Slate
Product OverviewData SourcesManual DataGovernance & Audit TrailExports

Industries

EcommerceB2BHospitality

Business Size

Small TeamsStartupsGrowthAgency
Why Slate
Connect sourcesReview and reconcileExport records
Pricing
BlogDocsAbout SlateSecurity
Sign inStart with your first source

SLATE

Slate Privacy Policy

Privacy disclosures for slatedata.app, my.slatedata.app, connected marketing platforms, and Slate-operated marketing systems

Effective date: August 30, 2026
Last updated: August 30, 2026
Version: 1.1

Contents

1. Scope and identity of the service

2. Slate roles: controller/business and processor/service provider

3. Definitions

4. Personal information and data Slate processes

5. Sources of information

6. Purposes and legal bases

7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive

8. Other connected advertising, analytics, ecommerce, and lifecycle platforms

9. Production service providers and subprocessors

10. Cookies, local storage, analytics, and tracking choices

11. Disclosures of information

12. Sale, sharing, targeted advertising, and Global Privacy Control

13. Retention, deletion, revocation, and backups

14. Security

15. International data transfers

16. Privacy rights and choices

17. California and other U.S. state disclosures

18. EEA, United Kingdom, and Switzerland disclosures

19. Children and business use

20. Changes to this Policy

21. Contact information

Appendix A. Detailed data inventory

Appendix B. Integration and provider matrix

Appendix C. Official platform notices reviewed


Read this first
This Policy distinguishes between Slate-controlled information (such as account, billing, website analytics, security, and Slate marketing data) and Customer-controlled information (such as data imported from a customer-connected advertising, analytics, ecommerce, or lifecycle platform). Slate must not use Customer Content, Connected Data, or Google API Data for Slate advertising, cross-customer profiling, data brokerage, or general-purpose model training.


1. Scope and identity of the service

Slate Data LLC, a Massachusetts limited liability company ("Slate," "we," "us," or "our"), owns and operates slatedata.app, my.slatedata.app, and the Slate-branded marketing-data aggregation, normalization, governance, reporting, and export services (collectively, the "Service"). This Privacy Policy explains how Slate collects, uses, stores, discloses, and otherwise processes information in connection with the Service.

Slate is designed for business use by marketing teams, agencies, finance-adjacent teams, and other organizations. This Policy applies to visitors, users, organization administrators, invited members, prospective customers, and individuals whose information is contained in data that an authorized Slate customer imports or connects to the Service.

This Policy does not govern the independent privacy practices of Google, Meta, LinkedIn, Microsoft, TikTok, Reddit, Shopify, Amazon, Stripe, Clerk, Vercel, Neon, Heap, Klaviyo, or any other third-party platform. Those providers process information under their own terms and privacy notices when a person uses their services directly.

Where an organization provides a separate privacy notice or contract that applies to its Slate workspace, that organization notice may provide additional details about the organization's processing. If an organization controls data in Slate, questions about that data should ordinarily be directed to the organization first.

2. Slate roles: controller/business and processor/service provider

2.1 Slate as controller or business

Slate determines the purposes and means of processing for information needed to operate its own business and Service, including public-site data, account administration, authentication configuration, billing records, security logs, product analytics, support communications, legal compliance, and Slate's own marketing. For this information, Slate acts as a controller under the GDPR and analogous laws and as a business under the California Consumer Privacy Act, where those laws apply.

2.2 Slate as processor or service provider

For Customer Content and Connected Data submitted, imported, synchronized, normalized, edited, governed, reported, or exported at an organization's direction, the organization generally determines why and how that information is processed. Slate processes that information to provide the contracted Service and acts as a processor, service provider, or contractor, as applicable. The organization is responsible for its instructions, lawful basis, notices, consents, platform permissions, and responses to data-subject requests.

2.3 Platform-specific restrictions

Google API Data and data obtained from other connected platforms remain subject to the applicable platform terms, developer policies, approved scopes, and user instructions. A customer's ability to access information through Slate does not expand the customer's rights in that information or override the connected platform's restrictions.

3. Definitions

Term

Meaning

Account Data

Information used to create, authenticate, secure, administer, and support an individual Slate account, including identity, contact, session, and organization-membership information.

Customer

The organization, business, agency, or other entity that creates or controls a Slate workspace, including an authorized administrator acting for that entity.

Customer Content

Information submitted directly by or for a Customer, including uploaded files, pasted rows, manual entries, labels, notes, corrections, rules, saved views, reports, and export configurations.

Connected Data

Information retrieved from or sent to a third-party service at a Customer's direction through an authorized integration, including raw, normalized, derived, and metadata fields.

Google API Data

Information obtained from Google API Services through Google OAuth scopes, together with data aggregated, normalized, or derived from that information.

Personal Information

Information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to a person or household, and analogous terms under applicable law.

Service Data

Technical, operational, diagnostic, security, and usage information generated by use of Slate.

Slate Marketing Data

Information collected by Slate for its own website analytics, product analytics, advertising measurement, lead management, and marketing communications. It excludes Customer Content, Connected Data, and Google API Data.

User

An individual who visits, registers for, is invited to, or uses the Service.


4. Personal information and data Slate processes

4.1 Account, identity, and authentication data

  •   Identity and contact: name, business email address, profile or avatar image, and similar account information.
  •   Authentication identifiers: Clerk user identifiers, Google Sign-In identifiers when Google is selected, organization identifiers, membership identifiers, and session identifiers.
  •   Authentication and security events: sign-in, sign-out, invitation, session, device, browser, IP address, authentication outcome, and related timestamps or risk signals made available by authentication and hosting providers.
  •   Organization membership: workspace name, role, invitation status, permissions, and administrator actions. Slate currently uses Admin, Editor, and Viewer roles.
  •   Preferences: user-interface, display, notification, saved-view, and other account preferences stored by Slate.
  •   Passwords and payment credentials: Slate does not intend to receive or store a user's Google password, Clerk-managed password, complete payment-card number, card verification code, or bank-account credentials. Those values are handled by the relevant authentication or payment provider.

