SLATE
Slate Privacy Policy
Privacy disclosures for slatedata.app, my.slatedata.app, connected marketing platforms, and Slate-operated marketing systems
Effective date: August 30, 2026
Last updated: August 30, 2026
Version: 1.1
Contents
1. Scope and identity of the service
2. Slate roles: controller/business and processor/service provider
3. Definitions
4. Personal information and data Slate processes
5. Sources of information
6. Purposes and legal bases
7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive
8. Other connected advertising, analytics, ecommerce, and lifecycle platforms
9. Production service providers and subprocessors
10. Cookies, local storage, analytics, and tracking choices
11. Disclosures of information
12. Sale, sharing, targeted advertising, and Global Privacy Control
13. Retention, deletion, revocation, and backups
14. Security
15. International data transfers
16. Privacy rights and choices
17. California and other U.S. state disclosures
18. EEA, United Kingdom, and Switzerland disclosures
19. Children and business use
20. Changes to this Policy
21. Contact information
Appendix A. Detailed data inventory
Appendix B. Integration and provider matrix
Appendix C. Official platform notices reviewed
|
Read this first |
1. Scope and identity of the service
Slate Data LLC, a Massachusetts limited liability company ("Slate," "we," "us," or "our"), owns and operates slatedata.app, my.slatedata.app, and the Slate-branded marketing-data aggregation, normalization, governance, reporting, and export services (collectively, the "Service"). This Privacy Policy explains how Slate collects, uses, stores, discloses, and otherwise processes information in connection with the Service.
Slate is designed for business use by marketing teams, agencies, finance-adjacent teams, and other organizations. This Policy applies to visitors, users, organization administrators, invited members, prospective customers, and individuals whose information is contained in data that an authorized Slate customer imports or connects to the Service.
This Policy does not govern the independent privacy practices of Google, Meta, LinkedIn, Microsoft, TikTok, Reddit, Shopify, Amazon, Stripe, Clerk, Vercel, Neon, Heap, Klaviyo, or any other third-party platform. Those providers process information under their own terms and privacy notices when a person uses their services directly.
Where an organization provides a separate privacy notice or contract that applies to its Slate workspace, that organization notice may provide additional details about the organization's processing. If an organization controls data in Slate, questions about that data should ordinarily be directed to the organization first.
2. Slate roles: controller/business and processor/service provider
2.1 Slate as controller or business
Slate determines the purposes and means of processing for information needed to operate its own business and Service, including public-site data, account administration, authentication configuration, billing records, security logs, product analytics, support communications, legal compliance, and Slate's own marketing. For this information, Slate acts as a controller under the GDPR and analogous laws and as a business under the California Consumer Privacy Act, where those laws apply.
2.2 Slate as processor or service provider
For Customer Content and Connected Data submitted, imported, synchronized, normalized, edited, governed, reported, or exported at an organization's direction, the organization generally determines why and how that information is processed. Slate processes that information to provide the contracted Service and acts as a processor, service provider, or contractor, as applicable. The organization is responsible for its instructions, lawful basis, notices, consents, platform permissions, and responses to data-subject requests.
2.3 Platform-specific restrictions
Google API Data and data obtained from other connected platforms remain subject to the applicable platform terms, developer policies, approved scopes, and user instructions. A customer's ability to access information through Slate does not expand the customer's rights in that information or override the connected platform's restrictions.
3. Definitions
|
Term |
Meaning |
|
Account Data |
Information used to create, authenticate, secure, administer, and support an individual Slate account, including identity, contact, session, and organization-membership information. |
|
Customer |
The organization, business, agency, or other entity that creates or controls a Slate workspace, including an authorized administrator acting for that entity. |
|
Customer Content |
Information submitted directly by or for a Customer, including uploaded files, pasted rows, manual entries, labels, notes, corrections, rules, saved views, reports, and export configurations. |
|
Connected Data |
Information retrieved from or sent to a third-party service at a Customer's direction through an authorized integration, including raw, normalized, derived, and metadata fields. |
|
Google API Data |
Information obtained from Google API Services through Google OAuth scopes, together with data aggregated, normalized, or derived from that information. |
|
Personal Information |
Information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to a person or household, and analogous terms under applicable law. |
|
Service Data |
Technical, operational, diagnostic, security, and usage information generated by use of Slate. |
|
Slate Marketing Data |
Information collected by Slate for its own website analytics, product analytics, advertising measurement, lead management, and marketing communications. It excludes Customer Content, Connected Data, and Google API Data. |
|
User |
An individual who visits, registers for, is invited to, or uses the Service. |
4. Personal information and data Slate processes
4.1 Account, identity, and authentication data
- Identity and contact: name, business email address, profile or avatar image, and similar account information.
- Authentication identifiers: Clerk user identifiers, Google Sign-In identifiers when Google is selected, organization identifiers, membership identifiers, and session identifiers.
- Authentication and security events: sign-in, sign-out, invitation, session, device, browser, IP address, authentication outcome, and related timestamps or risk signals made available by authentication and hosting providers.
- Organization membership: workspace name, role, invitation status, permissions, and administrator actions. Slate currently uses Admin, Editor, and Viewer roles.
- Preferences: user-interface, display, notification, saved-view, and other account preferences stored by Slate.
- Passwords and payment credentials: Slate does not intend to receive or store a user's Google password, Clerk-managed password, complete payment-card number, card verification code, or bank-account credentials. Those values are handled by the relevant authentication or payment provider.
4.2 Organization and workspace administration data
- organization name and external organization identifier;
- default currency, time zone, fiscal-year start, date format, business type, onboarding status, and workspace settings;
- roles, permissions, membership history, administrator actions, and invitation information;
- source ownership, labels, channels, notes, statuses, and data-governance configuration; and
- rules, conditions, actions, run history, and exception information used to govern or transform records.
4.3 Subscription, billing, and transaction administration data
- plan, billing status, trial status, subscription status, current billing-period end, and cancellation status;
- records needed for internal subscription administration, accounting, fraud prevention, and dispute handling; and
- communications about trials, renewals, plan changes, cancellations, or support. Slate does not identify a production payment processor as enabled as of the effective date and does not collect complete payment-card numbers or card verification codes.
4.4 Integration authorization and connection data
- provider name, approved OAuth scopes or permissions, external account identifier and name, token issue and expiration information, and connection status;
- OAuth access and refresh tokens stored in encrypted form, together with encrypted or protected state and verifier values used during authorization;
- the user who connected or updated an organization integration, authorization and callback events, and disconnection or error status;
- synchronization start and finish times, status, summary information, retry information, error messages, and records of the source accounts selected by a Customer; and
- provider-specific metadata needed to select an account, attribute imported rows, refresh authorization, or operate a scheduled import or export.
4.5 Connected advertising and analytics data
Depending on the provider, permissions approved, Customer configuration, and report level, Slate may retrieve and store account, campaign, campaign-group, ad-group, ad-set, ad, keyword, creative, placement, device, geography, network, objective, status, date, currency, time-zone, source, medium, and attribution information. Metrics may include spend or cost, impressions, clicks, reach, conversions, conversion value, revenue, engagements, likes, shares, comments, follows, leads, video views, video completion metrics, and related calculated metrics such as click-through rate, cost per click, cost per acquisition, return on ad spend, or other ratios derived in Slate.
