Privacy Policy
Last updated: August 30, 2026
Metric Hive is a business data integration and analytics service. We process customer data only to provide, secure, support, and improve the service our customers configure.
This Privacy Policy explains what information Metric Hive collects and processes when you visit our site, create an account, invite team members, connect third-party platforms, import data, transform data, query data, or export data to destinations such as Google Sheets or BigQuery.
Information We Process
Account and user information
We store information needed to create and administer Metric Hive accounts, including user name, last name, email address, Firebase authentication identifier, subscription or workspace membership, account membership, role, status, invitation email address, invitation role, invite status, and related timestamps.
Workspace, account, and configuration information
We store customer-configured workspace information such as subscription name, account name, source definitions, connected platform names, selected report types, source identifiers, advertiser or remote account identifiers, field definitions, custom fields, semantic mappings, saved dashboard or explore views, export configuration, schedules, deletion requests, job status, and operational timestamps.
Customer data from connected platforms
When a customer connects a source, Metric Hive imports and stores the data needed for that source and the reports the customer selects. Depending on the integration, this may include advertising performance data, campaign names and IDs, ad set and ad IDs, clicks, impressions, spend, conversions, conversion value, currency, country, device, landing page dimensions, spreadsheet headers and cell values, CRM object IDs and selected CRM properties, affiliate or partner conversion data, and other rows returned by the connected platform for the configured report.
Google Sheets sources can contain arbitrary spreadsheet content chosen by the customer. CRM and commerce integrations may contain personal data if the customer chooses to connect sources that include it. Customers are responsible for ensuring they have the rights and permissions to process the data they connect to Metric Hive.
Credentials, OAuth tokens, and API keys
When a customer connects a third-party platform, Metric Hive may store OAuth access tokens, refresh tokens, ID tokens, API tokens, basic-auth credentials, service account JSON, scopes, token expiry, provider account ID, project ID, client email, and related secret metadata. Secret values are stored server-side in managed secret storage. Public API responses are designed to return credential metadata, not raw token or secret material.
Metric Hive also supports API keys for service access. We store API key names, scope, key prefix, key hash, status, creation time, last-used time, expiration time, and revocation time. We do not store the raw API key after creation.
Usage, logs, and diagnostics
We process operational information such as request activity, authentication method, API key usage time, ingestion jobs, export runs, query runs, queue message IDs, row counts, latency, data scanned, success and failure counts, error messages, and security or abuse-prevention signals. These records help operate, debug, secure, and measure the service.
Cookies and Browser Storage
Metric Hive uses an essential backend session cookie for authenticated app sessions. The cookie is configured as an HttpOnly secure session cookie and is used to authenticate requests to the Metric Hive API. Because it is HttpOnly, it is not available to JavaScript running in the browser.
The Metric Hive app also uses browser storage for product functionality. Local storage may cache non-authoritative app/API data with an expiration time so screens can load efficiently. Session storage may temporarily remember OAuth flow state, such as the account being connected to Google Sheets, while the OAuth redirect completes.
We do not use these cookies or browser storage entries to sell personal data or to run third-party advertising. Optional Google Analytics storage is used only after you choose to allow analytics in the cookie preferences. We store a small consent record in browser storage so we can remember that choice, and you can change it later through Privacy settings or the cookie preferences control.
Firebase or Google reCAPTCHA Enterprise may assess email/password account creation and sign-in activity for automated abuse. These security services may process technical request, device, browser, network, interaction, and risk signals. Metric Hive uses the resulting assessments only to secure authentication operations.
How We Use Information
- Provide the Metric Hive service, including authentication, account administration, source connections, ingestion, transformations, analytics queries, exports, schedules, and deletion workflows.
- Validate, refresh, and use connected credentials only for integrations and destinations configured by the customer.
- Show product metadata such as connected account names, report schemas, fields, source status, job progress, saved views, and export status.
- Secure the service, prevent abuse, enforce access controls, verify sessions, audit API key use, and investigate errors or unauthorized activity.
- Provide customer support, troubleshoot reliability issues, and communicate service or account notices.
- Improve product quality, performance, and reliability using operational metrics and aggregated usage information.
- Comply with legal obligations, enforce agreements, and protect the rights and safety of Metric Hive, customers, users, and others.
Connected Platform Data
Metric Hive accesses third-party platform data only after a customer authorizes or configures the connection. The exact data accessed depends on the platform, the permissions granted, and the sources, report types, date ranges, fields, and destinations selected by the customer.
For advertising platforms such as Meta Ads, Google Ads, and Search Ads 360, Metric Hive is designed to process reporting and performance data for configured ad accounts and reports. For Google Sheets, Metric Hive may read spreadsheet metadata and selected sheet values, and may write exported data to spreadsheets the customer configures. For CRM, affiliate, commerce, warehouse, or future integrations, Metric Hive processes the categories of data needed to run the integration selected by the customer.
Google API Services User Data
If you connect a Google account, Metric Hive may request basic identity permissions, such as openid and email, to associate the authorization with the correct connected account. Metric Hive also requests only the product-specific Google permissions needed for the integration or destination you choose.