4.2 Organization and workspace administration data

  •   organization name and external organization identifier;
  •   default currency, time zone, fiscal-year start, date format, business type, onboarding status, and workspace settings;
  •   roles, permissions, membership history, administrator actions, and invitation information;
  •   source ownership, labels, channels, notes, statuses, and data-governance configuration; and
  •   rules, conditions, actions, run history, and exception information used to govern or transform records.

4.3 Subscription, billing, and transaction administration data

  •   plan, billing status, trial status, subscription status, current billing-period end, and cancellation status;
  •   records needed for internal subscription administration, accounting, fraud prevention, and dispute handling; and
  •   communications about trials, renewals, plan changes, cancellations, or support. Slate does not identify a production payment processor as enabled as of the effective date and does not collect complete payment-card numbers or card verification codes.

4.4 Integration authorization and connection data

  •   provider name, approved OAuth scopes or permissions, external account identifier and name, token issue and expiration information, and connection status;
  •   OAuth access and refresh tokens stored in encrypted form, together with encrypted or protected state and verifier values used during authorization;
  •   the user who connected or updated an organization integration, authorization and callback events, and disconnection or error status;
  •   synchronization start and finish times, status, summary information, retry information, error messages, and records of the source accounts selected by a Customer; and
  •   provider-specific metadata needed to select an account, attribute imported rows, refresh authorization, or operate a scheduled import or export.

4.5 Connected advertising and analytics data

Depending on the provider, permissions approved, Customer configuration, and report level, Slate may retrieve and store account, campaign, campaign-group, ad-group, ad-set, ad, keyword, creative, placement, device, geography, network, objective, status, date, currency, time-zone, source, medium, and attribution information. Metrics may include spend or cost, impressions, clicks, reach, conversions, conversion value, revenue, engagements, likes, shares, comments, follows, leads, video views, video completion metrics, and related calculated metrics such as click-through rate, cost per click, cost per acquisition, return on ad spend, or other ratios derived in Slate.

Slate may retain raw API response fields and payloads, normalized records, source-account metadata, identifiers needed for deduplication, and audit records showing when and how a value was imported, normalized, edited, corrected, excluded, labeled, or exported. Raw platform data may contain personal information even when Slate primarily presents aggregate marketing metrics.

4.6 Ecommerce and order data

For Shopify and any later-approved ecommerce integration, Connected Data can include store and account identifiers, order identifiers, order date, order status, currency, subtotal, discounts, shipping, taxes, refunds, total, item counts, source or landing-site information, referring site, customer or buyer identifier, and campaign or UTM parameters. Slate should not be configured to ingest names, email addresses, postal addresses, phone numbers, full payment information, or other protected customer data unless the applicable feature, platform approval, Customer instructions, contracts, and privacy controls expressly require and authorize it.

4.7 Customer-created, uploaded, and manually entered data

  •   CSV, TSV, spreadsheet, pasted, uploaded, or manually entered marketing records;
  •   vendor or source names, dates, amounts, currency, campaign details, notes, reference identifiers, and custom tags;
  •   correction reasons, old and new values, approval or actor information, overwrite decisions, edit history, and audit entries;
  •   saved filters, columns, grouping, sorting, reports, templates, dashboards, exports, alerts, and scheduling settings; and
  •   any personal information a Customer chooses to place in free-text, notes, file contents, custom fields, or raw uploads. Customers must not place sensitive or unrelated personal information in Slate.

4.8 Export and destination data

  •   Google spreadsheet identifier, URL, name, destination mode, export type, date range, filters, columns, dimensions, sorting, schedule, status, row count, and error information;
  •   CSV export configuration and download events;
  •   scheduled export creator, next-run and last-run timestamps, and export history; and
  •   information sent to the destination selected by the Customer. Once information is exported, the destination provider and Customer control further access and retention.

4.9 Support, communications, and feedback

  •   support requests, messages, screenshots, attachments, call notes, issue details, and troubleshooting data;
  •   survey responses, feedback, feature requests, testimonials submitted with permission, and communications with Slate;
  •   administrative and service notices, including security, billing, integration, and policy communications; and
  •   marketing subscription status, consent records, unsubscribe or suppression status, campaign interaction data, and attribution information.

4.10 Device, usage, cookie, and diagnostic data

  •   IP address, browser, operating system, device type, language, approximate location inferred from IP, referring URL, landing page, and page path;
  •   cookie, local-storage, advertising, analytics, session, and device identifiers;
  •   pages and features viewed, buttons or links used, timestamps, navigation sequences, errors, latency, and performance data;
  •   authentication, authorization, webhook, API, job, database, hosting, and application logs; and
  •   product and website analytics events, including normalized page paths, page views, navigation and interaction events, technical event metadata, and vendor-generated pseudonymous user and session identifiers. Slate does not enable session replay or target-text capture.

4.11 Information Slate does not intentionally request

Slate is not designed to collect or process protected health information, Social Security numbers, government identification numbers, biometric templates, precise geolocation, children's data, complete payment-card data, passwords, data about sex life or sexual orientation, genetic data, or other special-category or highly sensitive information. Customers must not upload or connect such information unless Slate has expressly agreed in a written contract and implemented the required product, legal, and security controls. No such agreement or special regulated-data feature is identified as active as of the effective date of this Policy.

