Privacy Policy
Privacy Policy
Last Updated: October 8, 2026
Odo Marketing website, agency services, the Odo Marketing Dashboard, Glint and Campaign Manager
Introduction
At Odo Marketing, we take your privacy seriously. This Privacy Policy explains how we collect, use and protect information across everything we operate. By using our website, our agency services or any of our products, you consent to this policy.
This policy is divided into five parts:
- Part A: Website visitors and marketing agency clients
- Part B: Glint, our social media app for subscribers (socialapp.odomarketing.com), and Campaign Manager, our ads app (campaigns.odomarketing.com)
- Part C: The Odo Marketing Dashboard for agency clients (dashboard.odomarketing.com)
- Part D: Every third-party platform permission we request, what it is for and what we store
- Part E: Retention, deletion, your rights, sub-processors and contact details
One policy for all our products.This page is the privacy policy we provide to Meta, Google, LinkedIn, X, TikTok, Snap, Pinterest, Amazon, Shopify, Canva and Dropbox for every Odo Marketing app. If you reached it from a platform's app listing or consent screen, Part D lists exactly what that app requests.
Part A: Website and Marketing Agency Services
1. Information Collection
1.1 Personal Information
We collect personal information such as your name, email address, phone number, company and other contact details when you provide them through forms, registrations, proposals or direct communication.
1.2 Usage Data
We also collect non-personally identifiable information about your visit, including IP address, browser, device, pages viewed and referring site. We use first-party analytics to understand how the site is used and to improve it.
2. Use of Information
2.1 Internal Use
We use the information you give us to respond to enquiries, prepare proposals, deliver the services you engage us for, provide support and improve our website and services.
2.2 Communication
We may send you updates, newsletters or offers related to our services. You can opt out at any time using the unsubscribe link in the email or by contacting us.
3. Information Security
We use industry-standard measures to protect your information from unauthorised access, disclosure, alteration or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
4. Third-Party Disclosure
We do not sell, trade or transfer your personal information to third parties without your consent unless required by law. We share data with the service providers listed in Part E only as needed to operate our business, and they are bound to keep it confidential.
5. Cookies and Tracking Technologies
Our products use cookies and similar technologies to keep you signed in and remember your preferences. Those are needed for the products to work.
On this website we also use measurement cookies: Google Analytics and Google Tag Manager to see how the site is used, and the Google Ads tag and the Meta Pixel to measure our own advertising and to show our ads to people who have visited. These are a choice:
- A banner asks you the first time you visit. You can accept or decline, and the site works the same either way.
- If you are in Europe, nothing is measured until you accept.
- Elsewhere, measurement runs unless you decline. Declining stops it and removes the measurement cookies already set.
- If your browser sends a Global Privacy Control signal, we treat that as declining.
- You can change your answer at any time with "Your privacy choices" at the bottom of every page.
Sharing visit information with Google and Meta for advertising can count as "sharing" or "selling" personal information under some United States state laws. Declining in the banner, or sending a Global Privacy Control signal, is how you opt out of that.
6. Links to Third-Party Websites
Our website links to third-party sites. We do not control their privacy practices and encourage you to review their policies before providing personal information.
7. Children's Privacy
Our website and products are not intended for anyone under 16. We do not knowingly collect personal information from children, and we remove it if we learn we have.
Part B: Glint, the Odo Marketing Social Media App
This part applies when you create a Glint account at https://socialapp.odomarketing.com, whether as a subscriber, a team member invited to an organisation, or a tester.
1. What Glint Does
Glint lets you connect your social media accounts, write and schedule posts, generate images, videos and voiceovers with AI, manage messages and reviews in one inbox, and see analytics. If you connect a Shopify store, Glint can also use your product catalogue as a starting point for content.
2. Information We Collect in Glint
- Account data: your name, email address, password (stored only as a hash), passkeys if you add them, organisation name, industry, brand profile details and billing status.
- Connected account data: the profile details, access tokens, posts, engagement metrics, messages and reviews that each platform permission in Part D gives us access to. Permissions are requested only when you actively connect an account.
- Content you create: post text, media you upload or import, AI prompts, reference images, scripts, generated images, videos and audio, and your content library.
- Shopify data: if you link a store, your products and the sales data used to rank best sellers, as described under Shopify in Part D.
- Usage data: which features you use, device and browser details, and security events such as sign-ins.
3. How We Use Glint Data
- Publishing: store your scheduled posts and publish them to the accounts you chose at the times you set.
- Analytics: read and display follower counts, impressions, reach and engagement for your connected accounts.
- Inbox and reviews: show messages, comments and reviews from your connected accounts and send the replies you write.
- AI studios: send the prompts, product details, scripts and images you submit to the AI providers in Part E to generate the content you asked for.
