ViewMetrics logo ViewMetrics

Privacy Policy

Last updated: 24/06/2026

Privacy Policy

Last updated: 24 June 2026

This Privacy Policy explains how ViewMetrics collects, uses, shares, stores and deletes personal data when you visit our website, create an account, join or manage a workspace, connect a third-party platform account, subscribe to a plan or otherwise use the ViewMetrics service.

1. Who we are

ViewMetrics is operated by Viewmetrics Ltd, a company registered in England and Wales under company number 17273580.

Contact email: hello@viewmetrics.co

For the personal data described in this policy, Viewmetrics Ltd is generally the data controller.

2. Scope of this policy

This policy applies to:

  • the ViewMetrics website;

  • the ViewMetrics web application;

  • ViewMetrics accounts and workspaces;

  • connected YouTube channels;

  • connected Facebook Pages;

  • connected Instagram professional accounts;

  • subscriptions, trials and billing;

  • reports and exports created using ViewMetrics;

  • support and operational communications.

Third-party platforms such as Google, YouTube and Meta also process data under their own privacy policies and terms. ViewMetrics does not control how those platforms independently collect or use information.

3. Information we collect

3.1 Account and profile information

We may collect:

  • your email address;

  • your name or display name, where provided;

  • your authentication identifiers;

  • your account preferences;

  • your timezone and localisation settings;

  • your active workspace;

  • records relating to account creation, access and deletion;

  • communications you send to us.

ViewMetrics primarily uses email-based authentication. You are not required to use your Facebook or Google account to sign in to ViewMetrics.

3.2 Workspace and membership information

We may collect:

  • workspace names and identifiers;

  • workspace membership and role;

  • invitations;

  • ownership transfers;

  • member-removal and departure records;

  • tags, partners, brands, campaigns and other organisational information;

  • assets you upload, such as logos;

  • records of actions carried out by workspace owners, administrators and managers.

Workspace roles may include owner, administrator, manager and viewer.

3.3 Information from connected platforms

When an authorised user connects a supported platform, we may collect information made available through that platform’s APIs.

This may include:

  • YouTube channel IDs and names;

  • Facebook Page IDs and names;

  • Instagram professional-account IDs and names;

  • account or channel type;

  • video, post, Reel and media identifiers;

  • titles, descriptions, captions and publication dates;

  • thumbnails, links and content types;

  • views, watch time, reach, reactions, likes, comments, shares and other performance information;

  • audience, country and geography information where available;

  • channel or account statistics;

  • raw API responses needed to process or verify imported data;

  • connection, synchronisation and import status;

  • records showing whether an authorisation remains valid.

The particular information available depends on the platform, permissions granted, account type and content type.

3.4 OAuth credentials and authorisation information

When you connect a platform, ViewMetrics may receive:

  • access tokens;

  • refresh tokens;

  • token expiry information;

  • platform user or authorisation identifiers;

  • the identity of the ViewMetrics user who supplied the credential;

  • connection and reauthorisation status.

Credentials are encrypted at rest and are not made visible to other workspace members.

More than one member of a workspace may independently authorise the same channel, Page or Instagram account. ViewMetrics may retain those authorisations as separate credential sources so that one person’s token failure or departure does not unnecessarily interrupt the workspace.

3.5 Billing and subscription information

When you subscribe, begin a trial or make a payment, we may collect:

  • your selected plan;

  • subscription status;

  • trial eligibility and trial history;

  • billing dates;

  • payment status;

  • Stripe customer, subscription and invoice references;

  • billing address and tax information where required;

  • records of cancellations, refunds and failed payments.

Payment-card details are processed by Stripe. ViewMetrics does not normally receive or store the complete card number.

3.6 Public platform identity and commercial history

We may retain a minimal historical record of a platform account that has previously connected to ViewMetrics, including:

  • platform;

  • YouTube channel, Facebook Page or Instagram professional-account ID;

  • current or last-known public name;

  • first and last connection dates;

  • trial and subscription history;

  • relevant links to billing history;

  • minimal deletion and audit status.

