Privacy Policy

Effective date: September 29, 2026 (last updated September 30, 2026)

Who we are: Tie In LLC ("Tie In," "we," "us"), United States. Contact: hello@gotiein.com.

This policy covers two things: the gotiein.com website, and AdMgr, the internal tool our team uses to analyze advertising and social accounts that a client has authorized us to read. It says what we collect, why, where it lives, who can see it, and how to make us stop.

1. The website

When you fill out a form on gotiein.com, we collect what you type: usually a name, an email address, a company, and a message. That goes into our CRM (HubSpot) so a real person can reply. We also use UTM parameters and standard analytics cookies to see which page, post or campaign a visitor came from before filling out a form; this connects a form submission to the channel that produced it and is not used to track you elsewhere on the web. We do not sell this information and we do not run advertising networks on this site.

2. AdMgr and Google user data

AdMgr is a tool Tie In's team uses on behalf of clients. It is not a public product. A client account is only connected when a person with access to that account signs in with Google and clicks Allow on Google's consent screen.

What AdMgr accesses. With your authorization, AdMgr reads from Google's APIs:

  • Google Ads: campaigns, ad groups, keywords, search terms, ads, budgets, bidding settings, conversion actions and their settings, and performance metrics (spend, clicks, impressions, conversions).
  • Google Search Console: search queries, pages, clicks, impressions and positions for the properties you authorize.
  • Chrome UX Report: public page-speed data for those properties (no user data is involved).

What AdMgr does with it. It analyzes that data to produce recommendations for the account owner: where spend is not converting, which settings do not match the account's goals, and where a change would help. Every recommendation is shown to a person on our team or on the client's team, who decides whether to act on it. Where AdMgr is configured to make a change to an account, that change is bounded by limits the account owner sets and is recorded with who approved it and when.

Where it lives. Authorization tokens are stored encrypted in Supabase Vault. Account data and analysis results are stored in a Supabase Postgres database. The application runs on Vercel, and scheduled jobs run through Inngest. All three are infrastructure providers acting on our instructions; none of them uses this data for their own purposes.

Who sees it. Tie In team members working on that client's account, and the client's own authorized users. Nobody else. We do not sell Google user data, we do not use it to build advertising profiles, we do not use it to train machine-learning models, and we do not share it with third parties except the infrastructure providers named above, and only as needed to run the service.

AI model providers. To write the plain-language explanation on a recommendation, AdMgr may send a model provider (currently none; when enabled, named here) the figures already computed from your account, such as spend, conversions and cost per conversion for a campaign. It never sends your credentials, and the provider processes the figures only on our instructions, keeps no copy beyond the request, and does not use them to train models. We update this policy when a provider is enabled.

How long we keep it. For as long as the account is connected. When an account is disconnected, or when you ask us, we delete the stored token immediately and the account's data within 30 days.

How to revoke access. At any time, from your Google Account at https://myaccount.google.com/permissions, remove AdMgr. Or email hello@gotiein.com and we will disconnect it and confirm.

Google's policy. AdMgr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Meta (Facebook and Instagram) advertising and Page data

Where a client authorizes Tie In to connect a Meta Ads account, Facebook Page, or Instagram account, we access that data through Meta's Marketing API, Meta's Ads MCP server, and the Pages API, only after an admin of that account signs in through Meta's own consent screen and grants access.

What we access.

  • Ad account structure, campaigns, ad sets, ads and creative, budgets, targeting settings and performance metrics (spend, reach, clicks, conversions), read through the Marketing API and, where the account owner has authorized AI-driven management, created and adjusted through Meta's Ads MCP server, the interface Meta provides for AI tools to manage ads on an advertiser's behalf.
  • Page-level data for Pages the client authorizes: posts, comments (to moderate them), engagement and follower counts and insights.
  • Where enabled, Meta's Conversions API, to send back conversion events tied to ads the client is running, so Meta can optimize delivery toward real outcomes for that client.
  • Where the client runs Meta lead ads and authorizes it, the leads submitted through those ads. See "Lead form data" below, this is a different kind of data than the rest of this section and gets its own rules.

