Legal

Privacy Policy

Last updated: May 31, 2026

3RDPIPE (“3RDPIPE,” “we,” “us,” or “our”) provides a local SEO and social media content management platform to digital marketing agencies and their small-business clients. The 3RDPIPE product family also includes Social Alerts, an optional browser extension and dashboard that helps a signed-in user spot potential sales leads in the Facebook groups they already belong to (data practices specific to Social Alerts are described in Section 4). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. By using our platform you agree to this Policy.

1. Information We Collect

Information you provide directly

  • Account information. Name, email address, and authentication credentials (managed by our auth provider, Clerk).
  • Client business information. Company names, addresses, phone numbers, websites, industries, contacts, and notes you enter into your workspace.
  • Stored credentials. Usernames and passwords you choose to store for third-party services on behalf of your clients. Passwords are encrypted at rest using AES-256-GCM and decrypted only on authorized admin requests.
  • Tracked keywords and locations. SEO keywords, target geographies, and store-location data you add for each client.

Information collected via Google APIs

  • Google Business Profile performance data — insights such as calls, views, direction requests, website clicks, search queries, and discovery counts — retrieved from Google APIs that your agency Google account is authorized to access.
  • Google Business Profile metadata — location name, address, place ID, and category — used to match Google locations to your in-app client records.
  • Google account identifiers sufficient to maintain the authorization (refresh tokens, account email) — stored encrypted in our database.

Information collected automatically

  • Usage data. Pages viewed, features used, and timestamps, used to operate and improve the service.
  • Device and log data. IP address, browser type, operating system, and request timestamps.
  • Cookies. Required only for authentication and session management. We do not use third-party advertising cookies.

2. How We Use Information

  • To operate and maintain the platform — including displaying analytics and performance dashboards to authorized users.
  • To authenticate users and protect against unauthorized access.
  • To communicate with you about your account, security, and product updates.
  • To improve our features based on aggregate usage patterns.
  • To comply with legal obligations and enforce our Terms of Service.

3. Google API Services - Limited Use

3RDPIPE's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide and improve the features visible to the user who authorized access (analytics dashboards for your agency and your linked clients).
  • We do not transfer Google user data to third parties except as necessary to provide or improve the service, or as required by law.
  • We do not use Google user data for advertising purposes.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
  • We do not allow humans to read Google user data unless we obtain affirmative agreement from the user, it is necessary for security purposes, to comply with applicable law, or for our own internal operations (and then only on de-identified or aggregated data).

4. Social Alerts Browser Extension

Social Alerts is an optional Chrome browser extension and companion dashboard that helps a signed-in user spot potential sales leads in the Facebook groups they already belong to. This section describes the data practices specific to Social Alerts.

What the extension accesses

  • It reads only the posts already visible to you, in groups you have joined and explicitly added, using your own logged-in Facebook session in your own browser.
  • It is read-only: it does not scroll, click, like, comment, post, send messages, or take any action on your behalf. It does not access your friends list, profile, private messages, or any content outside the groups you configure.
  • We never receive or store your Facebook username or password, and we never log in as you.

What we store

  • Matched posts.For posts that match one of your keyword rules, we store the post text, a short snippet, the post URL, the author's public display name, and the group name.
  • Configuration. The group URLs and keyword rules you set up, plus your notification preferences.
  • A short-lived processing log. Recently-seen posts (matched or not) are briefly recorded for troubleshooting and then automatically pruned; we retain only a small, capped number of recent entries per account.

Notifications (SMS and email)

  • Email notifications are sent via Resend and SMS notifications via Twilio, only for posts that match your rules.
  • SMS is sent only after you enter your own phone number and tick an explicit consent checkbox. Message frequency varies with your rules (typically 5–20 messages per week); message and data rates may apply. Reply STOP to opt out or HELP for help.
  • We use phone numbers solely to notify the account holder. We never sell, rent, or share phone numbers with third parties for marketing.

What we do not do

  • We do not store Facebook credentials or act as you on Facebook.
  • We do not use content read by the extension for advertising, and we do not use it to train generalized or non-personalized AI or machine-learning models.
  • We do not sell your information.

5. How We Share Information

We do not sell your information. We share information only as described below:

  • Service providers. We rely on trusted vendors who process data on our behalf:
    • Clerk — user authentication, session management, and email invitations.
    • Neon — primary database hosting.
    • Vercel — application hosting and edge delivery.
    • Stripe — subscription billing, invoicing, and payment processing. Stripe handles card details directly; we never see or store full card numbers.
    • Local Viking / Local Optics — Google Business Profile API access (geo-grid scans, performance metrics, reviews, scheduled tracking).
    • Google Maps Platform — address autocomplete and Place ID verification when adding locations.
    • Twilio — delivery of SMS lead notifications for Social Alerts users who have opted in.
    • Resend — delivery of email lead notifications for Social Alerts users.
    Each provider is contractually bound to confidentiality and security obligations.
  • Within your workspace. Information you enter is visible to authorized members of your agency workspace. Customer-account users can only see data linked to the specific client business they are assigned to.
  • Legal compliance. We may disclose information if required by law, subpoena, or to protect the rights, property, or safety of our users or the public.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any change in ownership or use of your information.

6. Data Security

We use industry-standard safeguards to protect information, including TLS encryption in transit, encryption at rest for stored credentials and OAuth tokens, role-based access controls, and audit logging. No method of transmission or storage is 100% secure, but we work continuously to reduce risk.

7. Data Retention

We retain account, client, and integration data for as long as your workspace is active. You may delete clients, credentials, keywords, and other data at any time from within the platform — deletions are permanent. When you close your account, we delete or anonymize remaining personal information within 30 days, except as required by law.

8. Your Rights and Choices

Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can:

  • Access or update most account data directly from within the platform.
  • Request a copy of your data, or request deletion of your account, by emailing support@3rdpipe.io. We respond within 30 days.
  • Revoke Google API access at any time from your Google Account permissions page.
  • Contact us with any privacy concern at the email above.

California residents (CCPA / CPRA)

If you reside in California, you have the right to:

  • Know the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which we use it, and the third parties with whom we share it.
  • Delete personal information we have collected from you, subject to limited exceptions (e.g., information needed to complete a transaction, detect fraud, or comply with law).
  • Correct inaccurate personal information we maintain about you.
  • Opt out of sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
  • Limit use of sensitive personal information. We only use sensitive information for the purposes permitted under the CCPA and as needed to provide the Service.
  • Non-discrimination. We will not deny service, charge a different price, or provide a different quality of service because you exercised any of these rights.

To exercise these rights, email support@3rdpipe.io. We may need to verify your identity before fulfilling the request.

EU / UK residents (GDPR)

If you are in the EU, UK, or Switzerland, you have additional rights including access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with your local supervisory authority.

Our lawful bases for processing your personal information are:

  • Performance of a contract — to provide the Service you signed up for and process payments.
  • Legitimate interests — to operate, secure, and improve the Service, prevent fraud, and communicate with you about your account.
  • Consent — for any data processing where required by law (e.g., certain cookies, marketing emails). You may withdraw consent at any time.
  • Legal obligation — where we are required to retain or disclose data to comply with law.

9. Children's Privacy

Our platform is intended for business use and is not directed to anyone under the age of 16. We do not knowingly collect information from children. If you believe we have collected information from a child, please contact us so we can remove it.

10. International Users

The platform is operated from the United States. By using it, you consent to the transfer of your information to the United States, which may have data protection laws different from your country.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and notify users with active accounts by email or in-app notice. Your continued use of the platform after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions about this Privacy Policy or our handling of your information, contact us:

3RDPIPE
support@3rdpipe.io