events to show client meetings, their cadence and whether they took place.
- Your basic profile (name and email address) — to identify which Google account was connected.
In handling this data:
- We use it only to provide and improve the features described above, which are visible to you in the product.
- We do not transfer it to others except as needed to provide those features, for security purposes, to comply with the law, or as part of a merger or sale with your prior consent.
- We do not use it for advertising.
- Our staff do not read it unless you have asked us to look at something specific, it is necessary for security or to comply with the law, or it has been aggregated for internal operations.
- We do not use Google Calendar data to create, train or improve any AI or machine-learning model. Agency Stack’s use of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
You can revoke our access at any time from the integration screen in the app, or from your Google Account permissions page. Revoking deletes the stored tokens (see Data deletion).
5. Meta platform data
You choose which Meta assets to connect, and we request only the permissions for those:
- Ad accounts — we read account, campaign, ad set, ad and creative performance, and apply the advertising changes you create or approve.
- Facebook Pages — we read the Pages you manage, their posts, comments, reviews and insights, and publish the posts and replies you create or approve.
- Instagram business accounts — we read insights and comments, and publish the content and replies you create or approve.
- Business assets — we read which ad accounts, Pages and Instagram accounts belong to a business, so the right assets are attached to the right client.
We use this data to run and report on that client’s advertising and social presence, and for nothing else.
We do not sell, license or transfer Meta Platform Data, and we retain it only as long as it is needed for those purposes. To delete it, follow the instructions on our Data deletion page, or remove Agency Stack from the Business Integrations section of your Facebook settings.
6. Sharing
We share personal data only with:
- Service providers that operate the service on our behalf and are bound by contract: hosting and storage, email delivery, search and keyword data, AI model providers, error monitoring, and website analytics. A current list is available on request from privacy@agencystack.ai.
- Other members of your workspace, according to the roles and client assignments your account owner configures.
- Authorities, where we are legally compelled, and where permitted we will tell you first.
- An acquirer, in a merger or sale, subject to this policy.
7. Security
- All third-party credentials — API keys, OAuth access and refresh tokens, CMS logins — are encrypted at rest with AES-256-GCM and decrypted only at the point of use. Decrypted values are never logged.
- Data is separated by workspace, and every query is scoped to the owning organisation.
- Access is role-based, and privileged actions are recorded in an audit log.
- Backups are taken continuously and restores are tested.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay and as required by law.
8. Retention
- Workspace content is kept while your workspace is active.
- Connected-account credentials are deleted when you disconnect the integration.
- After a workspace is closed, its content is erased 30 days later and ages out of backups within about 35 days after that, except where we must keep records longer for legal, tax or fraud-prevention reasons.
- Operational logs are retained for up to 90 days.
- Waitlist addresses are kept until launch and deleted on request at any time.
9. International transfers
We and our subprocessors may process data outside your country. Where required, transfers rely on Standard Contractual Clauses or another approved safeguard. Details are available on request.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict processing of your personal data, to object to it, and to complain to a supervisory authority. Contact privacy@agencystack.ai and we will respond within the period the law allows.
If your data sits in a workspace operated by an agency, we will refer your request to that agency as the controller and support them in answering it.
11. Deleting your data
See Data deletion for how to disconnect an integration, delete a workspace, or request erasure by email.
12. Children
The service is for business use and is not directed to anyone under 16. We do not knowingly collect their data; if we learn that we have, we delete it.
13. Cookies and analytics
We use cookies and similar technologies to keep the site and the application working, to understand how they are used, and to measure which of our own marketing led to a sign-up. To measure our advertising, we may share limited information with the advertising platforms we use, such as a hashed version of your email address and the identifier of an ad you clicked. You can block cookies in your browser settings, and the website works without them.
This is about how we market Agency Stack itself. It is separate from the data in the client accounts you connect, which is never used for advertising.
14. Changes
Material changes bump the version above and, where the change affects consent, you will be asked to accept the new version when you next sign in.
15. Contact
Questions or requests: privacy@agencystack.ai, or by post:
Shadyne LLC7533 S Center View Ct, # 5946West Jordan, UT 84084United StatesA Data Processing Agreement is available on request.