Last updated: August 21, 2026
Metricbay is a reporting automation tool for digital marketing agencies. Agencies connect their clients’ analytics and advertising accounts, and Metricbay generates monthly performance reports from that data.
This policy explains what we collect, why, and what we do with it. It covers metricbay.cloud and the Metricbay reporting application.
Account information. When an agency signs up, we collect a name, email address, company name, and billing details. Payments are processed by third-party providers; we never store full card numbers.
Client configuration. Agencies tell us which of their clients to report on, including client names, websites, recipient email addresses, and the identifiers of the analytics and advertising accounts to pull from.
Performance data. With the agency’s authorization, we retrieve read-only performance metrics from connected platforms. This includes traffic, search, and campaign metrics such as sessions, users, clicks, impressions, cost, and conversions.
Usage data. Standard server logs: IP address, browser type, pages visited, and timestamps. Used for security and diagnostics.
Metricbay connects to third-party platforms only when an agency explicitly authorizes it, and only for the accounts that agency selects.
Access is read-only in every case. Metricbay does not create, edit, pause, or delete campaigns; does not change bids, budgets, or targeting; and does not modify any account setting on any connected platform.
An agency can revoke our access at any time through their Google or Meta account settings, or by contacting us to disconnect an account.
Metricbay’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
We do not use client performance data to train machine learning models, and we do not aggregate it into benchmarks or sell it in any form.
We rely on a small set of vendors to run Metricbay. Each processes data only as needed to provide their service:
Reports are delivered by email as private links containing a unique access token. Anyone holding a report link can view that report, so agencies should share links only with intended recipients. We can revoke and reissue a report link on request.
We keep report data for as long as an agency’s account is active, so historical reports and month-over-month comparisons remain available. When an account is closed, we delete its data within 90 days, except where we are required to retain records for legal or accounting purposes.
An agency can request deletion of a specific client’s data at any time.
Data is encrypted in transit and at rest. Platform credentials are stored in encrypted credential storage and are never exposed in the application interface. Access to production systems is limited to personnel who need it.
No system is perfectly secure. If a breach affects your data, we will notify you promptly.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any of these, email us at the address below and we will respond within 30 days.
Where Metricbay processes data on behalf of an agency, that agency is the data controller and we act as a processor. Requests from an agency’s clients should be directed to the agency.
Metricbay is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
We may update this policy as the service changes. The date at the top reflects the current version. Material changes will be announced by email to account holders.
Questions about this policy, or about data we hold: