Security
Security and data handling at MarketLin
This page is the short version of our Privacy Policy, Data Processing Agreement and sub-processor list, written for the person at an agency who has to answer a client's security questionnaire. Everything here is also in those documents; nothing here goes beyond them.
How MarketLin gets access
You sign in to each platform yourself through its official OAuth flow. We never see or store an ad-account password. The scopes we request are listed per platform in the Privacy Policy. Two things are worth knowing before you connect:
- Google Ads has no read-only scope. Google offers one standard scope, so that is what we request. What limits its use is the approval rule below, not the scope itself.
- Meta and LinkedIn write scopes are requested only if you turn on applying approved changes. Until then we hold read scopes only.
You can disconnect any account in MarketLin at any time, or revoke our access from the platform's own settings.
What MarketLin can change
Nothing on its own. MarketLin reads your accounts every day and drafts changes: a budget move, a paused ad set, a new ad. A workspace is read-only by default, which means approving a recommendation hands you the change list to apply yourself. An owner can switch a workspace to apply approved changes; then a change is applied only after a person with approval rights confirms it, and every applied change is logged with who and when.
Where data lives
| What | Where |
|---|---|
| Application, database, encryption keys | Google Cloud, Stockholm (europe-north1), EU |
| Uploaded and mirrored assets | AWS S3, France, EU |
| AI generation of analysis, recommendations and ads | Anthropic, OpenAI and Google (Vertex AI), USA, under the EU-U.S. Data Privacy Framework and standard contractual clauses |
The AI providers receive aggregated campaign metrics and your brand context. They do not receive end-customer personal data, and none of them train models on your data.
Encryption, isolation and access
Data is encrypted in transit (TLS) and at rest. Tenant isolation is enforced by a central authorisation layer with deny-by-default; OAuth tokens are stored encrypted and owned at the organisation level. Internal access follows least privilege on a need-to-know basis. Monitoring supports notifying affected controllers within 72 hours of a confirmed breach.
Roles inside a workspace
- Owner: billing, connecting and disconnecting accounts, approving changes, inviting people.
- Admin: connecting accounts, editing brand context, approving changes, scheduling and sending reports.
- Member: sees the clients assigned to them, drafts ads, prepares reports, and can approve changes only if an owner grants it.
Clients do not log in; they receive the reports you schedule, with your agency's logo on the PDF.
Retention and deletion
Daily backups. When you disconnect an account or end a subscription, you can export your reports and generated ads for 30 days. After that, workspace data is deleted as described in the Privacy Policy and DPA, except where law requires us to keep records. You can ask for deletion earlier at any time.
What we do not have yet
- No SOC 2 or ISO 27001 certification.
- No public status page.
- No contractual uptime commitment on Business, Agency or Pro; an availability commitment can be agreed in an Enterprise agreement.
If your client's questionnaire asks for something not covered here, email hello@marketlin.com and we will answer in writing.
Questions
- Do you have SOC 2 or ISO 27001?
- Not yet, and we say so rather than imply it. The controls below are what is in place today. When a certification is scheduled we will put the date on this page.
- Can MarketLin change anything in my accounts on its own?
- No. Workspaces are read-only by default. A change is applied only after a person with approval rights in your workspace confirms it, and every applied change is logged with who approved it and when.
- Where is my data stored?
- On Google Cloud in Stockholm (europe-north1), with uploaded assets on AWS S3 in France. AI models that write recommendations and ads run with US providers under EU transfer safeguards and receive aggregated campaign metrics and your brand context, not end-customer personal data.