1. Introduction
AgencyKit is a product of Win Market Agency, Cairo, Egypt. AgencyKit ("we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, and protect your information when you use our platform at agencykit.tech and app.agencykit.tech.
By using AgencyKit, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our service.
2. Information We Collect
We collect the following types of information to provide and improve our service:
- Account information, your name, email address, and password (stored as a bcrypt hash)
- Business information, client data, proposals, contracts, invoices, and time logs you create
- Usage data, how you interact with the app (pages visited, features used)
- Payment information, processed by Stripe, PayPal, or Paymob; we never see or store your full card number
- Log data, IP address, browser type, operating system, and timestamps of requests
- Google account data, only if you choose to connect Google Calendar. See section 6 for exactly what this covers and how it is used
3. How We Use Your Information
- To provide, operate, and improve the AgencyKit platform
- To send transactional emails (invoice notifications, contract signing confirmations)
- To send product updates and announcements (you can opt out at any time)
- To ensure platform security and prevent fraud or abuse
- To respond to support requests and communications
- To comply with legal obligations
4. Data Storage and Security
- Data is stored on secure servers located in the EU
- All data transmission is encrypted via SSL/TLS
- Passwords are hashed using bcrypt, we cannot recover them
- Payment data is handled exclusively by PCI-compliant processors
- We never store full credit card numbers or CVV codes
- Access to production systems is restricted to authorized personnel only
5. Third-Party Services
We integrate with the following third-party services, each with their own privacy policies:
We do not use Google Analytics, Facebook Pixel, or any third-party advertising trackers.
6. Google User Data
AgencyKit offers an optional Google Calendar connection so that meetings you book in AgencyKit appear on your own calendar. This section describes exactly what that connection accesses, why, and how to end it. It applies only if you choose to connect a Google account. Every other part of AgencyKit works without it.
What we access
When you connect Google Calendar, AgencyKit requests these scopes and no others:
- https://www.googleapis.com/auth/calendar.events, to create, read, update, and delete the calendar events for meetings booked through AgencyKit
- openid and email, to identify which Google account you connected, so the correct calendar is used and so you can see which account is linked
We do not request access to Gmail, Google Drive, Contacts, or any other Google service.
Why we access it
- To create a calendar event when a meeting is booked with you, including the time, title, and video conferencing link
- To update or cancel that event when the meeting is rescheduled or cancelled in AgencyKit
- To read your existing busy times so the public booking page does not offer a slot you are not free for
The connection is used for the Meetings feature only. It is never used for advertising, profiling, or any purpose you did not ask for.
What we store
- An OAuth access token and refresh token, so the connection keeps working without asking you to sign in repeatedly. These are stored in our database on our own server in Europe
- The email address of the connected Google account, so the app can show you which account is linked
- The identifier of each calendar event AgencyKit created, so it can be updated or removed later
We do not copy your calendar into our database. Free and busy times are read at the moment a booking page is opened and are not retained afterwards.
Limited Use
AgencyKit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means all of the following:
- We use Google user data only to provide and improve the Meetings feature, which is visible in the AgencyKit interface
- We do not sell Google user data, and we do not transfer it to third parties except where required by law
- We do not use Google user data for advertising of any kind, including personalised, retargeted, or interest-based advertising
- We do not allow any person to read Google user data. It is accessed only by automated systems, except where you have given specific consent (for example, when you send us a screenshot while asking for support), where it is necessary for security purposes such as investigating abuse, or where required by law
- We do not use Google user data to train generalised artificial intelligence or machine learning models
Revoking access
You can disconnect at any time, and you do not need our permission or assistance to do it:
- Inside AgencyKit, open the Meetings page and click Disconnect on the "Google Meet & Calendar" card. This deletes the stored access and refresh tokens from our database immediately
- From your Google account, open myaccount.google.com/permissions, select AgencyKit, and choose Remove access. This revokes the tokens at Google's end
Once access is revoked, AgencyKit can no longer read or change anything in your calendar. Calendar events that were already created remain on your calendar and are yours to keep or delete. Deleting your AgencyKit account removes the stored tokens along with the rest of your account data, as described in section 7.
7. Facebook and Instagram Lead Data
AgencyKit offers an optional Meta connection so that leads from a business's own Facebook and Instagram lead forms arrive in AgencyKit automatically. This section describes exactly what that connection accesses and how to end it. It applies only if a Facebook Page is connected. Every other part of AgencyKit works without it.
What we access
When a Page is connected, AgencyKit requests these permissions and no others:
- pages_show_list, to show which Pages you manage so you can choose one
- pages_read_engagement and pages_manage_metadata, to install AgencyKit on the Page you chose so Facebook notifies us when a lead form is submitted
- leads_retrieval, to read the answers a person gave on that form
- pages_manage_ads, to list the Page's lead forms so each question can be mapped to the right field
We do not request access to post on a Page, to read messages, to read your profile beyond your name and picture, or to your friends.
What we receive about a person who fills in a form
- The answers they gave, which is whatever the business chose to ask: typically a name, an email address and a phone number
- Which consent boxes they ticked or left unticked, and the exact wording they were shown
- Facebook's own reference numbers for the lead, the form, the Page and the ad, so the lead can be attributed to the campaign that produced it
We do not receive their Facebook profile, their posts, or anything they did not type into that form.
Who controls that data
The agency running the ad decides what is collected and what happens to it. AgencyKit stores it on their behalf and does not use it for its own purposes. We never sell it, never use it for advertising, and never combine it across customers.
What we store from the connection itself
- An access token for each connected Page, encrypted, used only to read that Page's lead forms and leads
- An app-scoped Facebook user identifier, which is a number Facebook gives us that is different for every app and identifies the person to AgencyKit and to nobody else
- The name and identifier of each connected Page
How to end it, and how to request deletion
- In AgencyKit, remove the Page from Settings, then the Meta tab. We tell Facebook to stop sending and delete the stored token.
- On Facebook, go to Settings and privacy, then Settings, then Business Integrations, and remove AgencyKit. This revokes our access immediately.
- To have data we already hold deleted, follow the steps on our Facebook Data Deletion page, or email privacy@agencykit.tech. We acknowledge within 5 working days and complete within 30 days.
Deleting data from AgencyKit does not delete it from Facebook, which keeps its own copy. That has to be requested from Facebook separately.
8. Data Retention
- Active account data, retained for as long as your account exists
- Deleted account data, permanently removed within 30 days of account deletion
- Backup data, removed from backups within 90 days
- Log data, retained for up to 12 months for security purposes
9. Your Rights (GDPR)
If you are located in the European Union, you have the following rights regarding your personal data:
- Right to access, request a copy of the data we hold about you
- Right to rectification, correct any inaccurate or incomplete data
- Right to erasure, request deletion of your personal data
- Right to data portability, export your data in a machine-readable format
- Right to object, object to processing for direct marketing purposes
To exercise any of these rights, contact us at privacy@agencykit.tech. We will respond within 30 days.
10. Cookies
We use only essential cookies required for authentication and user preferences (such as dark/light mode). We do not use advertising cookies, third-party tracking cookies, or analytics cookies.
For full details, see our Cookie Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of any material changes by email (if you have notifications enabled) and by updating the "Last updated" date above.
Continued use of AgencyKit after changes are posted constitutes your acceptance of the updated policy.
12. Contact
For privacy-related questions, data requests, or concerns: