Slate
Product OverviewData SourcesManual DataGovernance & Audit TrailExports
Why Slate
Connect sourcesReview and reconcileExport records
Pricing
BlogDocsAbout SlateSecurity
Sign inStart with your first source

SLATE

Slate Privacy Policy

Privacy disclosures for slatedata.app, my.slatedata.app, connected marketing platforms, and Slate-operated marketing systems

Effective date: July 21, 2026
Last updated: July 21, 2026
Version: 1.0

Publication status
The substantive policy is complete for the audited Slate architecture and the platform stack identified for use. A verified legal operator name, business mailing address, and public privacy-request method were not available and were not invented. Those three items must be displayed with this Policy before external personal data is collected or a public OAuth/platform review is submitted.


Contents

1. Scope and identity of the service

2. Slate roles: controller/business and processor/service provider

3. Definitions

4. Personal information and data Slate processes

5. Sources of information

6. Purposes and legal bases

7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive

8. Other connected advertising, analytics, ecommerce, and lifecycle platforms

9. Hosting, authentication, database, billing, analytics, and marketing providers

10. Cookies, local storage, pixels, analytics, and session replay

11. Disclosures of information

12. Sale, sharing, targeted advertising, and Global Privacy Control

13. Retention, deletion, revocation, and backups

14. Security

15. International data transfers

16. Privacy rights and choices

17. California and other U.S. state disclosures

18. EEA, United Kingdom, and Switzerland disclosures

19. Children and business use

20. Changes to this Policy

21. Contact and publication condition

Appendix A. Detailed data inventory

Appendix B. Integration and provider matrix

Appendix C. Official platform notices reviewed


Read this first
This Policy distinguishes between Slate-controlled information (such as account, billing, website analytics, security, and Slate marketing data) and Customer-controlled information (such as data imported from a customer-connected advertising, analytics, ecommerce, or lifecycle platform). Slate must not use Customer Content, Connected Data, or Google API Data for Slate advertising, cross-customer profiling, data brokerage, or general-purpose model training.


1. Scope and identity of the service

This Privacy Policy explains how the person or legal entity that owns and operates Slate (collectively, "Slate," "we," "us," or "our") collects, uses, stores, discloses, and otherwise processes information in connection with the public website at slatedata.app, the Slate application at my.slatedata.app, related pages and communications, and the marketing-data aggregation, normalization, governance, reporting, and export services made available through Slate (collectively, the "Service").

Slate is designed for business use by marketing teams, agencies, finance-adjacent teams, and other organizations. This Policy applies to visitors, users, organization administrators, invited members, prospective customers, and individuals whose information is contained in data that an authorized Slate customer imports or connects to the Service.

This Policy does not govern the independent privacy practices of Google, Meta, LinkedIn, Microsoft, TikTok, Reddit, Shopify, Amazon, Stripe, Clerk, Vercel, Neon, Heap, Klaviyo, or any other third-party platform. Those providers process information under their own terms and privacy notices when a person uses their services directly.

Where an organization provides a separate privacy notice or contract that applies to its Slate workspace, that organization notice may provide additional details about the organization's processing. If an organization controls data in Slate, questions about that data should ordinarily be directed to the organization first.

2. Slate roles: controller/business and processor/service provider

2.1 Slate as controller or business

Slate determines the purposes and means of processing for information needed to operate its own business and Service, including public-site data, account administration, authentication configuration, billing records, security logs, product analytics, support communications, legal compliance, and Slate's own marketing. For this information, Slate acts as a controller under the GDPR and analogous laws and as a business under the California Consumer Privacy Act, where those laws apply.

2.2 Slate as processor or service provider

For Customer Content and Connected Data submitted, imported, synchronized, normalized, edited, governed, reported, or exported at an organization's direction, the organization generally determines why and how that information is processed. Slate processes that information to provide the contracted Service and acts as a processor, service provider, or contractor, as applicable. The organization is responsible for its instructions, lawful basis, notices, consents, platform permissions, and responses to data-subject requests.

2.3 Platform-specific restrictions

Google API Data and data obtained from other connected platforms remain subject to the applicable platform terms, developer policies, approved scopes, and user instructions. A customer's ability to access information through Slate does not expand the customer's rights in that information or override the connected platform's restrictions.

3. Definitions

Term

Meaning

Account Data

Information used to create, authenticate, secure, administer, and support an individual Slate account, including identity, contact, session, and organization-membership information.

Customer

The organization, business, agency, or other entity that creates or controls a Slate workspace, including an authorized administrator acting for that entity.

Customer Content

Information submitted directly by or for a Customer, including uploaded files, pasted rows, manual entries, labels, notes, corrections, rules, saved views, reports, and export configurations.

Connected Data

Information retrieved from or sent to a third-party service at a Customer's direction through an authorized integration, including raw, normalized, derived, and metadata fields.

Google API Data

Information obtained from Google API Services through Google OAuth scopes, together with data aggregated, normalized, or derived from that information.

Personal Information

Information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to a person or household, and analogous terms under applicable law.

Service Data

Technical, operational, diagnostic, security, and usage information generated by use of Slate.

Slate Marketing Data

Information collected by Slate for its own website analytics, product analytics, advertising measurement, lead management, and marketing communications. It excludes Customer Content, Connected Data, and Google API Data.

User

An individual who visits, registers for, is invited to, or uses the Service.


4. Personal information and data Slate processes

4.1 Account, identity, and authentication data

  •   Identity and contact: name, business email address, profile or avatar image, and similar account information.
  •   Authentication identifiers: Clerk user identifiers, Google Sign-In identifiers when Google is selected, organization identifiers, membership identifiers, and session identifiers.
  •   Authentication and security events: sign-in, sign-out, invitation, session, device, browser, IP address, authentication outcome, and related timestamps or risk signals made available by authentication and hosting providers.
  •   Organization membership: workspace name, role, invitation status, permissions, and administrator actions. Slate currently uses Admin, Editor, and Viewer roles.
  •   Preferences: user-interface, display, notification, saved-view, and other account preferences stored by Slate.
  •   Passwords and payment credentials: Slate does not intend to receive or store a user's Google password, Clerk-managed password, complete payment-card number, card verification code, or bank-account credentials. Those values are handled by the relevant authentication or payment provider.

4.2 Organization and workspace administration data

  •   organization name and external organization identifier;
  •   default currency, time zone, fiscal-year start, date format, business type, onboarding status, and workspace settings;
  •   roles, permissions, membership history, administrator actions, and invitation information;
  •   source ownership, labels, channels, notes, statuses, and data-governance configuration; and
  •   rules, conditions, actions, run history, and exception information used to govern or transform records.

4.3 Subscription, billing, and transaction administration data

  •   plan, billing status, trial status, subscription status, current billing-period end, and cancellation status;
  •   Stripe customer, subscription, price, invoice, and checkout identifiers;
  •   payment status, tax-related or invoicing information provided through the payment flow, and records needed for accounting, fraud prevention, and dispute handling; and
  •   communications about trials, renewals, failed payments, plan changes, cancellations, or support. Stripe may independently collect payment-method, device, transaction, fraud-prevention, and identity information under Stripe's privacy notice.