Slate may retain raw API response fields and payloads, normalized records, source-account metadata, identifiers needed for deduplication, and audit records showing when and how a value was imported, normalized, edited, corrected, excluded, labeled, or exported. Raw platform data may contain personal information even when Slate primarily presents aggregate marketing metrics.
4.6 Ecommerce and order data
For Shopify and any later-approved ecommerce integration, Connected Data can include store and account identifiers, order identifiers, order date, order status, currency, subtotal, discounts, shipping, taxes, refunds, total, item counts, source or landing-site information, referring site, customer or buyer identifier, and campaign or UTM parameters. Slate should not be configured to ingest names, email addresses, postal addresses, phone numbers, full payment information, or other protected customer data unless the applicable feature, platform approval, Customer instructions, contracts, and privacy controls expressly require and authorize it.
4.7 Customer-created, uploaded, and manually entered data
- CSV, TSV, spreadsheet, pasted, uploaded, or manually entered marketing records;
- vendor or source names, dates, amounts, currency, campaign details, notes, reference identifiers, and custom tags;
- correction reasons, old and new values, approval or actor information, overwrite decisions, edit history, and audit entries;
- saved filters, columns, grouping, sorting, reports, templates, dashboards, exports, alerts, and scheduling settings; and
- any personal information a Customer chooses to place in free-text, notes, file contents, custom fields, or raw uploads. Customers must not place sensitive or unrelated personal information in Slate.
4.8 Export and destination data
- Google spreadsheet identifier, URL, name, destination mode, export type, date range, filters, columns, dimensions, sorting, schedule, status, row count, and error information;
- CSV export configuration and download events;
- scheduled export creator, next-run and last-run timestamps, and export history; and
- information sent to the destination selected by the Customer. Once information is exported, the destination provider and Customer control further access and retention.
4.9 Support, communications, and feedback
- support requests, messages, screenshots, attachments, call notes, issue details, and troubleshooting data;
- survey responses, feedback, feature requests, testimonials submitted with permission, and communications with Slate;
- administrative and service notices, including security, billing, integration, and policy communications; and
- marketing subscription status, consent records, unsubscribe or suppression status, campaign interaction data, and attribution information.
4.10 Device, usage, cookie, and diagnostic data
- IP address, browser, operating system, device type, language, approximate location inferred from IP, referring URL, landing page, and page path;
- cookie, local-storage, advertising, analytics, session, and device identifiers;
- pages and features viewed, buttons or links used, timestamps, navigation sequences, errors, latency, and performance data;
- authentication, authorization, webhook, API, job, database, hosting, and application logs; and
- product and website analytics events, including normalized page paths, page views, navigation and interaction events, technical event metadata, and vendor-generated pseudonymous user and session identifiers. Slate does not enable session replay or target-text capture.
4.11 Information Slate does not intentionally request
Slate is not designed to collect or process protected health information, Social Security numbers, government identification numbers, biometric templates, precise geolocation, children's data, complete payment-card data, passwords, data about sex life or sexual orientation, genetic data, or other special-category or highly sensitive information. Customers must not upload or connect such information unless Slate has expressly agreed in a written contract and implemented the required product, legal, and security controls. No such agreement or special regulated-data feature is identified as active as of the effective date of this Policy.
5. Sources of information
- Directly from Users and Customers: registration, invitations, settings, files, manual entries, forms, support, billing, and communications.
- From Customer administrators and coworkers: invitations, roles, workspace configuration, account details, and content submitted about or by organization members.
- From Google and other connected platforms: authorized OAuth profile information, account lists, platform reports, analytics, orders, metadata, tokens, and API responses.
- From Clerk, Vercel, Neon, and other verified service providers: authentication events, hosting logs, security signals, service telemetry, and operational data needed to provide the Service.
- Automatically from browsers and devices: cookies, IP address, page events, diagnostics, and usage information.
- From Slate marketing activities: direct communications, referrals, event or content interactions, and campaign parameters.
- From public or business sources: business contact information and company information used for legitimate business-to-business sales, fraud prevention, due diligence, or customer support, where permitted by law.
6. Purposes and legal bases
Slate processes information only for purposes that are compatible with the context in which the information was collected, the Customer's instructions, the applicable platform permissions, and applicable law. Where the GDPR, UK GDPR, or a similar law requires a legal basis, the basis depends on the information and context.
|
Purpose |
Information involved |
Typical legal basis |
|
Provide and administer the Service |
Account Data, organization settings, Customer Content, Connected Data, integration data, exports, and Service Data |
Performance of a contract; steps requested before entering a contract; legitimate interests in providing the Service |
|
Authenticate and control access |
Identity, Google Sign-In data, Clerk identifiers, sessions, roles, device and security information |
Contract; legitimate interests in secure access; legal obligation where applicable |
|
Connect, synchronize, normalize, govern, report, and export data |
OAuth permissions and tokens, Connected Data, raw payloads, normalized metrics, rules, corrections, and destination data |
Contract; Customer instructions; legitimate interests; consent where platform or law requires |
|
Bill and manage subscriptions |
Plan, subscription status, trial information, internal billing status, and related communications |
Contract; legal obligation; legitimate interests in fraud prevention and collections |
|
Secure, monitor, and troubleshoot the Service |
Logs, IP, device, error, webhook, job, database, authentication, and audit information |
Legitimate interests in security, reliability, fraud prevention, and abuse prevention; legal obligation |
|
Provide support and communicate |
Account and contact data, support content, diagnostics, billing and service status |
Contract; legitimate interests; consent where required |
|
Analyze and improve Slate |
Slate-controlled usage and product analytics; deidentified or aggregate service statistics |
Legitimate interests; consent for non-essential cookies where required. Google API Data and other restricted Connected Data are excluded unless the use is a permitted user-facing feature. |
|
Market Slate and measure campaigns |
Public-site events, marketing contact information, consent and suppression status, campaign and advertising identifiers |
Consent where required; legitimate interests for permitted business marketing; compliance with opt-out rights |
|
Comply with law and protect rights |
Any information reasonably necessary for legal process, tax, accounting, sanctions, investigations, disputes, and enforcement |
Legal obligation; legitimate interests; establishment, exercise, or defense of legal claims |
Where Slate relies on consent, a person may withdraw consent at any time through the available preference mechanism or request channel. Withdrawal does not affect processing already completed lawfully. Where Slate relies on legitimate interests, Slate considers the purpose, necessity, and effects on individuals and applies safeguards appropriate to the information.
7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive
|
Google Limited Use commitment |
7.1 Google Sign-In
A User may choose Google Sign-In through Clerk. Google Sign-In is used to authenticate the User and create or link the User's Slate account. Depending on the User's Google and Clerk configuration, Slate may receive the User's Google account identifier, name, email address, profile image, and authentication metadata. Signing in with Google does not itself authorize Slate to read Google Ads, Google Analytics, Google Sheets, Google Docs, Google Slides, or Google Drive content.
