Legal
How MarketPilot handles data.
This policy explains how MarketPilot OS collects, uses and protects personal data.
1. Who we are
MarketPilot OS is operated by GK STUDIO LTD, a company registered in England and Wales with company number 16048293. Our registered office is London, UK. For privacy requests, contact support@marketpilotos.com. Business or ownership matters can be escalated to founder@marketpilotos.com.
2. Information we collect
We may collect account details, authentication information, business profile information, campaign settings, uploaded media, generated marketing content, leads, messages, booking information, integration settings, usage data, billing records and support communications.
3. How we use information
We use information to provide the MarketPilot service, create and manage accounts, generate campaign recommendations, process uploads, manage leads and inbox activity, support connected integrations, process payments, maintain security, provide support, improve the product and comply with legal obligations.
4. AI processing
MarketPilot uses AI systems to help prepare recommendations, marketing content, image prompts, campaign plans, lead follow-up suggestions and performance summaries. Information you provide may be processed by AI providers only for the purposes of delivering the service. You remain responsible for reviewing and approving outputs before use.
5. Third-party services
We use trusted providers for authentication, hosting, database, payment, email delivery, AI processing, storage, consent-based error monitoring and advertising-platform integrations. These may include Clerk, Vercel, Neon, Stripe, Resend, OpenAI, Cloudflare R2, Sentry, Google and Meta where enabled by you.
6. Connected advertising accounts
If you connect Google, Meta, Facebook or Instagram accounts, we process the account, page, campaign, pixel, lead form and performance information needed to provide the features you enable. We do not launch adverts or external spend without the approval controls provided in the product.
7. Google Ads access
When you connect Google Ads, MarketPilot requests Google Ads access so it can list accounts you own or are authorised to manage, store your selected customer account, provide Search keyword planning, prepare and manage user-approved Search campaign structures, and read campaign performance and account health. Google OAuth data access and Google Ads API Basic Access are approved; the controlled 24-operation validation and a real PAUSED provider-creation read-back passed. Eligible paid workspaces can create and manage Search campaigns only after the required account, billing and explicit approval gates pass. Activation is a separate explicit decision that may start advertising spend. MarketPilot does not activate campaigns, increase budgets or start spend autonomously. Where a visitor explicitly permits marketing measurement, a successful hosted booking-enquiry submission may send Google Ads a conversion event with a deduplication identifier and no lead name, email, telephone number or message. We do not use enhanced conversions. We do not collect your Google password. You can disconnect Google Ads in MarketPilot settings or revoke access from your Google Account security settings.
7A. Google Search Console and Analytics access
When you connect Google Search Console or Google Analytics 4, MarketPilot requests read-only Google scopes for the service you choose. Search Console data may include verified properties, queries, pages, countries, devices, clicks, impressions, CTR, average position and sitemap information. GA4 data is restricted to Organic Search reports and may include properties, sessions, users, conversions, events, landing pages, traffic sources and audience country data. Search Console clicks and GA4 sessions use different collection, consent, timezone and attribution boundaries and are not expected to match. MarketPilot uses this data to show reports and prepare recommendations for your workspace. Where you request an AI-assisted report summary or recommendation, relevant Google-derived reporting data may be processed by our contracted AI service provider only to provide that requested MarketPilot feature; it is not used by MarketPilotOS to train or fine-tune a general-purpose or personalised AI model.
7B. Google OAuth, disconnection and revocation
Google connections use OAuth. You can connect Google Ads only, Search Console only, Analytics only, or any combination of those supported Google services. OAuth access and refresh tokens are stored only on MarketPilot servers and are encrypted at rest; they are not stored in your browser. Google user data is used only to provide the connected features you choose for your workspace and is not sold or used for unrelated advertising. It is shared only with service providers acting for MarketPilot where necessary to deliver, operate and secure the features you request. Disconnect from this workspace clears the local Google token and integration settings without changing the Google Account permission. Remove Google access asks Google to revoke the provider grant and then clears the reusable local token. You can also revoke MarketPilot access directly from your Google Account permissions page.