4.4 Integration authorization and connection data

  •   provider name, approved OAuth scopes or permissions, external account identifier and name, token issue and expiration information, and connection status;
  •   OAuth access and refresh tokens stored in encrypted form, together with encrypted or protected state and verifier values used during authorization;
  •   the user who connected or updated an organization integration, authorization and callback events, and disconnection or error status;
  •   synchronization start and finish times, status, summary information, retry information, error messages, and records of the source accounts selected by a Customer; and
  •   provider-specific metadata needed to select an account, attribute imported rows, refresh authorization, or operate a scheduled import or export.

4.5 Connected advertising and analytics data

Depending on the provider, permissions approved, Customer configuration, and report level, Slate may retrieve and store account, campaign, campaign-group, ad-group, ad-set, ad, keyword, creative, placement, device, geography, network, objective, status, date, currency, time-zone, source, medium, and attribution information. Metrics may include spend or cost, impressions, clicks, reach, conversions, conversion value, revenue, engagements, likes, shares, comments, follows, leads, video views, video completion metrics, and related calculated metrics such as click-through rate, cost per click, cost per acquisition, return on ad spend, or other ratios derived in Slate.

Slate may retain raw API response fields and payloads, normalized records, source-account metadata, identifiers needed for deduplication, and audit records showing when and how a value was imported, normalized, edited, corrected, excluded, labeled, or exported. Raw platform data may contain personal information even when Slate primarily presents aggregate marketing metrics.

4.6 Ecommerce and order data

For Shopify and any later-approved ecommerce integration, Connected Data can include store and account identifiers, order identifiers, order date, order status, currency, subtotal, discounts, shipping, taxes, refunds, total, item counts, source or landing-site information, referring site, customer or buyer identifier, and campaign or UTM parameters. Slate should not be configured to ingest names, email addresses, postal addresses, phone numbers, full payment information, or other protected customer data unless the applicable feature, platform approval, Customer instructions, contracts, and privacy controls expressly require and authorize it.

4.7 Customer-created, uploaded, and manually entered data

  •   CSV, TSV, spreadsheet, pasted, uploaded, or manually entered marketing records;
  •   vendor or source names, dates, amounts, currency, campaign details, notes, reference identifiers, and custom tags;
  •   correction reasons, old and new values, approval or actor information, overwrite decisions, edit history, and audit entries;
  •   saved filters, columns, grouping, sorting, reports, templates, dashboards, exports, alerts, and scheduling settings; and
  •   any personal information a Customer chooses to place in free-text, notes, file contents, custom fields, or raw uploads. Customers must not place sensitive or unrelated personal information in Slate.

4.8 Export and destination data

  •   Google spreadsheet identifier, URL, name, destination mode, export type, date range, filters, columns, dimensions, sorting, schedule, status, row count, and error information;
  •   CSV export configuration and download events;
  •   scheduled export creator, next-run and last-run timestamps, and export history; and
  •   information sent to the destination selected by the Customer. Once information is exported, the destination provider and Customer control further access and retention.

4.9 Support, communications, and feedback

  •   support requests, messages, screenshots, attachments, call notes, issue details, and troubleshooting data;
  •   survey responses, feedback, feature requests, testimonials submitted with permission, and communications with Slate;
  •   administrative and service notices, including security, billing, integration, and policy communications; and
  •   marketing subscription status, consent records, unsubscribe or suppression status, campaign interaction data, and attribution information.

4.10 Device, usage, cookie, and diagnostic data

  •   IP address, browser, operating system, device type, language, approximate location inferred from IP, referring URL, landing page, and page path;
  •   cookie, local-storage, advertising, analytics, session, and device identifiers;
  •   pages and features viewed, buttons or links used, timestamps, navigation sequences, errors, latency, and performance data;
  •   authentication, authorization, webhook, API, job, database, hosting, and application logs; and
  •   product analytics events and, if specifically enabled, session-replay data subject to consent, page exclusions, and masking controls described below.

4.11 Information Slate does not intentionally request

Slate is not designed to collect or process protected health information, Social Security numbers, government identification numbers, biometric templates, precise geolocation, children's data, complete payment-card data, passwords, data about sex life or sexual orientation, genetic data, or other special-category or highly sensitive information. Customers must not upload or connect such information unless Slate has expressly agreed in a written contract and implemented the required product, legal, and security controls. No such agreement or special regulated-data feature is identified as active as of the effective date of this Policy.

5. Sources of information

  •   Directly from Users and Customers: registration, invitations, settings, files, manual entries, forms, support, billing, and communications.
  •   From Customer administrators and coworkers: invitations, roles, workspace configuration, account details, and content submitted about or by organization members.
  •   From Google and other connected platforms: authorized OAuth profile information, account lists, platform reports, analytics, orders, metadata, tokens, and API responses.
  •   From Clerk, Stripe, Vercel, Neon, and other service providers: authentication events, billing status, hosting logs, security signals, service telemetry, and operational data needed to provide the Service.
  •   Automatically from browsers and devices: cookies, IP address, page events, diagnostics, and usage information.
  •   From Slate marketing activities: advertising platforms, lead or campaign forms, Klaviyo communications, referrals, event or content interactions, and campaign parameters.
  •   From public or business sources: business contact information and company information used for legitimate business-to-business sales, fraud prevention, due diligence, or customer support, where permitted by law.

6. Purposes and legal bases

Slate processes information only for purposes that are compatible with the context in which the information was collected, the Customer's instructions, the applicable platform permissions, and applicable law. Where the GDPR, UK GDPR, or a similar law requires a legal basis, the basis depends on the information and context.

Purpose

Information involved

Typical legal basis

Provide and administer the Service

Account Data, organization settings, Customer Content, Connected Data, integration data, exports, and Service Data

Performance of a contract; steps requested before entering a contract; legitimate interests in providing the Service

Authenticate and control access

Identity, Google Sign-In data, Clerk identifiers, sessions, roles, device and security information

Contract; legitimate interests in secure access; legal obligation where applicable

Connect, synchronize, normalize, govern, report, and export data

OAuth permissions and tokens, Connected Data, raw payloads, normalized metrics, rules, corrections, and destination data

Contract; Customer instructions; legitimate interests; consent where platform or law requires

Bill and manage subscriptions

Plan, subscription, Stripe identifiers, payment status, invoicing and tax information

Contract; legal obligation; legitimate interests in fraud prevention and collections

Secure, monitor, and troubleshoot the Service

Logs, IP, device, error, webhook, job, database, authentication, and audit information

Legitimate interests in security, reliability, fraud prevention, and abuse prevention; legal obligation

Provide support and communicate

Account and contact data, support content, diagnostics, billing and service status

Contract; legitimate interests; consent where required

Analyze and improve Slate

Slate-controlled usage and product analytics; deidentified or aggregate service statistics

Legitimate interests; consent for non-essential cookies where required. Google API Data and other restricted Connected Data are excluded unless the use is a permitted user-facing feature.