5. Sources of information

  •   Directly from Users and Customers: registration, invitations, settings, files, manual entries, forms, support, billing, and communications.
  •   From Customer administrators and coworkers: invitations, roles, workspace configuration, account details, and content submitted about or by organization members.
  •   From Google and other connected platforms: authorized OAuth profile information, account lists, platform reports, analytics, orders, metadata, tokens, and API responses.
  •   From Clerk, Vercel, Neon, and other verified service providers: authentication events, hosting logs, security signals, service telemetry, and operational data needed to provide the Service.
  •   Automatically from browsers and devices: cookies, IP address, page events, diagnostics, and usage information.
  •   From Slate marketing activities: direct communications, referrals, event or content interactions, and campaign parameters.
  •   From public or business sources: business contact information and company information used for legitimate business-to-business sales, fraud prevention, due diligence, or customer support, where permitted by law.

6. Purposes and legal bases

Slate processes information only for purposes that are compatible with the context in which the information was collected, the Customer's instructions, the applicable platform permissions, and applicable law. Where the GDPR, UK GDPR, or a similar law requires a legal basis, the basis depends on the information and context.

Purpose

Information involved

Typical legal basis

Provide and administer the Service

Account Data, organization settings, Customer Content, Connected Data, integration data, exports, and Service Data

Performance of a contract; steps requested before entering a contract; legitimate interests in providing the Service

Authenticate and control access

Identity, Google Sign-In data, Clerk identifiers, sessions, roles, device and security information

Contract; legitimate interests in secure access; legal obligation where applicable

Connect, synchronize, normalize, govern, report, and export data

OAuth permissions and tokens, Connected Data, raw payloads, normalized metrics, rules, corrections, and destination data

Contract; Customer instructions; legitimate interests; consent where platform or law requires

Bill and manage subscriptions

Plan, subscription status, trial information, internal billing status, and related communications

Contract; legal obligation; legitimate interests in fraud prevention and collections

Secure, monitor, and troubleshoot the Service

Logs, IP, device, error, webhook, job, database, authentication, and audit information

Legitimate interests in security, reliability, fraud prevention, and abuse prevention; legal obligation

Provide support and communicate

Account and contact data, support content, diagnostics, billing and service status

Contract; legitimate interests; consent where required

Analyze and improve Slate

Slate-controlled usage and product analytics; deidentified or aggregate service statistics

Legitimate interests; consent for non-essential cookies where required. Google API Data and other restricted Connected Data are excluded unless the use is a permitted user-facing feature.

Market Slate and measure campaigns

Public-site events, marketing contact information, consent and suppression status, campaign and advertising identifiers

Consent where required; legitimate interests for permitted business marketing; compliance with opt-out rights

Comply with law and protect rights

Any information reasonably necessary for legal process, tax, accounting, sanctions, investigations, disputes, and enforcement

Legal obligation; legitimate interests; establishment, exercise, or defense of legal claims


Where Slate relies on consent, a person may withdraw consent at any time through the available preference mechanism or request channel. Withdrawal does not affect processing already completed lawfully. Where Slate relies on legitimate interests, Slate considers the purpose, necessity, and effects on individuals and applies safeguards appropriate to the information.

7. Google Sign-In, Google Ads, Google Analytics, Google Sheets, Docs, Slides, and Drive

Google Limited Use commitment
Slate's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.


7.1 Google Sign-In

A User may choose Google Sign-In through Clerk. Google Sign-In is used to authenticate the User and create or link the User's Slate account. Depending on the User's Google and Clerk configuration, Slate may receive the User's Google account identifier, name, email address, profile image, and authentication metadata. Signing in with Google does not itself authorize Slate to read Google Ads, Google Analytics, Google Sheets, Google Docs, Google Slides, or Google Drive content.

7.2 Google Ads as a connected data source

When a Customer connects Google Ads, Slate requests the Google Ads OAuth scope `https://www.googleapis.com/auth/adwords`. This scope permits access to Google Ads accounts that the authorizing User is entitled to access. Slate uses that access to list selectable customer or manager accounts and retrieve reporting data for the Customer-facing aggregation, normalization, audit, reporting, and export features of Slate.

Google Ads data can include customer and manager account identifiers and names; account currency and time zone; campaign, ad group, ad, keyword, network, device, geography, status, and date fields; cost, impressions, clicks, conversions, conversion value, and other report metrics selected for the implemented Slate reporting level; and raw response metadata needed to validate and normalize those records.

Slate is a reporting and data-governance product, not a full-service Google Ads campaign-management tool as currently implemented. Slate limits the connector to Customer-directed reporting and complies with the Google Ads API terms and requirements applicable to its approved access.

7.3 Google Analytics 4 as a connected data source

When a Customer connects Google Analytics 4, Slate requests the read-only OAuth scope `https://www.googleapis.com/auth/analytics.readonly`. Slate uses that access to identify properties and retrieve Customer-selected analytics dimensions and metrics for Customer-facing reporting and reconciliation. Depending on the report configuration, data can include property identifiers and names, date, source, medium, campaign, device, geography, sessions, users, events, conversions or key events, revenue, and related aggregate measurements.

Slate does not use a Customer's connected Google Analytics data to advertise Slate, build cross-customer audiences, identify visitors on unrelated services, or train general-purpose artificial-intelligence or machine-learning models.