7C. Google API data retention and Limited Use
MarketPilot retains selected Google account or property identifiers, reporting evidence and encrypted tokens while the connection is active so it can provide the features you selected. MarketPilotOS does not use Google user data to train or fine-tune generalized or personalized AI or machine-learning models. Disconnecting or removing Google access deletes the stored token and local Google integration settings, except for limited security, audit or legal records that do not contain reusable provider credentials. You can also request deletion through /data-deletion or support@marketpilotos.com. MarketPilotOS’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Meta, Facebook and Instagram access
When you connect Meta, MarketPilot requests the permissions needed to read authorised ad accounts, Pages, Instagram Business account metadata, pixels and lead forms, create paused campaign structures, retrieve authorised lead form responses and read performance. Instagram Business metadata may include account ID, username, profile picture, connected Page and follower count where Meta returns it. We use this data only for the workspace you connect. We do not request Instagram publishing or messaging permissions. You can disconnect Meta in settings, remove the app from Meta settings, or request deletion using the contact below.
8A. Meta tokens, leads and deletion
Meta OAuth tokens are stored encrypted and are never shown in the browser. Lead data returned from authorised Meta lead forms is stored in your workspace with source attribution, including Instagram attribution where the lead is tied to an Instagram-selected campaign. Disconnecting Meta clears local token and integration settings and attempts provider revocation. Meta data deletion and deauthorisation callbacks remove matching local integration data where the signed Meta request can be verified.
8B. Instagram messaging and publishing data
MarketPilot currently keeps Instagram messaging and organic publishing disabled unless the required Meta permissions and production workflows are approved. If those features are enabled later, relevant message thread metadata, replies, media assets, captions, schedules, publish statuses and provider errors will be processed only for the workspace and account you authorise.
9. TikTok Ads access
When you connect TikTok, MarketPilot uses TikTok OAuth/Login to request the scopes needed for the features you enable. TikTok tokens are exchanged server-side, stored encrypted and never shown in the browser. MarketPilot may store connected account identifiers, granted scopes, missing scopes, selected advertiser details, destination URL, pixel ID, identity ID, budget preference, video/media metadata, publishing readiness, Ads readiness and reporting readiness. Live TikTok organic publishing, Ads campaign creation and reporting remain approval-first and are enabled only where TikTok has approved the required API access.
9A. TikTok media, reporting and recommendations
If TikTok organic publishing is enabled, uploaded or selected video assets, captions, validation metadata, publish status and provider errors may be processed to prepare or submit user-approved posts. If TikTok reporting is enabled, MarketPilot uses only real TikTok-returned metrics such as impressions, clicks, spend, conversions, leads or video views where available. AI-assisted TikTok recommendations may use connected setup details and real synced performance data, but recommendations do not automatically publish content, modify campaigns or spend money.
9B. TikTok disconnect, retention and deletion
Disconnecting TikTok clears local TikTok tokens and integration settings, and provider revocation is attempted where supported. TikTok audit, security, billing or dispute records may be retained where legally required. You can request deletion using /data-deletion or by contacting support@marketpilotos.com.
10. Platform billing and ad spend
MarketPilot subscription fees cover the software and service workflow. Advertising spend is billed by the connected advertising platform or the customer's own advertising account, such as Google Ads, Meta Ads or TikTok Ads. MarketPilot does not take ownership of your ad account balance.
11. Legal bases
Where UK GDPR applies, we process personal data on the basis of contract performance, legitimate interests, consent where required, legal obligation, and in limited cases the establishment or defence of legal claims.
12. Data retention and deletion
We retain account and business data while your account is active. Lead, campaign, integration and operational records may be retained for up to 24 months unless a longer period is required for legal, billing, security or dispute purposes. Stripe webhook storage is minimised at receipt rather than retaining complete provider objects, and that minimised operational evidence is retained for up to 24 months. Canonical invoice or subscription records may be retained longer only where required for legal, tax, fraud-prevention or dispute purposes. If Google, Meta or another platform connection is disconnected, MarketPilot removes stored provider tokens and local integration settings unless lawful retention is required for audit, security or billing records. You may request deletion at support@marketpilotos.com or review /data-deletion.
13. Your rights
You may have rights to access, correct, delete, restrict or object to processing of your personal data, and to request portability. You may also withdraw consent where processing is based on consent. Contact support@marketpilotos.com to exercise these rights.
14. International transfers
Some providers may process data outside the United Kingdom. Where this happens, we take steps designed to protect personal data through appropriate contractual safeguards or recognised transfer mechanisms.
15. Security
We use reasonable technical and organisational measures including secure authentication, encrypted token storage where applicable, access controls, audit logs and operational monitoring. No system is completely secure and users must keep account credentials safe.
16. Changes to this policy
We may update this Privacy Policy as the service evolves. Material changes will be reflected on this page and, where appropriate, communicated through the product or by email.
Questions about this page can be sent to support@marketpilotos.com. Business or ownership matters can be sent to founder@marketpilotos.com.