Market Slate and measure campaigns

Public-site events, marketing contact information, consent and suppression status, campaign and advertising identifiers

Consent where required; legitimate interests for permitted business marketing; compliance with opt-out rights

Comply with law and protect rights

Any information reasonably necessary for legal process, tax, accounting, sanctions, investigations, disputes, and enforcement

Legal obligation; legitimate interests; establishment, exercise, or defense of legal claims


Where Slate relies on consent, a person may withdraw consent at any time through the available preference mechanism or request channel. Withdrawal does not affect processing already completed lawfully. Where Slate relies on legitimate interests, Slate considers the purpose, necessity, and effects on individuals and applies safeguards appropriate to the information.

7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive

Google Limited Use commitment
Slate's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.


7.1 Google Sign-In

A User may choose Google Sign-In through Clerk. Google Sign-In is used to authenticate the User and create or link the User's Slate account. Depending on the User's Google and Clerk configuration, Slate may receive the User's Google account identifier, name, email address, profile image, and authentication metadata. Signing in with Google does not itself authorize Slate to read Google Ads, Google Analytics, Google Sheets, Google Docs, Google Slides, or Google Drive content.

7.2 Google Ads as a connected data source

When a Customer connects Google Ads, Slate requests the Google Ads OAuth scope `https://www.googleapis.com/auth/adwords`. This scope permits access to Google Ads accounts that the authorizing User is entitled to access. Slate uses that access to list selectable customer or manager accounts and retrieve reporting data for the Customer-facing aggregation, normalization, audit, reporting, and export features of Slate.

Google Ads data can include customer and manager account identifiers and names; account currency and time zone; campaign, ad group, ad, keyword, network, device, geography, status, and date fields; cost, impressions, clicks, conversions, conversion value, and other report metrics selected for the implemented Slate reporting level; and raw response metadata needed to validate and normalize those records.

Slate is a reporting and data-governance product, not a full-service Google Ads campaign-management tool as currently implemented. Google Ads reporting-only Required Minimum Functionality and developer-token requirements may apply depending on Slate's developer-token access level and interface. Those operational qualifications are addressed in the separate Legal Readiness Register.

7.3 Google Analytics 4 as a connected data source

When a Customer connects Google Analytics 4, Slate requests the read-only OAuth scope `https://www.googleapis.com/auth/analytics.readonly`. Slate uses that access to identify properties and retrieve Customer-selected analytics dimensions and metrics for Customer-facing reporting and reconciliation. Depending on the report configuration, data can include property identifiers and names, date, source, medium, campaign, device, geography, sessions, users, events, conversions or key events, revenue, and related aggregate measurements.

Slate does not use a Customer's connected Google Analytics data to advertise Slate, build cross-customer audiences, identify visitors on unrelated services, or train general-purpose artificial-intelligence or machine-learning models.

7.4 Google Sheets as an export destination

When a Customer connects Google Sheets, Slate requests `https://www.googleapis.com/auth/spreadsheets` and `https://www.googleapis.com/auth/drive.file`. The spreadsheets scope allows Slate to create and edit spreadsheets as directed by the Customer. The `drive.file` scope is intended to limit Drive access to files that the User creates with Slate or explicitly opens or shares with Slate; it does not grant general access to every file in the User's Drive.

Slate stores destination spreadsheet identifiers, URLs, names, export settings, schedules, row counts, and status information necessary to run and audit exports. Slate writes only the data selected for export by an authorized User or scheduled configuration. After data is written to Google Sheets, the Customer and Google control access, sharing, version history, retention, and downstream use in the destination file.

7.5 Google Docs, Google Slides, and broader Google Drive access

As of the effective date, the audited Slate implementation does not register an active Google Docs connector, Google Slides connector, or general Google Drive connector, and does not request broad Drive scopes that read all Drive files. Slate therefore does not currently access the contents of Google Docs or Google Slides through those APIs. Before any such feature is activated, Slate must implement only the minimum necessary scope, update this Policy and in-product disclosures, complete any required Google verification or security assessment, and obtain fresh, contextual authorization from affected Users.

7.6 How Slate uses, shares, and protects Google API Data

  •   Permitted use: provide or improve the Customer-facing feature for which the User authorized access, including account selection, import, normalization, governance, reporting, reconciliation, and export.
  •   No advertising use: Slate does not sell, transfer, or use Google API Data for serving ads, retargeting, personalized advertising, audience creation, or interest-based advertising.
  •   No data brokerage or surveillance: Slate does not sell or distribute Google API Data to data brokers, information resellers, surveillance providers, credit providers, or unrelated third parties.
  •   No general model training: Slate does not use Google API Data to train general-purpose artificial-intelligence or machine-learning models. Any future user-facing model feature involving Google API Data would require a permitted use, specific disclosures, appropriate controls, and any required consent or Google approval before launch.
  •   Limited disclosure: Slate discloses Google API Data only to infrastructure or service providers that process it for Slate under appropriate confidentiality and data-protection restrictions, to the Customer and its authorized Users, to a destination expressly chosen by the Customer, or when legally required.
  •   Human access: Slate personnel may access Google API Data only when necessary for security, abuse investigation, support requested by the Customer, legal compliance, or operation of a permitted user-facing feature, and only under access restrictions and confidentiality obligations.
  •   Security: Google OAuth tokens are stored encrypted at rest; Google API Data must be transmitted over secure protocols and protected using access controls, secret management, logging, and incident-response procedures.
  •   Minimum permissions: Slate must request only the scopes needed for active features and must not request speculative scopes for unimplemented Docs, Slides, Drive, or other features.

7.7 Disconnecting Google and deleting Google API Data

An authorized administrator or User can disconnect the applicable Google integration through the available Slate connection controls and can also revoke Slate's access through the User's Google account security settings. Disconnection stops new API access after the revocation is processed. Slate will delete or render inaccessible the associated active tokens and will delete Google API Data when required by the Customer's instruction, account deletion, platform terms, or applicable law, subject to narrowly limited legal-retention obligations and backup aging.

Deleting a Slate account does not automatically delete data already exported to a Customer-owned Google spreadsheet. The Customer must delete or restrict the destination file separately. Likewise, revoking Google access does not necessarily remove historical data that the Customer lawfully imported before revocation; the Customer or authorized User must submit a deletion instruction if historical data should also be removed, unless platform rules require automatic removal.

8. Other connected advertising, analytics, ecommerce, and lifecycle platforms

The integrations below are described according to the audited implementation as of the effective date. A provider may impose additional review, permission, retention, attribution, branding, or deletion rules. Slate processes only the accounts and data that an authorized User selects and only within the provider access approved for Slate.