7.2 Google Ads as a connected data source
When a Customer connects Google Ads, Slate requests the Google Ads OAuth scope `https://www.googleapis.com/auth/adwords`. This scope permits access to Google Ads accounts that the authorizing User is entitled to access. Slate uses that access to list selectable customer or manager accounts and retrieve reporting data for the Customer-facing aggregation, normalization, audit, reporting, and export features of Slate.
Google Ads data can include customer and manager account identifiers and names; account currency and time zone; campaign, ad group, ad, keyword, network, device, geography, status, and date fields; cost, impressions, clicks, conversions, conversion value, and other report metrics selected for the implemented Slate reporting level; and raw response metadata needed to validate and normalize those records.
Slate is a reporting and data-governance product, not a full-service Google Ads campaign-management tool as currently implemented. Slate limits the connector to Customer-directed reporting and complies with the Google Ads API terms and requirements applicable to its approved access.
7.3 Google Analytics 4 as a connected data source
When a Customer connects Google Analytics 4, Slate requests the read-only OAuth scope `https://www.googleapis.com/auth/analytics.readonly`. Slate uses that access to identify properties and retrieve Customer-selected analytics dimensions and metrics for Customer-facing reporting and reconciliation. Depending on the report configuration, data can include property identifiers and names, date, source, medium, campaign, device, geography, sessions, users, events, conversions or key events, revenue, and related aggregate measurements.
Slate does not use a Customer's connected Google Analytics data to advertise Slate, build cross-customer audiences, identify visitors on unrelated services, or train general-purpose artificial-intelligence or machine-learning models.
7.4 Google Sheets as an export destination
When a Customer connects Google Sheets, Slate requests `https://www.googleapis.com/auth/spreadsheets` and `https://www.googleapis.com/auth/drive.file`. The spreadsheets scope allows Slate to create and edit spreadsheets as directed by the Customer. The `drive.file` scope is intended to limit Drive access to files that the User creates with Slate or explicitly opens or shares with Slate; it does not grant general access to every file in the User's Drive.
Slate stores destination spreadsheet identifiers, URLs, names, export settings, schedules, row counts, and status information necessary to run and audit exports. Slate writes only the data selected for export by an authorized User or scheduled configuration. After data is written to Google Sheets, the Customer and Google control access, sharing, version history, retention, and downstream use in the destination file.
7.5 Google Docs, Google Slides, and broader Google Drive access
As of the effective date, the audited Slate implementation does not register an active Google Docs connector, Google Slides connector, or general Google Drive connector, and does not request broad Drive scopes that read all Drive files. Slate therefore does not currently access the contents of Google Docs or Google Slides through those APIs. Before any such feature is activated, Slate must implement only the minimum necessary scope, update this Policy and in-product disclosures, complete any required Google verification or security assessment, and obtain fresh, contextual authorization from affected Users.
7.6 How Slate uses, shares, and protects Google API Data
- Permitted use: provide or improve the Customer-facing feature for which the User authorized access, including account selection, import, normalization, governance, reporting, reconciliation, and export.
- No advertising use: Slate does not sell, transfer, or use Google API Data for serving ads, retargeting, personalized advertising, audience creation, or interest-based advertising.
- No data brokerage or surveillance: Slate does not sell or distribute Google API Data to data brokers, information resellers, surveillance providers, credit providers, or unrelated third parties.
- No general model training: Slate does not use Google API Data to train general-purpose artificial-intelligence or machine-learning models. Any future user-facing model feature involving Google API Data would require a permitted use, specific disclosures, appropriate controls, and any required consent or Google approval before launch.
- Limited disclosure: Slate discloses Google API Data only to infrastructure or service providers that process it for Slate under appropriate confidentiality and data-protection restrictions, to the Customer and its authorized Users, to a destination expressly chosen by the Customer, or when legally required.
- Human access: Slate personnel may access Google API Data only when necessary for security, abuse investigation, support requested by the Customer, legal compliance, or operation of a permitted user-facing feature, and only under access restrictions and confidentiality obligations.
- Security: Google OAuth tokens are stored encrypted at rest; Google API Data must be transmitted over secure protocols and protected using access controls, secret management, logging, and incident-response procedures.
- Minimum permissions: Slate must request only the scopes needed for active features and must not request speculative scopes for unimplemented Docs, Slides, Drive, or other features.
7.7 Disconnecting Google and deleting Google API Data
An authorized administrator or User can disconnect the applicable Google integration through the available Slate connection controls and can also revoke Slate's access through the User's Google account security settings. Disconnection stops new API access after the revocation is processed. Slate will delete or render inaccessible the associated active tokens and will delete Google API Data when required by the Customer's instruction, account deletion, platform terms, or applicable law, subject to narrowly limited legal-retention obligations and backup aging.
Deleting a Slate account does not automatically delete data already exported to a Customer-owned Google spreadsheet. The Customer must delete or restrict the destination file separately. Likewise, revoking Google access does not necessarily remove historical data that the Customer lawfully imported before revocation; the Customer or authorized User must submit a deletion instruction if historical data should also be removed, unless platform rules require automatic removal.
8. Other connected advertising, analytics, ecommerce, and lifecycle platforms
The integrations below are described according to the audited implementation as of the effective date. A provider may impose additional review, permission, retention, attribution, branding, or deletion rules. Slate processes only the accounts and data that an authorized User selects and only within the provider access approved for Slate.
8.1 Meta Ads
Slate requests Meta permissions `ads_read` and `business_management` for the Meta Ads connector. Slate may use them to identify businesses and ad accounts the authorizing User can access and to retrieve account, campaign, ad set, ad, placement, device, geography, objective, spend, impression, reach, click, conversion, value, engagement, and video-performance data. Slate stores connection metadata, encrypted tokens, selected account identifiers, raw response data, normalized metrics, and sync history. Meta data is used only for Customer-facing Slate features and remains subject to Meta Platform Terms and Developer Policies.
8.2 LinkedIn Ads
Slate requests LinkedIn permissions `r_ads` and `r_ads_reporting`. Slate may retrieve authorized ad-account, campaign, campaign-group, creative, date, currency, status, objective, spend, impression, click, conversion, value, reach, and engagement information. Slate must maintain LinkedIn program approval and comply with the LinkedIn Marketing Developer Terms, including restrictions on access, client relationships, security, storage, use, and onward disclosure.
8.3 Microsoft Advertising
Slate requests `openid`, `offline_access`, and `https://ads.microsoft.com/msads.manage`. The Microsoft Ads permission is broader than read-only naming may suggest, even though Slate currently uses the connection for account discovery and reporting. Slate may process Microsoft identity and authorized account information, reporting-job metadata, campaign and ad identifiers, status, keyword or search-query fields where implemented, device and network dimensions, spend, impressions, clicks, conversions, revenue, and related metrics. Slate must protect the developer token and OAuth credentials and must not expose management functionality that has not been designed, authorized, and disclosed.
8.4 TikTok Ads
Slate uses TikTok API for Business authorization to access the advertiser accounts and scopes approved for the Slate app. TikTok scopes can be returned dynamically by TikTok rather than being fixed in the current source code. Slate may process advertiser and campaign identifiers, date, currency, campaign status, objective, placements, geography, device, spend, impressions, reach, clicks, conversions, conversion value, video metrics, and engagement metrics. Any separate TikTok Pixel, Events API, Advanced Matching, or Customer Audience use by Slate as an advertiser is governed by Section 9 and requires the applicable notice and consent; it is not sourced from Customer-connected TikTok Ads data.