What we do with it. We analyze performance and produce recommendations a person reviews before anything changes on the account. Any action Meta's Ads MCP server takes, such as creating a campaign or adjusting a budget, follows the same bounded limits and approval logging described in Section 2 for AdMgr generally; nothing executes without those guardrails. We do not use Meta data to build advertising audiences for anyone other than the authorizing client, we do not combine one client's Meta data with another's, and we do not sell or share it with any third party except the infrastructure providers named in Section 2.

Lead form data. When a client runs Meta lead ads, people who are not our client, potential customers of theirs, fill out a form on Facebook or Instagram with their own name, email, phone number, and answers to any custom questions the client set up. With the client's authorization, we retrieve those submissions through Meta's Marketing API so the client can follow up. This is personal data about a third party, not about our client, and we treat it accordingly:

  • We act as a processor on the client's behalf. The client, as the business the person contacted, is the one who decides what happens with a lead; we retrieve and hand it off, we do not use it for our own purposes or for any other client.
  • Access is limited to the people on our team and the client's team working that lead.
  • We keep the raw submission only as long as needed to deliver it to the client and confirm it was received, generally no more than 30 days, then it is deleted from our systems. The client's own records of their leads are theirs to keep or delete under their own policies.
  • A person who filled out a lead form and wants their information corrected or deleted should contact the business whose ad they responded to. If that request reaches us instead, we will delete our copy and pass the request to the client.

Storage, retention and revocation. Everything except lead form data above follows the same rule as Google: tokens live encrypted in Supabase Vault, account data lives in our Supabase database, tokens are deleted immediately on disconnection and account data within 30 days. Revoke access any time from Meta Business Settings (Business Settings > Accounts > Apps, or Users > System Users) or by emailing hello@gotiein.com.

Meta's policy. Our use of information received from Meta's APIs adheres to the Meta Platform Terms and Meta Developer Policies, including the restriction against using Platform Data to build a profile of a person for purposes unrelated to the authorizing client's own account, and against transferring Platform Data to any ad network, data broker or other advertising or monetization-related service.

4. LinkedIn organization Page data

Where a client authorizes Tie In to manage their LinkedIn Page, we connect through LinkedIn's Community Management API, after an admin of that Page signs in through LinkedIn's own consent screen and grants access.

What we access. Organization data for the LinkedIn Page the client authorizes: the ability to create, schedule and publish posts on the Page's behalf, and to read the Page's own social metrics (follower counts, post impressions, clicks and engagement). We do not access a Page admin's personal LinkedIn profile, connections, messages or feed beyond what LinkedIn's API exposes for the authorizing Page's own account.

What we do with it. Posts are drafted by Tie In's team or tools and always reviewed by a person before publishing, per our standing content-approval process. Engagement data is used only to report back to that client on their own Page's performance.

Storage, retention and revocation. Same as above: access tokens live encrypted in Supabase Vault and are deleted immediately on disconnection; Page data is deleted within 30 days of disconnection. A client can revoke our access at any time from LinkedIn's own Settings under "Manage authorized apps," or by removing Tie In as a Page admin or partner, or by emailing hello@gotiein.com.

LinkedIn's policy. Our access to and use of LinkedIn data adheres to the LinkedIn API Terms of Use and, where applicable, the LinkedIn Marketing API terms. We do not use LinkedIn data to build advertising profiles outside LinkedIn, we do not sell it, and we do not retain it longer than needed to provide the authorized service to that client.

5. Other advertising or search platforms

Where a client connects any other advertising or search platform not named above, the same rules apply: read with the client's authorization, used only for analysis on that client's account, stored the same way, deleted the same way, revocable from that platform's own settings or by emailing us.

6. Security

Data moves over HTTPS. Credentials sit in an encrypted vault, not in application code or logs. Access to a client's data is gated by database-level membership rules, so a signed-in user who is not on that client's team sees nothing.

7. Your rights

Ask us what we hold about you or your account, ask us to correct it, or ask us to delete it. Email hello@gotiein.com. We answer within 30 days. If you are someone who filled out a client's lead ad rather than a Tie In client, see "Lead form data" above, that request goes to the business you contacted, and to us as well if it reaches us first.

8. Changes

If this policy changes in a way that matters, we update the date above and, for connected accounts, email the person who authorized the connection.