Privacy Policy

Last updated: June 2026

BrandGrid ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and delete information when you use our platform, including when you connect social accounts such as Facebook, Instagram, LinkedIn, X (Twitter), or Pinterest, or when you connect advertising and commerce integrations such as Google Ads and Shopify.

1. Information We Collect

When you connect a third-party account to BrandGrid through OAuth, we receive and store only the information needed to authenticate your account and provide the features you authorize. This may include:

  • Account identifiers (user ID, page ID, or business account ID)
  • Display name and username
  • Email address (where provided by the platform)
  • OAuth access tokens and refresh tokens (where applicable)
  • Token expiry information
  • Platform-specific metadata required for publishing (e.g. linked Facebook Page, Instagram Business account, LinkedIn organization pages, Pinterest boards)

Facebook

When you connect Facebook, BrandGrid uses the Facebook Graph API to access your selected Facebook Page, page access tokens, and related page metadata (name, username, follower counts). If you connect for advertising, we may also access ad account identifiers you authorize.

Instagram

When you connect Instagram, BrandGrid uses the Instagram Graph API to access your Instagram Business or Creator account ID, username, and the Facebook Page linked to that account, along with tokens required to publish posts.

LinkedIn

When you connect LinkedIn, BrandGrid uses the LinkedIn API to access your profile identifier, name, email (if granted), and organization pages you authorize for posting.

X (Twitter)

When you connect X, BrandGrid uses the X API to access your account identifier, display name, username, and tokens required to publish posts on your behalf.

Pinterest

When you connect Pinterest, BrandGrid uses the Pinterest API to access your account identifier, username, board and pin data needed to publish content, and OAuth tokens required to create pins on your behalf.

Google Ads

When you connect Google Ads, BrandGrid uses the Google Ads API to access the Google Ads customer accounts you select, OAuth refresh tokens, and campaign performance data (such as impressions, clicks, spend, and conversions) needed to launch, manage, and optimize paid search and display campaigns on your behalf.

Shopify

When you connect Shopify, BrandGrid uses the Shopify Admin API to access your store identifier, store domain, store name, contact email, and OAuth access tokens needed to publish blog content to your Shopify store.

2. How We Use This Information

We use connected account information only to:

  • Authenticate and link your connected accounts to your BrandGrid brand
  • Publish posts, images, and videos you create in BrandGrid to the platforms you select
  • Publish blog content you create in BrandGrid to your connected Shopify store
  • Launch, manage, and optimize Google Ads campaigns you authorize in BrandGrid
  • Schedule and manage content you explicitly choose to publish
  • Retrieve post and campaign performance insights where you have granted the relevant permissions
  • Maintain secure, working connections by refreshing OAuth tokens when needed

We do not use your connected account data to build advertising profiles, sell data, or contact your followers or customers independently of actions you take through BrandGrid.

3. Data Storage & Retention

While a connected account remains linked, BrandGrid stores your connection record in our secure database, including OAuth tokens and the minimum account metadata needed to provide the authorized features on your behalf. Social and commerce connections (such as Facebook, Instagram, LinkedIn, X, Pinterest, and Shopify) are stored in our social connections table. Google Ads connections are stored separately in our ad connections table.

We retain this data only for as long as your account remains connected or as needed to complete publishing actions you have scheduled. OAuth tokens expire according to each platform's policies and are refreshed only to keep your connection active.

4. Data Sharing

We do not sell, rent, or license your personal data or platform-derived data to third parties.

We do not resell or redistribute Facebook, Instagram, LinkedIn, X, Pinterest, Google Ads, or Shopify content or data obtained through their APIs to third parties. Data accessed through these platforms is used solely to provide BrandGrid services to you.

We may share data only when required by law, to protect our rights and users, or with infrastructure providers that process data on our behalf under strict confidentiality and security obligations.

5. User Control & Permissions

You control which accounts are linked to BrandGrid. You can disconnect any platform at any time from Manage Brands within BrandGrid.

You may also revoke BrandGrid's access directly from each platform's account or app permissions settings (Facebook, Instagram, LinkedIn, X, Pinterest, Google, or Shopify).

6. Data Deletion

When you disconnect an account in BrandGrid, we delete your connection record from our database, including stored OAuth tokens and platform-specific metadata associated with that connection. For Google Ads, we also attempt to revoke the refresh token at Google before deletion.

Content you already published to a social platform remains on that platform under your control and is governed by that platform's policies. Disconnecting BrandGrid does not remove posts already published.

To request deletion of your BrandGrid account or any remaining personal data, contact support@brandgrid.ai.

7. Pinterest API Data & Compliance

BrandGrid integrates with the Pinterest API to enable Pinterest-related publishing and content management features that you explicitly authorize.

When you connect your Pinterest account to BrandGrid, we may access and process Pinterest account information, including your Pinterest account identifier, username, board identifiers, board metadata, pin-related information, and OAuth authentication credentials required to create, schedule, manage, and publish Pins on your behalf.

Pinterest API data is used solely for providing the Pinterest functionality requested by you within BrandGrid. This includes authenticating your Pinterest account, maintaining your authorized connection, allowing you to select boards, creating Pins, scheduling Pins, publishing Pins, and managing Pinterest content through BrandGrid.

BrandGrid does not sell, rent, license, redistribute, transfer, disclose, or otherwise make Pinterest content or Pinterest-derived data available to third parties for their independent use. Pinterest data obtained through the Pinterest API is used exclusively to provide BrandGrid services and for no other purpose inconsistent with Pinterest's Developer Policies.

When you disconnect Pinterest from BrandGrid, we delete the associated Pinterest connection record from our systems, including stored Pinterest OAuth tokens, board identifiers, account metadata, and other Pinterest-derived data that is no longer required for operational, legal, or security purposes. Once deleted, BrandGrid can no longer access or publish content to the disconnected Pinterest account unless you reconnect the account and grant authorization again.

Any Pins or content that were previously published to Pinterest through BrandGrid remain on Pinterest and continue to be governed by Pinterest's policies and your Pinterest account settings. Disconnecting Pinterest from BrandGrid does not remove content that has already been published to Pinterest.

BrandGrid is an independent service and is not endorsed by, affiliated with, authorized by, sponsored by, or otherwise officially associated with Pinterest, Inc. Pinterest is a trademark of Pinterest, Inc.

8. Platform Disclaimers

BrandGrid is an independent service. BrandGrid is not endorsed by, affiliated with, or sponsored by Meta (Facebook or Instagram), LinkedIn, X Corp., Pinterest, Google, or Shopify.

Use of Facebook, Instagram, LinkedIn, X, Pinterest, Google Ads, and Shopify through BrandGrid is subject to each platform's respective terms, policies, and developer guidelines. You are responsible for ensuring your use of BrandGrid complies with those platform policies.

9. Security

We follow industry-standard security practices to protect your data, including encrypted storage of credentials and access controls on our systems. We also comply with applicable platform developer policies for Meta, LinkedIn, X, Pinterest, Google, and Shopify.

10. Third-Party Services & APIs

BrandGrid integrates with the following third-party services when you choose to connect them:

  • Facebook Login & Facebook Graph API
  • Instagram Graph API
  • LinkedIn OAuth & LinkedIn API
  • X (Twitter) OAuth & X API
  • Pinterest OAuth & Pinterest API
  • Google OAuth & Google Ads API
  • Shopify OAuth & Shopify Admin API
11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of BrandGrid after changes are posted constitutes acceptance of the revised policy.

12. Contact Us

For privacy questions or data deletion requests, contact support@brandgrid.ai.