We use this information to identify returning channels, determine trial and promotional eligibility, understand subscription history and churn, reconcile billing, provide customer support, prevent fraud or abuse, and maintain an accurate record of our commercial relationship.

This retained record does not contain OAuth credentials, content-level analytics or individual video, post or media data after those have been deleted.

3.7 Technical, usage and security information

We and our service providers may process:

  • IP address;

  • browser and device information;

  • operating system;

  • pages and features used;

  • timestamps;

  • authentication and security events;

  • API and import logs;

  • error and diagnostic information;

  • email-delivery events;

  • audit and administrative activity;

  • cookie or similar-technology identifiers.

We use this information to operate, protect, diagnose and improve the service.

4. How we obtain information

We obtain information:

  • directly from you;

  • from other members of your workspace;

  • from connected third-party platforms;

  • from payment and billing providers;

  • automatically when you use the service;

  • from service providers that help us operate ViewMetrics;

  • from publicly available platform endpoints where permitted.

5. How and why we use information

We use information for the following purposes.

Providing the service

We use account, workspace, platform and billing information to:

  • create and manage accounts;

  • provide workspaces and roles;

  • connect authorised platform accounts;

  • import and display content and analytics;

  • generate charts and reports;

  • organise content using tags, partners, brands and campaigns;

  • process subscriptions and payments;

  • provide customer support.

Our lawful basis is normally performance of our contract with you.

Operating connected-platform authorisations

We use credentials and platform information to:

  • access information you have authorised;

  • refresh credentials;

  • determine whether an authorisation remains valid;

  • select another independently supplied credential where one fails;

  • detect when data collection has stopped;

  • reconnect accounts;

  • comply with platform API rules.

Our lawful basis is normally performance of our contract and, where applicable, our legitimate interests in operating a reliable and secure service.

OAuth authorisation is the technical permission granted through the relevant platform. It is not necessarily the same as “consent” as a lawful basis under UK data-protection law.

Service and security communications

We may send essential non-marketing communications about:

  • login and authentication;

  • workspace invitations and ownership;

  • token failure or loss;

  • interrupted data collection;

  • reliance on another independent authorisation;

  • reconnection;

  • impending platform-data deletion;

  • account, workspace or subscription changes;

  • security incidents.

Our lawful basis is performance of our contract and our legitimate interests in operating and securing the service.

Billing, trial eligibility and fraud prevention

We use public platform identity and commercial history to:

  • determine whether a channel has previously received a trial or promotion;

  • prevent repeated promotional use through different user accounts;

  • associate subscriptions and billing with the correct platform account;

  • reconcile Stripe transactions;

  • investigate fraud or abuse;

  • understand subscription, churn and reactivation patterns.

Our lawful basis is our legitimate interests in operating our business fairly, preventing abuse and maintaining accurate commercial records.

Where this information relates to an identifiable individual, you may object to this processing. We will consider your circumstances and whether our compelling legitimate grounds require continued processing.

Improving the service

We may use usage, performance and diagnostic information to:

  • monitor reliability;

  • fix errors;

  • improve features and usability;

  • understand how ViewMetrics is used;

  • plan capacity and product development.

Our lawful basis is our legitimate interests in improving and operating the service.

Legal, regulatory and accounting purposes

We may use and retain information to:

  • keep accounting and tax records;

  • enforce or defend legal rights;

  • respond to lawful requests;

  • comply with regulatory and platform obligations;

  • investigate security incidents.

Our lawful basis is legal obligation or legitimate interests, depending on the circumstances.

Cookies and marketing

Where required, we rely on consent for:

  • non-essential analytics cookies;

  • marketing cookies;

  • optional email marketing.

You can withdraw that consent at any time.

6. Shared channels and independent authorisations

ViewMetrics stores channel content and analytics as a single canonical dataset rather than making a separate copy for every workspace.

