Privacy Policy
Last updated: August 20, 2026
1. Who we are
RMA is a platform by UpNXT for planning, approving, and tracking
marketing campaigns. This privacy policy explains what data we collect,
why, and how you stay in control of it — in particular when you connect
your Google account.
2. What data we collect
- Account details you provide yourself (name, email address, organization)
- Content and data you create within campaigns
- If you connect Google: your email address (for identification) and, only with your explicit consent, read access to the Google Analytics (GA4) property you select
- Performance metrics (such as sessions, engaged sessions, page views, and bounce rate) fetched from your GA4 property, stored so your Performance dashboard can show historical trends over time rather than only the latest snapshot
- If you connect Meta: your Facebook name and account ID (for identification), and the names/IDs of the Facebook Pages and Instagram accounts that account manages, so an admin can choose which one each client organization publishes to
- A Page access token for each Facebook Page/Instagram account an admin selects, used only to publish approved campaign content and to read insights (impressions, reach, likes, comments, shares) for posts RMA published on that Page/account
3. Use of Google user data
RMA uses Google Sign-In solely to identify your account via your email
address. When you explicitly grant the analytics.readonly
scope, we use that read access only to fetch the data of the GA4 property
you chose and display it in your own Performance dashboard within RMA.
This data is never used for advertising purposes, never sold, and never
shared with third parties beyond what's necessary to operate RMA itself.
3a. Use of Meta (Facebook & Instagram) data
RMA uses Facebook Login solely to let an admin authorize which Facebook
Pages and Instagram accounts RMA may publish to on behalf of an
organization. We request pages_show_list,
pages_read_engagement, pages_read_user_content,
pages_manage_posts, instagram_basic,
instagram_content_publish, instagram_manage_insights,
read_insights, and business_management so RMA
can list Pages/Instagram accounts, publish approved posts, and read
performance metrics for the posts it publishes — nothing is published or
read beyond the specific Page/account an admin selects.
This data is never used for advertising purposes, never sold, and never
shared with third parties beyond what's necessary to operate RMA itself.
4. Storage and security
We protect sensitive data with the following mechanisms:
- Encryption at rest: Google and Meta access/refresh/page tokens are encrypted using AES-256-GCM authenticated encryption before being stored, with a unique random initialization vector generated for every encryption operation. Tokens are never stored in plain text.
- Encryption in transit: all communication between your browser and RMA, and between RMA and Google's/Meta's APIs, is encrypted using HTTPS/TLS.
- Access control: stored tokens and analytics/insights data are only accessible to RMA's backend systems, used solely to fetch or publish data on your behalf at your request.
- Deletion on disconnect: disconnecting an integration permanently deletes its stored tokens from our database — this is an immediate, irreversible deletion, not a soft-disable.
- Retention: performance data fetched from your GA4 property or from Meta is retained for as long as the connection remains active, so your Performance dashboard can show historical trends. You may request deletion of this historical data at any time by contacting developer@cruxdigits.nl.
5. Revoking access
You can disconnect the Google integration at any time via the Performance
page within RMA, or directly through your
Google Account permissions.
You can disconnect the Meta integration at any time via Koppelingen
within RMA, or directly through your
Facebook Business Integrations settings.
Once access is revoked, RMA deletes the associated tokens — see our
Data Deletion Instructions for details.
6. Contact
Questions about this privacy policy or your data? Contact us at
developer@cruxdigits.nl.