Privacy Policy
Effective date: September 15, 2026
Updated September 26, 2026: added the Meta Platform Data and Requesting Deletion sections.
This Privacy Policy describes how No Code Labs Inc., a Delaware corporation (“No Code Labs Inc.,” “we,” “us”), collects, uses, and protects your information when you visit our website, submit intake forms, or engage our diagnostic and execution services. By using our website or services, you consent to the practices described in this policy.
Information We Collect. We collect personal information that you voluntarily provide when interacting with our services, including your name, email address, company name, website URL, and business information submitted through our intake forms and contact form. We also automatically collect technical data through standard web server logs, including your IP address, browser type, operating system, referring URLs, and pages visited on our site. This technical data is used for security monitoring and to improve the performance and usability of our website.
How We Use Your Information. We use the information we collect to deliver diagnostic audit reports and governed execution services as described in your engagement scope. We use your contact information to communicate about your engagement, including transmitting findings, recommendations, and approval requests related to governed execution actions. We use payment information to process transactions through Stripe. We may also use aggregated, de-identified data to improve our diagnostic methodology, scoring algorithms, and overall service delivery. We do not use your information for purposes unrelated to the services we provide.
Information Sharing. We do not sell, rent, or trade your personal information to third parties. We share data only with the following service providers as necessary to deliver our services: Stripe for secure payment processing, Amazon Web Services (AWS) for form submission processing and cloud infrastructure, and any third-party tools required to deliver your specific engagement, which will be disclosed to you during the intake process prior to access being granted. All third-party service providers are bound by their own privacy policies and data protection obligations.
Google User Data. When you connect your Google accounts to the NoCode Labs platform, we access your data only through the OAuth scopes you explicitly authorize. We request the following scopes for these specific purposes:
- Business Profile Management (
business.manage): to read your Google Business Profile listing data, track verification status, and generate GBP metrics within your Digital Presence Score. - Search Console Read (
webmasters.readonly): to retrieve crawl errors, indexing status, and search performance data used to calculate your DPS technical health scores. - Analytics Read (
analytics.readonly): to read Google Analytics 4 traffic, session, and engagement data incorporated into your Digital Presence Score and engagement analysis.
Data accessed under these scopes is used exclusively to generate your Digital Presence Score, produce recommendations, and populate your private client portal. We do not sell, share, or disclose your Google account data to any third party for purposes unrelated to your engagement. We do not use Google account data for advertising targeting or to train machine learning models. Retention of Google account data follows the schedule in the Data Retention section below. If you revoke OAuth access or terminate your engagement, all Google account data we hold will be deleted within 30 days. To review or revoke connected application permissions at any time, visit https://myaccount.google.com/permissions.
Limited Use of Google User Data. NoCode Labs’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Meta Platform Data. When you connect a Facebook Page, Instagram business account, or WhatsApp Business account to the NoCode Labs platform, we receive data from Meta Platforms, Inc. only through the permissions you explicitly grant. We use this data solely to deliver the audit, publishing, advertising, and messaging services described in your engagement scope. Depending on the permissions you grant, the data we access may include:
- Facebook Pages: Page ID, Page name, and post and Page insights.
- Instagram: Instagram business account ID, media IDs, and media insights.
- Advertising: ad account IDs and ad performance metrics.
- WhatsApp Business: phone number ID, message templates, and message delivery status.
We do not store raw ad audience data, and we do not store the personal profile data of people who interact with your Pages, posts, or ads. We do not sell Meta Platform data, use it for advertising targeting outside your own campaigns, or use it to train machine learning models. Meta Platform data is processed and stored only on our cloud infrastructure providers, Amazon Web Services and Railway, and is not shared with any other third party. By connecting a Meta account, you represent that you have obtained any consent required from end users whose data you cause us to receive from Meta on your behalf.
Meta Platform Data Retention. We keep Meta Platform data only while your account is connected and your engagement is active. If you disconnect your Meta account or end your engagement, all Meta Platform data we hold is deleted within 30 days. You can remove NoCode Labs’ access at any time from the Business Integrations or Apps and Websites section of your Facebook settings.
Requesting Deletion. You may request deletion of any data we hold about you, including Meta Platform data, by emailing info@nocodelabs.io or by following the steps on our data deletion page. We will confirm deletion within 30 days.
Data Retention. We retain engagement data, including contact information and project records, for the duration of your active engagement plus 12 months following its conclusion. Diagnostic reports, audit trails, and associated deliverables are retained for 24 months to support re-audit comparisons and longitudinal analysis of improvements. Upon expiration of these retention periods, data is securely deleted. You may request deletion of your personal data at any time by contacting info@nocodelabs.io, and we will process such requests within 30 days, subject to any legal obligations requiring continued retention.
Security. We implement industry-standard security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission via TLS/SSL, secure cloud infrastructure hosted on reputable platforms, and access controls that limit data access to authorized team members on a need-to-know basis. While no method of electronic transmission or storage is completely secure, we are committed to maintaining appropriate safeguards commensurate with the sensitivity of the information we process.
Your Rights. You have the right to request access to the personal data we hold about you, to request correction of any inaccurate information, and to request deletion of your personal data. To exercise any of these rights, contact us at info@nocodelabs.io. We will respond to all legitimate requests within 30 days.
Changes to This Policy. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Your continued use of our website or services following the posting of changes constitutes your acceptance of those changes.