8.1 Meta Ads

Slate requests Meta permissions `ads_read` and `business_management` for the Meta Ads connector. Slate may use them to identify businesses and ad accounts the authorizing User can access and to retrieve account, campaign, ad set, ad, placement, device, geography, objective, spend, impression, reach, click, conversion, value, engagement, and video-performance data. Slate stores connection metadata, encrypted tokens, selected account identifiers, raw response data, normalized metrics, and sync history. Meta data is used only for Customer-facing Slate features and remains subject to Meta Platform Terms and Developer Policies.

8.2 LinkedIn Ads

Slate requests LinkedIn permissions `r_ads` and `r_ads_reporting`. Slate may retrieve authorized ad-account, campaign, campaign-group, creative, date, currency, status, objective, spend, impression, click, conversion, value, reach, and engagement information. Slate must maintain LinkedIn program approval and comply with the LinkedIn Marketing Developer Terms, including restrictions on access, client relationships, security, storage, use, and onward disclosure.

8.3 Microsoft Advertising

Slate requests `openid`, `offline_access`, and `https://ads.microsoft.com/msads.manage`. The Microsoft Ads permission is broader than read-only naming may suggest, even though Slate currently uses the connection for account discovery and reporting. Slate may process Microsoft identity and authorized account information, reporting-job metadata, campaign and ad identifiers, status, keyword or search-query fields where implemented, device and network dimensions, spend, impressions, clicks, conversions, revenue, and related metrics. Slate must protect the developer token and OAuth credentials and must not expose management functionality that has not been designed, authorized, and disclosed.

8.4 TikTok Ads

Slate uses TikTok API for Business authorization to access the advertiser accounts and scopes approved for the Slate app. TikTok scopes can be returned dynamically by TikTok rather than being fixed in the current source code. Slate may process advertiser and campaign identifiers, date, currency, campaign status, objective, placements, geography, device, spend, impressions, reach, clicks, conversions, conversion value, video metrics, and engagement metrics. Any separate TikTok Pixel, Events API, Advanced Matching, or Customer Audience use by Slate as an advertiser is governed by Section 9 and requires the applicable notice and consent; it is not sourced from Customer-connected TikTok Ads data.

8.5 Reddit Ads

Slate requests Reddit permissions `adsread` and `identity`. Slate may process Reddit account identity needed for authorization, ad-account identifiers and metadata, campaign and ad identifiers, placement or community dimensions, location, spend, impressions, clicks, conversions, value, reach, video metrics, and leads. Reddit requires accurate identification, a compliant privacy policy, adherence to API limits and attribution requirements, and deletion of cached or stored Reddit material when required upon termination. Slate must also use an accurate production user-agent identifier.

8.6 Shopify

The audited Shopify connector defaults to the `read_orders` scope, subject to the production app configuration and Shopify approval. Slate may process store and account identifiers, order identifiers, dates, status, currency, subtotal, discounts, shipping, taxes, refunds, totals, item counts, customer or buyer identifier, referring or landing-site information, source information, and UTM parameters. Shopify order and customer-related data can be Protected Customer Data. Slate and each Customer must comply with Shopify's API terms, protected-data requirements, data-minimization rules, access review requirements, and mandatory privacy webhooks where applicable.

8.7 Amazon Ads

The Slate data model contains an Amazon Ads provider designation, but the audited implementation did not establish a live Amazon Ads connector. Slate does not represent that it currently accesses Amazon Ads data. Before activation, Slate must complete the Amazon Ads application and approval process, document the precise scopes and reports, update this Policy, obtain Customer authorization, and satisfy Amazon-specific security, retention, attribution, and use restrictions.

8.8 Klaviyo as a Customer-connected data source

Klaviyo is identified as a desired Slate data source, but it is not registered as an active connector in the audited implementation. This is separate from Slate's own use of Klaviyo for marketing communications described in Section 9. Before a Customer-facing Klaviyo connector is activated, Slate must document the approved authentication method and scopes, the profile, campaign, flow, event, revenue, consent, and suppression fields accessed, the controller/processor roles, and the deletion and retention behavior, and must update this Policy before processing begins.

8.9 Pinterest and Spotify

Pinterest and Spotify appeared only as inactive, unregistered, or placeholder integration concepts in the reviewed product context and are not described as live data connections. Slate does not represent that it currently accesses those platforms. A future activation requires a policy update, exact scope disclosure, platform approval, contextual authorization, and a documented data lifecycle.

9. Hosting, authentication, database, billing, analytics, and marketing providers

Slate uses service providers to operate the Service. A provider may process personal information as a processor or service provider for Slate and may also process limited account, security, fraud, or business-relationship information as an independent controller under its own privacy notice. The precise provider list, plan, region, and features must be maintained as a current subprocessor register.

Provider or category

Role in Slate

Information involved

Clerk

Authentication, sessions, user and organization management, invitations, and Google Sign-In orchestration

Identity, email, avatar, user and organization IDs, membership, authentication events, sessions, device and security information

Vercel

Hosting, deployment, serverless or application execution, networking, logs, and scheduled jobs

Requests, IP and device data, application traffic, logs, environment configuration, and Customer data processed by the application

Neon

PostgreSQL database infrastructure used by Slate through Prisma and PostgreSQL clients

Account, organization, integration, Customer Content, Connected Data, raw and normalized metrics, audit, export, alert, billing, and operational records stored by Slate

Stripe

Checkout, subscription billing, payment processing, fraud prevention, invoicing, and billing administration

Billing contact and account information, payment and transaction data, device or fraud signals, and Stripe identifiers; Slate stores only the billing metadata needed to administer the subscription

Google and connected platforms

Authentication, authorized data import, reporting, and Customer-directed exports

The platform data and OAuth information described in Sections 7 and 8

Google Analytics

Slate-controlled website and product analytics where configured

Cookie and device identifiers, page and event activity, campaign/referrer information, approximate location, and technical data; not Customer Content, Connected Data, or Google API Data

Heap

Slate-controlled product analytics and, if enabled, session replay

Product events, page interactions, device and technical data, and replay reconstruction data subject to masking, exclusions, and consent; not Connected Data or sensitive fields

Klaviyo

Slate-owned marketing email, lifecycle communications, subscription preferences, and campaign measurement

Business contact details, consent and suppression status, message events, campaign attribution, and Slate marketing profile data; not Customer-connected platform data

Google Ads and Meta Ads

Slate-owned advertising delivery, attribution, conversion measurement, and audience activity where configured and permitted

Public-site events, advertising and cookie identifiers, campaign/referrer information, and conversion events; not Customer Content, Connected Data, or Google API Data

Professional and compliance providers

Legal, accounting, audit, security, insurance, and corporate administration

Only information reasonably necessary for the engagement and subject to confidentiality or professional obligations


The Slate source code is maintained in private GitHub repositories. GitHub is a development and source-control provider, not an intended production Customer-data store. Developers must not commit production secrets, OAuth tokens, database contents, Customer uploads, or personal information to source control, issues, pull requests, logs, fixtures, or test artifacts.

