Privacy policy
Last updated: 15 September 2026
This policy explains what DrMarketo collects, why it collects it, who it is shared with, and how long it is kept. It covers the DrMarketo panel and every connected marketing account managed through it.
Who we are
DrMarketo is a marketing management panel. Businesses connect the accounts they already own — Google Business Profile, Google Ads, Facebook, Instagram, LinkedIn, X and WhatsApp Business — and use DrMarketo to publish content, read performance, and manage those listings from one place.
We act as a data processor for the account data a customer connects. The customer remains the owner of their listings, their advertising accounts and the content they publish.
What we collect
Account information
- Name, email address and phone number, supplied at sign-up.
- Organisation name and billing details, where a paid plan is in use.
- Sign-in events, including time and approximate location, kept for account security.
Connected platform data
When a customer connects a marketing account, we store the access and refresh tokens that platform issues, together with the data needed to render the screens that account powers. We request the narrowest set of permissions each feature needs, and nothing is connected without the customer completing that platform's own consent screen.
Google user data
DrMarketo uses Google APIs. This section sets out exactly what we do with data obtained through them.
What we access, and why
-
Google Business Profile (
business.manage) — to read and update the listings a customer manages: business name, categories, opening hours, services, description, photos, posts, reviews and performance figures. Every one of those is shown on a screen the customer opened, or changed by an edit the customer saved. -
Google Ads (
adwords) — to read campaign, ad group and ad performance for the advertising accounts a customer manages, and to create or update campaigns the customer builds in the panel. -
Basic profile (
openid,email,profile) — to identify which Google account was connected, so the right listings appear against the right connection.
Limited Use
DrMarketo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through Google APIs is:
- used only to provide and improve the features described above;
- never sold, and never transferred to anyone except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition under equivalent commitments;
- never used for advertising of our own, including retargeting or personalised advertising;
- never read by a human, except with the customer's explicit permission for support, where required by law, or where strictly necessary for security or to comply with applicable law.
We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. Content suggestion features in the panel send only the prompt or draft the customer is working on, and never the contents of a Google account.
Disconnecting
A customer can disconnect a Google account at any time from the Accounts screen in the panel, which revokes the tokens we hold and stops all further access. Access can also be revoked directly at myaccount.google.com/permissions. Stored figures belonging to that connection are deleted within thirty days of disconnection.
How we use what we collect
- To provide the panel and the features a customer has asked for.
- To authenticate people, and to keep accounts secure.
- To bill for paid plans, and to send service messages about an account.
- To diagnose faults. Application logs record errors and the request that caused them; they do not record credentials or access tokens.
We do not sell personal data. We do not share it with advertisers or data brokers.
Who we share it with
We use a small number of processors, each for a stated purpose:
- Hosting and storage — to run the application and hold its database.
- Payment processing — to take payment for paid plans. Card details are handled by the payment provider and never reach our servers.
- Email and messaging delivery — to send account and service messages.
- The marketing platforms a customer connects — data flows to and from those platforms because that is the purpose of connecting them.
We disclose data to law enforcement only where we are legally required to, and we notify the affected customer unless the law forbids it.
How long we keep it
- Account records — for as long as the account is open, and for up to twelve months afterwards so an account can be restored and so billing records meet statutory retention requirements.
- Connected platform tokens — until the connection is removed or the token is revoked, whichever comes first.
- Performance figures mirrored from a platform — up to eighteen months rolling, or until the connection is removed.
- Application logs — ninety days.
Security
- All traffic to the panel is encrypted in transit.
- Access tokens are stored encrypted at rest and are never displayed back in full.
- Each organisation's data is isolated at the query level, so one customer cannot read another's records.
- Administrative access is restricted and logged.
No system is perfectly secure. If a breach affects personal data, we will notify affected customers and any regulator we are required to notify, without undue delay.
Your rights
Depending on where a person lives, they may have the right to access, correct, export or delete their personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to us at the address below and we will respond within thirty days.
Where a customer's end customers are involved — for example, people who leave reviews on a connected Business Profile — the customer is the controller of that data and requests should go to them first.
Children
DrMarketo is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under sixteen.
International transfers
Data may be processed in a country other than the one a customer is based in. Where that happens we rely on appropriate safeguards, including standard contractual clauses where they apply.
Changes
We will update this page when our practices change and revise the date at the top. Material changes are announced in the panel before they take effect.
Contact
Questions about this policy, or a request about your data, go to drmarketoofficial@gmail.com.