Privacy Policy
Updated September 14, 2026
This policy explains how Agency OS handles information supplied by users and information accessed through connected platforms.
Information the ERP stores
We store the information needed to operate an agency workspace, including user identity, organization membership, CRM records created by users, security logs, and basic integration connection status.
Connected-platform data
When an authorized agency administrator connects Google Calendar, Google Ads, Meta and Instagram Ads, QuickBooks Online, Stripe, or Twilio, the provider displays its own authorization screen. The ERP stores an encrypted authorization grant and the minimum account, company, calendar, or advertising-account identifiers needed to operate the connection.
Provider business records—such as campaigns, performance metrics, calendar events, invoices, payments, expenses, and message bodies—are requested when an authorized user opens the corresponding view. The ERP is designed not to automatically persist those provider records in its database. An agency may explicitly save selected, normalized advertising metrics and its own commentary as a client report. Saved reports include the reporting period, source settings and agency branding, rather than raw provider responses or credentials.
How connected data is used
Connected data is used only to display reporting and operational information requested by the authorized organization. The ERP does not sell connected account data or use it for unrelated advertising.
Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Service providers
Vercel hosts the application runtime and Supabase provides authentication and database services. Connected platforms process authorization and API requests under their own terms and privacy policies. Our configured transactional email provider processes recipient email addresses, report invitations and verification codes when those messages are requested. We may also disclose information when required by law or to protect the service and its users.
Security and retention
Integration grants are server-only and encrypted at rest. Access is limited by organization membership and role. No internet service can guarantee absolute security, but we use reasonable technical and organizational safeguards and remove grants when a connection is disconnected or deleted.
Saved client reports remain in the agency archive. Private links have independent email verification, expiration and revocation controls. Ending recipient access does not delete the agency's original report or a copy the recipient downloaded. Report deletion requests follow the contact process below.
Your choices
Organization administrators can disconnect an integration inside the ERP and can also revoke it from the connected provider. To request access, correction, or deletion, visit the data-deletion page or contact us.
Contact
Tribble Digital, LLC
3300 Sandpiper Circle
Northlake, Texas 76226
alec@tribbledigital.com