The application uses the Svix software library for webhook verification or handling. The audited dependency alone does not prove that Slate uses the hosted Svix service as a direct subprocessor. Slate must add Svix to the public subprocessor list only if a hosted Svix account processes Slate Customer data directly.

10. Cookies, local storage, pixels, analytics, and session replay

10.1 Categories of technology

Category

Purpose

Consent treatment

Strictly necessary

Authentication, session continuity, security, fraud prevention, load balancing, user preferences essential to a requested feature, and checkout

Used as necessary to provide the requested Service, subject to applicable law

Functional

Remember non-essential preferences, improve usability, and provide optional features

Consent or opt-out as required by jurisdiction

Analytics and performance

Understand traffic, product usage, errors, reliability, and feature performance through Google Analytics, Heap, or similar configured tools

Prior consent where required; otherwise subject to applicable opt-out rights

Advertising and measurement

Measure Slate campaigns, attribute conversions, limit frequency, build permitted audiences, and deliver or evaluate Slate advertising through Google Ads, Meta Ads, or similar tools

Prior consent and opt-out where required; GPC honored where legally required


10.2 Google Analytics used by Slate

Slate may use Google Analytics on Slate-controlled websites or application surfaces to understand traffic and product usage. Google Analytics can receive online identifiers, device and browser information, IP-derived location, referrer and campaign information, page paths, events, and conversion data. Slate must configure consent behavior, data retention, advertising features, Google Signals, User-ID, IP handling, and data-sharing settings consistently with this Policy and applicable law. Customer Content, Connected Data, and Google API Data must not be sent to Google Analytics.

10.3 Heap and session replay

Slate may use Heap for product analytics. If Heap Session Replay is enabled, Heap reconstructs a user session from captured page changes and interaction events. Slate must disclose session replay, obtain consent where required, block or exclude authentication, billing, integration, raw-data, customer, and other sensitive pages as appropriate, mask all text and form fields unless a documented review supports a narrower configuration, and test the configuration in a non-production environment before production activation.

Heap must not receive passwords, payment-card data, OAuth tokens, API credentials, Customer Content, Connected Data, Google API Data, sensitive personal information, or unrestricted free-text. If Slate discovers that sensitive information was captured, Slate must stop capture, preserve appropriate incident evidence, request deletion or purge from Heap, assess notification duties, and correct the configuration before resuming.

10.4 Slate advertising through Google Ads and Meta Ads

Slate may advertise its own Service through Google Ads and Meta Ads and may use first-party tags, pixels, conversion APIs, enhanced or advanced matching, customer-list audiences, retargeting, or similar advertising features only when configured, disclosed, and permitted. Those features can disclose public-site activity, campaign identifiers, cookie or device identifiers, and, if expressly configured with a lawful basis, hashed business contact information. They must never receive Customer Content, Connected Data, Google API Data, platform OAuth data, raw marketing records, or data obtained from a Customer workspace.

10.5 Klaviyo used by Slate for marketing

Slate may use Klaviyo to manage Slate's own marketing subscribers, business leads, lifecycle messages, consent records, suppression lists, and campaign analytics. Slate must send marketing only where permitted, identify the sender, provide a functioning unsubscribe mechanism, honor opt-outs and suppression records, and use consent standards appropriate to the recipient's location. Klaviyo marketing profiles must remain logically separate from Customer-connected Klaviyo data and other Customer Content.

10.6 Consent and preference controls

Before deploying non-essential analytics, advertising, or session-replay technologies in jurisdictions that require prior consent, Slate must present a clear preference interface that allows a person to accept or reject categories without using misleading design. Slate must preserve consent records, make withdrawal as easy as acceptance, avoid firing non-essential tags before the required choice, and propagate the choice to configured vendors. Browser settings alone may not prevent all server-side or authenticated processing.

11. Disclosures of information

Slate may disclose information only as described below and subject to applicable platform and legal restrictions.

  •   To the Customer and authorized Users: workspace administrators, members, and collaborators can access information according to their roles, Customer settings, and exports. An administrator may manage membership, revoke access, or view activity.
  •   To service providers and subprocessors: providers that host, authenticate, store, secure, support, bill, analyze, or communicate for Slate may process information under contract and only for authorized purposes.
  •   To connected platforms at the Customer's direction: Slate sends authentication requests, API requests, and Customer-selected exports to the provider selected by an authorized User.
  •   To Slate marketing and advertising providers: only Slate Marketing Data may be disclosed for Slate's own analytics, email, advertising, or measurement. Customer Content, Connected Data, and Google API Data are excluded.
  •   For legal, safety, and security reasons: Slate may disclose information when reasonably necessary to comply with law, court order, legal process, sanctions, regulatory request, or to protect rights, safety, security, and the integrity of the Service. Slate will seek to limit disclosure to what is legally required where permitted.
  •   In a business transaction: information may be disclosed in connection with financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality and applicable law. A successor must remain bound by Google and other platform restrictions for platform data.
  •   With explicit direction or consent: Slate may disclose information when a User or Customer instructs Slate to do so, such as exporting a report or authorizing support access.
  •   Deidentified or aggregate information: Slate may disclose statistics that cannot reasonably identify a person or Customer, provided Slate does not attempt reidentification and the use is not prohibited for Google API Data or another restricted platform data set.

Slate does not grant service providers independent rights to sell Customer Content or use it for their own cross-context advertising. A service provider may process separate account or business-relationship data as an independent controller only as described in its own notice and contract.

12. Sale, sharing, targeted advertising, and Global Privacy Control

12.1 No sale of Customer data

Slate does not sell Customer Content, Connected Data, Google API Data, OAuth tokens, or workspace records for money or other value. Slate does not share those data sets for cross-context behavioral advertising or use them to advertise Slate.

12.2 Slate website advertising may constitute sharing or targeted advertising

When Slate uses Google Ads, Meta Ads, or similar advertising technologies on Slate-controlled public pages, disclosure of cookie identifiers, device identifiers, and public-site activity can be considered "sharing," "targeted advertising," or a sale under certain U.S. state laws even when no money is paid for the data. Where required, Slate will provide a conspicuous privacy-choice method, honor valid opt-out requests, and avoid using opted-out data for the covered purpose.

12.3 Global Privacy Control

Where legally required, Slate will treat a recognized Global Privacy Control signal as a request to opt out of sale or sharing for the browser or device from which the signal is received. Slate must connect the signal to authenticated accounts when required and reasonably feasible, and must not require a person to create an account solely to exercise the opt-out.

12.4 Sensitive personal information

Slate does not use sensitive personal information to infer characteristics about individuals. Slate should not collect sensitive personal information beyond what is necessary for authentication, security, legal compliance, or a specifically contracted feature. If a use triggers a right to limit, Slate will provide the required mechanism before the use begins.