- Service operation: authentication, billing, support, security and abuse prevention.
We do not:
- Sell your data or the data of your connected accounts.
- Use data from your connected accounts to advertise to you or to anyone else.
- Share your connected-account data with other Glint users outside your organisation.
- Post, message or reply on your behalf without an instruction you gave through Glint.
- Use your content or connected-account data to train AI models.
4. AI-Generated Content
When you use an AI studio, the text, product details and images you provide are sent to the provider named in Part E only for the purpose of generating your output, and the result is stored in your library. Reference images you upload for video or try-on generation are used for that generation and kept in your library until you delete them. Do not upload images of people without their permission.
When a post's picture or video was made in our AI studios or by Autopilot, Glint marks the post as made with AI when it goes out, unless you switch that off for the post. TikTok and YouTube show their own mark; on Facebook, Instagram, LinkedIn and X the line "Made with AI." is added to the end of the caption.
5. Teams and Organisations
Glint accounts belong to organisations. An organisation owner can see the connected accounts, posts, library and analytics of that organisation and can invite and remove members. If you join a client's organisation, that client controls the data in it.
6. Campaign Manager
Campaign Manager, at https://campaigns.odomarketing.com, is our app for building advertising campaigns and publishing them to the ad accounts you connect. Everything in this part applies to it in the same way as to Glint, with these additions:
- What we collect: the campaigns you build (their text, pictures, video, audience settings, budgets and schedules), the ad accounts and Pages you choose, and the results the advertising platforms report for them.
- Results are totals: platforms report spend, impressions, clicks and conversions to us as daily totals per campaign and per ad. We do not receive the personal details of the people who see or click your ads.
- Publishing is your decision: a campaign or an ad reaches a platform only when you press publish, and you choose whether it starts live or paused.
- Your budget stays with the platform: advertising spend is charged by the platform to your own ad account. We do not hold or move it.
- Permissions: what Campaign Manager asks for on each advertising platform, and why, is listed in Part D.
Part C: The Odo Marketing Dashboard
This part applies to clients of Odo Marketing's agency services who are given access to https://dashboard.odomarketing.com as part of their engagement.
1. What the Dashboard Does
The Dashboard reports on the marketing we run for you: advertising spend and results, website traffic, search performance, store sales, profit and loss, and leads. To do this it connects, with your authorisation, to the advertising, analytics and store platforms you use.
2. Information We Collect in the Dashboard
- Account data: your name, email, company, the organisations you can view and your sign-in credentials.
- Platform data: the aggregated daily performance metrics that each permission in Part D provides (spend, impressions, clicks, conversions, sessions, search queries, orders and revenue). We store aggregated metrics, not individual customer or visitor records, with the exception of Shopify order data described in Part D.
- Leads: enquiries submitted through forms on websites we build or run for you, including the contact details the person entered.
- Data you provide: cost and revenue figures you enter or share with us, such as product costs or a sales spreadsheet.
3. How We Use Dashboard Data
Only to produce your reports, to plan and run the marketing you engaged us for, and to operate the service. Access to a client's data is limited to that client's users and the Odo Marketing staff assigned to the account. We do not share one client's data with another.
4. Website Previews and Analytics
Where we host a preview or production website for you, we collect first-party analytics (page views, referrers, device type, approximate location from IP) to report on it. We do not use third-party advertising trackers on those sites unless you ask us to.
Part D: Platform Permissions We Request and Why
Each permission below is requested only when you connect that platform. Nothing is requested on sign-up. For every permission we state what it lets the app do, why the app needs it, and what we keep.
How we choose permissions
- Only what a feature needs. Every permission is tied to something you can see in the app: a screen, a button or a report. If no feature uses a permission, we do not ask for it.
- The narrowest one the platform offers. Where a platform has a read-only permission and reading is all we do, that is the one we ask for. Some platforms offer a single permission for everything (Google Ads, Snapchat Ads and Amazon Ads, for example). Where that is so, we say it, and we say what we do not use it for.
- Nothing happens without you. Having permission to publish is not the same as publishing. A post or an ad reaches a platform only when you schedule or publish it yourself.
- You can say no.If you decline a permission on the platform's own screen, the feature that depends on it does not work and everything else does. The "Why we need it" column says which feature that is.
- You can take it back.Disconnect the account in the app's Settings, or remove Odo Marketing in the platform's own list of connected apps. Either way our access ends at once, and the stored tokens are deleted when you disconnect.
Access tokens for every platform are encrypted at rest with AES-256-GCM and are deleted when you disconnect the account. Where we say data is "fetched live", it is read from the platform when you open the screen and is not retained afterwards. We do not sell data received through any of these permissions, do not use it to advertise to you, and do not use it to train AI models.