7.4 Google Sheets as an export destination

When a Customer connects Google Sheets, Slate requests `https://www.googleapis.com/auth/spreadsheets` and `https://www.googleapis.com/auth/drive.file`. The spreadsheets scope allows Slate to create and edit spreadsheets as directed by the Customer. The `drive.file` scope is intended to limit Drive access to files that the User creates with Slate or explicitly opens or shares with Slate; it does not grant general access to every file in the User's Drive.

Slate stores destination spreadsheet identifiers, URLs, names, export settings, schedules, row counts, and status information necessary to run and audit exports. Slate writes only the data selected for export by an authorized User or scheduled configuration. After data is written to Google Sheets, the Customer and Google control access, sharing, version history, retention, and downstream use in the destination file.

7.5 Google Docs, Google Slides, and broader Google Drive access

As of the effective date, the audited Slate implementation does not register an active Google Docs connector, Google Slides connector, or general Google Drive connector, and does not request broad Drive scopes that read all Drive files. Slate therefore does not currently access the contents of Google Docs or Google Slides through those APIs. Before any such feature is activated, Slate must implement only the minimum necessary scope, update this Policy and in-product disclosures, complete any required Google verification or security assessment, and obtain fresh, contextual authorization from affected Users.

7.6 How Slate uses, shares, and protects Google API Data

  •   Permitted use: provide or improve the Customer-facing feature for which the User authorized access, including account selection, import, normalization, governance, reporting, reconciliation, and export.
  •   No advertising use: Slate does not sell, transfer, or use Google API Data for serving ads, retargeting, personalized advertising, audience creation, or interest-based advertising.
  •   No data brokerage or surveillance: Slate does not sell or distribute Google API Data to data brokers, information resellers, surveillance providers, credit providers, or unrelated third parties.
  •   No general model training: Slate does not use Google API Data to train general-purpose artificial-intelligence or machine-learning models. Any future user-facing model feature involving Google API Data would require a permitted use, specific disclosures, appropriate controls, and any required consent or Google approval before launch.
  •   Limited disclosure: Slate discloses Google API Data only to infrastructure or service providers that process it for Slate under appropriate confidentiality and data-protection restrictions, to the Customer and its authorized Users, to a destination expressly chosen by the Customer, or when legally required.
  •   Human access: Slate personnel may access Google API Data only when necessary for security, abuse investigation, support requested by the Customer, legal compliance, or operation of a permitted user-facing feature, and only under access restrictions and confidentiality obligations.
  •   Security: Google OAuth tokens are stored encrypted at rest; Google API Data must be transmitted over secure protocols and protected using access controls, secret management, logging, and incident-response procedures.
  •   Minimum permissions: Slate must request only the scopes needed for active features and must not request speculative scopes for unimplemented Docs, Slides, Drive, or other features.

7.7 Disconnecting Google and deleting Google API Data

An authorized administrator or User can disconnect the applicable Google integration through the available Slate connection controls and can also revoke Slate's access through the User's Google account security settings. Disconnection stops new API access after the revocation is processed. Slate will delete or render inaccessible the associated active tokens and will delete Google API Data when required by the Customer's instruction, account deletion, platform terms, or applicable law, subject to narrowly limited legal-retention obligations and backup aging.

Deleting a Slate account does not automatically delete data already exported to a Customer-owned Google spreadsheet. The Customer must delete or restrict the destination file separately. Likewise, revoking Google access does not necessarily remove historical data that the Customer lawfully imported before revocation; the Customer or authorized User must submit a deletion instruction if historical data should also be removed, unless platform rules require automatic removal.

8. Other connected advertising, analytics, ecommerce, and lifecycle platforms

The integrations below are described according to the audited implementation as of the effective date. A provider may impose additional review, permission, retention, attribution, branding, or deletion rules. Slate processes only the accounts and data that an authorized User selects and only within the provider access approved for Slate.

8.1 Meta Ads

Slate requests Meta permissions `ads_read` and `business_management` for the Meta Ads connector. Slate may use them to identify businesses and ad accounts the authorizing User can access and to retrieve account, campaign, ad set, ad, placement, device, geography, objective, spend, impression, reach, click, conversion, value, engagement, and video-performance data. Slate stores connection metadata, encrypted tokens, selected account identifiers, raw response data, normalized metrics, and sync history. Meta data is used only for Customer-facing Slate features and remains subject to Meta Platform Terms and Developer Policies.

8.2 LinkedIn Ads

Slate requests LinkedIn permissions `r_ads` and `r_ads_reporting`. Slate may retrieve authorized ad-account, campaign, campaign-group, creative, date, currency, status, objective, spend, impression, click, conversion, value, reach, and engagement information. Slate must maintain LinkedIn program approval and comply with the LinkedIn Marketing Developer Terms, including restrictions on access, client relationships, security, storage, use, and onward disclosure.

8.3 Microsoft Advertising

Slate requests `openid`, `offline_access`, and `https://ads.microsoft.com/msads.manage`. The Microsoft Ads permission is broader than read-only naming may suggest, even though Slate currently uses the connection for account discovery and reporting. Slate may process Microsoft identity and authorized account information, reporting-job metadata, campaign and ad identifiers, status, keyword or search-query fields where implemented, device and network dimensions, spend, impressions, clicks, conversions, revenue, and related metrics. Slate must protect the developer token and OAuth credentials and must not expose management functionality that has not been designed, authorized, and disclosed.

8.4 TikTok Ads

Slate uses TikTok API for Business authorization to access the advertiser accounts and scopes approved for the Slate app. TikTok scopes can be returned dynamically by TikTok rather than being fixed in the current source code. Slate may process advertiser and campaign identifiers, date, currency, campaign status, objective, placements, geography, device, spend, impressions, reach, clicks, conversions, conversion value, video metrics, and engagement metrics. Any separate TikTok Pixel, Events API, Advanced Matching, or Customer Audience use by Slate as an advertiser is governed by Section 9 and requires the applicable notice and consent; it is not sourced from Customer-connected TikTok Ads data.

