Legal / 01
Privacy, in plain language.
Hubly uses first-party data to operate each business page and explain which channels lead to customer actions. Businesses can also choose to connect Google Analytics or enable clearly disclosed third-party measurement tags. We do not sell personal information or build advertising profiles for Hubly.
01 / Information we collect
When you use Hubly, we collect:
- Account information: name, email address, username, and authentication credentials.
- Account agreement receipt: the account's authentication identifier, the exact Terms and Privacy Policy versions accepted, whether acceptance happened during Independent signup, activation, or Workspace-invitation signup, and the server-recorded time. This receipt does not contain the account email, IP address, or browser details.
- Founding-access application data: contact and organization details, expected Hub or client Workspace count, operating category, provider stack, and the business question you ask Hubly to assess.
- Business-page data: display name, bio, avatar, links, operating details, and content you add.
- Traffic and action data: pseudonymous browser and session IDs, page views, referral origin, allow-listed campaign identifiers, coarse location, device category, and actions used to provide attribution.
- Audience signup data: the email address a visitor deliberately submits, the mailing list selected, the consent wording and form version shown, signup time, Hub, and limited source or campaign context needed to prove and manage that request.
- Business setup data: business name, category, primary goal, and agency relationship when applicable.
- Confirmed business outcomes: a narrow, normalized record that a connected provider says a booking, lead, call, visit, or purchase reached a supported status. Hubly does not retain raw provider webhook bodies in the delivery journal.
- Connected Google Analytics data: when an authorized owner chooses to connect Google Analytics 4, Hubly receives the Google account identifier and email used for that grant, the identifiers and names of GA4 accounts and properties the account can view, and aggregate daily property and acquisition metrics. Those metrics can include date, source, medium, campaign, sessions, users, engagement, events, key events, revenue, and currency. Hubly does not use this connection to import individual visitor profiles or raw event payloads.
- Hubly AI records: when an authorized owner deliberately runs Hubly AI analysis, Hubly records the resulting interpretation, its model provenance, the evidence summary and candidate action it used, and the owner's later approval or rejection. The AI request uses bounded aggregate Hubly traffic and action evidence; it does not include connected Google Analytics data.
02 / How we use it
- Operate and improve your Hubly workspace and public business page.
- Connect traffic sources to visits, calls, bookings, directions, and other outcomes.
- Use read-only, aggregate Google Analytics data in Hubly reports so an owner can compare channel attention, engagement, key events, and reported revenue. The connection cannot edit Google Analytics settings, tags, audiences, or data.
- At an authorized owner's request, use a configured AI model to interpret bounded aggregate Hubly evidence and propose a guarded action. Hubly does not let model output bypass the owner's selected operating mode, policy checks, or approval boundary.
- Record a visitor's explicit request to hear from a business, maintain that business's subscriber list, document consent, prevent duplicate signups, and support suppression or deletion requests.
- Maintain account security and communicate service updates.
- Review founding-access applications, assess provider fit, and arrange an onboarding conversation.
- Respond to support requests and investigate product issues.
03 / Sharing
We do not sell, rent, or trade your personal information. We share data only with service providers needed to operate Hubly, when required by law, to protect the service, or when you give us permission.
Subscriber information is available to authorized administrators of the business Hub that collected it, including an agency only when that business has granted the required access. A business may later connect captured requests to an email provider. Standard exports include only ownership-confirmed active addresses and exclude captured-not-verified, suppressed, unsubscribed, and anonymized records.
Google Analytics account and property metadata and imported aggregate metrics are available only to authorized members of the relevant Workspace, including an agency with access granted by that business, and to infrastructure providers that process the data to operate Hubly. Hubly does not send Google Analytics data to advertising platforms or AI model providers. If a future owner-initiated AI feature would send Google Analytics data to a model provider, Hubly will first provide a specific disclosure and require the owner to initiate that use.
When an authorized owner selects Run Hubly AI analysis, Hubly sends the bounded native Hubly evidence described above to OpenRouter, which routes it to Hubly's configured model provider. Hubly requests zero-data-retention routing and does not use customer prompts or outputs to train a Hubly model. The resulting interpretation and provenance are stored in the relevant Workspace so the recommendation, decision, and later result remain auditable.
