eGiiG Agency Suite
  • Home
  • Privacy
  • Terms
Login Get Started

Privacy Policy

Effective Date: March 27, 2026 | Last Updated: June 5, 2026

eGiiG ("we," "us," "our") operates the eGiiG Agency Suite platform accessible at https://egiig.com and https://apps.egiig.com, including the eGiiG browser extension (collectively, the "Service"). eGiiG is a multi-tenant SaaS platform for digital marketing agencies that enables centralized management of client ad accounts, social media, analytics, and outreach across multiple advertising and marketing platforms. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Full name, email address, and password (hashed using bcrypt)
  • Business/agency name and website URL
  • Billing address and payment information (processed by Stripe — we do not store credit card numbers)
  • Team member names and email addresses
  • Subscription plan and usage data

1.2 Client and Prospect Data

When you use our platform to manage clients and prospects, you may store:

  • Client names, email addresses, phone numbers, and business details
  • Prospect names, LinkedIn profile URLs, job titles, and company information
  • Communication history (messages sent and received via LinkedIn, email)
  • Campaign performance data (connection acceptance rates, reply rates)
  • Proposal and invoice records
  • Service agreements and onboarding data

1.3 LinkedIn Data (via Browser Extension)

Our browser extension collects the following data from LinkedIn with your explicit authorization:

  • Session cookies (li_at, JSESSIONID): Used to authenticate API requests to LinkedIn on your behalf. These cookies are encrypted in transit and stored encrypted at rest on our servers to enable cloud-based campaign execution.
  • Profile information: Your LinkedIn name, profile photo URL, headline, and connection count — used to display your account in our dashboard.
  • Prospect profile data: Names, titles, companies, and profile URLs of prospects you add to campaigns — collected only from profiles you explicitly select or search for.
  • Message content: Connection request notes and follow-up messages you compose or that our AI generates on your behalf, and replies received from prospects.

What we do NOT collect from LinkedIn:

We do not scrape or bulk-download LinkedIn user data. We do not access LinkedIn data of users who have not been explicitly added to your campaigns. We do not collect or store LinkedIn passwords. We do not sell LinkedIn data to third parties.

1.4 LinkedIn Data (via OAuth 2.0)

In addition to the browser extension, agencies may connect LinkedIn accounts via OAuth for publishing and advertising features. We request the following scopes through LinkedIn's official OAuth 2.0 flow:

ScopeWhat It AccessesWhy We Need It
openidOpenID Connect identity verificationSecurely identify the LinkedIn user during the OAuth login flow.
profileBasic profile info (name, photo)Display your name and photo within the eGiiG dashboard for account identification.
emailEmail address on file with LinkedInAssociate the connection with your eGiiG account and send connection-related notifications.
w_member_socialPublish posts on your LinkedIn profileAllow agencies to schedule and publish thought-leadership content on behalf of connected LinkedIn profiles via the Social Scheduler.
r_adsRead LinkedIn ad account dataDisplay LinkedIn ad campaign performance metrics (impressions, clicks, spend) in the Ad Control dashboard.
rw_adsCreate and manage LinkedIn ad campaignsAllow agencies to create, edit, pause, and manage LinkedIn advertising campaigns from within eGiiG.
r_ads_reportingAccess LinkedIn advertising reportsGenerate detailed performance reports for client-facing reporting within the platform.
r_ad_libraryView publicly available ads from the LinkedIn Ad LibraryEnable competitive analysis by viewing competitor ad activity within the Brand Intelligence module.
r_eventsRead LinkedIn event dataDisplay events associated with a LinkedIn Page or profile for campaign coordination.
w_eventsCreate and manage LinkedIn eventsAllow agencies to create and manage professional events on behalf of connected accounts.

Data safety: LinkedIn OAuth tokens are encrypted at rest and stored on a per-team, per-account basis. Tokens are automatically refreshed before expiry and immediately deleted when an account is disconnected. We never share LinkedIn data with third parties or use it for purposes beyond what is described above.