13. Retention, deletion, revocation, and backups

Slate retains information only for as long as reasonably necessary for the purposes described in this Policy, the Customer's documented instructions, platform requirements, security and dispute needs, and legal obligations. Because exact periods depend on account status, feature, provider, configuration, and legal requirements, the criteria below govern unless a contract, in-product notice, or published retention schedule states a shorter period.

Data category

Retention criterion

Account and organization data

For the active account or workspace, plus a limited period needed for closure, reactivation prevention, fraud, security, disputes, and legal obligations.

Billing and transaction administration

As needed to administer the subscription and satisfy tax, accounting, payment-network, fraud, chargeback, and legal-retention requirements.

OAuth tokens and connection credentials

Until disconnection, revocation, account deletion, expiration without refresh, or another required removal event. Active tokens should be revoked and encrypted token material deleted or rendered inaccessible promptly after disconnection.

Customer Content and Connected Data

For the Customer's active workspace and according to Customer instructions, contract, platform terms, and feature needs. Deleted or terminated workspace data may remain temporarily in protected backups until the backup cycle expires.

Raw payloads and normalized metrics

As needed for the Customer-facing history, audit, reconciliation, reporting, and export functions, subject to Customer deletion instructions and platform restrictions.

Audit, edit, and security records

For the period reasonably necessary to provide governance history, investigate incidents, enforce rights, meet contractual commitments, and satisfy legal obligations. Claims that records are "immutable" must be reconciled with lawful deletion requirements.

Support records

For the support relationship and a reasonable period for quality, security, dispute, and legal purposes, with sensitive attachments removed when no longer needed.

Slate marketing records

Until consent is withdrawn, the purpose ends, or the record is no longer needed, while retaining a minimal suppression record where necessary to honor an unsubscribe or do-not-contact request.

Analytics and advertising identifiers

According to the configured vendor retention setting, consent, and applicable law. Slate must choose and publish a configuration rather than relying solely on vendor defaults.

Backups

Until overwritten or expired under Slate's documented backup schedule. Deleted data must not be restored to active use except for disaster recovery and must be re-deleted or isolated after restoration.


13.1 Customer requests and termination

A Customer may request export or deletion through the Service or the published request method, subject to role authorization and legal restrictions. Slate may retain deidentified aggregate statistics, security evidence, billing records, and information necessary to establish, exercise, or defend legal claims, provided such retention is lawful and not prohibited by a platform policy.

13.2 Platform revocation and deletion

When a connected platform requires deletion, refresh-token revocation, data invalidation, privacy-webhook processing, or cache expiration, Slate will follow that requirement even if the general Slate retention criteria would otherwise permit longer retention. Customers must not reconnect or reimport data to circumvent a platform deletion request or legal right.

14. Security

Slate uses administrative, technical, and organizational safeguards designed for the nature of the Service and information processed. No system is completely secure, and Slate cannot guarantee that unauthorized access, loss, or misuse will never occur.

  •   Transport security: secure modern protocols for data in transit between users, Slate, and connected providers.
  •   Token encryption: OAuth access and refresh tokens are encrypted at rest using authenticated encryption. The audited implementation uses AES-256-GCM and a separate encryption key supplied through the environment.
  •   Access controls: authenticated access, organization scoping, role-based permissions, least-privilege administrative access, and separate development and production access where implemented.
  •   Auditability: records of material imports, edits, corrections, synchronization, settings changes, and exports where the feature supports them.
  •   Secrets and key management: production secrets must be kept outside source control, limited to authorized systems and personnel, rotated when required, and monitored for accidental exposure.
  •   Application and infrastructure controls: dependency management, code review, deployment controls, database protections, logging, monitoring, backup, recovery, and vulnerability remediation appropriate to the Service.
  •   Vendor diligence: review of subprocessors, data-protection terms, security documentation, region and transfer mechanisms, and notification procedures.
  •   Personnel controls: confidentiality obligations, access approval and removal, security awareness, and access only for a legitimate business need.
  •   Incident response: detection, containment, investigation, remediation, evidence preservation, Customer and regulator notification, and platform notification where required. Google requires notification to Google for a known or suspected unauthorized access involving Google Data under applicable policy.

Users are responsible for maintaining the security of their devices, email accounts, Google accounts, authentication factors, and Customer platform accounts; using strong authentication; limiting roles; reviewing integrations; and promptly reporting suspected compromise.

15. International data transfers

Slate and its providers may process information in the United States and other countries where they or their subprocessors operate. Those countries may have privacy laws different from the laws where an individual lives. Where required, Slate will use an approved transfer mechanism, such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework or an applicable extension when the recipient is certified, or another lawful mechanism.

The exact production hosting and database regions, Vercel and Neon plan configuration, provider transfer mechanisms, and subprocessor list must be documented before external processing begins. A provider's certification does not replace Slate's responsibility to select, configure, contract with, and disclose the provider appropriately.

16. Privacy rights and choices

Depending on location and relationship to Slate, an individual may have rights to know or confirm processing; access; obtain a copy; correct; delete; restrict or object; withdraw consent; obtain portability; opt out of sale, sharing, targeted advertising, or certain profiling; limit sensitive-information use; appeal a denial; and complain to a regulator.

16.1 How requests are handled

  1.  1. Submit the request through the privacy-request method published with this Policy or through an available authenticated account-support channel.
  2.  2. Describe the right being exercised, the Slate account or organization involved, and enough information for Slate to locate the relevant records without collecting excessive new information.
  3.  3. Slate may verify identity, authority, and account relationship using proportionate methods. Slate will not request a password, complete payment-card number, or unrelated sensitive information.
  4.  4. If Slate processes the information solely for a Customer, Slate may direct the request to that Customer or assist the Customer as required by contract and law.
  5.  5. Slate will respond within the period required by applicable law and will explain any denial, exception, extension, or appeal method.

16.2 Authorized agents

Where permitted, an authorized agent may submit a request. Slate may require evidence of authorization and may verify the individual directly, except where a valid power of attorney or another legal rule provides otherwise.

16.3 Account and platform controls

  •   update available profile or organization settings through Slate;
  •   disconnect a platform integration and separately revoke access in the platform account;
  •   control membership and roles through an authorized administrator;
  •   unsubscribe from marketing using the message link while Slate retains a minimal suppression record;
  •   use the cookie or privacy-choice interface when available; and
  •   enable Global Privacy Control where supported and legally applicable.

16.4 Non-discrimination

Slate will not unlawfully discriminate against a person for exercising a privacy right. Slate may offer a different price or service level when the difference is reasonably related to the value of data and permitted by law, but no financial-incentive program is identified as active as of the effective date.

17. California and other U.S. state disclosures

This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws. Applicability depends on legal thresholds, exemptions, context, and Slate's actual operations. The categories below use California statutory terminology and describe the information Slate can collect in the course of operating the Service.