Hubly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
04 / Storage and security
Hubly uses managed infrastructure and encryption in transit and at rest. Audience email addresses are encrypted before storage, with a one-way digest used for duplicate and abuse controls. Raw IP addresses are not retained in analytics or audience records; Hubly may store a keyed fingerprint for limited abuse controls and may store coarse country and city information for analytics. Analytics does not collect a visitor's name, email address, phone number, or form content.
Workspace data is protected by tenant-aware access rules. Provider signing secrets and Google OAuth access and refresh tokens are encrypted and are not selectable by browser clients. Google account and property metadata and imported aggregate metrics are stored inside the Workspace that authorized the connection. No online system is risk-free, so we design collection and access around the least data needed for each feature.
05 / Cookies and third-party measurement
Hubly uses essential cookies for authentication, security, and session continuity. Public business pages may use first-party pseudonymous visitor and session cookies for attribution, depending on that business's analytics policy and your choice.
Agreeing to receive a business's emails is separate from allowing Hub analytics. A visitor can submit an audience form without accepting optional analytics, and accepting analytics never signs a visitor up for marketing.
A business may configure Google Analytics 4 for website measurement, or Meta Pixel and TikTok Pixel for advertising measurement. Hubly names each configured tag before a visitor chooses. Those third-party scripts load only after that visitor allows optional measurement and can receive page-view and Hub-action events, along with page, browser, or device information those providers collect under their own policies. Hubly does not send form content through these tags. Under Hubly's current single optional-measurement choice, Google advertising storage, advertising user data, and ad personalization remain denied.
You can reopen Privacy choices on any public business page to allow optional measurement, decline and delete Hubly data associated with this browser, or download that Hubly data. Declining stops future third-party tags on that browser but does not recall data a provider received after an earlier choice; the relevant business or provider controls those requests. Declining does not stop you from using the business page.
06 / Your choices
- Download or delete pseudonymous traffic and action data associated with your current browser.
- Withdraw mailing consent through the sender contact shown on the signup form or an unsubscribe method supplied with future messages. The business can then suppress the address from future use.
- Access and correct the personal data associated with your Hubly account.
- Download a workspace export that excludes raw visitor identifiers, IP hashes, user-agent strings, and provider secrets.
- As an authorized owner, export the Google Analytics account/property metadata and aggregate metrics retained for your Workspace.
- Disconnect Google Analytics at any time. Hubly revokes the grant when the provider is available and erases its stored access and refresh tokens. You can choose to delete the imported Google metadata and metrics immediately or retain them only until they age out under the 365-day limit.
- Request deletion of your account or other data, subject to records Hubly or the relevant business must retain.
- Ask us to delete or correct a founding-access application.
- Disconnect an agency relationship.
07 / Retention
Businesses can choose a 30-day, 90-day, 180-day, one-year, or two-year retention period for raw Hubly visit and action analytics. Hubly applies that boundary on a schedule and allows an authorized owner to run it immediately. Separately, imported Google Analytics daily metrics are limited to a rolling 365 days, including while a connection remains active. Disconnecting always erases the stored Google access and refresh tokens; the owner can delete the associated imported metadata and metrics immediately or let them age out under that 365-day limit. A minimal security and revocation record may remain. Subscriber records remain available to the collecting business until they are anonymized, deleted, or no longer needed. Suppression removes the readable address from the owner view and standard exports while retaining a tenant-scoped one-way digest and narrow consent/suppression ledger when reasonably required to prevent future contact and document the request. Short-lived abuse-control fingerprints are purged by scheduled maintenance. Founding-access applications are kept while we assess fit, manage the prospective relationship, or meet reasonable business and legal recordkeeping needs; you may ask us to delete yours. Confirmed business outcomes, security records, and records required for legal or operational reasons may follow separate retention periods. The minimal account-agreement receipt described above is treated as one of those legal or operational records and does not duplicate the account email, IP address, or browser details.
08 / Changes
We may update this policy as Hubly changes. If a change materially affects how we handle your data, we will provide notice through the product or by email.
09 / Contact
Questions or assisted access and deletion requests can be sent to hubly@zenivadigital.com. Privacy rights and exceptions vary by location, and Hubly may need to verify the request before acting.