This means that the same YouTube channel, Facebook Page or Instagram account may be independently connected by:

  • several members of one workspace;

  • members of different workspaces.

If one user disconnects, leaves a workspace, is removed, loses platform access or deletes their ViewMetrics account:

  • ViewMetrics removes credentials supplied by that user where required;

  • that user’s workspace access is removed as applicable;

  • ViewMetrics does not disclose the identity of another authorising user or workspace;

  • collection may continue if another valid independent authorisation remains;

  • canonical content and analytics may remain available to other independently authorised workspaces.

A deletion request from one authorising user does not automatically require deletion of data that remains independently and validly authorised by another current user.

A retained public platform-account identity does not itself grant access, count as an authorisation or permit analytics collection.

7. YouTube and Google API data

ViewMetrics uses YouTube API Services and Google OAuth.

Your use of YouTube features within ViewMetrics is also subject to:

ViewMetrics’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We do not:

  • use Google API data for personalised advertising;

  • sell Google API data;

  • transfer Google API data to data brokers or unauthorised parties;

  • allow human access to Google user data except where necessary for support, security, legal compliance or another permitted purpose.

You can review or revoke ViewMetrics’ access to your Google account through Google’s permissions page:

https://security.google.com/settings/security/permissions

You may also disconnect YouTube or request deletion through ViewMetrics.

Deleting data from ViewMetrics does not delete your channel or content from YouTube. To delete information held by YouTube, you must use YouTube or another appropriately authorised YouTube application.

8. Meta, Facebook and Instagram data

ViewMetrics uses Meta APIs to connect Facebook Pages and Instagram professional accounts.

Facebook Pages and Instagram professional accounts are treated as separate connections, even where they were authorised through the same Meta login.

When a Meta user disconnects, removes ViewMetrics, requests deletion or deletes their ViewMetrics account:

  • ViewMetrics removes their affected local credential sources;

  • ViewMetrics deletes Meta app-user information associated exclusively with them where required;

  • each Facebook Page and Instagram account is reassessed independently;

  • canonical data may continue where another user or workspace has independently authorised the same entity;

  • ViewMetrics does not disclose the other user or workspace;

  • where no valid independent authorisation remains, provider-derived content and analytics enter the deletion lifecycle described below.

Disconnecting one Facebook Page does not automatically disconnect an Instagram account, and disconnecting an Instagram account does not automatically disconnect its parent Facebook Page.

ViewMetrics provides an accessible way to request deletion through the application and at hello@viewmetrics.co. We also process properly validated deletion requests received through Meta’s applicable deletion mechanisms.

Deleting information from ViewMetrics does not delete content held by Facebook or Instagram.

9. Who we share information with

We may share information with:

Workspace members

Information may be visible to authorised members of your workspace according to their role and the workspace’s active connections.

People with whom you share reports

Where you choose to generate or share a report, its recipients may see the information included in that report.

Service providers

We use service providers to help operate ViewMetrics, including providers of:

  • database and application infrastructure;

  • hosting;

  • authentication;

  • payment processing;

  • email delivery;

  • error monitoring;

  • analytics;

  • security and support services.

These may include Supabase, Netlify, Stripe and Resend.

Providers acting as our processors may process personal data only for the services we ask them to perform and under appropriate contractual protections.

Google, YouTube, Meta and similar platform providers process information under their own terms and privacy policies.

Professional advisers and authorities

We may disclose information:

  • to lawyers, accountants, auditors or insurers;

  • to comply with law, regulation, court order or lawful authority;

  • to protect our users, rights, property or service;

  • in connection with a merger, acquisition, financing or sale of all or part of our business, subject to appropriate safeguards.

We do not sell personal data.

10. International transfers

Some service providers may process information outside the United Kingdom.

Where personal data is transferred internationally, we use an appropriate safeguard where required, such as:

  • a UK adequacy regulation;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to the EU Standard Contractual Clauses;

  • another legally recognised transfer mechanism.

