Skip to content
Security

What we can see, and how we look after it.

You’re connecting your Google and Meta accounts to a company you may have just found. Here’s exactly what that means, in plain terms.

What we access

Only what you hand us.

Only what you connect

We read Google Business Profile, Search Console and Analytics data only through the OAuth scopes you approve. Facebook Pages, Instagram and WhatsApp Business data comes only through the Meta permissions you grant.

Your public website

The audit reads the pages anyone on the internet can already see. It does not sign in to your site.

Nothing changes without approval

Every change to your listings or site is proposed first and waits for your yes. You can disconnect any account at any time.

How it’s protected

Handled the boring, careful way.

Encrypted in transit

Data moving between you, our platform and the services we connect to travels over TLS.

Need-to-know access

Access to client data is limited to the people working on your engagement, and only for that work.

Where it lives

Our platform runs on two cloud infrastructure providers, Amazon Web Services and Railway. Meta Platform data stays with those two and is shared with no one else.

Payments

Payments run through Stripe. Card details go to Stripe, not to us.

Retention

How long we keep it.

Google and Meta account data
Deleted within 30 days of disconnecting the account or ending the engagement.
Engagement records
Kept for the length of the engagement plus 12 months.
Audit reports and audit trails
Kept for 24 months so re-audits can be compared against the baseline.
Deletion on request
Ask any time. We confirm deletion within 30 days.

How to request deletion · Full privacy policy

What we don’t do

We never:

  • Sell, rent or trade your data.
  • Use Google account data for ad targeting or to train machine-learning models.
  • Share Meta Platform data with anyone beyond our two infrastructure providers.
Certifications

No SOC 2 report today.

We don’t hold a SOC 2 report or another third-party security certification yet, and we won’t imply otherwise. If your vendor review needs one, ask and we’ll tell you where things stand and answer your questionnaire directly.

Questions or a concern

Tell us.

Security questions, a vendor questionnaire, or something that looks wrong: email info@nocodelabs.io with “Security” in the subject line.