Privacy Policy
Effective date: August 2, 2026
Brandwave provides marketing analytics software for agencies, internal teams, and business owners. This policy explains what information we collect, how we use it, and how to request deletion of data connected through Facebook, Instagram, Google Ads and other integrations.
What we collect
We collect account information you provide directly, such as your name, email address, organisation details, billing contacts, and workspace preferences.
When you connect a platform, we may store access tokens, account identifiers, page or ad account names, permissions granted, and performance data returned by the platform APIs.
How we use data
We use connected platform data to authenticate your integrations, sync analytics into your workspace, generate reports, power diagnostics, and improve the reliability of the service.
We do not sell your connected platform data. Access is limited to authorised users in your organisation and to subprocessors required to run the service.
Facebook and Meta platform data
If you connect Facebook Pages or Meta Ads, Brandwave may access the pages, businesses, ad accounts, post metadata, engagement statistics, audience aggregates, and reporting data that Meta authorises for your app and account permissions.
Brandwave does not receive your Facebook password. Authentication happens on Meta's own consent screens.
Google user data and Limited Use
If you connect Google Ads, Brandwave requests the https://www.googleapis.com/auth/adwords scope. We use it to read the Google Ads accounts your login can reach and their campaign performance: account names, currencies and time zones, campaign names, statuses, budgets, channel types, and metrics such as cost, impressions, clicks, conversions and conversion value.
Access is read-only. Brandwave does not create, edit, pause or delete campaigns, budgets or any other object in your Google Ads account, and it does not access Gmail, Drive, Contacts or any other Google service.
Brandwave's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data to serve advertising, we do not sell it, we do not transfer it except as necessary to provide or improve the features you connected it for, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
Google Ads data is stored in your own Brandwave workspace and is visible only to members of your organisation. You can disconnect Google Ads at any time from the Accounts screen, which removes the stored credential and the synced reporting data.
Credentials and security
Brandwave never receives your password for any connected platform. Authentication happens on the platform's own consent screen, and Brandwave receives only the access and refresh tokens that screen issues.
Tokens are stored in our database with row-level access controls that restrict them to your organisation, and are transmitted only over TLS to the platform that issued them. Revoking Brandwave's access from your Google or Meta account settings invalidates them immediately.
Retention
Workspace data is retained while your account is active and for any additional retention period configured in your Brandwave settings, unless deletion is requested earlier or a longer retention period is required by law.
Your choices
You can disconnect integrations from the Brandwave app, request exports of stored data, or request deletion by emailing info@inhsystem.com.
For Facebook-originated deletion requests, see our Data Deletion Instructions.
You can also revoke Brandwave's access directly at Google Account permissions, which stops all further Google Ads syncing immediately.
Contact
If you have privacy questions or want to exercise your rights, contact info@inhsystem.com.