8.5 Reddit Ads

Slate requests Reddit permissions `adsread` and `identity`. Slate may process Reddit account identity needed for authorization, ad-account identifiers and metadata, campaign and ad identifiers, placement or community dimensions, location, spend, impressions, clicks, conversions, value, reach, video metrics, and leads. Reddit requires accurate identification, a compliant privacy policy, adherence to API limits and attribution requirements, and deletion of cached or stored Reddit material when required upon termination. Slate must also use an accurate production user-agent identifier.

8.6 Shopify

Slate's Shopify managed-install configuration has no universally required data scope. The merchant's selected tables determine the minimum optional scopes requested from `read_orders`, `read_customers`, `read_products`, `read_inventory`, `read_locations`, and `read_marketing_events`. Orders and order line items are selected for a new connection by default and require `read_orders`. Order-attribution visits require `read_orders` and `read_marketing_events`. Slate does not request `read_all_orders`; if Shopify has separately granted it, Slate may use it for older order history. Every connection and synchronization remains limited to the scopes actually granted by Shopify.

Depending on the merchant's selected tables and granted scopes, Slate processes the following Shopify resources for these purposes:

  •   Shop and connection metadata: authorize and secure the exact connection, enforce granted scopes, configure ingestion, and present shop-level reporting and exports.
  •   Orders and order line items: ingest commerce activity; normalize and report order metrics; join orders to customers, products, variants, and attribution visits; support attribution; export merchant-selected results; and locate customer-linked data for privacy requests.
  •   Limited customer records: link merchant customers to their orders, report aggregate customer/order relationships, support merchant exports, and locate or redact the exact customer's stored data.
  •   Products and variants: ingest and report catalog data, join catalog objects to order line items and inventory, and include merchant-selected fields in exports.
  •   Inventory items and levels: ingest and report inventory state, join items and quantities to variants and locations, and support inventory exports.
  •   Locations: identify and report inventory locations, join location context to inventory levels, and support location-aware exports.
  •   Order-attribution visits and UTM/referrer data: attribute orders to marketing sources, campaigns, landing pages, and referrers; join visits to orders; and provide attribution reporting and exports.
  •   Privacy webhooks: authenticate, secure, deduplicate, and fulfill customer data requests and customer/shop redaction instructions without retaining raw webhook bodies.
  •   Raw, linked, normalized, and derived reporting records: provide reporting, joins, attribution, rules, governance, exports, security/audit controls, and privacy-request fulfillment from the final stored state.

Slate does not intentionally retain direct Shopify customer email addresses, telephone numbers, or postal addresses. Slate does not sell merchant or merchant-customer data, use it to advertise Slate, combine it for cross-merchant profiling, or use it for automated decisions that produce legal or similarly significant effects. That merchant-controlled data is separate from Slate Marketing Data collected on Slate-controlled public sites for Slate's own analytics, advertising, and communications as described in Sections 9, 10, and 12.

A verified Shopify app uninstall or administrator disconnect immediately clears reusable credentials and stops synchronization, then deletes the disconnected shop's Slate data after 48 hours unless the same connection is restored first. A verified `customers/redact` request immediately hard-deletes the exact customer-linked records, and a verified `shop/redact` request immediately purges the exact shop. For `customers/data_request`, Slate prepares a protected JSON export of the data it stores for the customer and provides it to the merchant; the merchant remains responsible for authenticating the requester and delivering the customer-facing response. Deleted data may persist only until protected backups expire under the backup schedule, must not return to ordinary active use, and is re-deleted or isolated if a backup is restored.

Shopify order and customer-related data can be Protected Customer Data. Slate and each Customer must comply with Shopify's API terms, protected-data requirements, data-minimization rules, access review requirements, and mandatory privacy webhooks where applicable.

8.7 Amazon Ads

The Slate data model contains an Amazon Ads provider designation, but the audited implementation did not establish a live Amazon Ads connector. Slate does not represent that it currently accesses Amazon Ads data. Before activation, Slate must complete the Amazon Ads application and approval process, document the precise scopes and reports, update this Policy, obtain Customer authorization, and satisfy Amazon-specific security, retention, attribution, and use restrictions.

8.8 Klaviyo as a Customer-connected data source

Klaviyo is not registered as an active Customer-facing connector and is not enabled as Slate's production marketing provider as of the effective date. Slate will update this Policy, document the applicable authorization, data, roles, and lifecycle, and obtain Customer authorization before activating a Klaviyo connection.

8.9 Pinterest and Spotify

Pinterest and Spotify appeared only as inactive, unregistered, or placeholder integration concepts in the reviewed product context and are not described as live data connections. Slate does not represent that it currently accesses those platforms. A future activation requires a policy update, exact scope disclosure, platform approval, contextual authorization, and a documented data lifecycle.

9. Production service providers and subprocessors

Slate uses the production providers listed below. Customer-selected source platforms and export destinations are not Slate subprocessors merely because a Customer directs Slate to exchange data with them. Stripe, Sentry, Klaviyo, Google Ads, Meta Ads, the hosted Svix service, and separate email, support, monitoring, logging, backup, or security services are not identified as enabled Slate production providers as of the effective date.

Provider

Function and information

Processing region

Transfers and service retention

Clerk, Inc.

Authentication, sessions, user and organization management, invitations, and Google Sign-In; identity, contact, membership, session, device, network, authentication, and security data. Slate-controlled data.