1.5 Google Data (via OAuth 2.0)

When agencies connect client Google accounts, we request access to multiple Google services through a single OAuth 2.0 consent flow. Each scope below corresponds to a specific feature within eGiiG. Only the data necessary for the authorized feature is accessed.

ScopeGoogle ServiceWhat It AccessesWhy We Need It
adwordsGoogle Ads APIAd accounts, campaigns, ad groups, keywords, performance metrics, conversionsDisplay campaign performance in the Ad Control dashboard, allow agencies to create and manage Google Ads campaigns, create conversion actions, and generate client reports.
analyticsGoogle AnalyticsWebsite traffic data, user behavior, conversion events, audience demographicsDisplay website analytics in the reporting dashboard so agencies can correlate ad spend with website performance.
analytics.editGoogle Analytics (write)Create goals, audiences, link Google Ads, manage Measurement Protocol secretsSet up conversion goals and create Measurement Protocol secrets required for server-side event tracking on behalf of clients.
analytics.readonlyGoogle Analytics (read)List properties, data streams, account configurationDiscover which Analytics properties a client has so the agency can select the correct one for reporting.
tagmanager.manage.accountsGoogle Tag ManagerList GTM accounts and containersDiscover the client's GTM setup so the agency can identify where tracking tags need to be installed.
tagmanager.edit.containersGoogle Tag Manager (write)Create, edit, and deploy tags, triggers, and variablesInstall conversion tracking tags (Google Ads, Analytics, Meta Pixel) on client websites via GTM without requiring direct website access.
tagmanager.readonlyGoogle Tag Manager (read)View existing tags, triggers, and variablesAudit current tracking setups on client websites and verify required tags are properly configured.
webmastersGoogle Search ConsoleSearch performance data, keyword rankings, crawl errors, sitemapsDisplay organic search performance and keyword ranking data in the SEO and reporting modules.
business.manageGoogle Business ProfileBusiness listing data, reviews, photos, business informationManage client Google Business Profiles within the Reputation Management module — respond to reviews, update business info, and monitor listing health.
contentGoogle Merchant CenterProduct feeds, product data, shopping campaign inventorySync client product catalogs for Google Shopping campaigns, ensuring product data is accurate and up-to-date.
datamanagerGoogle Data Manager APIServer-side conversion events, offline conversion data, enhanced conversion signalsUpload server-side conversion events (purchases, leads, bookings) to Google on behalf of clients for accurate conversion tracking and attribution.

Google API Services — Limited Use Disclosure: eGiiG's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google data only to provide the features described in this policy as directed by the agency user. We do not use Google data for advertising, do not sell Google data, and do not allow humans to read Google data except for security purposes, to comply with applicable law, or with explicit user consent.

Data safety: Google OAuth tokens are encrypted at rest. Refresh tokens maintain access without requiring re-authorization. We access only the data required for features the agency actively uses. When an account is disconnected, all tokens are immediately revoked and deleted. Agencies and their clients can also revoke access at any time via Google Account Permissions.

1.6 Meta / Facebook Data (via OAuth 2.0)

When agencies connect client Facebook or Instagram accounts, we request different scopes depending on the intended use. The agency selects whether the connection is for advertising management, social media posting, or both. Only the scopes relevant to the selected purpose are requested.

Base Scopes (always requested):

ScopeWhat It AccessesWhy We Need It
business_managementBusiness assets, ad accounts, Pages within Meta Business SuiteConnect and discover client business assets — identify which ad accounts, Pages, and Instagram accounts are available for agency management.
pages_show_listList of Facebook Pages the user managesDisplay client Facebook Pages in the connection flow so the agency can select which Pages to manage.
pages_read_engagementPage posts, comments, reactions, follower countsDisplay social engagement data in the analytics and reputation dashboards.