8.5 Reddit Ads
Slate requests Reddit permissions `adsread` and `identity`. Slate may process Reddit account identity needed for authorization, ad-account identifiers and metadata, campaign and ad identifiers, placement or community dimensions, location, spend, impressions, clicks, conversions, value, reach, video metrics, and leads. Reddit requires accurate identification, a compliant privacy policy, adherence to API limits and attribution requirements, and deletion of cached or stored Reddit material when required upon termination. Slate must also use an accurate production user-agent identifier.
8.6 Shopify
Slate's Shopify managed-install configuration has no universally required data scope. The merchant's selected tables determine the minimum optional scopes requested from `read_orders`, `read_customers`, `read_products`, `read_inventory`, `read_locations`, and `read_marketing_events`. Orders and order line items are selected for a new connection by default and require `read_orders`. Order-attribution visits require `read_orders` and `read_marketing_events`. Slate does not request `read_all_orders`; if Shopify has separately granted it, Slate may use it for older order history. Every connection and synchronization remains limited to the scopes actually granted by Shopify.
Depending on the merchant's selected tables and granted scopes, Slate processes the following Shopify resources for these purposes:
- Shop and connection metadata: authorize and secure the exact connection, enforce granted scopes, configure ingestion, and present shop-level reporting and exports.
- Orders and order line items: ingest commerce activity; normalize and report order metrics; join orders to customers, products, variants, and attribution visits; support attribution; export merchant-selected results; and locate customer-linked data for privacy requests.
- Limited customer records: link merchant customers to their orders, report aggregate customer/order relationships, support merchant exports, and locate or redact the exact customer's stored data.
- Products and variants: ingest and report catalog data, join catalog objects to order line items and inventory, and include merchant-selected fields in exports.
- Inventory items and levels: ingest and report inventory state, join items and quantities to variants and locations, and support inventory exports.
- Locations: identify and report inventory locations, join location context to inventory levels, and support location-aware exports.
- Order-attribution visits and UTM/referrer data: attribute orders to marketing sources, campaigns, landing pages, and referrers; join visits to orders; and provide attribution reporting and exports.
- Privacy webhooks: authenticate, secure, deduplicate, and fulfill customer data requests and customer/shop redaction instructions without retaining raw webhook bodies.
- Raw, linked, normalized, and derived reporting records: provide reporting, joins, attribution, rules, governance, exports, security/audit controls, and privacy-request fulfillment from the final stored state.
Slate does not intentionally retain direct Shopify customer email addresses, telephone numbers, or postal addresses. Slate does not sell merchant or merchant-customer data, use it to advertise Slate, combine it for cross-merchant profiling, or use it for automated decisions that produce legal or similarly significant effects. That merchant-controlled data is separate from Slate Marketing Data collected on Slate-controlled public sites for Slate's own analytics, advertising, and communications as described in Sections 9, 10, and 12.
A verified Shopify app uninstall or administrator disconnect immediately clears reusable credentials and stops synchronization, then deletes the disconnected shop's Slate data after 48 hours unless the same connection is restored first. A verified `customers/redact` request immediately hard-deletes the exact customer-linked records, and a verified `shop/redact` request immediately purges the exact shop. For `customers/data_request`, Slate prepares a protected JSON export of the data it stores for the customer and provides it to the merchant; the merchant remains responsible for authenticating the requester and delivering the customer-facing response. Deleted data may persist only until protected backups expire under the backup schedule, must not return to ordinary active use, and is re-deleted or isolated if a backup is restored.
Shopify order and customer-related data can be Protected Customer Data. Slate and each Customer must comply with Shopify's API terms, protected-data requirements, data-minimization rules, access review requirements, and mandatory privacy webhooks where applicable.
8.7 Amazon Ads
The Slate data model contains an Amazon Ads provider designation, but the audited implementation did not establish a live Amazon Ads connector. Slate does not represent that it currently accesses Amazon Ads data. Before activation, Slate must complete the Amazon Ads application and approval process, document the precise scopes and reports, update this Policy, obtain Customer authorization, and satisfy Amazon-specific security, retention, attribution, and use restrictions.
8.8 Klaviyo as a Customer-connected data source
Klaviyo is not registered as an active Customer-facing connector and is not enabled as Slate's production marketing provider as of the effective date. Slate will update this Policy, document the applicable authorization, data, roles, and lifecycle, and obtain Customer authorization before activating a Klaviyo connection.
8.9 Pinterest and Spotify
Pinterest and Spotify appeared only as inactive, unregistered, or placeholder integration concepts in the reviewed product context and are not described as live data connections. Slate does not represent that it currently accesses those platforms. A future activation requires a policy update, exact scope disclosure, platform approval, contextual authorization, and a documented data lifecycle.
9. Production service providers and subprocessors
Slate uses the production providers listed below. Customer-selected source platforms and export destinations are not Slate subprocessors merely because a Customer directs Slate to exchange data with them. Stripe, Sentry, Klaviyo, Google Ads, Meta Ads, the hosted Svix service, and separate email, support, monitoring, logging, backup, or security services are not identified as enabled Slate production providers as of the effective date.
Provider |
Function and information |
Processing region |
Transfers and service retention |
Clerk, Inc. |
Authentication, sessions, user and organization management, invitations, and Google Sign-In; identity, contact, membership, session, device, network, authentication, and security data. Slate-controlled data. |
United States; Clerk does not offer regional residency, and its disclosed subprocessors may process data from their disclosed locations. |
EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework certifications, with Standard Contractual Clauses and applicable UK or Swiss terms as fallback. Customer Personal Data is deleted within 90 days after service termination or expiration, subject to the DPA. |
Vercel Inc. |
Application and marketing-site hosting, compute, content delivery, networking, deployments, scheduled jobs, native logs, and Vercel Web Analytics; request, network, device, route, deployment, log, sanitized page-analytics, Slate-controlled, and Customer data processed through application compute. |
Primary production compute in iad1, Washington, D.C., United States (AWS us-east-1); global content-delivery locations and possible global backup or subprocessor processing. |
EU Standard Contractual Clauses and UK International Data Transfer Agreement where applicable. Pro runtime logs are retained for one day; Vercel Web Analytics visitor-session hashes expire after 24 hours. |
Databricks, Inc. — Neon product; Neon, LLC affiliate |
Production PostgreSQL database and native recovery history; Account Data, organization records, encrypted integration credentials, Customer Content, Connected Data, metrics, audit, rules, reports, exports, billing metadata, and operational records. Customer and Slate-controlled data. |
Production database storage and compute in AWS us-east-1, United States; authorized support, control-plane, and subprocessors may operate in other disclosed locations. |
EU Standard Contractual Clauses and UK Addendum for restricted transfers. Native production recovery history is configured for six hours; this does not determine Slate's application-record retention periods. |
Heap, Inc., a Contentsquare Group company |
Product and website behavioral analytics; Heap-generated pseudonymous user and session identifiers, device identifiers, page views, normalized navigation and interaction events, browser and operating-system data, referrer, campaign, session, and technical metadata. Slate-controlled data only. |
United States Product Analytics environment in Virginia (AWS us-east-1); authorized affiliates, support functions, and subprocessors may process data globally. |
Data Privacy Framework for eligible U.S. transfers and EU or UK Standard Contractual Clauses where adequacy or the Framework is unavailable. Heap analytics data is retained for up to 37 months. Session replay, target-text capture, IP capture, and geolocation capture are disabled. |
Google LLC — Google Tag Manager and Google Analytics 4 |
Tag orchestration and Slate-controlled website and product analytics; normalized page location, path, same-origin referrer, page-view events, cookie and device identifiers, browser information, and technical data. Customer Content, Connected Data, and Google API Data are excluded. |
Google's global infrastructure; no fixed customer-selectable GTM or standard GA4 processing region is represented. |
Data Privacy Framework, Standard Contractual Clauses, and adequacy mechanisms as applicable under Google's data-processing terms. GTM HTTP request logs are retained for 14 days. GA4 user-level and event-level data is retained for 14 months, with retention reset on new activity disabled. |
10. Cookies, local storage, analytics, and tracking choices
10.1 Necessary technologies
Slate and its authentication, hosting, and security providers use cookies, browser storage, and comparable technologies that are necessary to authenticate Users, maintain sessions, prevent fraud, secure the Service, balance traffic, remember requested settings, and provide requested functionality. Blocking these technologies may prevent the Service from working.