Which app requests what
- Every app: Sign in with Google, only if you choose that button to sign in.
- Glint (subscribers who manage their own social media): Facebook, Instagram, LinkedIn, X, TikTok, YouTube, Google Business Profile, Dropbox, Canva, Shopify.
- Campaign Manager (subscribers who run their own advertising): Meta Ads, Google Ads, TikTok for Business, Snapchat Ads, LinkedIn Ads, X Ads, Pinterest Ads, Amazon Ads, ChatGPT Ads, Shopify. Some of these are still waiting for the platform to approve our app; the app says so on its Connect page.
- Odo SEO (businesses we have given access to our search tools): Google Search Console.
- Odo Marketing Dashboard (Odo Marketing agency clients): Meta Ads, Google Ads, Google Analytics 4, Google Search Console, TikTok for Business, Snapchat Ads, Shopify.
Sign in with Google
Provider: Google. Used by: Glint, Campaign Manager, Odo SEO and Odo Marketing Dashboard.
Requested only if you choose the Sign in with Google button instead of an email and password. It signs you in to our app. It does not connect any Google product to it.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
openid | Confirms to our app that Google has signed you in. | It is the basis of signing in with Google. Without it the button cannot work; you can always use an email and password instead. | Your Google account ID, so the same account is recognised next time. |
email | Gives us the email address of the Google account you chose. | Your email is your account with us: invitations, receipts and security notices go to it. It also stops a second account being made for the same person. | Your email address. |
profile | Gives us your name and profile picture. | So the app can greet you by name and show your picture next to your work, instead of asking you to type them in. | Your name and the address of your profile picture. |
- Signing in with Google gives us no access to your Gmail, Drive, calendar, contacts or any other Google product.
Facebook Pages and Instagram (via Facebook Login)
Provider: Meta. Used by: Glint.
Requested when you connect a Facebook Page, or an Instagram professional account that is linked to a Facebook Page, to Glint.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
public_profile | Shows your name and profile picture so you can see which Facebook account is connected. | Meta grants it with every sign-in; it cannot be left out. It is how Settings tells two connected accounts apart. | Name, Facebook user ID, profile picture URL. |
business_management | Lists the Business portfolios you belong to, so Pages and Instagram accounts owned through a Business can be selected. | A Page owned by a Business portfolio does not appear in a plain list of your Pages. Without this, agencies and teams that manage Pages through Meta Business Suite would see an empty list and could connect nothing. | Business IDs and names, and the IDs of the Pages you choose to connect. |
pages_show_list | Lists the Facebook Pages you manage so you can choose which one to connect. | It is the list you pick from. Without it no Page could be connected. Only the Page you choose is kept. | Page name, Page ID, Page picture URL, and a Page access token for the Page you select. |
pages_read_engagement | Reads your Page's posts and their likes, comments and shares. | It fills the Analytics and Results screens for Facebook, and it is how Glint learns which of your own posts did well, so the times and topics it suggests get better. Without it those screens stay empty for Facebook. | Post IDs and text, engagement counts, a daily analytics snapshot per Page. |
pages_manage_posts | Publishes the posts you write or schedule in Glint to your Page at the time you choose. | This is what scheduling is. Without it nothing can be published to your Page. Glint publishes only posts you wrote or approved. | Your draft and scheduled posts, attached media, publish status and the published post ID. |
pages_messaging | Reads Messenger conversations with your Page and sends the replies you write in the Glint inbox. | The Inbox needs it to show messages from your customers and to send your answers. Without it the Inbox has no Messenger conversations. Glint never sends a message you did not write. | Messages are fetched from Meta when you open the inbox and are not kept on our servers beyond the session. |
pages_manage_metadata | Subscribes your Page to notifications, so Meta tells Glint when a new message or comment arrives. | Without it Glint would have to ask Meta again and again whether anything is new, and the Inbox would be slow or out of date. It is not used to change your Page's name, details or settings. | Whether the Page is subscribed. |
instagram_basic | Finds the Instagram professional account linked to your Page and reads its profile, follower count and list of posts. | An Instagram account connected this way is reached through its Page. Without this permission Glint cannot find it or show its results. | Instagram account ID, username, profile picture URL, follower count, media IDs. |
instagram_manage_messages | Reads Instagram Direct conversations and sends the replies you write in the Glint inbox. | It is what puts Instagram conversations in the Inbox next to Messenger. Without it the Inbox shows no Instagram messages. | Messages are fetched live and are not kept beyond the session. |
- Glint does not read your personal Facebook profile, your friends, your private messages or any Page you did not choose.
Instagram (Instagram Login)
Provider: Meta. Used by: Glint.
