A
ActionLab Agency
FeaturesPricingIntegrationsLog inStart Free Trial
Start Free Trial

Privacy Policy

Last updated: April 7, 2026

1. Introduction

ActionLab Agency (“we,” “us,” or “our”) operates the ActionLab Agency platform at actionlabagency.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

By using ActionLab Agency, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access the service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and password (stored as a bcrypt hash, and we never store plaintext passwords). If you represent an agency, we also collect your organization name.

2.2 Billing Information

Payment processing is handled by Stripe, Inc. We do not store credit card numbers, CVVs, or full card details on our servers. Stripe's privacy policy governs the handling of your payment information. We store only your Stripe customer ID and subscription status.

2.3 Third-Party Platform Data (OAuth Integrations)

When you connect third-party platforms (such as Google Analytics, Google Ads, Meta Ads, LinkedIn, TikTok, HubSpot, Salesforce, Mailchimp, Klaviyo, and others) to ActionLab Agency, we request OAuth access tokens that allow us to read analytics and performance data from those platforms on your behalf.

What we access: Aggregated marketing metrics such as impressions, clicks, conversions, sessions, page views, ad spend, keyword rankings, email open rates, and similar performance data. We access this data solely to display it in your dashboards and reports.

What we do NOT access: We do not access personally identifiable information (PII) of your end users or customers through these integrations. We do not read individual user profiles, contact lists, email content, ad creative content, private messages, or customer records unless specifically required by the integration (e.g., HubSpot contact counts for CRM metrics).

Token storage: OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM encryption before being stored in our database. Tokens are only decrypted in memory when actively syncing data from the connected platform.

Token revocation:You can disconnect any integration at any time, which immediately deletes the stored tokens. You can also revoke access directly from the third-party platform's settings.

2.4 Usage Data

We collect standard server logs including IP addresses, browser type, pages visited, timestamps, and referring URLs. This data is used for security, debugging, and service improvement.

2.5 Client Data

You may create client profiles within ActionLab Agency that include your client's business name, domain, and logo. This data is provided by you and is used solely to organize your dashboards, reports, and portal access.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the ActionLab Agency service
  • Sync marketing data from connected third-party platforms into your dashboards
  • Generate and deliver scheduled reports to your specified recipients
  • Generate AI-powered insights and analysis of your marketing data
  • Process payments and manage your subscription
  • Send transactional emails (account verification, password reset, report delivery)
  • Monitor service health and prevent abuse
  • Respond to your support requests
  • Comply with legal obligations

We do notsell, rent, or trade your personal information or your clients' marketing data to third parties. We do not use your connected platform data for advertising, profiling, or any purpose other than displaying it within your ActionLab Agency account.

4. AI-Powered Features

ActionLab Agency uses artificial intelligence (powered by Anthropic's Claude API) to generate insights and summaries of your marketing data. When you use AI features:

  • Aggregated, non-personally-identifiable metrics from your dashboards are sent to Anthropic's API for analysis
  • Anthropic does not use your data to train their models (per their data processing agreement for API customers)
  • AI-generated insights are stored in your account for display purposes and are deleted when you delete your account

5. Data Retention

Marketing metrics data: Synced data from third-party platforms is retained for up to 2 years in our analytics database. Daily and monthly aggregations are retained for the duration of your subscription.

Account data: Your account information is retained for the duration of your subscription. Upon account deletion, all personal data, organization data, client data, connected integration tokens, dashboards, reports, and synced metrics are permanently deleted within 30 days.

Server logs: Standard access logs are retained for 90 days and then automatically purged.

Backups: Database backups may retain deleted data for up to 30 additional days, after which backups are rotated and the data is permanently removed.

6. Data Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted via TLS 1.2 or higher
  • OAuth tokens are encrypted at rest using AES-256-GCM
  • Passwords are hashed using bcrypt with appropriate cost factors
  • Database access is restricted to application services via private networking
  • Administrative access requires SSH key authentication
  • Rate limiting is applied to all authentication endpoints
  • Security headers (CSP, HSTS, X-Frame-Options) are enforced on all responses

While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

7. Sub-Processors

We use the following third-party services to operate ActionLab Agency:

ServicePurposeLocation
DigitalOceanCloud hosting & infrastructureUnited States
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
AnthropicAI insights (Claude API)United States
SentryError monitoringUnited States

8. Cookies

ActionLab Agency uses a single essential cookie (al_token) to maintain your authenticated session. This cookie is HttpOnly, Secure, and SameSite=Lax. It contains a signed JWT and expires after 7 days.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not participate in cross-site tracking.

9. Your Rights

9.1 General Rights (All Users)

You have the right to:

  • Access your personal data held by us
  • Correct inaccurate or incomplete personal data
  • Delete your account and all associated data
  • Disconnect any third-party integration and revoke our access
  • Export your data in a machine-readable format

9.2 European Economic Area (GDPR)

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability, the right to restrict processing, and the right to object to processing. Our legal basis for processing your data is contractual necessity (to provide the service you subscribed to) and legitimate interest (to maintain security and improve the service).

To exercise any of these rights, contact us at legal@hubrigcrewmarketing.com.

9.3 California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. You have the right to request disclosure of the categories and specific pieces of personal information we have collected, the right to request deletion, and the right to opt out of the sale of personal information.

We do not sell personal information. To exercise your rights, contact us at legal@hubrigcrewmarketing.com.

10. Children's Privacy

ActionLab Agency is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

legal@hubrigcrewmarketing.com

A
ActionLab Agency

Flat-rate agency reporting.
$99/mo. Unlimited everything.

Product

  • Features
  • Pricing
  • Integrations

Legal

  • Privacy Policy
  • Terms of Service

Contact

  • legal@hubrigcrewmarketing.com

© 2026 ActionLab Agency. All rights reserved.

Software and website development by Hubrig Crew Marketing