10.2 Google Tag Manager and Google Analytics 4
Slate uses Google Tag Manager to deliver a Google Analytics 4 configuration tag and a GA4 page-view tag on Slate-controlled production sites. Slate sends normalized page location, page path, and same-origin referrer values without URL queries or fragments. GA4 may also receive cookie and device identifiers, browser and technical information, and IP-derived approximate location. Slate does not send Customer Content, Connected Data, Google API Data, advertising identifiers supplied by Slate, names, email addresses, or Slate User-ID values to GA4.
GA4 is configured with a 14-month user-level and event-level retention period and does not reset retention when a user returns. Google Signals, advertising personalization, user-provided data collection, enhanced measurement, enhanced conversions, and Google Ads linking are disabled. Slate does not use GA4 for advertising audiences or cross-context behavioral advertising.
10.3 Heap product and website analytics
Slate uses Heap across Slate-controlled production surfaces to understand navigation, interactions, adoption, reliability, and feature performance. Heap may receive Heap-generated pseudonymous user and session identifiers, cookie and device identifiers, page views, normalized navigation and interaction events, browser and operating-system information, referrer, campaign and session metadata, and technical event metadata. Slate does not send names, email addresses, Customer identifiers, or Slate user or organization identifiers to Heap.
Heap data is retained for up to 37 months. Session replay, target-text capture, IP capture, and geolocation capture are disabled. Heap must not receive passwords, payment-card data, OAuth tokens, API credentials, Customer Content, Connected Data, Google API Data, sensitive personal information, form contents, unrestricted free text, or URL query strings.
10.4 Vercel Web Analytics
The Slate application uses Vercel Web Analytics for privacy-focused page measurement. Slate does not provide Vercel Web Analytics with a Slate User-ID or custom advertising identifier. Vercel's visitor-session hash expires after 24 hours, and Slate does not use this service for advertising or session replay.
10.5 Current consent and preference treatment
Slate currently offers the Service for United States business use. Necessary technologies operate as required to provide and secure the Service. Slate uses the analytics described above for its legitimate business purposes and provides any consent or opt-out treatment required by applicable law. A person may request that Slate stop or delete identifier-linked analytics through legal@slatedata.app. Slate does not currently use advertising pixels, retargeting, enhanced matching, session replay, Google Ads, Meta Ads, or Klaviyo marketing tracking on Slate-controlled production sites.
11. Disclosures of information
Slate may disclose information only as described below and subject to applicable platform and legal restrictions.
- To the Customer and authorized Users: workspace administrators, members, and collaborators can access information according to their roles, Customer settings, and exports. An administrator may manage membership, revoke access, or view activity.
- To service providers and subprocessors: providers that host, authenticate, store, secure, support, bill, analyze, or communicate for Slate may process information under contract and only for authorized purposes.
- To connected platforms at the Customer's direction: Slate sends authentication requests, API requests, and Customer-selected exports to the provider selected by an authorized User.
- To Slate marketing and advertising providers: only Slate Marketing Data may be disclosed for Slate's own analytics, email, advertising, or measurement. Customer Content, Connected Data, and Google API Data are excluded.
- For legal, safety, and security reasons: Slate may disclose information when reasonably necessary to comply with law, court order, legal process, sanctions, regulatory request, or to protect rights, safety, security, and the integrity of the Service. Slate will seek to limit disclosure to what is legally required where permitted.
- In a business transaction: information may be disclosed in connection with financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality and applicable law. A successor must remain bound by Google and other platform restrictions for platform data.
- With explicit direction or consent: Slate may disclose information when a User or Customer instructs Slate to do so, such as exporting a report or authorizing support access.
- Deidentified or aggregate information: Slate may disclose statistics that cannot reasonably identify a person or Customer, provided Slate does not attempt reidentification and the use is not prohibited for Google API Data or another restricted platform data set.
Slate does not grant service providers independent rights to sell Customer Content or use it for their own cross-context advertising. A service provider may process separate account or business-relationship data as an independent controller only as described in its own notice and contract.
12. Sale, sharing, targeted advertising, and Global Privacy Control
12.1 No sale or targeted-advertising sharing
Slate does not sell Personal Information, Customer Content, Connected Data, Google API Data, OAuth tokens, or workspace records for money or other value. Slate does not share Personal Information for cross-context behavioral advertising or process it for targeted advertising. Slate has not engaged in those practices during the 12 months preceding the effective date.
12.2 Global Privacy Control
Because Slate does not currently sell Personal Information or share it for cross-context behavioral advertising, a Global Privacy Control signal does not alter those practices. A person may nevertheless submit any applicable sale, sharing, targeted-advertising, or analytics opt-out request to legal@slatedata.app, and Slate will honor the request where required.
12.3 Sensitive personal information
Slate does not use or disclose sensitive personal information to infer characteristics about individuals. Slate limits sensitive personal information to what is necessary for authentication, security, legal compliance, or a specifically contracted feature and provides any legally required limitation mechanism.
13. Retention, deletion, revocation, and backups
Slate applies the following maximum periods, except where a shorter platform rule applies or a documented legal hold or legal obligation requires longer retention. When a period expires, Slate deletes, irreversibly anonymizes, or otherwise renders the information inaccessible.