Requested when you connect an Instagram professional account directly, without going through a Facebook Page.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
instagram_business_basic | Identifies your Instagram professional account and reads its profile, follower count and posts. | Without it Glint cannot tell which account you connected or show how its posts did. | Instagram account ID, username, profile picture URL, follower count, media IDs and their like and comment counts. |
instagram_business_content_publish | Publishes the photos, videos and reels you create or schedule in Glint to your account. | This is what lets a scheduled post go out. Without it posts for Instagram stay in Glint. Glint publishes only posts you wrote or approved. | Your scheduled posts, media, captions, publish status and the published media ID. |
instagram_business_manage_messages | Reads Instagram Direct conversations and sends the replies you write in the Glint inbox. | The Inbox needs it. Without it there are no Instagram conversations in Glint. | Messages are fetched live and are not kept beyond the session. |
- Instagram asks for this sign-in to be renewed about every 60 days. Glint renews it for you where Instagram allows, and tells you when you need to confirm the account yourself.
Provider: LinkedIn. Used by: Glint.
Requested when you connect your LinkedIn profile or a LinkedIn Company Page to Glint.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
r_basicprofile | Reads your name, headline and photo. | So Settings can show whose LinkedIn is connected. Nothing is posted with it. | LinkedIn member ID, name, profile picture URL. |
w_member_social | Publishes the posts you schedule in Glint to your personal LinkedIn feed. | Needed only if you post as yourself. Without it Glint could post to Company Pages but not to your own profile. | Your scheduled posts, media, publish status and the published post ID. |
rw_organization_admin | Lists the Company Pages where you are an administrator, and reads their follower and post statistics. | LinkedIn gives the list of Pages you administer only with this permission, so without it no Company Page could be chosen. Glint uses it to read. It does not change your Page's details, settings or administrators. | Organisation IDs and names for the Pages you administer, daily follower and post statistics. |
w_organization_social | Publishes posts on behalf of the Company Page you connected. | This is what lets a scheduled post reach your Company Page. Without it only personal profiles could be posted to. | Scheduled posts and their publish status. |
r_organization_social | Reads the Company Page's posts and their reactions, comments and impressions. | It fills the Analytics and Results screens for LinkedIn. Without it those screens stay empty. | Post IDs, engagement counts, a daily analytics snapshot per Page. |
- LinkedIn ends a sign-in after 60 days and offers no renewal, so Glint asks you to confirm the account again before that day.
X (Twitter)
Provider: X Corp.. Used by: Glint.
Requested when you connect an X account to Glint.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
users.read | Identifies the X account that is connected. | It is how the app knows which account signed in, so Settings can show where posts will go. | X user ID, handle, display name, profile picture URL. |
tweet.read | Reads your own recent posts and their public numbers. | X requires it together with the permission to post, and it is how results for the posts Glint published are read. | Post IDs and engagement counts. |
tweet.write | Publishes the posts you write or schedule in Glint. | This is what scheduling is. Without it nothing can be published to X. | Scheduled posts and their publish status. |
media.write | Uploads the picture or video that goes with a post you schedule. | X asks for this permission by name before it accepts a file. Without it a post with a picture cannot be sent. | The file until it is uploaded. Nothing else. |
offline.access | Lets the connection be renewed without you signing in again. | An X sign-in lasts about two hours without it, so a post scheduled for tomorrow would fail. | Encrypted access and refresh tokens. |
- Glint does not read your direct messages, follow or unfollow anyone, or like or repost on your behalf.
TikTok
Provider: TikTok. Used by: Glint.
Requested when you connect a TikTok account to Glint.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
user.info.basic | Shows the display name and avatar of the connected TikTok account. | So you can see which TikTok account a video will go to before you schedule it. | TikTok open ID, display name, avatar URL. |
video.upload | Uploads the videos you schedule in Glint to your TikTok account. | A video has to be handed to TikTok before it can be posted. Without it no video could leave Glint. | The video file until it is uploaded, and the upload status. |
video.publish | Publishes uploaded videos to your TikTok profile at the scheduled time. | Without it a video would only reach your TikTok drafts and you would have to post it by hand. | Publish status and the published video ID. |
YouTube
Provider: Google. Used by: Glint.
Requested when you connect a YouTube channel to Glint with your Google account.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
https://www.googleapis.com/auth/youtube.readonly | Reads your channel, your videos and their subscriber and view counts. | It is how Glint shows which channel is connected and fills the Analytics screen for YouTube. It is used only for your own channel and its videos. | Channel ID and name, video IDs, view and subscriber counts. |
https://www.googleapis.com/auth/youtube.upload | Uploads and publishes the videos you schedule in Glint to your channel. | This is what lets a scheduled video go out. Without it nothing can be published to YouTube. Glint uses it only to upload the videos you schedule; it does not delete or change the videos already on your channel. | The video file until upload completes, the publish status and the video ID. |
https://www.googleapis.com/auth/userinfo.profile | Shows the name and picture of the Google account that is connected. | So Settings can show which Google account the channel belongs to. | Google account name and picture URL. |
https://www.googleapis.com/auth/userinfo.email | Shows the email of the Google account that is connected. | Many people have more than one Google account. The email is how you tell them apart. | Google account email address. |
Google Business Profile
Provider: Google. Used by: Glint.