Google Ads. When you connect Google Ads, Metric Hive lists the advertiser accounts you are authorized to access and reads reporting data only for the accounts, report types, and date ranges you select. This may include account identifiers and names, campaign and ad identifiers and names, clicks, impressions, cost, conversions, conversion value, currency, geographic, device, keyword, search-term, landing-page, product, and creative-asset reporting fields. Metric Hive uses this data for customer-visible ingestion, scheduled refreshes, governed datasets, data health, dashboards, exploration, and customer-configured exports. Metric Hive does not use the Google Ads connection to create or change campaigns, ads, bids, or budgets.
Google BigQuery. When you connect a BigQuery export destination with Google OAuth, Metric Hive lists Google Cloud projects available to the connected account so you can choose a destination. In the project, dataset, and tables you configure, Metric Hive may inspect destination metadata; create datasets, tables, views, and temporary staging tables; load or replace customer-selected export rows; update table schemas; run the queries needed to apply an export safely; and remove temporary staging tables. Metric Hive does not use this authorization to browse or export unrelated BigQuery data.
Metric Hive stores Google OAuth access and refresh tokens in managed server-side secret storage and uses refresh tokens for customer-configured scheduled imports and exports. Google credentials remain connected until they expire, are revoked, are removed in Metric Hive, or are deleted at the customer's request, subject to the retention and backup limits described below. Customers can disconnect credentials in Metric Hive and can revoke access in their Google Account settings.
Metric Hive does not sell Google user data, use it for advertising, or use it to train generalized AI or machine learning models. Metric Hive shares Google user data only with service providers needed to operate and secure the customer-requested feature, with a destination the customer directs Metric Hive to use, or when legally required. Metric Hive's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Shopify API Data
When a merchant installs Metric Hive from Shopify, Metric Hive uses Shopify's authenticated app installation and read-only permissions to connect the merchant's store to the Metric Hive workspace the merchant chooses. Depending on the datasets the merchant enables, Metric Hive may process store metadata; order and line-item identifiers, timestamps, quantities, financial totals, currencies, discounts, taxes, refunds, returns, fulfillments, checkout events, payment transaction data, product and variant catalog data, inventory data, and Shopify customer identifiers needed to connect commerce records across their lifecycle.
Metric Hive does not request or store Shopify customer names, email addresses, phone numbers, or physical addresses. Shopify data is used only to provide the merchant-configured ingestion, governed datasets, data health, analytics, and exports. Shopify access and refresh tokens are kept in managed server-side secret storage and are not exposed through public API responses.
Merchants can disconnect Shopify in Metric Hive or uninstall the app in Shopify. Metric Hive receives Shopify's mandatory customer data request, customer redact, and shop redact webhooks and processes access and deletion requests through its documented privacy workflow, subject to the retention and backup limits described below.
How We Share Information
We do not sell customer data. We share information only as needed to operate Metric Hive, provide integrations requested by customers, comply with law, or protect rights and safety.
- Infrastructure and operations providers, including cloud hosting, databases, storage, queues, logging, secret storage, monitoring, and security services.
- Authentication providers used to sign users in and verify sessions.
- Security and abuse-prevention providers used to assess automated account, sign-in, invitation, and password-recovery traffic.
- Email or messaging providers used for service notices, invitations, and support communications.
- Third-party platforms and destinations that customers choose to connect, but only to perform the requested import, refresh, validation, query, or export.
- Professional advisers, authorities, or other parties where required by law or necessary to enforce agreements or protect Metric Hive, customers, users, or others.
Security
We use administrative, technical, and organizational safeguards designed to protect customer data. These include account-based access controls, subscription and account membership checks, server-side session verification, API key hashing, server-side secret storage, limited credential exposure in API responses, and operational controls for background jobs and deletion workflows.
No internet service can guarantee perfect security. Customers should use strong authentication, limit access to authorized team members, remove users who no longer need access, and revoke third-party credentials that should no longer be used.
Retention and Deletion
We retain account, workspace, integration, customer data, logs, and operational records for as long as needed to provide the service, maintain security and auditability, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary by data type, customer configuration, backup cycle, and legal or operational need.
Customers may request deletion of account data, connected credentials, integration metadata, or customer data by contacting us. Where deletion is supported by the product, we delete or disconnect the requested data from active systems, subject to legal, security, backup, and operational retention limits. Third-party platform access can also be revoked directly in the relevant platform's app or account settings.
International Processing
Metric Hive and its service providers may process information in countries other than where you are located. When we transfer personal data internationally, we use safeguards appropriate to the data and transfer, as required by applicable law.
Your Choices and Rights
Depending on your location and relationship with Metric Hive, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal data. Customers can also manage team access, remove users, delete credentials, disconnect sources, revoke API keys, and request data deletion.
If your data was processed by Metric Hive on behalf of a Metric Hive customer, please contact that customer first. We may need to route requests through the customer because they control the connected sources and customer data they process with Metric Hive.
Children
Metric Hive is a business service and is not directed to children. We do not knowingly collect personal data from children.
Changes to This Policy
We may update this Privacy Policy as Metric Hive, our integrations, or legal requirements change. The updated version will be posted on this page with a new last updated date.
Contact
For privacy questions, data requests, or deletion requests, contact integrations@metrichive.ai.