Data category |
Maximum retention |
Production Customer Data after non-Shopify termination |
30 days after effective termination or account closure, then deleted from active production systems. |
Account and organization records |
90 days after account or organization closure, then deleted or irreversibly anonymized, except for minimal information retained under another listed schedule. |
OAuth tokens and connection credentials |
Until disconnection, revocation, expiration without refresh, account deletion, or another required removal event; reusable credentials are cleared promptly when access ends. |
Support records |
24 months after the support case or correspondence closes. |
Security and audit records |
24 months after creation, unless an active security investigation or documented legal hold requires longer retention. |
GA4 analytics identifiers and user-level event data |
14 months from collection; the period does not reset when the same user returns. |
Heap analytics identifiers and user-level event data |
Up to 37 months from collection, consistent with Heap's configured Product Analytics retention. |
Vercel Web Analytics and runtime logs |
Visitor-session hashes expire after 24 hours; Pro runtime logs are retained for one day. |
Slate marketing records |
24 months after the last meaningful marketing engagement. A suppression-only record may remain for seven years after opt-out solely to prevent future marketing. |
Application and database backups |
No more than 30 days after creation. The configured Neon production recovery-history window is six hours. |
Legal and accounting records |
Seven years after the end of the fiscal year in which the transaction occurred or the matter closed, whichever is later, unless a documented legal hold requires longer retention. |
13.1 Customer requests and termination
A Customer may request export or deletion through the Service or the published request method, subject to role authorization and legal restrictions. Slate may retain deidentified aggregate statistics, security evidence, billing records, and information necessary to establish, exercise, or defend legal claims, provided such retention is lawful and not prohibited by a platform policy.
13.2 Platform revocation and deletion
When a connected platform requires deletion, refresh-token revocation, data invalidation, privacy-webhook processing, or cache expiration, Slate will follow that requirement even if the general Slate retention criteria would otherwise permit longer retention. Customers must not reconnect or reimport data to circumvent a platform deletion request or legal right.
13.3 Shopify deletion and privacy requests
A verified Shopify uninstall or administrator disconnect starts a 48-hour deletion period for the disconnected shop after credentials are cleared and synchronization stops. Verified customer and shop redaction requests are processed immediately. A Shopify customer data request is fulfilled through a protected merchant-facing export; the merchant is responsible for the response to its customer. Protected backups age out under the backup schedule, and deleted Shopify data is re-deleted or isolated after any disaster-recovery restoration.
14. Security
Slate uses administrative, technical, and organizational safeguards designed for the nature of the Service and information processed. No system is completely secure, and Slate cannot guarantee that unauthorized access, loss, or misuse will never occur.
- Transport security: secure modern protocols for data in transit between users, Slate, and connected providers.
- Token encryption: OAuth access and refresh tokens are encrypted at rest using authenticated encryption. The audited implementation uses AES-256-GCM and a separate encryption key supplied through the environment.
- Access controls: authenticated access, organization scoping, role-based permissions, least-privilege administrative access, and separate development and production access where implemented.
- Auditability: records of material imports, edits, corrections, synchronization, settings changes, and exports where the feature supports them.
- Secrets and key management: production secrets must be kept outside source control, limited to authorized systems and personnel, rotated when required, and monitored for accidental exposure.
- Application and infrastructure controls: dependency management, code review, deployment controls, database protections, logging, monitoring, backup, recovery, and vulnerability remediation appropriate to the Service.
- Vendor diligence: review of subprocessors, data-protection terms, security documentation, region and transfer mechanisms, and notification procedures.
- Personnel controls: confidentiality obligations, access approval and removal, security awareness, and access only for a legitimate business need.
- Incident response: detection, containment, investigation, remediation, evidence preservation, Customer and regulator notification, and platform notification where required. Google requires notification to Google for a known or suspected unauthorized access involving Google Data under applicable policy.
Users are responsible for maintaining the security of their devices, email accounts, Google accounts, authentication factors, and Customer platform accounts; using strong authentication; limiting roles; reviewing integrations; and promptly reporting suspected compromise.
15. International data transfers
Slate and its providers may process information in the United States and other countries where they or their subprocessors operate. Those countries may have privacy laws different from the laws where an individual lives. Where required, Slate will use an approved transfer mechanism, such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework or an applicable extension when the recipient is certified, or another lawful mechanism.
Slate's primary application compute is in Vercel's Washington, D.C. region (AWS us-east-1), its production Neon database is in AWS us-east-1, Heap Product Analytics is hosted in Virginia (AWS us-east-1), Clerk hosts Customer Personal Data in the United States, and Google processes GTM and GA4 data through global infrastructure without a fixed customer-selectable processing region. Section 9 identifies the applicable Data Privacy Framework certifications, Standard Contractual Clauses, UK transfer terms, and adequacy mechanisms.
16. Privacy rights and choices
Depending on location and relationship to Slate, an individual may have rights to know or confirm processing; access; obtain a copy; correct; delete; restrict or object; withdraw consent; obtain portability; opt out of sale, sharing, targeted advertising, or certain profiling; limit sensitive-information use; appeal a denial; and complain to a regulator.
16.1 How requests are handled
- 1. Email legal@slatedata.app. Requests received through another Slate-controlled channel are forwarded to that monitored inbox and logged without requiring resubmission.
- 2. Describe the right being exercised, the Slate account or organization involved, and enough information for Slate to locate the relevant records without collecting excessive new information.
- 3. Slate may verify identity, authority, and account relationship using proportionate methods. Slate will not request a password, complete payment-card number, or unrelated sensitive information.
- 4. If Slate processes the information solely for a Customer, Slate may direct the request to that Customer or assist the Customer as required by contract and law.
- 5. Slate targets completion of ordinary requests within 30 calendar days. California requests to know, delete, or correct are acknowledged within 10 business days and answered within 45 calendar days, subject to a permitted 45-day extension with notice. California sale, sharing, and sensitive-information requests are honored as soon as feasible and no later than 15 business days. EEA and UK requests are answered ordinarily within one month, subject to a permitted two-month extension with timely notice. Shopify compliance requests are completed within 30 days.
16.2 Authorized agents
Where permitted, an authorized agent may submit a request. Slate may require evidence of authorization and may verify the individual directly, except where a valid power of attorney or another legal rule provides otherwise.
16.3 Denials and appeals
A denial or partial denial will identify the unfulfilled portion, explain the reason to the extent legally permitted, and describe any applicable appeal or regulator-complaint route. Appeals may be emailed to legal@slatedata.app and should identify the original request and the decision being appealed. Slate targets an appeal decision within 30 calendar days or sooner where law requires. A different qualified reviewer will conduct the appeal where reasonably available; otherwise, the original decision-maker will perform and document a second review.
16.4 Account and platform controls
- update available profile or organization settings through Slate;
- disconnect a platform integration and separately revoke access in the platform account;
- control membership and roles through an authorized administrator;
- unsubscribe from marketing using the message link while Slate retains a minimal suppression record;
- email legal@slatedata.app to request an applicable analytics or marketing opt-out; and
- enable Global Privacy Control where supported and legally applicable.
16.5 Non-discrimination
Slate will not unlawfully discriminate against a person for exercising a privacy right. Slate may offer a different price or service level when the difference is reasonably related to the value of data and permitted by law, but no financial-incentive program is identified as active as of the effective date.
