Legal
Privacy Policy
Last updated 30 July 2026 · Draft pending legal review
Who we are
Make Noise is an internal marketing-operations platform operated by the agency named in the contact section. It is used by agency staff to plan and measure marketing activity for the agency’s clients. It has no public sign-up and no consumer users.
What we collect
Three categories, and nothing else:
- Account data for agency staff. Name, email address, and the role and client scope that determine what each person can see. Used solely to authenticate people and enforce permissions.
- Connected platform credentials. When an agency user connects a client’s account — Google Search Console, YouTube, TikTok, or Meta — we store the OAuth tokens that platform issues, plus the account identifier the tokens belong to. We request the narrowest scopes that let the feature work, and we list them before you authorise.
- Marketing performance data. Metrics the connected platforms return about the client’s own accounts and content: impressions, clicks, ranking positions, views, engagement rates, and publication timestamps. Plus data the agency enters about its clients — brand positioning, approved claims, and campaign plans.
We do not collect personal data about a client’s customers or audience. Platform analytics are ingested only in the aggregated form the platforms provide.
How credentials are protected
Platform tokens are encrypted with AES-256-GCM before they are written to the database. The plaintext exists only in memory during a sync. Specifically:
- Credentials are never stored in environment variables or configuration files. A lint rule fails the build if code attempts it.
- No API endpoint or screen returns a stored credential. The application interface can report only whether a connection is configured, never its value.
- Credentials are excluded from audit records and application logs by a redaction step applied before writing.
How we use it
To read performance data for the client accounts you connect, to compute the metrics and recommendations the product presents, and — where you explicitly approve it — to publish content you have created to those accounts. Nothing publishes without a recorded human approval.
We do not sell data, use it for advertising, or use one client’s data to benefit another. Data is separated by client throughout the system, and access is limited to the agency staff assigned to that client.
AI processing
Some features send text to a third-party AI provider to draft or summarise content — for example, drafting a description of a client’s brand from its public website. What is sent is limited to the marketing data described above. Platform credentials are never sent. We keep a record of every such call so any output can be traced to its inputs.
Sharing
We share data only with the infrastructure providers required to run the service — our database and application hosting providers, and the AI provider described above — and only to the extent needed to operate it. We do not share data with advertisers or data brokers.
Retention and deletion
Performance data is retained while the client relationship is active. You can disconnect any connected account at any time from the integrations screen, which revokes and deletes the stored credential immediately; you can also revoke access from the platform’s own security settings. To request deletion of a client’s data, contact us at the address below.
Records of who changed what and when are retained for accountability, and cannot be altered after the fact by design. These records contain no credentials.
Your rights
Depending on where you are, you may have rights to access, correct, export, or delete personal data we hold, and to object to certain processing. Contact us to exercise them and we will respond within the period the applicable law requires.
Contact
[Add the agency’s legal entity name, postal address, and a monitored contact email before publishing.]