Privacy Policy
How Mad Fish Elements collects, uses, safeguards, and discloses information provided through the website and services.
Effective Date: December 1, 2020. Last Updated: August 9, 2026.
This Privacy Policy describes how Mad Fish SEO, Inc., an Oregon corporation based in Portland, Oregon (“Mad Fish,” “we,” “us”), collects, uses, and shares information in connection with Mad Fish Elements, including the customer portal, the MCP Gateway, the Data Visualization product, and the madfishelements.com website (together, the “Service”).
1. Scope
This policy covers the Service and the marketing website. The Service is a business-to-business product used by companies (“Customers”) and the individual users they authorize (“Users”). It is not offered to consumers for personal use and is not directed at children.
Capitalized terms not defined here have the meanings given in the Mad Fish Elements Terms of Use. “Connected Platform” means a third-party service (such as Google Ads, Google Analytics 4, Meta, LinkedIn, TikTok, Shopify, HubSpot, Salesforce, Mailchimp, Workamajig, Bill.com, Rippling, Toggl, Pinpoint, BigQuery, or Google Docs, Sheets, and Slides) that a User connects to the Service. “Connected Platform Data” means data retrieved from, written to, or deleted from a Connected Platform through the Service at a User’s direction.
2. Data We Collect
We collect the following categories of information. In each case, we collect only what is needed for the purposes described in Section 3.
Account and contact data. Name, business email address, company name, role, seat permissions, and account settings, collected when a Customer signs up or provisions Users. Customer administrators provide most of this information when they create Seats for their team.
Billing data. Subscription tier, usage volumes, invoicing records, and - for tiers priced partly on managed advertising spend - spend figures retrieved from connected advertising platforms’ reporting APIs at billing time. Payments are processed by Stripe; Mad Fish does not collect or store payment card numbers. The Service automatically rejects payment card numbers (PAN) submitted through it.
OAuth tokens and platform credentials. When a User connects a Connected Platform, we store the OAuth refresh token or API credential needed to maintain that connection. These credentials are encrypted and held in a managed key vault. Each connection is tied to the individual User who authorized it and is scoped by that User’s Seat permissions.
Connected Platform Data. Data flowing between a User’s AI assistant and Connected Platforms is processed at the User’s direction. This data is largely transient: it passes through the Service to fulfill the requested operation and is not retained as a copy of the Connected Platform’s records. Report and dashboard data is stored when a User creates or publishes a report in the Data Visualization product; that stored data remains under the Customer’s control and can be deleted by the Customer at any time.
Audit logs. Every operation performed through the Service is logged to an audit trail, including the User’s identity, the operation performed, the target platform, and a timestamp. Audit logs exist so that Customers can review exactly what was done in their connected accounts, by whom, and when.
Usage and telemetry data. API call volumes, feature usage, performance metrics, device and browser information, IP address, and diagnostic logs.
Support communications. Messages, attachments, and related records when you contact us.
Cookies. The marketing website uses cookies and similar technologies for functionality and analytics.
3. How We Use Information
We use the information above to:
- Provide and operate the Service - authenticate Users, maintain platform connections, execute User-directed operations, and render reports and dashboards;
- Bill and account - administer subscriptions, meter API usage, and measure managed advertising spend through the connected platforms’ own reporting APIs for spend-based pricing;
- Secure and audit - enforce per-seat permissions, maintain the audit trail, detect and prevent fraud, abuse, and security incidents;
- Support - respond to questions and troubleshoot issues;
- Improve the Service - using aggregated or de-identified data that does not identify a Customer, User, or other person;
- Comply with law - meet legal, tax, and regulatory obligations.
We do not sell personal information. We do not use Customer content or Connected Platform Data for advertising, and we do not use it to train advertising or marketing models.
A note on prohibited data. The Service is not designed to process protected health information (PHI) or payment card data. Customers agree in the Terms of Use not to submit either through the Service, and the Service automatically rejects detected payment card numbers. If we discover such data has been submitted despite these controls, we will delete it.
4. Google API Services - Limited Use Disclosure
The Service accesses Google APIs (including Google Ads, Google Analytics 4, BigQuery, and Google Docs, Sheets, and Slides) only at the direction of the User who authorized the connection.
Mad Fish Elements’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, with respect to Google user data:
- We use Google user data only to provide and improve user-facing features of the Service that are prominent in its interface - executing the operations Users request and rendering the reports Users create.
- We do not transfer Google user data to others except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users; or with the user’s consent; or for security purposes (such as investigating abuse).