Requested when you connect a Google Business Profile location to Glint.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
https://www.googleapis.com/auth/business.manage | Lists your business locations, reads your Google reviews and profile insights, and sends the review replies you write in Glint. | It is what the Reviews screen runs on. Google offers a single permission for Business Profile: there is no narrower one that still allows replying to a review. Glint does not change your business name, hours, address or other profile details. | Location IDs and names, review text and ratings while displayed, and the replies you send. |
openid, email, profile | Identifies the Google account that is connected. | So Settings can show which Google account manages the location. | Google account ID, name, email and picture URL. |
Dropbox
Provider: Dropbox. Used by: Glint.
Optional. Requested only if you choose to import media from Dropbox into your Glint library.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
account_info.read | Shows which Dropbox account is connected. | So you can see whose Dropbox you are browsing. | Dropbox account ID and display name. |
files.metadata.read | Lets you browse your folders and file names to pick what to import. | Without it the file picker would be empty. Names are read to show them to you and are not kept. | Nothing beyond the current browsing session. |
files.content.read | Downloads only the files you select into your Glint media library. | It is how a file you picked gets into your library. Files you do not pick are never downloaded. | A copy of each file you import, in your library until you delete it. |
- Glint never writes to, moves or deletes anything in your Dropbox.
Canva
Provider: Canva. Used by: Glint.
Optional. The Odo Marketing app for Canva runs inside the Canva editor and lets you send the design you are working on to your Glint media library.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
design:content:read | Exports the design that is open in the Canva editor, and only when you press Export in the Odo panel. | It is the only way a design can leave Canva for your library. Nothing is read until you press Export. | The exported image or video file, saved to your Glint library for the organisation you choose. |
- Signing in to the Canva app uses your existing Glint account (email and password, or Google). The Canva app does not see your Canva password.
- The app cannot read your other Canva designs, folders or brand kit.
Shopify
Provider: Shopify. Used by: Glint, Campaign Manager and Odo Marketing Dashboard.
Requested when you install the Odo Marketing app from your Shopify admin and link the store to your Odo Marketing organisation. The app is being reviewed by Shopify and is not yet open to every store.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
read_products | Reads your product catalogue: titles, descriptions, pictures, prices and stock. | Your own products are the starting point for the posts, pictures, videos and ads our apps help you make, so what is written matches what you sell. Without it you would type every product in by hand. | Products and variants as listed, kept current by Shopify webhooks. |
read_orders | Reads your orders: totals, the items in them, payment status and where the sale came from. | Orders are how best sellers are ranked, which a product list alone cannot tell us, and in the Dashboard they are the revenue, order count and average order value in your reports. | Orders with totals, line items, payment status, sales channel, referral source, shipping country, and the customer name and email Shopify includes with the order. |
- The app is read-only. It never creates or changes products, orders, customers or settings in your store.
- Shopify's customer data request and customer redaction requests are honoured automatically through Shopify's compliance webhooks.
- Uninstalling the app removes the connection immediately; Shopify's shop redaction webhook then deletes every product and order we hold for the store within 48 hours.
Meta Ads (Facebook and Instagram advertising)
Provider: Meta. Used by: Campaign Manager and Odo Marketing Dashboard.
Requested when you connect a Meta ad account: to Campaign Manager, to build and publish your own campaigns, or to the Dashboard, where an Odo Marketing client connects it for reporting.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
ads_management | In Campaign Manager: creates the campaigns, ad sets and ads you build, uploads their pictures and video, and pauses or resumes them when you ask. In the Dashboard: only lists the ad accounts you can access so you can choose which one to report on. | Meta has no permission that allows creating an ad without it, so Campaign Manager cannot publish without it. Nothing is published until you press publish. The Dashboard does not create, edit or pause ads. | Ad account IDs and names, and the IDs of the campaigns, ad sets and ads you publish. |
ads_read | Reads campaign, ad set and ad performance (spend, impressions, clicks, conversions), and lists the campaigns already in the account. | It fills the results and scorecard screens and the client reports. Without it you would see what you published but not how it performed. | Daily aggregated metrics per campaign and per ad. No audience data. |
business_management | Lists the Business portfolios you belong to and the ad accounts they own. | Most ad accounts belong to a Business portfolio and do not appear without it, so the account picker would be empty for most businesses. | Business IDs and names. |
pages_show_list | Campaign Manager only. Lists the Facebook Pages you manage. | Meta requires every ad to belong to a Page. This is the list you choose that Page from. | Page ID and name for the Page you choose. |
pages_read_engagement | Campaign Manager only. Reads the chosen Page's details, including the Instagram account linked to it. | So your ads run under the right Page and Instagram name, and can be shown to you as they will appear before you publish. | Page ID and name, and the linked Instagram account ID. |
read_insights | Dashboard only. Reads the insights Meta exposes for the ad accounts and Pages in the report. | It supplies the figures in the client reports. | Daily aggregated metrics. |
- Advertising spend is charged by Meta to your own ad account. We never hold or move your advertising budget.