Advertising Scopes (requested when "Ads" purpose is selected):

ScopeWhat It AccessesWhy We Need It
ads_managementCreate, edit, pause, and delete ad campaignsBuild and manage Meta advertising campaigns on behalf of clients from the Ad Control module.
ads_readAd performance metrics — spend, impressions, clicks, conversions, ROASDisplay campaign performance data in the dashboard and generate client-facing reports.
pages_manage_adsCreate ads directly from Page posts (boost posts)Promote organic Page posts as paid ads without leaving the eGiiG platform.
leads_retrievalLead data from Facebook Lead Ads formsPull leads generated by Lead Ad campaigns into eGiiG's CRM for agency follow-up.
catalog_managementProduct catalogs for Dynamic Product AdsManage e-commerce product feeds for clients running Dynamic Product Ads and Shopping campaigns.

Social Posting Scopes (requested when "Social" purpose is selected):

ScopeWhat It AccessesWhy We Need It
pages_manage_postsPublish, edit, and delete posts on connected Facebook PagesSchedule and publish organic content on client Facebook Pages via the Social Scheduler module.
pages_manage_engagementManage comments and moderate Page engagementRespond to comments, hide spam, and moderate engagement on client Pages from the Unified Inbox.
pages_read_user_contentContent posted by visitors on the PageDisplay visitor posts and comments in the agency dashboard for monitoring and community management.
instagram_basicInstagram Business account profile info and mediaDisplay the connected Instagram account within the social management dashboard. Requested only when Instagram is selected as a connected asset.
instagram_content_publishPublish photos, videos, reels, and stories to InstagramSchedule and publish Instagram content on behalf of clients through the Social Scheduler. Requested only when Instagram is selected.

Meta Platform Compliance: Our use of Meta Platform data complies with Meta Platform Terms and Meta's Developer Policy. We only request the minimum scopes necessary for the features selected. We do not sell, license, or share Meta user data with third parties.

Data safety: Meta OAuth tokens are encrypted at rest and scoped per-client. When an account is disconnected, tokens are immediately revoked. Clients can also revoke access via Facebook Business Integrations settings.

1.7 TikTok Data (via OAuth 2.0)

When agencies connect client TikTok Business accounts, we request access through TikTok's Marketing API OAuth flow for advertising management and reporting.

Scope / PermissionWhat It AccessesWhy We Need It
ad_account_managementTikTok ad account settings and configurationConnect and identify client TikTok ad accounts for management within the Ad Control dashboard.
campaign_managementCreate, edit, and manage ad campaigns, ad groups, and adsBuild and manage TikTok advertising campaigns from within eGiiG.
Audience ManagementCustom and lookalike audience dataCreate and manage audience segments for targeted ad delivery on behalf of clients.
ReportingCampaign performance metrics — impressions, clicks, spend, conversionsDisplay TikTok ad performance in the dashboard and generate cross-platform reports.
Creative ManagementAd creative assets — videos, images, playable adsUpload and manage ad creative assets within the Creative Studio module.
Pixel ManagementTikTok Pixel configuration and eventsSet up and manage conversion tracking pixels on client websites.
Lead ManagementLead data from TikTok Lead Gen formsPull leads generated by TikTok campaigns into eGiiG's CRM for agency follow-up.
MeasurementAttribution and conversion measurement dataAnalyze conversion attribution across campaigns for accurate ROI reporting.

TikTok Events API (Server-Side Tracking): When enabled, eGiiG transmits conversion events to TikTok's Events API on behalf of the client. Data transmitted includes event type, event timestamp, and anonymized user parameters (hashed email, hashed phone). The TikTok click identifier (ttclid) and tracking parameter (ttp) are captured client-side by our tracking snippet to enable accurate attribution. All user identifiers are hashed using SHA-256 before transmission.

Compliance: Our use of TikTok Marketing API data complies with TikTok for Business Developer Terms. We access ad account data solely for campaign management and reporting.

1.8 Microsoft Advertising / Bing Data (via OAuth 2.0)

When agencies connect client Microsoft Advertising (Bing Ads) accounts, we request the following scope:

ScopeWhat It AccessesWhy We Need It
msads.manageFull management of Microsoft Advertising campaigns — accounts, campaigns, ad groups, keywords, performance data, and spendManage Bing/Microsoft search campaigns from eGiiG. Microsoft's search network covers approximately 30% of US desktop search traffic (Bing, Yahoo, DuckDuckGo), so agencies need centralized management alongside Google Ads.