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have the user’s affirmative agreement to view specific data; (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized and is used for internal operations.
5. How We Share Information
We share information only as described below. We use subprocessors to run the Service:
Subprocessor
Purpose
Data involved
Microsoft Azure
Hosting, managed key vault, cache, and database
All Service data, including encrypted credentials
Stripe
Payment processing
Billing contact and payment details (card data goes directly to Stripe)
Transactional email provider
Account and service emails
Name, email address, message content
Connected Platforms
Executing User-directed operations
Connected Platform Data, at the User’s direction
Subprocessors are bound by contracts requiring them to protect the data and use it only to provide their services to us. We will maintain a current subprocessor list and make it available to Customers.
Connected Platforms. When a User directs an operation, the relevant data flows to and from the Connected Platform the User selected. That transfer happens at the Customer’s direction, and the platform’s own privacy policy governs its handling of the data. Mad Fish does not control, and is not responsible for, the privacy practices of Connected Platforms.
Corporate events. If Mad Fish is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy and with notice where required.
Legal process. We may disclose information when required by law, subpoena, or court order, or to protect the rights, safety, or property of Mad Fish, our Customers, or others. Where legally permitted, we will notify the affected Customer before disclosing its data.
We do not share personal information with third parties for their own marketing.
6. Data Retention
We keep information only as long as needed for the purposes described in this policy, then delete or de-identify it. Current retention periods are:
Data
Retention
OAuth tokens and platform credentials
Until the User disconnects the platform or the account is terminated; then deleted
Audit logs
90 days (standard tiers); 365 days (premium tiers)
Reports and dashboards
Until the Customer or User deletes them, or account termination
Account and billing records
For the life of the account and as required for legal, tax, and accounting purposes
Backups
Deleted according to the rolling backup retention schedule after deletion from active systems
On termination, Customers have a 30-day window to export stored reports and data, after which Customer data - including stored credentials - is deleted from active systems, subject to backup cycles and legal retention obligations.
7. Security
Mad Fish maintains a security program that includes:
- Encryption in transit (TLS) and encryption at rest for stored data;
- Managed key vault storage for OAuth tokens and API credentials;
- Per-seat access controls - read, write, and delete permissions enforced server-side for every operation;
- Audit trail logging of every operation, supporting review and incident investigation.
No system is perfectly secure. Customers are responsible for safeguarding their own login credentials and configuring seat permissions appropriately.
8. Your Rights and Choices
All users. You may access and update account information in the portal, disconnect Connected Platforms at any time (through the Service or the platform’s own security settings), and contact us with privacy questions at legal@madfishelements.com. Disconnecting a platform stops future access through the Service and triggers deletion of the stored credential for that connection. You may also opt out of non-essential emails using the unsubscribe link in any marketing message; transactional Service emails (such as billing and security notices) will continue while you have an account.
EEA, UK, and similar jurisdictions. Where the GDPR or similar laws apply, you may have rights to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. You may also lodge a complaint with your supervisory authority. Where we act as a processor for a Customer (see Section 12), we will refer your request to that Customer and assist them in responding.
California residents. Under the CCPA/CPRA, California residents have the right to know what personal information we collect and how it is used and shared; to access and receive a portable copy; to correct inaccurate information; to delete personal information; and to not be discriminated against for exercising these rights. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, so we do not offer an opt-out for sale or sharing. To exercise rights, email legal@madfishelements.com with the subject line “Privacy Request.” We will verify your identity before responding. You may use an authorized agent by providing signed permission; we may require the agent to prove authorization and may require you to verify your identity directly.
9. International Data Transfers
The Service is hosted in the United States on Microsoft Azure. If you use the Service from outside the United States, your information is transferred to and processed in the United States. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards.
10. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to This Policy
We may update this policy from time to time. For material changes, we will notify Customers by email or in-product notice before the changes take effect, and we will update the “Last Updated” date above. Continued use of the Service after the effective date constitutes acceptance.
12. Contact; Controller and Processor Roles
Roles. For Connected Platform Data and content Customers process through the Service, the Customer is the controller (or a processor for its own clients) and Mad Fish acts as a processor, handling the data only on the Customer’s documented instructions. For account, billing, audit, usage, and website data, Mad Fish acts as the controller. A Data Processing Addendum is available on request.
Contact. Mad Fish SEO, Inc. 721 SW Oak, Suite 200, Portland, Oregon 97205, USA Email: legal@madfishelements.com