- We do not receive the personal details of the people who see or click your ads. Meta reports results to us as totals.
Google Ads
Provider: Google. Used by: Campaign Manager and Odo Marketing Dashboard.
Requested when you connect a Google Ads account: to Campaign Manager, to build and publish your own campaigns, or to the Dashboard, where an Odo Marketing client connects it for reporting.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
https://www.googleapis.com/auth/adwords | In Campaign Manager: creates the campaigns, ad groups, ads and keywords you build, pauses or resumes them when you ask, and reads their results. In the Dashboard: only reads campaign performance (spend, impressions, clicks, conversions). | This is the one permission Google offers for Google Ads. There is no read-only or narrower one, so the same permission serves both apps. Nothing is published until you press publish, and the Dashboard does not change bids, budgets or campaigns. | Ad account IDs and names, the IDs of the campaigns you publish, daily aggregated metrics per campaign, and an encrypted refresh token. |
- Advertising spend is charged by Google to your own Google Ads account.
Google Analytics 4
Provider: Google. Used by: Odo Marketing Dashboard.
Used for website traffic reporting. Connected either with your Google account, or by adding Odo Marketing's service account to your GA4 property as a Viewer.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
https://www.googleapis.com/auth/analytics.readonly | Reads sessions, users, conversions and channel breakdowns for the property you choose. | It supplies the website traffic part of your reports. It is read-only: nothing in your Analytics property can be changed with it. | Daily aggregated metrics. No individual visitor data. |
Google Search Console
Provider: Google. Used by: Odo SEO and Odo Marketing Dashboard.
Used for search reporting. In Odo SEO you connect it by signing in with your own Google account. In the Dashboard it is connected by adding Odo Marketing's service account to your Search Console property as a user.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
https://www.googleapis.com/auth/webmasters.readonly | Reads the searches your site appeared for, with clicks, impressions and average position, and the list of sites on the account. | It is where rank tracking and the search report get their figures from Google itself. It is read-only: nothing in Search Console can be changed with it. | Daily aggregated query and page metrics, the address of the site you choose, and an encrypted refresh token when you sign in with your own account. |
https://www.googleapis.com/auth/userinfo.email | Odo SEO only. Shows the email of the Google account that is connected. | So you can see which Google account the search data comes from. | Google account email address. |
TikTok for Business
Provider: TikTok. Used by: Campaign Manager and Odo Marketing Dashboard.
Requested when you connect a TikTok advertiser account: to Campaign Manager, to build and publish your own campaigns, or to the Dashboard for reporting.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
Advertiser account access (TikTok Marketing API) | In Campaign Manager: creates the campaigns, ad groups and ads you build, uploads their video, and reads their results. In the Dashboard: reads ad account performance (spend, impressions, clicks, conversions) for the reports. | TikTok grants access by advertiser account, which you choose on TikTok's own screen, rather than by a list of named permissions. Nothing is published until you press publish. | Advertiser ID, an encrypted access token, the IDs of the campaigns you publish, daily aggregated metrics. |
Snapchat Ads
Provider: Snap Inc.. Used by: Campaign Manager and Odo Marketing Dashboard.
Requested when you connect a Snapchat ad account: to Campaign Manager, to build and publish your own campaigns, or to the Dashboard for reporting.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
snapchat-marketing-api | In Campaign Manager: creates the campaigns, ad squads and ads you build, uploads their pictures and video, and reads their results. In the Dashboard: reads ad account performance (spend, impressions, swipes, conversions) for the reports. | It is the one permission Snapchat offers for advertising, so the same permission serves both apps. Nothing is published until you press publish. | Ad account ID, an encrypted access token, the IDs of the campaigns you publish, daily aggregated metrics. |
LinkedIn Ads
Provider: LinkedIn. Used by: Campaign Manager.