You may contact us for further information about safeguards relevant to your data.

11. Security

We use technical and organisational measures designed to protect information, including:

  • encryption of OAuth credentials at rest;

  • encryption in transit;

  • role-based access;

  • row-level database security;

  • server-side permission checks;

  • restricted service-role access;

  • audit logging;

  • credential and token isolation;

  • monitoring and testing.

No online service can guarantee absolute security. You should contact us promptly if you believe your account or workspace has been compromised.

12. Data retention and deletion

We keep information only for as long as reasonably necessary for the purposes described in this policy, to comply with platform requirements and law, and to establish or defend legal rights.

Account and profile information

We retain account information while your account is active.

When you delete your account, we delete or anonymise your profile, authentication data, credentials and memberships without undue delay, subject to:

  • technical backup rotation;

  • security and fraud-prevention records;

  • legal claims;

  • accounting and regulatory requirements;

  • independently authorised shared-channel data;

  • the minimal platform identity and commercial history described below.

OAuth credentials

OAuth credentials are retained only while needed for an active authorised connection.

Credentials you supplied are removed when required following:

  • exact connection disconnection;

  • departure from a workspace;

  • removal from a workspace;

  • deletion of your account;

  • token invalidation;

  • an applicable platform deletion request.

YouTube credentials may also be revoked with Google on a best-effort basis after local deletion.

For Meta, ViewMetrics avoids broad app-user-wide permission revocation where doing so could inadvertently invalidate other separately managed Facebook Page or Instagram connections. Local credential deletion remains mandatory.

Platform content and analytics

Where another independently valid authorisation remains, canonical content and analytics may continue to be collected and stored for that authorised relationship.

Where no valid independent authorisation remains:

  • following an explicit in-app disconnect, workspace deletion, account deletion or direct data-deletion request, affected provider-derived content and analytics are deleted as soon as reasonably practicable and no later than seven calendar days where that deadline applies;

  • following externally detected revocation or an authorisation that cannot be refreshed, affected YouTube API data is deleted as soon as reasonably practicable and no later than 30 calendar days;

  • ViewMetrics aims operationally to complete the external-loss deletion before the end of that 30-day period;

  • ViewMetrics applies a similar short deletion lifecycle to Meta-derived content and analytics where no independent valid authorisation remains, subject to any shorter binding requirement.

During an external-authorisation-loss period, we may send an initial notice, an urgent reminder approximately 21 days after loss and a final reminder approximately 28 days after loss.

Reconnecting before deletion may cancel a pending deletion where permitted. Reconnecting after data has been deleted requires a new import and does not guarantee restoration of earlier analytics.

We may delete information sooner where required by law, a platform policy or a valid deletion request.

Public platform identity and commercial history

After content and analytics have been deleted, we may retain:

  • the public YouTube channel, Facebook Page or Instagram professional-account ID;

  • current or last-known public name;

  • first and last connection dates;

  • trial and subscription history;

  • links to billing records;

  • minimal deletion and audit facts.

We retain this information for as long as reasonably necessary to:

  • enforce channel-level trial and promotional limits;

  • identify returning platform accounts;

  • maintain subscription and churn history;

  • reconcile billing;

  • provide support;

  • prevent fraud and abuse;

  • maintain accurate commercial records;

  • establish or defend legal rights.

We periodically review whether this information remains necessary.

For retained YouTube public identity obtained through the YouTube API, ViewMetrics may refresh the current public identity within the period required by YouTube. If a channel can no longer be found, we may retain its last-known name as historical commercial information while marking the current identity as unavailable or unverified.

Workspace information

Workspace tags, brands, partners, campaigns, invitations and memberships are retained while the workspace exists.

When a workspace is deleted:

  • its memberships and invitations are removed;

  • its connections and credentials are removed;

  • its workspace-created tags, brands, partners and related organisation data are deleted;

  • the workspace loses access to analytics;

  • canonical data independently authorised by another workspace may remain;

  • minimal public platform identity and ViewMetrics commercial history may remain.

