Privacy policy

Last updated: September 29, 2026

AccessLink is a service operated by Mio Puerto Rico LLC ("we"). This policy explains what data AccessLink collects, how it uses it, and how you can ask for it to be deleted.

There are two parties in AccessLink: the agency, which uses AccessLink to request access, and the client, the business that grants that access to the agency. This policy applies to both.

Data we collect

Business profile: the data the client fills in before granting access (legal name, trade name, contact person with name and email, phone, mailing address and business registration number).

Assets and grants: the IDs and names of the ad accounts, pages, pixels, properties and containers the client chooses to share, the access level granted, the date and the result of each step.

Agency team: name and email of the agency's people who use AccessLink.

Technical data: server logs (IP address, browser, date and time) that we use to run and protect the service.

Google data

When the client connects Google, AccessLink asks for these scopes and uses them only as described:

openid and email: identify the Google account that authorizes.

adwords (Google Ads): list the client's Google Ads accounts and accept the link invitation sent by the agency's manager account.

analytics.manage.users (Google Analytics 4): list the client's properties and add the agency's email with the role the agency requested.

tagmanager.manage.users (Google Tag Manager): list the client's containers and add the agency's email with the permission the agency requested.

AccessLink does not read metrics, campaigns, audiences or any other data in those accounts. We do not use Google data for advertising, we do not sell it, and we do not use it to train artificial intelligence models. No person reads it, except with your permission, for security, or when the law requires it.

AccessLink's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Meta data

When the client connects Meta, they sign in with Facebook Login for Business and AccessLink asks for permissions such as business_management, ads_management, ads_read, pages_show_list and pages_read_engagement.

AccessLink uses them only to list the assets in the client's Business Manager (ad accounts, pages, pixels, catalogs and Instagram accounts) and to add the agency's Business Manager as a partner on the assets the client picks, with the tasks the agency requested.

AccessLink does not read posts, messages, metrics or audience data. We do not sell Meta data or use it for advertising. We handle that data in accordance with the Meta Platform Terms.

Meta and Google credentials

The client's OAuth credentials (the access tokens Meta and Google issue when the client grants permission) are used only during their session to list their assets and make the grant. Then they are discarded: they are not stored in our database.

AccessLink never sees or stores the client's Meta or Google password: sign-in happens on Meta's and Google's own pages.

The only thing kept is what is needed to show the status: asset IDs and names, the level granted and the request history.

The credential for the agency's Google Ads manager account (the agency's, not the client's) is stored encrypted, because the agency needs it to send link invitations.

How we use the data

To provide the service: create the access request, make the grants the client asks for and show their status.

To notify: send the agency and the client confirmation emails and one reminder if the request is left incomplete.

To deliver the business profile and the grants to the agency, including into its internal systems (for example, its CRM).

To run and protect the service, and to comply with the law.

Who we share data with

The agency the client grants access to: it sees the business profile, the granted assets and the request history. Each agency sees only its own data.

The providers that run AccessLink for us: Supabase (database and authentication), Vercel (hosting) and Resend (email delivery).

Authorities, only when the law requires it.

We do not sell or rent personal data.

How long we keep data

We keep the business profile, grants and history while the agency uses AccessLink, or until deletion is requested. Technical logs are kept only as long as needed to run and protect the service.

Deleting your data and revoking access

To ask for your data to be deleted, email privacy@useaccesslink.com with your business name and contact email. We delete it within 30 days and confirm by email.

You can remove AccessLink's permission from your Google or Meta account at any time in that account's settings.

Removing AccessLink's permission does not remove the agency's access: that access lives in your Meta or Google account. To remove it, remove the agency as a partner in your Business Manager, or its user or link in Google Ads, Analytics or Tag Manager.

Security

All traffic is encrypted (HTTPS). Each agency's data is separated at the database level. Each request link uses a random 256-bit token that cannot be guessed.

Your rights

You can ask us to see, correct or delete your data by emailing privacy@useaccesslink.com. If you are an agency's client, you can also ask the agency.

Minors

AccessLink is for businesses and is not directed to anyone under 18.

Changes to this policy

If we change this policy, we will post the new version on this page with its date. If the change is significant, we will notify agencies by email.

Contact

Mio Puerto Rico LLC, Puerto Rico. Email: privacy@useaccesslink.com.