Requested when you connect a LinkedIn ad account to Campaign Manager.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
r_ads | Lists the ad accounts you can use and reads the campaigns in them. | It is the list you choose an ad account from. It is also how the Company Page an ad account belongs to is found. | Ad account IDs and names. |
rw_ads | Creates the campaigns and sponsored content you build, and changes them when you ask. | Without it nothing can be published to LinkedIn. Nothing is published until you press publish. | The IDs of the campaigns and ads you publish. |
r_ads_reporting | Reads campaign results (spend, impressions, clicks, conversions). | It fills the results screen. Without it you would see what you published but not how it performed. | Daily aggregated metrics per campaign. |
r_organization_social | Reads the Company Page your sponsored content runs under. | LinkedIn ads belong to a Company Page, so the Page has to be read before an ad can be attached to it. | Organisation ID and name. |
w_organization_social | Creates the post each ad is made from, on the Company Page your ad account belongs to. | A LinkedIn sponsored ad is a post from your Page that is shown as an ad. Without this permission there is nothing for the ad to show. A post is created only when you publish a campaign. | The IDs of the posts created for your ads. |
X Ads
Provider: X Corp.. Used by: Campaign Manager.
Requested when you connect an X ads account to Campaign Manager. X's Ads API uses its older sign-in (OAuth 1.0a), which has no separate permissions to tick: the app is given read and write access to the account that signs in.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
Read and write (OAuth 1.0a) | Lists the ads accounts you can use, creates the campaigns you build and the promoted-only posts they show, uploads their pictures, and reads campaign results. | X's Ads API accepts no narrower sign-in. A promoted-only post runs as an ad and never appears on your profile. Nothing is published until you press publish. | Ads account IDs and names, your X user ID and handle, the IDs of the campaigns you publish, and an encrypted access token and secret. |
- Campaign Manager does not post to your profile, read your direct messages or follow anyone.
- Advertising spend is charged by X to your own ads account.
Pinterest Ads
Provider: Pinterest. Used by: Campaign Manager.
Requested when you connect a Pinterest ad account to Campaign Manager.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
ads:read | Lists the ad accounts you can use and reads campaign results. | It is the list you choose an ad account from, and it fills the results screen. | Ad account IDs and names, daily aggregated metrics. |
ads:write | Creates the campaigns and promoted Pins you build. | Without it nothing can be published to Pinterest. Nothing is published until you press publish. | The IDs of the campaigns you publish. |
pins:read | Reads the Pins on your account. | A Pinterest ad is a Pin that is promoted, so the Pins made for your ads have to be read back. | Pin IDs. |
pins:write | Creates the Pin each ad is made from, with the picture and words you wrote. | Without it there is no Pin to promote. A Pin is created only when you publish a campaign. | The IDs of the Pins created for your ads. |
boards:read, boards:write | Finds a board on your account to save the ad Pins to. If you have no board yet, one called Ads is made. | Pinterest requires every Pin to be saved to a board. Your other boards are not changed. | The ID of the board used. |
catalogs:read | Reads the product catalogues on your account. | Requested for shopping campaigns, which show products from a catalogue. Nothing in a catalogue is changed. | Catalogue IDs and names. |
Amazon Ads
Provider: Amazon. Used by: Campaign Manager.
Requested when you connect an Amazon Ads account to Campaign Manager with Login with Amazon.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
advertising::campaign_management | Lists the advertising accounts and marketplaces you can use, and creates the Sponsored Products campaigns, ad groups, product ads and search words you build. | This is the one permission Amazon offers for its advertising products; there is no read-only or narrower one. Nothing is published until you press publish. It gives no access to your Amazon shopping account, orders or payment details. | Advertising account (profile) IDs, names, marketplaces and currencies, the IDs of the campaigns you publish, and encrypted access and refresh tokens. |
- Amazon asks you to sign in again once a year. Campaign Manager tells you before that day.
- Advertising spend is charged by Amazon to your own advertising account.
ChatGPT Ads
Provider: OpenAI. Used by: Campaign Manager.
There is no sign-in for ChatGPT ads. You create an API key in your own OpenAI ads account and paste it into Campaign Manager.
| Permission | What it lets the app do | Why we need it | What we store |
|---|---|---|---|
An API key you create and paste in | Creates the campaigns, ad groups and ads you build in your ChatGPT ads account, and uploads their pictures. | OpenAI gives access to an ads account by key rather than by sign-in. The key works only for the ads account you made it in, and you can delete it at OpenAI at any time. | The key, encrypted, and the IDs of the campaigns you publish. |
Part E: Retention, Deletion, Your Rights and Contact
1. How Long We Keep Data
- Access tokens: until you disconnect the account, delete your account, or the platform revokes them.
- Posts and content library: until you delete them or delete your account. Published posts stay in your history so analytics can reference them.
- Messages, comments and reviews: fetched live from the platform and not retained, other than the replies you send.
- Analytics snapshots: daily aggregates kept for historical reporting while your account or engagement is active.