17. California and other U.S. state disclosures
This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws. Applicability depends on legal thresholds, exemptions, context, and Slate's actual operations. The categories below use California statutory terminology and describe the information Slate can collect in the course of operating the Service.
|
California category |
Examples in Slate |
Collected from |
Disclosed to |
|
Identifiers |
Name, business email, IP, account, Clerk, Google, organization, platform, cookie, and device identifiers |
User, Customer, browser, Clerk, and connected platforms |
Customer users; Clerk; Vercel; Neon; support or security providers; connected platforms at direction |
|
Customer-record information |
Business contact, account and billing administration information |
User and Customer |
Service providers; professional advisers; Customer administrators |
|
Commercial information |
Subscription, plan, transaction administration, product interest, marketing engagement, order or revenue records in Customer data |
User, Customer, Shopify, and other connected platforms |
Service providers; Customer users; connected destinations |
|
Internet or electronic activity |
Pages, clicks, sessions, referrers, browser, device, logs, feature activity, ad interactions |
Browser, device, hosting, analytics and advertising tools |
Vercel; Google Analytics; Heap; advertising providers subject to choice; security providers |
|
Geolocation |
Approximate location inferred from IP and connected-platform country or region dimensions |
Browser, analytics provider, connected platform |
Analytics/service providers; Customer users for connected reports |
|
Professional or employment-related information |
Business email, company, title or role if provided, organization membership |
User, Customer, business sources |
Customer users; Slate-controlled communications records; service providers |
|
Inferences |
Product-interest, feature-use, marketing engagement, or account-health inferences derived from Slate-controlled data |
Slate-controlled activity |
Slate service providers and authorized staff. No inferences from Customer Content or Google API Data for Slate advertising. |
|
Sensitive personal information |
Account authentication data and security information; payment credentials remain with Stripe or the authentication provider |
User and Clerk |
Necessary authentication, security, payment, and hosting providers only |
17.1 Business purposes and categories of recipients
The business and commercial purposes are described in Section 6. Categories of recipients are described in Sections 9 and 11. Slate does not sell Personal Information and does not share it for cross-context behavioral advertising or process it for targeted advertising. Google Ads, Meta Ads, and comparable advertising tags are not enabled on Slate-controlled production sites as of the effective date.
17.2 Notice at collection
The categories collected at a particular interaction depend on the feature. Slate must link this Policy or a concise notice at or before registration, marketing forms, cookie collection, payment, support intake, and OAuth authorization. The notice must identify the relevant categories and purposes and must not rely on this long-form Policy when a timely contextual notice is required.
17.3 Minors
Slate has no actual knowledge that it sells or shares personal information of persons under 16 and does not intend to do so. The Service is for business users who are at least 18.
17.4 Appeals
Where a state law provides an appeal right, email legal@slatedata.app and identify the original request and decision. Slate targets a decision within 30 calendar days or sooner where applicable law requires and will provide the reason for its decision and any required attorney-general or regulator complaint route.
18. EEA, United Kingdom, and Switzerland disclosures
18.1 Controller and representative information
For Slate-controlled processing, Slate Data LLC is the controller. Slate Data LLC is a Massachusetts limited liability company with a business mailing address at 333 Ricciuti Drive #1404, Quincy, MA 02169, United States, and can be contacted at legal@slatedata.app. Slate currently offers the Service for United States business use. If an EU or UK representative or data protection officer becomes legally required, Slate will update this Policy with the applicable contact information.
18.2 Legal bases and rights
The legal bases are described in Section 6. Individuals may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal, and complaint to a supervisory authority. Individuals also may object to direct marketing at any time. Slate does not identify automated decision-making that produces legal or similarly significant effects as an active feature.
18.3 Customer-controlled data
When Slate acts as a processor, the Customer is responsible for the legal basis, transparency, data-subject response, and instructions. Slate will assist as required by the applicable data-processing agreement. A written Slate DPA, including processing details, confidentiality, security, subprocessors, deletion, audits, assistance, incident notice, and transfer terms, must be available before regulated Customer data is processed at scale.
18.4 Complaints
An individual may complain to the supervisory authority where the individual resides, works, or believes an infringement occurred. Slate requests an opportunity to address the concern through the published privacy contact first, but that request does not limit the right to contact a regulator.
19. Children and business use
Slate is a business-to-business service and is not directed to children. A User must be at least 18 and able to form a binding contract. Slate does not knowingly collect personal information directly from children under 13. A Customer must not upload, connect, or otherwise process children's personal information through Slate. If Slate learns that such information was collected without appropriate authorization, Slate will take reasonable steps to delete it and restrict the responsible account.
20. Changes to this Policy
Slate may update this Policy to reflect changes in law, platform requirements, providers, products, or processing. The updated version will state the new effective date and be posted at the public Privacy Policy URL. For a material change involving a new use of Google API Data or other information beyond the use originally disclosed and authorized, Slate will provide additional notice and obtain renewed consent or authorization when required before the new use begins.
A Customer is responsible for reviewing updates and maintaining its own notices. Continued use after an effective update constitutes acceptance only to the extent permitted by law and does not replace consent where consent is legally required.
21. Contact information
Slate Data LLC
333 Ricciuti Drive #1404
Quincy, MA 02169
United States
Email: legal@slatedata.app
Use this monitored address for privacy-rights requests, deletion requests, appeals, analytics or marketing opt-outs, platform-data deletion requests, security reports, legal notices, and regulator communications. The Founder and Managing Member monitors the inbox at least weekly and handles escalations.
