Privacy Policy
Clientdeck, operated by Fusion Marketing. Last updated August 2026.
Clientdeck is a reporting and lead management tool for marketing agencies. This policy explains what information we handle, why, and the choices you have. It applies to the Clientdeck website and app. In this policy, "we" and "us" mean Fusion Marketing.
Who the data belongs to
Agencies are our customers. When an agency uses Clientdeck for their own clients, the agency is the controller of that client and lead data, and we process it on the agency's behalf as their service provider. If you are an individual whose details were captured as a lead, please contact the agency you enquired with, or us, using the details below.
Information we collect
- Agency account information. Name, email address, and a securely hashed password. We never store passwords in plain text.
- Billing information. Subscription and payment details are handled by our payment processor, Stripe. We do not store full card numbers.
- Client and report content. The client names, brand settings, and campaign figures an agency enters or imports to build reports.
- Lead information. The details a person submits through a client's capture form, or that flow in from a connected source (name, email, phone, message, and the campaign it came from). This is captured for, and on behalf of, the relevant agency and their client.
- Connected platform data. When an agency connects an advertising or data account, we access only what is needed to build reports or manage leads:
- Meta (Facebook/Instagram): aggregate ad performance numbers (spend, reach, results and similar), read with the ads_read permission, and, where the agency enables it, lead form submissions. We never access private messages, friend lists, or content unrelated to the ad account.
- Google: we offer sign in with Google, which reads your basic Google profile (your name and email address) only to create and sign you into your account. Where an agency connects Google Analytics, we read that property's aggregate reporting metrics (such as sessions, users, key events, conversions, traffic channels and landing pages) on a read only basis, using the analytics.readonly scope, solely to build that agency's client report. We never create, change or delete any Analytics data, and we access nothing outside the property the agency chooses to link.
- Basic technical data. A single essential session cookie to keep you logged in. On our marketing website and sign up pages we also run Google Ads conversion tracking, described below.
How we use information
We use the information solely to provide and operate the Clientdeck service: to authenticate agencies, build and display reports, capture and display leads to the agency and their client, process subscription payments, and keep the service secure. We do not sell personal information, and we do not use platform data for advertising or for any purpose other than providing the service to the connecting business.
Google user data and Google API Services
When an agency signs in with Google, Clientdeck reads only their basic Google profile (name and email address) to authenticate them. When an agency connects Google Analytics, Clientdeck reads that property's aggregate reporting metrics on a read only basis, using the analytics.readonly scope. When an agency connects Google Search Console, Clientdeck reads that property's aggregate search performance, such as clicks, impressions, average position, top queries and top pages, on a read only basis using the webmasters.readonly scope. When an agency connects Google Ads, Clientdeck reads that account's aggregate campaign performance, such as impressions, clicks, cost, conversions and campaign names, using the adwords scope. That scope has no read only variant, so we want to be plain about what we do with it: every request Clientdeck makes to Google Ads is a read. We never create, change, pause or delete a campaign, a budget, a keyword or anything else in the account. Every one of these connections is read for the single purpose of generating that agency's client report. We do not use this Google data for advertising, we do not sell or rent it, and we do not share it with anyone beyond the service providers listed below that are needed to run Clientdeck. Access tokens are encrypted at rest and never displayed, and an agency can disconnect a Google account at any time, which immediately removes the stored token.
Clientdeck's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Ads conversion tracking
Our marketing website and sign up pages use Google Ads with enhanced conversions switched on, so we can see which adverts led to a new free trial. When you start a trial, we pass Google a hashed version of the email address you signed up with, not the plain text address, along with the click information Google Ads already collects when you follow one of our adverts. Google matches and reports this on an aggregate basis. We use it only to measure which adverts are working, and it is limited to our public marketing pages, the sign up page and the one time trial confirmation on the welcome page.
Automated report writing
To turn campaign figures into a written report, we send the numbers only to our AI processor (Anthropic) to draft the report copy. We do not send lead contact details or other personal information to the AI for this purpose.
How we store and protect information
Data is stored in a secured database hosted on Railway. Access tokens for connected accounts are encrypted at rest and are never displayed. Access to the app is protected by login, and each agency can only see their own data. Client portals are reachable only through an unguessable private link.
How long we keep it, and deletion
We keep information for as long as the agency's account is active and as needed to provide the service. An agency can disconnect any connected account at any time, which removes the stored access token. You can request deletion of your data at any time. See our Data Deletion page for how, or email us at the address below.
Who we share information with
We share information only with the service providers that help us run Clientdeck, and only as needed:
- Stripe: subscription payments.
- Anthropic: AI processing of report figures.
- Railway: application and database hosting.
- Meta and Google: only when an agency connects those accounts, to read the data described above.
- Google Ads: conversion tracking with enhanced conversions on our marketing and sign up pages, as described above. Only a hashed email address is shared, never the plain text address.
We do not sell or rent personal information to anyone.
Your rights
You may ask us to access, correct, or delete the personal information we hold about you, and to disconnect any connected account. We handle personal information in line with the New Zealand Privacy Act 2020. To exercise any of these, contact us below.
Children
Clientdeck is a business tool and is not intended for anyone under 16.
Changes to this policy
If we make material changes, we will update this page and the "last updated" date above.
Contact us
Fusion Marketing
Dunedin, Otago, New Zealand
marketing@clientdeck.co.nz
Clientdeck