California category

Examples in Slate

Collected from

Disclosed to

Identifiers

Name, business email, IP, account, Clerk, Google, organization, Stripe, platform, cookie, and device identifiers

User, Customer, browser, Clerk, Stripe, connected platforms

Customer users; Clerk; Vercel; Neon; Stripe; support/security providers; connected platforms at direction

Customer-record information

Business contact, account and billing administration information

User, Customer, Stripe

Service providers; professional advisers; Customer administrators

Commercial information

Subscription, plan, transaction administration, product interest, marketing engagement, order or revenue records in Customer data

User, Customer, Stripe, Shopify and other connected platforms

Service providers; Customer users; connected destinations

Internet or electronic activity

Pages, clicks, sessions, referrers, browser, device, logs, feature activity, ad interactions

Browser, device, hosting, analytics and advertising tools

Vercel; Google Analytics; Heap; advertising providers subject to choice; security providers

Geolocation

Approximate location inferred from IP and connected-platform country or region dimensions

Browser, analytics provider, connected platform

Analytics/service providers; Customer users for connected reports

Professional or employment-related information

Business email, company, title or role if provided, organization membership

User, Customer, business sources

Customer users; CRM or Klaviyo for Slate marketing; service providers

Inferences

Product-interest, feature-use, marketing engagement, or account-health inferences derived from Slate-controlled data

Slate-controlled activity

Slate service providers and authorized staff. No inferences from Customer Content or Google API Data for Slate advertising.

Sensitive personal information

Account authentication data and security information; payment credentials remain with Stripe or the authentication provider

User, Clerk, Stripe

Necessary authentication, security, payment, and hosting providers only


17.1 Business purposes and categories of recipients

The business and commercial purposes are described in Section 6. Categories of recipients are described in Sections 9 and 11. Slate does not sell Customer Content, Connected Data, or Google API Data. Slate-controlled public-site identifiers and activity may be shared with Google Ads, Meta Ads, or similar providers for cross-context advertising or targeted advertising when configured, subject to consent, opt-out, and GPC obligations.

17.2 Notice at collection

The categories collected at a particular interaction depend on the feature. Slate must link this Policy or a concise notice at or before registration, marketing forms, cookie collection, payment, support intake, and OAuth authorization. The notice must identify the relevant categories and purposes and must not rely on this long-form Policy when a timely contextual notice is required.

17.3 Minors

Slate has no actual knowledge that it sells or shares personal information of persons under 16 and does not intend to do so. The Service is for business users who are at least 18.

17.4 Appeals

Where a state law provides an appeal right, the response to a denied request will explain how to appeal through the published privacy-request method. Slate will respond within the legally required period and will provide any available regulator complaint route.

18. EEA, United Kingdom, and Switzerland disclosures

18.1 Controller and representative information

For Slate-controlled processing, the Slate operator is the controller. The operator's verified legal name, address, and contact method must be published before offering the Service to individuals in the EEA, United Kingdom, or Switzerland. Slate must appoint and identify an EU or UK representative if legally required and must identify a data protection officer only if the appointment criteria are met.

18.2 Legal bases and rights

The legal bases are described in Section 6. Individuals may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal, and complaint to a supervisory authority. Individuals also may object to direct marketing at any time. Slate does not identify automated decision-making that produces legal or similarly significant effects as an active feature.

18.3 Customer-controlled data

When Slate acts as a processor, the Customer is responsible for the legal basis, transparency, data-subject response, and instructions. Slate will assist as required by the applicable data-processing agreement. A written Slate DPA, including processing details, confidentiality, security, subprocessors, deletion, audits, assistance, incident notice, and transfer terms, must be available before regulated Customer data is processed at scale.

18.4 Complaints

An individual may complain to the supervisory authority where the individual resides, works, or believes an infringement occurred. Slate requests an opportunity to address the concern through the published privacy contact first, but that request does not limit the right to contact a regulator.

19. Children and business use

Slate is a business-to-business service and is not directed to children. A User must be at least 18 and able to form a binding contract. Slate does not knowingly collect personal information directly from children under 13. A Customer must not upload, connect, or otherwise process children's personal information through Slate. If Slate learns that such information was collected without appropriate authorization, Slate will take reasonable steps to delete it and restrict the responsible account.

20. Changes to this Policy

Slate may update this Policy to reflect changes in law, platform requirements, providers, products, or processing. The updated version will state the new effective date and be posted at the public Privacy Policy URL. For a material change involving a new use of Google API Data or other information beyond the use originally disclosed and authorized, Slate will provide additional notice and obtain renewed consent or authorization when required before the new use begins.

A Customer is responsible for reviewing updates and maintaining its own notices. Continued use after an effective update constitutes acceptance only to the extent permitted by law and does not replace consent where consent is legally required.

21. Contact and publication condition

Required before publication or external processing
The following facts were not available in the audited materials and are not replaced with invented values: the legal name of the Slate operator, the operator's business mailing address, and a monitored public privacy-request contact method. Those facts must be displayed in this section and on the same public webpage as this Policy before Slate collects personal information from external users, submits OAuth or platform review, or offers the Service outside a private development environment.


Until the required contact details are published, a person with access to a private Slate environment should direct privacy or security concerns through the authenticated account administrator or the established communication channel through which access was provided. That temporary instruction is not a substitute for the public contact method required for launch.

The public contact method must be capable of receiving privacy requests, deletion requests, platform-data deletion requests, security reports, legal notices, and regulator communications; must be monitored; and must have documented routing and response procedures.


Appendix A. Detailed data inventory

Record or field group

Examples

Purpose

Primary location or recipient

User record

User ID, email, name, avatar, user type, preferences, creation time

Account and experience administration

Clerk and Slate database on Neon

Organization record

Clerk organization ID, name, currency, time zone, fiscal year, date format, business type, settings

Workspace configuration and reporting context

Slate database on Neon

Membership

Organization ID, user ID, Admin/Editor/Viewer role, creation time

Authorization and organization governance

Clerk and Slate database on Neon

Billing

Plan, status, Stripe customer/subscription/price IDs, trial and billing period

Subscription administration

Stripe and Slate database on Neon

Integration connection

Provider, external account, encrypted access/refresh token, expiry, scopes, sync time, connecting user

Authorized platform access

Slate application and Neon; connected provider

Sync run

Provider, queued/running/succeeded/failed, summary, error, actor, timestamps

Reliability, audit, troubleshooting

Slate database and operational logs

Data source

Platform, provider, kind, owner, label, channel, notes, status, metadata

Source governance

Slate database

Source account

External account ID/name, currency, time zone, status, metadata

Account selection and attribution

Slate database

Raw metric fact

Date, grain, raw dimensions, raw metrics, raw payload, currency, time zone, idempotency key

Traceability, normalization, deduplication

Slate database

Normalized metric record

Source, medium, campaign, ad group, ad, creative, country, region, device, placement, metrics, tags, notes, edit status

Editable governed reporting record

Slate database and Customer-authorized exports

Rules and applications

Triggers, conditions, actions, run status, rows checked/matched/changed, old/new value