Data safety: Microsoft OAuth tokens are encrypted at rest. We access only the campaign and performance data necessary for the Ad Control dashboard. Clients can revoke access at any time via Microsoft Account Permissions.

1.9 Server-Side Conversion Tracking

eGiiG provides a server-side conversion tracking engine that enables agencies to accurately measure the performance of their clients' ad campaigns across Google, Meta, and TikTok.

How it works: A lightweight JavaScript tracking snippet is installed on the client's website. This snippet captures platform-specific click identifiers when a visitor arrives from an ad:

  • Google: gclid, gbraid, wbraid parameters
  • TikTok: ttclid, ttp parameters
  • Meta: fbclid parameter

When a conversion event occurs (e.g., a purchase, form submission, or phone call), the conversion data is sent to our servers. eGiiG then transmits the conversion event to the appropriate advertising platform via their official server-side APIs:

  • Google: Via the Data Manager API (using the datamanager OAuth scope)
  • Meta: Via the Conversions API (CAPI) using the client's Meta access token and dataset/pixel ID
  • TikTok: Via the Events API using the client's TikTok access token and pixel ID

Data safety: All user identifiers (email addresses, phone numbers) are hashed using SHA-256 before being transmitted to any advertising platform. Click identifiers are stored temporarily in the browser (sessionStorage + first-party cookie) and on our servers only for the duration needed for attribution (typically 30–90 days). The tracking snippet does not collect browsing history, form inputs, or any data beyond the click identifiers and conversion events explicitly configured by the agency.

1.10 Website and SEO Data

When agencies connect client websites via our SEO plugin or Google Search Console integration:

  • Website content, meta tags, page structure, and performance metrics
  • Search engine ranking data, keyword positions, and backlink information
  • Google Analytics and Google Search Console data (accessed via the OAuth scopes described in Section 1.5)
  • PageSpeed and Core Web Vitals data (via public Google PageSpeed API)

1.11 Brand Intelligence Data

Our BrandEngine feature analyzes publicly available business information to generate brand profiles for campaign planning. Data sources include:

  • Publicly accessible website content (crawled with user authorization)
  • Google Business Profile data (via the business.manage scope when connected, or via public listings)
  • Publicly available review data from business directories
  • Public website performance metrics (PageSpeed, technology detection)

Data safety: Brand analysis is performed only on businesses that the agency has explicitly added as clients. We do not perform unsolicited data collection. All crawled data is processed through our AI pipeline and stored as structured analysis — raw crawl data is not permanently retained.

1.12 Payment Data

  • Payment processing is handled entirely by Stripe, Inc.
  • We store Stripe customer IDs and subscription status, but never store credit card numbers, CVVs, or full card details.
  • Stripe's privacy policy applies: https://stripe.com/privacy

1.13 Technical Data

We automatically collect:

  • IP address, browser type, operating system, and device information
  • Pages visited, features used, and session duration
  • Error logs and performance data
  • Cookies and similar tracking technologies

2. How We Use Your Information

We use the collected information for the following purposes:

  • Service delivery: Executing LinkedIn outreach campaigns, managing ad accounts across Google, Meta, TikTok, Microsoft, and LinkedIn, generating reports, processing invoices and proposals
  • AI-powered features: Generating personalized connection notes, composing auto-replies, analyzing brand data, creating ad creative suggestions, and building brand intelligence profiles
  • Cloud execution: Running LinkedIn campaigns via our servers using your authenticated session and residential proxy connections
  • Cross-platform campaign management: Creating, monitoring, and optimizing ad campaigns across all connected advertising platforms from a single dashboard
  • Server-side conversion tracking: Transmitting conversion events to advertising platforms for accurate campaign attribution and optimization
  • Client management: Storing client data, onboarding information, and communication history
  • Billing: Processing payments, managing subscriptions, and sending invoices
  • Service improvement: Analyzing usage patterns to improve features and performance
  • Communication: Sending transactional emails (account verification, billing receipts, campaign notifications)
  • Security: Detecting and preventing fraud, unauthorized access, and abuse

3. How We Share Your Information

We do NOT sell your personal information or your clients' data to third parties.

