Privacy Policy
Last updated: August 14, 2026
This policy explains what information Metronoms collects, why we collect it, and how you can control it. In short: we collect what's needed to run a social-media management platform for agencies — and nothing we collect is ever sold or used for advertising.
1. Who we are
Metronoms (“we”, “us”) operates the website at metronoms.com and the application at platform.metronoms.com. Metronoms is operated from Sweden and complies with the EU General Data Protection Regulation (GDPR). For any privacy matter, contact info@metronoms.com.
Metronoms is built for marketing agencies. Agencies use it to manage social media, reviews and marketing for the businesses they serve (“clients”). That shapes how data flows here: for the account data of agency users we act as a data controller; for the content and social-platform data agencies connect on behalf of their clients, we act as a data processor on the agency’s instructions. The social networks themselves (Meta, Google and others) are independent controllers of the data on their own platforms, under their own policies.
2. Information we collect
- Account information — name, email address and password hash when you create an account; agency name, branding and settings you configure.
- Client and business information — the business names, contact details, addresses, opening hours and other details that agencies add for the clients they manage.
- Connected social accounts — when an agency connects a client’s Facebook Page, Instagram account, Google Business Profile or other social account, we receive access tokens and the data those platforms return (described in sections 3 and 4).
- Content — posts, images, videos, captions and drafts created or uploaded in the platform, the schedule they publish on, and messages, comments and reviews synced from connected accounts so agencies can respond.
- CRM and contact data — contacts, form submissions, bookings and campaign activity that agencies collect from their own clients and audiences through platform features.
- Billing information — subscription status, plan, and invoice records. Card details are collected and processed by Stripe and never touch our servers.
- Usage and log data — standard technical logs (IP address, browser type, timestamps, pages viewed) used for security, debugging and keeping the service working.
- Support communication — emails you send us, so we can answer them.
3. Google user data
When an agency connects a client’s Google Business Profile through Google sign-in, Metronoms requests the business.manage permission and accesses, on the agency’s behalf: the list of business accounts and locations the connecting Google account manages, business information for those locations, their reviews, their posts, and their performance insights.
We use this data solely to provide the product’s features:
- publishing and scheduling posts to the connected profile;
- showing and replying to the profile’s reviews;
- displaying performance insights for the profile;
- keeping business information in sync when the agency edits it.
Limited Use disclosure: Metronoms’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, use it for advertising, or transfer it to third parties except as needed to provide these features, to comply with law, or as part of a merger or acquisition with equivalent protections. Google access tokens are stored encrypted and used only to make the API calls the features above require. You can revoke Metronoms’ access at any time at myaccount.google.com/permissions, and disconnecting an account in the platform deletes its stored tokens.
4. Facebook, Instagram & Meta platform data
When an agency connects a client’s Facebook Page or Instagram professional account, we receive and store, on the agency’s behalf: the Page or account name and identifier, access tokens, published posts and their media, comments and messages where the agency has enabled the inbox, and post/page insights. We use this data only to provide publishing, scheduling, inbox and analytics features for that connected account.
Metronoms’ use of Meta platform data complies with the Meta Platform Terms. We do not sell Meta platform data or use it outside the features described here. Disconnecting an account deletes its stored tokens; see Data Deletion for removing all associated data.
5. How we use information
- to provide, operate, secure and improve the platform;
- to authenticate you and manage your account and team;
- to publish and schedule the content agencies create, and to sync the messages, comments and reviews they respond to;
- to send transactional email — approvals, billing, alerts about failed posts or expiring connections (agency users control non-critical email in their notification settings);
- to bill subscriptions and process invoice payments through Stripe;
- to prevent abuse and enforce our Terms of Service;
- to comply with legal obligations.
We do not sell personal data, and we do not use your data or your clients’ data for advertising.
6. AI features
Some features use AI models to draft content — for example suggested posts or reply drafts. When you use them, relevant business context (such as the client’s name, description or website text) is sent to our AI provider to generate the draft. Two commitments:
- Your data is not used to train AI models — ours or anyone else’s. Prompts are processed to generate your output and are not retained by us for training.
- AI drafts are suggestions; nothing is published without an action by you or rules you configured.
7. Legal bases (GDPR)
- Contract — most processing is necessary to provide the service you signed up for.
- Legitimate interests — service security, preventing abuse, and improving the product.
- Legal obligation — retaining invoicing records for accounting law.
- Consent — where required, for example optional emails; consent can be withdrawn at any time.
8. Who we share information with
We share data only with the service providers needed to run the platform, each under a data-processing agreement, and only for the tasks below:
- Microsoft Azure — application and database hosting (EU region);
- Amazon Web Services — media file storage;
- Stripe — payments, subscriptions and payouts (PCI-DSS certified; card data goes directly to Stripe);
- Mailgun — transactional email delivery (EU region);
- Mistral AI — processing prompts for the AI drafting features (EU-based provider);
- the social platforms themselves — Google, Meta and the other networks receive the content agencies publish through them, under their own terms.
Beyond service providers, we disclose data only if required by law or valid legal process, to protect the rights and safety of users, or as described in section 13 (business transfers). Service providers may not use your data for their own purposes.
9. Data retention
Data is kept while the account it belongs to is active. When an agency’s account is closed, its data is deleted after a short grace period (during which closure can be reversed), except invoicing records we are legally required to keep for accounting purposes — those are retained with personal details removed. Disconnecting a social account deletes its stored access tokens immediately. Routine backups are cycled out on their own schedule. Full mechanics are on the Data Deletion page.
10. Security
Data is encrypted in transit (TLS) and at rest. Social platform tokens are stored encrypted. Access to production systems is restricted and audited, and administrative actions on the platform are logged. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security — but we treat the credentials agencies entrust to us — access to their clients’ public presence — as the most sensitive thing we hold, and we will notify affected users and authorities of a breach as the GDPR requires.
11. Your rights
Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or restrict certain processing. Write to info@metronoms.com and we will respond within 30 days. You also have the right to complain to your supervisory authority — in Sweden, the Integritetsskyddsmyndigheten (IMY). If your business is managed by an agency on Metronoms, that agency controls your data — we will forward your request to them and confirm the outcome. For deleting your data, see Data Deletion.
12. International transfers
Our primary infrastructure runs in the European Union. Where a provider processes data outside the EU/EEA, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.
13. Business transfers
If Metronoms is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction. It remains subject to protections equivalent to this policy, and we will notify account owners before a different privacy policy applies to their data.
14. Cookies
The platform uses cookies and similar storage strictly for signing you in and keeping your session — no advertising or cross-site tracking cookies, on either the marketing site or the application. The full list is in our Cookie Policy.
15. Links to other sites
The service links to external sites — the social networks, Stripe’s checkout, your own clients’ pages. Their privacy practices are their own; this policy covers only Metronoms.
16. Children
Metronoms is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16; if we learn we have, we delete it.
17. Changes to this policy
If we make material changes we will update this page and notify account owners by email before the changes take effect. The date at the top always reflects the current version.
18. Contact
Metronoms · Sweden · info@metronoms.com