United States; Clerk does not offer regional residency, and its disclosed subprocessors may process data from their disclosed locations.

EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework certifications, with Standard Contractual Clauses and applicable UK or Swiss terms as fallback. Customer Personal Data is deleted within 90 days after service termination or expiration, subject to the DPA.

Vercel Inc.

Application and marketing-site hosting, compute, content delivery, networking, deployments, scheduled jobs, native logs, and Vercel Web Analytics; request, network, device, route, deployment, log, sanitized page-analytics, Slate-controlled, and Customer data processed through application compute.

Primary production compute in iad1, Washington, D.C., United States (AWS us-east-1); global content-delivery locations and possible global backup or subprocessor processing.

EU Standard Contractual Clauses and UK International Data Transfer Agreement where applicable. Pro runtime logs are retained for one day; Vercel Web Analytics visitor-session hashes expire after 24 hours.

Databricks, Inc. — Neon product; Neon, LLC affiliate

Production PostgreSQL database and native recovery history; Account Data, organization records, encrypted integration credentials, Customer Content, Connected Data, metrics, audit, rules, reports, exports, billing metadata, and operational records. Customer and Slate-controlled data.

Production database storage and compute in AWS us-east-1, United States; authorized support, control-plane, and subprocessors may operate in other disclosed locations.

EU Standard Contractual Clauses and UK Addendum for restricted transfers. Native production recovery history is configured for six hours; this does not determine Slate's application-record retention periods.

Heap, Inc., a Contentsquare Group company

Product and website behavioral analytics; Heap-generated pseudonymous user and session identifiers, device identifiers, page views, normalized navigation and interaction events, browser and operating-system data, referrer, campaign, session, and technical metadata. Slate-controlled data only.

United States Product Analytics environment in Virginia (AWS us-east-1); authorized affiliates, support functions, and subprocessors may process data globally.

Data Privacy Framework for eligible U.S. transfers and EU or UK Standard Contractual Clauses where adequacy or the Framework is unavailable. Heap analytics data is retained for up to 37 months. Session replay, target-text capture, IP capture, and geolocation capture are disabled.

Google LLC — Google Tag Manager and Google Analytics 4

Tag orchestration and Slate-controlled website and product analytics; normalized page location, path, same-origin referrer, page-view events, cookie and device identifiers, browser information, and technical data. Customer Content, Connected Data, and Google API Data are excluded.

Google's global infrastructure; no fixed customer-selectable GTM or standard GA4 processing region is represented.

Data Privacy Framework, Standard Contractual Clauses, and adequacy mechanisms as applicable under Google's data-processing terms. GTM HTTP request logs are retained for 14 days. GA4 user-level and event-level data is retained for 14 months, with retention reset on new activity disabled.


10. Cookies, local storage, analytics, and tracking choices

10.1 Necessary technologies

Slate and its authentication, hosting, and security providers use cookies, browser storage, and comparable technologies that are necessary to authenticate Users, maintain sessions, prevent fraud, secure the Service, balance traffic, remember requested settings, and provide requested functionality. Blocking these technologies may prevent the Service from working.

10.2 Google Tag Manager and Google Analytics 4

Slate uses Google Tag Manager to deliver a Google Analytics 4 configuration tag and a GA4 page-view tag on Slate-controlled production sites. Slate sends normalized page location, page path, and same-origin referrer values without URL queries or fragments. GA4 may also receive cookie and device identifiers, browser and technical information, and IP-derived approximate location. Slate does not send Customer Content, Connected Data, Google API Data, advertising identifiers supplied by Slate, names, email addresses, or Slate User-ID values to GA4.

GA4 is configured with a 14-month user-level and event-level retention period and does not reset retention when a user returns. Google Signals, advertising personalization, user-provided data collection, enhanced measurement, enhanced conversions, and Google Ads linking are disabled. Slate does not use GA4 for advertising audiences or cross-context behavioral advertising.

10.3 Heap product and website analytics

Slate uses Heap across Slate-controlled production surfaces to understand navigation, interactions, adoption, reliability, and feature performance. Heap may receive Heap-generated pseudonymous user and session identifiers, cookie and device identifiers, page views, normalized navigation and interaction events, browser and operating-system information, referrer, campaign and session metadata, and technical event metadata. Slate does not send names, email addresses, Customer identifiers, or Slate user or organization identifiers to Heap.

Heap data is retained for up to 37 months. Session replay, target-text capture, IP capture, and geolocation capture are disabled. Heap must not receive passwords, payment-card data, OAuth tokens, API credentials, Customer Content, Connected Data, Google API Data, sensitive personal information, form contents, unrestricted free text, or URL query strings.

10.4 Vercel Web Analytics

The Slate application uses Vercel Web Analytics for privacy-focused page measurement. Slate does not provide Vercel Web Analytics with a Slate User-ID or custom advertising identifier. Vercel's visitor-session hash expires after 24 hours, and Slate does not use this service for advertising or session replay.

10.5 Current consent and preference treatment

Slate currently offers the Service for United States business use. Necessary technologies operate as required to provide and secure the Service. Slate uses the analytics described above for its legitimate business purposes and provides any consent or opt-out treatment required by applicable law. A person may request that Slate stop or delete identifier-linked analytics through legal@slatedata.app. Slate does not currently use advertising pixels, retargeting, enhanced matching, session replay, Google Ads, Meta Ads, or Klaviyo marketing tracking on Slate-controlled production sites.

11. Disclosures of information

Slate may disclose information only as described below and subject to applicable platform and legal restrictions.