We may share information with:

3.1 Service Providers

  • Stripe: Payment processing
  • Residential proxy providers (e.g., IPRoyal): For routing LinkedIn API requests through residential IP addresses. Only the HTTP request is routed — no personal data is shared with proxy providers.
  • AI providers (e.g., Azure OpenAI, Anthropic): Content may be sent to AI providers for generating personalized outreach messages, ad copy, brand analysis, and auto-replies. We use API-only access with no-data-retention agreements where available. No provider is trained on your data.
  • Cloud hosting providers: Server infrastructure for running the platform
  • Image generation services (e.g., fal.ai): Text prompts are sent to generate ad creative images. No personal or client data is included in generation prompts.

3.2 Advertising Platforms

We transmit data back to advertising platforms in the following scenarios, all explicitly initiated by the agency user:

  • Creating, modifying, or pausing ad campaigns (Google, Meta, TikTok, Microsoft, LinkedIn)
  • Uploading server-side conversion events for attribution (Google Data Manager API, Meta Conversions API, TikTok Events API)
  • Managing product catalogs for Shopping campaigns (Google Merchant Center, Meta Catalogs)
  • Publishing organic content to connected social pages (Facebook Pages, Instagram, LinkedIn)

3.3 Your Clients (White-Label)

If you use our white-label feature, your clients interact with the platform under your branding. We do not independently contact your clients.

3.4 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

4. Data Retention

  • Account data: Retained for the duration of your active account plus 30 days after account deletion.
  • Campaign data (LinkedIn, ads, social): Retained for the duration of your subscription. Deleted within 30 days of account closure or upon request.
  • LinkedIn session cookies: Retained only while the associated LinkedIn account is connected. Deleted immediately upon disconnection.
  • OAuth tokens (all platforms): Encrypted at rest. Automatically revoked and deleted when an account is disconnected.
  • Server-side conversion data: Click identifiers and conversion events retained for 90 days to enable accurate attribution, then automatically purged.
  • Prospect and client data: Retained for the duration of your subscription. You may delete individual records at any time.
  • Brand intelligence data: Analysis results retained for the duration of your subscription. Raw crawl data is processed and discarded.
  • Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
  • AI-generated content: Not retained by AI providers beyond the API call. Stored on our platform only as part of your campaign and brand data.

5. Data Security

We implement industry-standard security measures:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.2+
  • OAuth tokens for all platforms (Google, Meta, TikTok, Microsoft, LinkedIn) are encrypted at rest
  • LinkedIn session cookies are stored encrypted at rest
  • Passwords are hashed using bcrypt
  • User identifiers sent for server-side conversion tracking are hashed using SHA-256
  • Database access is restricted to authorized application services only
  • Our infrastructure is hosted on secure VPS providers with firewall protection
  • Regular security audits and dependency updates
  • API keys and OAuth tokens are encrypted before storage
  • Multi-tenant data isolation — each agency's data is logically separated at the database level

6. Your Rights and Choices

6.1 Access and Portability

You may request a copy of all personal data we hold about you by contacting support@egiig.com.

6.2 Correction

You may update your account information at any time through the dashboard Settings page.

6.3 Deletion

You may request deletion of your account and all associated data by contacting support@egiig.com. We will process deletion requests within 30 days. Deletion includes all OAuth tokens, campaign data, client records, and brand analysis data.

6.4 OAuth Revocation

You may disconnect any connected account at any time through our dashboard. This immediately revokes our access to that platform's data and deletes the stored tokens. You may also revoke access directly from each platform:

  • Google: myaccount.google.com/permissions
  • Meta / Facebook: Facebook Business Integrations
  • TikTok: TikTok Business Center → Settings → Data Sharing
  • Microsoft: account.live.com/consent/Manage
  • LinkedIn: LinkedIn Permitted Services

6.5 LinkedIn Extension

You may uninstall the browser extension at any time. Uninstalling immediately stops all data collection from LinkedIn. To also delete stored LinkedIn session data from our servers, disconnect the LinkedIn account from the dashboard.

