Privacy Policy
Last updated: May 29, 2026
1. Information We Collect
ClientPlug collects information you provide when creating an account, including your email address and password. When you connect third-party services (such as Stripe, Meta Ads, or Google Ads), we store access tokens necessary to retrieve your business data on your behalf.
2. How We Use Your Information
We use your information solely to provide the ClientPlug service, including syncing client payment statuses from Stripe and campaign performance data from Meta Ads and Google Ads. We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Third-Party Services
ClientPlug integrates with Stripe, Meta (Facebook), and Google to retrieve business data you authorize. These integrations only access data within the scopes you explicitly grant. You can disconnect these services at any time from your Settings page.
4. Data Storage and Security
Your data is stored securely using Supabase with row-level security policies ensuring you can only access your own data. Access tokens are stored encrypted and are never exposed to the browser.
5. Data Retention and Deletion
You may delete your account and all associated data at any time. When you disconnect a third-party service, the associated access tokens are immediately removed from our database. See our data deletion policy for details.
6. Google User Data and Limited Use
ClientPlug's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
ClientPlug does not use Google user data received from Google Workspace or Google Calendar APIs with any artificial intelligence or machine learning model, and never transfers this data to any third party to develop, train, or improve AI/ML models. ClientPlug's AI features analyze only advertising campaign performance data (from Meta and Google Ads) and do not access Google Calendar data. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
When you connect Google Calendar, ClientPlug accesses your calendar events (via the calendar.eventsscope) only to: (a) create, update, and delete calendar events that correspond to to-do tasks you create in ClientPlug, and (b) display your existing calendar events within ClientPlug so you can schedule tasks without conflicts. We also access your Google account's email address to show which account you connected.
We access this data only with your explicit consent, use it solely to provide the features described above, and do not transfer or sell it to third parties, use it for advertising, or allow humans to read it except (i) with your explicit consent, (ii) as necessary for security purposes such as investigating abuse, or (iii) to comply with applicable law. You can revoke ClientPlug's access at any time by disconnecting Google Calendar from the Integrations page, or through your Google Account permissions at myaccount.google.com/permissions.
How Google user data is protected. Google user data is transmitted over encrypted connections (HTTPS/TLS) and stored in our Supabase Postgres database under row-level security policies, so only your own account can read it. OAuth tokens are held server-side only and are never exposed to the browser or to other users.
What we retain, and deletion. We store only what is needed to provide the features above: your Google account email address, your OAuth tokens, and the Google event ID of events we create for your tasks. We do not store the contents of your other calendar events. They are fetched from Google on demand to render your calendar view and are not persisted by ClientPlug. When you disconnect Google Calendar, your OAuth tokens are deleted from our database immediately, and deleting your account removes all associated data. See our data deletion policy for details.
7. Contact
If you have questions about this privacy policy, please contact us at support@clientplug.io.