Appendix A. Detailed data inventory
|
Record or field group |
Examples |
Purpose |
Primary location or recipient |
|
User record |
User ID, email, name, avatar, user type, preferences, creation time |
Account and experience administration |
Clerk and Slate database on Neon |
|
Organization record |
Clerk organization ID, name, currency, time zone, fiscal year, date format, business type, settings |
Workspace configuration and reporting context |
Slate database on Neon |
|
Membership |
Organization ID, user ID, Admin/Editor/Viewer role, creation time |
Authorization and organization governance |
Clerk and Slate database on Neon |
|
Billing |
Plan, subscription status, trial, internal billing status, and billing period |
Subscription administration |
Slate database on Neon; no production payment processor identified as enabled |
|
Integration connection |
Provider, external account, encrypted access/refresh token, expiry, scopes, sync time, connecting user |
Authorized platform access |
Slate application and Neon; connected provider |
|
Sync run |
Provider, queued/running/succeeded/failed, summary, error, actor, timestamps |
Reliability, audit, troubleshooting |
Slate database and operational logs |
|
Data source |
Platform, provider, kind, owner, label, channel, notes, status, metadata |
Source governance |
Slate database |
|
Source account |
External account ID/name, currency, time zone, status, metadata |
Account selection and attribution |
Slate database |
|
Raw metric fact |
Date, grain, raw dimensions, raw metrics, raw payload, currency, time zone, idempotency key |
Traceability, normalization, deduplication |
Slate database |
|
Normalized metric record |
Source, medium, campaign, ad group, ad, creative, country, region, device, placement, metrics, tags, notes, edit status |
Editable governed reporting record |
Slate database and Customer-authorized exports |
|
Rules and applications |
Triggers, conditions, actions, run status, rows checked/matched/changed, old/new value |
Automated governance and audit |
Slate database |
|
Audit and edit logs |
Actor, action, before/after, reason, origin, timestamps, old/new amount |
Accountability and change history |
Slate database |
|
Saved views and reports |
Filters, columns, groupings, sorting, creator |
User-facing reporting |
Slate database |
|
Google Sheets export |
Spreadsheet ID/URL/name, export type, mode, schedule, filters, columns, status, row count |
Customer-directed export and history |
Slate database and Google Sheets |
|
Alerts |
Type, severity, status, title, message, metadata, email status |
Operational and reporting notifications |
Slate database and any configured email provider |
|
Webhooks |
Source, event ID, receipt time |
Deduplication and event handling |
Slate database and logs |
|
Site/product analytics |
Page, event, referrer, campaign, device, cookie, session, error |
Slate-controlled analytics and improvement |
Google Analytics and Heap only when configured and consented |
|
Slate marketing profile |
Business contact, subscription/consent, suppression, campaign engagement |
Slate communications and marketing |
Slate-controlled communications records; no production marketing automation vendor identified as enabled |
Appendix B. Integration and provider matrix
|
Integration or provider |
Status as of August 30, 2026 |
Access or role |
Privacy treatment |
|
Google Sign-In via Clerk |
Identified for use |
Authentication profile and session |
Separate from data-source authorization |
|
Google Ads |
Active code-backed connector |
`adwords` OAuth scope; reporting data |
Google Limited Use; no Slate advertising use |
|
Google Analytics 4 data source |
Active code-backed connector |
`analytics.readonly` |
Customer-facing aggregate analytics reporting |
|
Google Sheets |
Active code-backed export destination |
`spreadsheets` and `drive.file` |
Customer-directed file creation/editing only |
|
Google Docs |
Not active in audited implementation |
No active Docs scope identified |
No current access; policy/consent update required before activation |
|
Google Slides |
Not active in audited implementation |
No active Slides scope identified |
No current access; policy/consent update required before activation |
|
General Google Drive |
Not active; `drive.file` only for Sheets workflow |
No broad Drive scope identified |
Do not claim access to all Drive files |
|
Meta Ads |
Active code-backed connector |
`ads_read`, `business_management` |
Customer-facing reporting; Meta terms apply |
|
LinkedIn Ads |
Active code-backed connector |
`r_ads`, `r_ads_reporting` |
Customer-facing reporting; program approval required |
|
Microsoft Advertising |
Active code-backed connector |
`openid`, `offline_access`, `msads.manage` |
Used for reporting; disclose broader permission accurately |
|
TikTok Ads |
Active code-backed connector |
App-approved dynamic scopes |
Customer-facing reporting; app approval and data terms apply |
|
Reddit Ads |
Active code-backed connector |
`adsread`, `identity` |
Customer-facing reporting; production user-agent and commercial approval review required |
|
Shopify |
Active code-backed connector |
No universal required data scope; table-selected optional `read_orders`, `read_customers`, `read_products`, `read_inventory`, `read_locations`, and `read_marketing_events`; `read_all_orders` is used only if separately granted |
Shop, orders/line items, limited customers, products/variants, inventory, locations, attribution visits, privacy webhooks, and derived reporting; Protected Customer Data review applies |
|
Amazon Ads |
Provider enum only; no live connector established |
None confirmed |
Do not claim active access |
|
Klaviyo data source |
Planned/desired; not active in audited connector registry |
None confirmed |
Separate from Slate marketing Klaviyo account |
|
Pinterest / Spotify |
Inactive or placeholder concepts only |
None confirmed |
Do not claim active access |
|
Clerk |
Active dependency |
Authentication and organization management |
Processor/service provider plus independent-controller account data |
|
Neon Postgres |
Active infrastructure |
Primary application database |
Databricks/Neon processor in AWS us-east-1; six-hour recovery history; SCCs and UK Addendum for restricted transfers |
|
Vercel |
Active infrastructure |
Hosting, execution, deployment, logs, jobs |
Vercel processor in iad1 / AWS us-east-1; global CDN; one-day runtime logs; SCCs and UK IDTA |
|
Stripe |
Production enablement not established |
Subscription and payment administration |
Excluded from the verified production-provider list as of the effective date |
|
Google Analytics for Slate |
Enabled through the published production GTM container |
Slate website/product analytics |
GA4 page-view measurement only; 14-month user/event retention; reset off; Signals, advertising, enhanced measurement, and User-ID disabled |
|
Heap |
Enabled on Slate-controlled production surfaces through the shared production environment |
Product and website analytics, interactions, and Heap-generated pseudonymous user and session identifiers; no Slate identity calls |
US Product Analytics region; 37-month retention; replay, target text, IP, and geolocation capture disabled |
|
Google Ads / Meta Ads for Slate |
Not enabled in production |
Slate advertising and measurement |
No advertising pixel, retargeting, enhanced matching, audience, or conversion tag enabled |
|
Klaviyo for Slate marketing |
Not enabled in production |
Marketing profiles, consent, suppression, message events |
Excluded from the verified production-provider list as of the effective date |
|
GitHub |
Active private source-control repositories |
Code and development history |
Not a production Customer-data store; no secrets or live data |
|
Svix hosted service |
Not established by dependency alone |
Possible webhook service only if separately configured |
Hosted service not established and excluded from the production-provider list |
Appendix C. Official platform notices reviewed
The following official materials informed the platform-specific disclosures as of the effective date. Slate reviews applicable terms and notices when adding scopes or materially changing a connector.
- Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
- Google Workspace API User Data and Developer Policy: https://developers.google.com/workspace/workspace-api-user-data-developer-policy
- Google Ads API Required Minimum Functionality: https://developers.google.com/google-ads/api/docs/api-policy/rmf
- Google Ads API Terms and Policies: https://developers.google.com/google-ads/api/terms
- Google Analytics Terms: https://www.google.com/analytics/terms/
- Google EU User Consent Policy: https://www.google.com/about/company/user-consent-policy/
- Meta Platform Terms: https://developers.facebook.com/terms/
- Meta Developer Policies: https://developers.facebook.com/devpolicy/
- LinkedIn Marketing Developer Terms: https://www.linkedin.com/legal/l/marketing-api-terms
- Microsoft Advertising Policies: https://about.ads.microsoft.com/en-us/resources/policies
- TikTok Business Products Data Terms: https://ads.tiktok.com/i18n/official/policy/controller-to-controller/privacy
- Reddit Data API Terms: https://redditinc.com/policies/data-api-terms
- Shopify API License and Terms of Use: https://www.shopify.com/legal/api-terms
- Shopify Protected Customer Data Requirements: https://shopify.dev/docs/apps/launch/protected-customer-data
- Amazon Ads API documentation: https://advertising.amazon.com/API/docs/en-us/info/api-overview
- Clerk Privacy Policy and DPA: https://clerk.com/legal/privacy
- Vercel DPA: https://vercel.com/legal/dpa
- Neon Privacy and DPA resources: https://neon.com/privacy-policy
- Stripe Privacy Center: https://stripe.com/legal/privacy-center
- Heap Privacy and Session Replay guidance: https://help.heap.io/hc/en-us/sections/36055200771601-Session-Replay-Data-Privacy
- Klaviyo Privacy Center: https://privacy.klaviyo.com/
- California CCPA and Global Privacy Control guidance: https://oag.ca.gov/privacy/ccpa
- FTC privacy and security guidance: https://www.ftc.gov/business-guidance/privacy-security