  •   To the Customer and authorized Users: workspace administrators, members, and collaborators can access information according to their roles, Customer settings, and exports. An administrator may manage membership, revoke access, or view activity.
  •   To service providers and subprocessors: providers that host, authenticate, store, secure, support, bill, analyze, or communicate for Slate may process information under contract and only for authorized purposes.
  •   To connected platforms at the Customer's direction: Slate sends authentication requests, API requests, and Customer-selected exports to the provider selected by an authorized User.
  •   To Slate marketing and advertising providers: only Slate Marketing Data may be disclosed for Slate's own analytics, email, advertising, or measurement. Customer Content, Connected Data, and Google API Data are excluded.
  •   For legal, safety, and security reasons: Slate may disclose information when reasonably necessary to comply with law, court order, legal process, sanctions, regulatory request, or to protect rights, safety, security, and the integrity of the Service. Slate will seek to limit disclosure to what is legally required where permitted.
  •   In a business transaction: information may be disclosed in connection with financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality and applicable law. A successor must remain bound by Google and other platform restrictions for platform data.
  •   With explicit direction or consent: Slate may disclose information when a User or Customer instructs Slate to do so, such as exporting a report or authorizing support access.
  •   Deidentified or aggregate information: Slate may disclose statistics that cannot reasonably identify a person or Customer, provided Slate does not attempt reidentification and the use is not prohibited for Google API Data or another restricted platform data set.

Slate does not grant service providers independent rights to sell Customer Content or use it for their own cross-context advertising. A service provider may process separate account or business-relationship data as an independent controller only as described in its own notice and contract.

12. Sale, sharing, targeted advertising, and Global Privacy Control

12.1 No sale or targeted-advertising sharing

Slate does not sell Personal Information, Customer Content, Connected Data, Google API Data, OAuth tokens, or workspace records for money or other value. Slate does not share Personal Information for cross-context behavioral advertising or process it for targeted advertising. Slate has not engaged in those practices during the 12 months preceding the effective date.

12.2 Global Privacy Control

Because Slate does not currently sell Personal Information or share it for cross-context behavioral advertising, a Global Privacy Control signal does not alter those practices. A person may nevertheless submit any applicable sale, sharing, targeted-advertising, or analytics opt-out request to legal@slatedata.app, and Slate will honor the request where required.

12.3 Sensitive personal information

Slate does not use or disclose sensitive personal information to infer characteristics about individuals. Slate limits sensitive personal information to what is necessary for authentication, security, legal compliance, or a specifically contracted feature and provides any legally required limitation mechanism.

13. Retention, deletion, revocation, and backups

Slate applies the following maximum periods, except where a shorter platform rule applies or a documented legal hold or legal obligation requires longer retention. When a period expires, Slate deletes, irreversibly anonymizes, or otherwise renders the information inaccessible.

Data category

Maximum retention

Production Customer Data after non-Shopify termination

30 days after effective termination or account closure, then deleted from active production systems.

Account and organization records

90 days after account or organization closure, then deleted or irreversibly anonymized, except for minimal information retained under another listed schedule.

OAuth tokens and connection credentials

Until disconnection, revocation, expiration without refresh, account deletion, or another required removal event; reusable credentials are cleared promptly when access ends.

Support records

24 months after the support case or correspondence closes.

Security and audit records

24 months after creation, unless an active security investigation or documented legal hold requires longer retention.

GA4 analytics identifiers and user-level event data

14 months from collection; the period does not reset when the same user returns.

Heap analytics identifiers and user-level event data

Up to 37 months from collection, consistent with Heap's configured Product Analytics retention.

Vercel Web Analytics and runtime logs

Visitor-session hashes expire after 24 hours; Pro runtime logs are retained for one day.

Slate marketing records

24 months after the last meaningful marketing engagement. A suppression-only record may remain for seven years after opt-out solely to prevent future marketing.

Application and database backups

No more than 30 days after creation. The configured Neon production recovery-history window is six hours.

Legal and accounting records

Seven years after the end of the fiscal year in which the transaction occurred or the matter closed, whichever is later, unless a documented legal hold requires longer retention.


13.1 Customer requests and termination

A Customer may request export or deletion through the Service or the published request method, subject to role authorization and legal restrictions. Slate may retain deidentified aggregate statistics, security evidence, billing records, and information necessary to establish, exercise, or defend legal claims, provided such retention is lawful and not prohibited by a platform policy.

13.2 Platform revocation and deletion

When a connected platform requires deletion, refresh-token revocation, data invalidation, privacy-webhook processing, or cache expiration, Slate will follow that requirement even if the general Slate retention criteria would otherwise permit longer retention. Customers must not reconnect or reimport data to circumvent a platform deletion request or legal right.

13.3 Shopify deletion and privacy requests

A verified Shopify uninstall or administrator disconnect starts a 48-hour deletion period for the disconnected shop after credentials are cleared and synchronization stops. Verified customer and shop redaction requests are processed immediately. A Shopify customer data request is fulfilled through a protected merchant-facing export; the merchant is responsible for the response to its customer. Protected backups age out under the backup schedule, and deleted Shopify data is re-deleted or isolated after any disaster-recovery restoration.

14. Security

Slate uses administrative, technical, and organizational safeguards designed for the nature of the Service and information processed. No system is completely secure, and Slate cannot guarantee that unauthorized access, loss, or misuse will never occur.