- Shopify products and orders: kept current by webhooks while the app is installed; deleted within 48 hours of uninstall through Shopify's shop redaction webhook.
- Dashboard metrics: kept for the life of the client engagement and for up to 12 months after it ends, so historical reports remain available, unless you ask us to delete them sooner.
- Billing records: as long as required by tax and accounting law.
- Backups: deleted data can persist in encrypted backups for up to 30 days.
2. Deleting Your Data
- Disconnect a platform: Settings in Glint or the Dashboard. The token is deleted immediately and we stop accessing the account.
- Delete your Glint account: Settings, Account, Delete account. This deletes your connected accounts, posts, library, analytics and, if you own the organisation, the organisation itself.
- Uninstall the Shopify app: from your Shopify admin. The connection ends immediately and store data is purged within 48 hours.
- Revoke from the platform: you can also remove Odo Marketing from your Facebook, Google, LinkedIn, X, TikTok, Snapchat, Pinterest, Amazon, Dropbox or Canva connected-apps settings. We lose access as soon as you do.
- Email us: odo@odomarketing.com for anything else, including Dashboard data. See our data deletion instructions.
3. Your Rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal information, to object to certain processing, and to complain to a supervisory authority. We honour these rights for everyone, not only where the law requires it. Contact us and we will respond within 30 days.
If you live in the United States
Several states, including California, Colorado, Connecticut and Virginia, give their residents specific privacy rights. We apply them to every visitor and customer in the United States:
- To know what personal information we hold about you, and to get a copy of it.
- To have it corrected or deleted.
- To opt out of your information being "sold" or "shared" for advertising. We do not sell personal information for money. On this website we use advertising tags from Google and Meta, which some state laws count as sharing. To stop that, decline in the cookie banner, use "Your privacy choices" at the bottom of any page, or send a Global Privacy Control signal from your browser.
- Not to be treated differently for using any of these rights.
To use a right, email us at odo@odomarketing.com from the address on your account. We may ask you to confirm it is you, and we answer within 30 days.
4. Service Providers We Use
These providers process data on our behalf and only for the purpose stated:
- Supabase: Database, authentication (email and password, passkeys, Google sign-in) and file storage.
- Vercel: Hosting for the website, Glint, Campaign Manager, Odo SEO and the Dashboard.
- Render: Hosting for the API that talks to the platforms above.
- Cloudflare R2: Storage for the media in your library, AI studio outputs and Canva exports.
- Cloudflare Turnstile: A check on the sign-in and sign-up pages that tells people from automated traffic, where it is switched on.
- Amazon Web Services (SES): Transactional email for invitations, security notices and account notifications.
- Stripe: Subscription billing for Glint and Campaign Manager. Card details go directly to Stripe and never touch our servers.
- Google Gemini: AI text and image generation in the Glint and Campaign Manager studios, using the prompts, product details and images you submit.
- BytePlus (Seedance): AI video generation in the video studios, using the frames and scripts you approve.
- ElevenLabs: AI voiceover for videos, using the script text you approve.
The platforms in Part D (Meta, Google, LinkedIn, X, TikTok, Pinterest, Amazon, Shopify, Canva, Dropbox and Snap) are independent controllers of the data on their services and have their own privacy policies.
5. International Transfers
Odo Marketing is based in Australia, and our apps are made for businesses in Australia and the United States. Our providers store and process data in the regions they operate in, which may be outside your country. We rely on their standard contractual protections for those transfers.
6. Platform Policy Compliance
- Meta: we comply with the Meta Platform Terms and Developer Policies, including limited use of Page and Instagram data.
- Google: our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the feature, do not use it for advertising, and never allow humans to read it except with your consent, for security, or as required by law.
- YouTube: Glint uses YouTube API Services and is bound by the YouTube Terms of Service and the Google Privacy Policy. You can revoke access at Google security settings.
- Shopify: we comply with the Shopify API Terms and respond to Shopify's mandatory data request and redaction webhooks.
- LinkedIn, X, TikTok, Pinterest, Amazon, Canva, Dropbox and Snap: we comply with each platform's developer terms.
- GDPR and UK GDPR for users in the EU and UK, CCPA/CPRA for California residents, and the Australian Privacy Act.
7. Changes to This Policy
We update this page when our products or practices change and revise the date at the top. For significant changes to Glint or the Dashboard we notify you by email and, where the law requires it, ask for consent again.
8. Contact Us
- Company: Odo Marketing
- Email: odo@odomarketing.com
- Website: https://www.odomarketing.com
- Glint: https://socialapp.odomarketing.com
- Campaign Manager: https://campaigns.odomarketing.com
- Odo SEO: https://seo.odomarketing.com
- Dashboard: https://dashboard.odomarketing.com