If a channel is disconnected but the workspace survives, tag definitions may remain. Assignments to content that has been permanently deleted are removed.

Billing and accounting records

We retain invoices, payment records and related commercial information for the period required by tax, accounting and legal obligations. This is typically up to six years or longer where legally required or relevant to an ongoing dispute.

Security, audit and support records

We retain security, delivery, support, import and audit records for the period reasonably necessary to:

  • investigate incidents;

  • maintain service integrity;

  • prevent duplicate or abusive actions;

  • resolve support issues;

  • comply with legal and platform obligations.

Retention depends on the nature and sensitivity of the record and is reviewed under our internal retention schedule.

Backups

Deleted information may remain temporarily in protected backups until those backups are overwritten through the normal backup cycle. Backup information is not used for normal product operations and will not be restored except for legitimate disaster recovery.

Anonymous information

Information that has been irreversibly anonymised so that it no longer identifies an individual may be retained for research, statistics and product improvement.

13. Your account and deletion choices

You may:

  • disconnect a platform connection;

  • leave a workspace, subject to ownership requirements;

  • ask an owner or administrator to remove you;

  • delete a workspace where you have authority;

  • delete your ViewMetrics account;

  • request deletion by contacting hello@viewmetrics.co.

Leaving a workspace removes your membership and the credentials you supplied to that workspace. It does not remove credentials independently supplied by other members.

Deleting a workspace removes its organisation data and access. It does not necessarily delete canonical data that another workspace independently remains authorised to use.

Deleting your ViewMetrics account removes your profile, credentials and memberships. It does not:

  • delete content held by YouTube, Facebook or Instagram;

  • erase data still independently authorised for another current user or workspace;

  • require deletion of minimal public platform identity, billing records or justified commercial history.

If you own a workspace with other members, you may need to transfer ownership or delete the workspace before deleting your account.

14. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • be informed about processing;

  • access your personal data;

  • correct inaccurate or incomplete information;

  • request deletion;

  • restrict processing;

  • object to processing based on legitimate interests;

  • receive certain information in a portable format;

  • withdraw consent where processing is based on consent;

  • complain to a supervisory authority.

These rights are not absolute. For example, we may need to retain information to comply with law, protect another user’s independently authorised service, maintain accounting records, prevent fraud or establish legal claims.

To exercise your rights, email hello@viewmetrics.co.

We may need to verify your identity before acting on a request. We normally respond within one month, subject to any lawful extension.

You may also complain to the Information Commissioner’s Office:

https://ico.org.uk/make-a-complaint/

15. Automated eligibility decisions

We may automatically compare a connected platform account against historical platform-account records to determine trial or promotional eligibility.

This process is based on the stable public platform-account ID rather than email address.

It does not involve a decision that produces legal or similarly significant effects. You may contact us if you believe an eligibility decision is incorrect and ask for it to be reviewed.

16. Cookies and similar technologies

We use essential cookies and local-storage technologies to:

  • authenticate users;

  • maintain sessions;

  • remember security and workspace settings;

  • operate the service.

We may use optional analytics or performance cookies where permitted.

Where consent is required, optional cookies will not be used unless you accept them. You can change your choices through the available cookie settings.

Further details may be provided in a separate Cookie Policy or cookie-preference tool.

17. Children

ViewMetrics is intended for people aged 18 or over.

We do not knowingly offer accounts to children under 18. Contact us if you believe a child has provided personal data to ViewMetrics.

18. Changes to this policy

We may update this policy to reflect changes to:

  • the service;

  • connected platforms;

  • legal or regulatory requirements;

  • data-processing practices.

Where a change is material, we will provide reasonable notice through the application, by email or by another appropriate method.

The date at the beginning of this policy shows when it was last updated.

19. Contact

Questions, requests and complaints may be sent to:

ViewMetrics Ltd
Email: hello@viewmetrics.co
Website: https://www.viewmetrics.co