6.6 Server-Side Tracking Opt-Out

Agencies can disable server-side conversion tracking for any client at any time through the Ad Control dashboard. When disabled, no further conversion events are transmitted to advertising platforms. Existing conversion data is retained for the standard 90-day attribution window, then automatically purged.

6.7 Email Communications

You may opt out of non-essential emails by clicking "unsubscribe" in any marketing email or updating your notification preferences in Settings.

7. Cookies and Tracking

We use the following cookies:

CookiePurposeDuration
Session cookieAuthenticationBrowser session
Sanctum tokenAPI authentication30 days
Preference cookiesDashboard settings1 year

Client-side tracking snippet: When installed on a client's website for server-side conversion tracking, our snippet stores ad click identifiers (gclid, gbraid, wbraid, ttclid, ttp, fbclid) in the browser's sessionStorage and a first-party cookie. These identifiers are used solely for conversion attribution and are not used for cross-site tracking, behavioral profiling, or advertising.

We do not use third-party advertising trackers on the eGiiG platform itself. We do not serve ads within our platform.

8. International Data Transfers

Our servers are located in Europe. If you access our Service from outside Europe, your data may be transferred to and processed at our server locations. We ensure appropriate safeguards are in place for international data transfers, including encryption in transit and at rest.

9. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal information, we will delete it promptly.

10. GDPR Compliance (European Users)

If you are a resident of the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restrict processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

Legal bases for processing:

  • Contract performance: Providing the Service you signed up for
  • Legitimate interest: Improving our Service, preventing fraud
  • Consent: Marketing communications, AI processing of content, OAuth-based platform connections

To exercise any of these rights, contact us at privacy@egiig.com.

11. CCPA Compliance (California Users)

If you are a California resident, you have the right to:

  • Know what personal information we collect
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising your privacy rights

12. Specific Platform Compliance

12.1 Google API Services

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google data to provide and improve the eGiiG platform features described in this policy.
  • We do not transfer Google data to third parties except as necessary to provide the Service, with user consent, for security purposes, or to comply with applicable law.
  • We do not use Google data for serving advertisements.
  • We do not allow humans to read Google user data except with explicit consent, for security incidents, to comply with applicable law, or when aggregated and anonymized for internal operations.

12.2 Meta Platform

Our use of Meta Platform data complies with Meta Platform Terms and Meta's Developer Policy. We access only the data necessary to provide our advertising management and social posting services. We do not store Meta data longer than necessary.

12.3 TikTok for Business

Our use of TikTok Marketing API data complies with TikTok for Business Developer Terms. We access ad account data solely for campaign management, conversion tracking, and reporting.

12.4 LinkedIn

Our use of LinkedIn data complies with LinkedIn API Terms of Use. OAuth-based access is used for publishing and advertising features. Browser extension-based access is used for outreach automation. We do not scrape LinkedIn, bulk-download data, or use LinkedIn data for purposes beyond those authorized by the user.

12.5 Microsoft Advertising

Our use of Microsoft Advertising API data complies with Microsoft Advertising API Terms. We access campaign data solely for display and management within the eGiiG Ad Control dashboard.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices:

  • Email: support@egiig.com
  • Website: https://egiig.com
  • Data Protection Inquiries: privacy@egiig.com

15. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read the privacy policies of any third-party sites you visit.

eGiiG

All-in-one agency management platform for digital agencies. Manage leads, clients, campaigns, and more from a single dashboard.

Product
  • Get Started
  • Login
  • Features
  • Agency Website
Legal
  • Privacy Policy
  • Terms of Service
Support
  • Email Support
  • Privacy Questions
  • Main Website

© 2026 eGiiG. All rights reserved.

Privacy Policy Terms of Service Agency Website