Automated governance and audit

Slate database

Audit and edit logs

Actor, action, before/after, reason, origin, timestamps, old/new amount

Accountability and change history

Slate database

Saved views and reports

Filters, columns, groupings, sorting, creator

User-facing reporting

Slate database

Google Sheets export

Spreadsheet ID/URL/name, export type, mode, schedule, filters, columns, status, row count

Customer-directed export and history

Slate database and Google Sheets

Alerts

Type, severity, status, title, message, metadata, email status

Operational and reporting notifications

Slate database and any configured email provider

Webhooks

Source, event ID, receipt time

Deduplication and event handling

Slate database and logs

Site/product analytics

Page, event, referrer, campaign, device, cookie, session, error

Slate-controlled analytics and improvement

Google Analytics and Heap only when configured and consented

Slate marketing profile

Business contact, subscription/consent, suppression, campaign engagement

Slate communications and marketing

Klaviyo and Slate marketing systems


Appendix B. Integration and provider matrix

Integration or provider

Status as of July 21, 2026

Access or role

Privacy treatment

Google Sign-In via Clerk

Identified for use

Authentication profile and session

Separate from data-source authorization

Google Ads

Active code-backed connector

`adwords` OAuth scope; reporting data

Google Limited Use; no Slate advertising use

Google Analytics 4 data source

Active code-backed connector

`analytics.readonly`

Customer-facing aggregate analytics reporting

Google Sheets

Active code-backed export destination

`spreadsheets` and `drive.file`

Customer-directed file creation/editing only

Google Docs

Not active in audited implementation

No active Docs scope identified

No current access; policy/consent update required before activation

Google Slides

Not active in audited implementation

No active Slides scope identified

No current access; policy/consent update required before activation

General Google Drive

Not active; `drive.file` only for Sheets workflow

No broad Drive scope identified

Do not claim access to all Drive files

Meta Ads

Active code-backed connector

`ads_read`, `business_management`

Customer-facing reporting; Meta terms apply

LinkedIn Ads

Active code-backed connector

`r_ads`, `r_ads_reporting`

Customer-facing reporting; program approval required

Microsoft Advertising

Active code-backed connector

`openid`, `offline_access`, `msads.manage`

Used for reporting; disclose broader permission accurately

TikTok Ads

Active code-backed connector

App-approved dynamic scopes

Customer-facing reporting; app approval and data terms apply

Reddit Ads

Active code-backed connector

`adsread`, `identity`

Customer-facing reporting; production user-agent and commercial approval review required

Shopify

Active code-backed connector

Default `read_orders`, subject to production config

Protected Customer Data review and privacy webhooks may apply

Amazon Ads

Provider enum only; no live connector established

None confirmed

Do not claim active access

Klaviyo data source

Planned/desired; not active in audited connector registry

None confirmed

Separate from Slate marketing Klaviyo account

Pinterest / Spotify

Inactive or placeholder concepts only

None confirmed

Do not claim active access

Clerk

Active dependency

Authentication and organization management

Processor/service provider plus independent-controller account data

Neon Postgres

Active infrastructure

Primary application database

Processor/subprocessor; region and retention must be documented

Vercel

Active infrastructure

Hosting, execution, deployment, logs, jobs

Processor/subprocessor; region/log configuration must be documented

Stripe

Active dependency and billing data model

Subscription and payment administration

Payment provider; Slate should not store full card data

Google Analytics for Slate

Required by stated stack; tag/config not verified in repo

Slate website/product analytics

Consent, settings, data separation, and disclosure required

Heap

Required by stated stack; tag/config not verified in repo

Product analytics; session replay only if enabled

Masking, exclusions, consent, and data separation required

Google Ads / Meta Ads for Slate

Required by stated marketing stack; exact tags not verified

Slate advertising and measurement

Only Slate Marketing Data; consent/opt-out/GPC required

Klaviyo for Slate marketing

Required by stated marketing stack; exact configuration not verified

Marketing profiles, consent, suppression, message events

Marketing law and consent compliance required

GitHub

Active private source-control repositories

Code and development history

Not a production Customer-data store; no secrets or live data

Svix hosted service

Not established by dependency alone

Possible webhook service only if separately configured

List as subprocessor only if hosted service processes data


Appendix C. Official platform notices reviewed

The following official materials were reviewed for the platform-specific disclosures. They can change independently. Slate must recheck them before submission, launch, adding scopes, or materially changing a connector.

  •   Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
  •   Google Workspace API User Data and Developer Policy: https://developers.google.com/workspace/workspace-api-user-data-developer-policy
  •   Google Ads API Required Minimum Functionality: https://developers.google.com/google-ads/api/docs/api-policy/rmf
  •   Google Ads API Terms and Policies: https://developers.google.com/google-ads/api/terms
  •   Google Analytics Terms: https://www.google.com/analytics/terms/
  •   Google EU User Consent Policy: https://www.google.com/about/company/user-consent-policy/
  •   Meta Platform Terms: https://developers.facebook.com/terms/
  •   Meta Developer Policies: https://developers.facebook.com/devpolicy/
  •   LinkedIn Marketing Developer Terms: https://www.linkedin.com/legal/l/marketing-api-terms
  •   Microsoft Advertising Policies: https://about.ads.microsoft.com/en-us/resources/policies
  •   TikTok Business Products Data Terms: https://ads.tiktok.com/i18n/official/policy/controller-to-controller/privacy
  •   Reddit Data API Terms: https://redditinc.com/policies/data-api-terms
  •   Shopify API License and Terms of Use: https://www.shopify.com/legal/api-terms
  •   Shopify Protected Customer Data Requirements: https://shopify.dev/docs/apps/launch/protected-customer-data
  •   Amazon Ads API documentation: https://advertising.amazon.com/API/docs/en-us/info/api-overview
  •   Clerk Privacy Policy and DPA: https://clerk.com/legal/privacy
  •   Vercel DPA: https://vercel.com/legal/dpa
  •   Neon Privacy and DPA resources: https://neon.com/privacy-policy
  •   Stripe Privacy Center: https://stripe.com/legal/privacy-center
  •   Heap Privacy and Session Replay guidance: https://help.heap.io/hc/en-us/sections/36055200771601-Session-Replay-Data-Privacy
  •   Klaviyo Privacy Center: https://privacy.klaviyo.com/
  •   California CCPA and Global Privacy Control guidance: https://oag.ca.gov/privacy/ccpa
  •   FTC privacy and security guidance: https://www.ftc.gov/business-guidance/privacy-security
Slate

Trusted marketing data, without a data team.

Product

Product OverviewData SourcesManual DataGovernance & Audit TrailExports

Solutions

Marketing TeamsAgenciesFinance Teams

Use Cases

Monthly ReportingManual Vendor SpendExecutive Budget ReviewsAgency Client Reporting

Resources

BlogDocsAbout SlateSecurity

Get Started

Sign inStart with your first source
Terms of ServicePrivacy Policy