  •   Transport security: secure modern protocols for data in transit between users, Slate, and connected providers.
  •   Token encryption: OAuth access and refresh tokens are encrypted at rest using authenticated encryption. The audited implementation uses AES-256-GCM and a separate encryption key supplied through the environment.
  •   Access controls: authenticated access, organization scoping, role-based permissions, least-privilege administrative access, and separate development and production access where implemented.
  •   Auditability: records of material imports, edits, corrections, synchronization, settings changes, and exports where the feature supports them.
  •   Secrets and key management: production secrets must be kept outside source control, limited to authorized systems and personnel, rotated when required, and monitored for accidental exposure.
  •   Application and infrastructure controls: dependency management, code review, deployment controls, database protections, logging, monitoring, backup, recovery, and vulnerability remediation appropriate to the Service.
  •   Vendor diligence: review of subprocessors, data-protection terms, security documentation, region and transfer mechanisms, and notification procedures.
  •   Personnel controls: confidentiality obligations, access approval and removal, security awareness, and access only for a legitimate business need.
  •   Incident response: detection, containment, investigation, remediation, evidence preservation, Customer and regulator notification, and platform notification where required. Google requires notification to Google for a known or suspected unauthorized access involving Google Data under applicable policy.

Users are responsible for maintaining the security of their devices, email accounts, Google accounts, authentication factors, and Customer platform accounts; using strong authentication; limiting roles; reviewing integrations; and promptly reporting suspected compromise.

15. International data transfers

Slate and its providers may process information in the United States and other countries where they or their subprocessors operate. Those countries may have privacy laws different from the laws where an individual lives. Where required, Slate will use an approved transfer mechanism, such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework or an applicable extension when the recipient is certified, or another lawful mechanism.

Slate's primary application compute is in Vercel's Washington, D.C. region (AWS us-east-1), its production Neon database is in AWS us-east-1, Heap Product Analytics is hosted in Virginia (AWS us-east-1), Clerk hosts Customer Personal Data in the United States, and Google processes GTM and GA4 data through global infrastructure without a fixed customer-selectable processing region. Section 9 identifies the applicable Data Privacy Framework certifications, Standard Contractual Clauses, UK transfer terms, and adequacy mechanisms.

16. Privacy rights and choices

Depending on location and relationship to Slate, an individual may have rights to know or confirm processing; access; obtain a copy; correct; delete; restrict or object; withdraw consent; obtain portability; opt out of sale, sharing, targeted advertising, or certain profiling; limit sensitive-information use; appeal a denial; and complain to a regulator.

16.1 How requests are handled

  1.  1. Email legal@slatedata.app. Requests received through another Slate-controlled channel are forwarded to that monitored inbox and logged without requiring resubmission.
  2.  2. Describe the right being exercised, the Slate account or organization involved, and enough information for Slate to locate the relevant records without collecting excessive new information.
  3.  3. Slate may verify identity, authority, and account relationship using proportionate methods. Slate will not request a password, complete payment-card number, or unrelated sensitive information.
  4.  4. If Slate processes the information solely for a Customer, Slate may direct the request to that Customer or assist the Customer as required by contract and law.
  5.  5. Slate targets completion of ordinary requests within 30 calendar days. California requests to know, delete, or correct are acknowledged within 10 business days and answered within 45 calendar days, subject to a permitted 45-day extension with notice. California sale, sharing, and sensitive-information requests are honored as soon as feasible and no later than 15 business days. EEA and UK requests are answered ordinarily within one month, subject to a permitted two-month extension with timely notice. Shopify compliance requests are completed within 30 days.

16.2 Authorized agents

Where permitted, an authorized agent may submit a request. Slate may require evidence of authorization and may verify the individual directly, except where a valid power of attorney or another legal rule provides otherwise.

16.3 Denials and appeals

A denial or partial denial will identify the unfulfilled portion, explain the reason to the extent legally permitted, and describe any applicable appeal or regulator-complaint route. Appeals may be emailed to legal@slatedata.app and should identify the original request and the decision being appealed. Slate targets an appeal decision within 30 calendar days or sooner where law requires. A different qualified reviewer will conduct the appeal where reasonably available; otherwise, the original decision-maker will perform and document a second review.

16.4 Account and platform controls

  •   update available profile or organization settings through Slate;
  •   disconnect a platform integration and separately revoke access in the platform account;
  •   control membership and roles through an authorized administrator;
  •   unsubscribe from marketing using the message link while Slate retains a minimal suppression record;
  •   email legal@slatedata.app to request an applicable analytics or marketing opt-out; and
  •   enable Global Privacy Control where supported and legally applicable.

16.5 Non-discrimination

Slate will not unlawfully discriminate against a person for exercising a privacy right. Slate may offer a different price or service level when the difference is reasonably related to the value of data and permitted by law, but no financial-incentive program is identified as active as of the effective date.

17. California and other U.S. state disclosures

This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws. Applicability depends on legal thresholds, exemptions, context, and Slate's actual operations. The categories below use California statutory terminology and describe the information Slate can collect in the course of operating the Service.

California category

Examples in Slate

Collected from

Disclosed to

Identifiers

Name, business email, IP, account, Clerk, Google, organization, platform, cookie, and device identifiers

User, Customer, browser, Clerk, and connected platforms

Customer users; Clerk; Vercel; Neon; support or security providers; connected platforms at direction

Customer-record information

Business contact, account and billing administration information

User and Customer

Service providers; professional advisers; Customer administrators

Commercial information

Subscription, plan, transaction administration, product interest, marketing engagement, order or revenue records in Customer data

User, Customer, Shopify, and other connected platforms

Service providers; Customer users; connected destinations

Internet or electronic activity

Pages, clicks, sessions, referrers, browser, device, logs, feature activity, ad interactions

Browser, device, hosting, analytics and advertising tools

Vercel; Google Analytics; Heap; advertising providers subject to choice; security providers

Geolocation

Approximate location inferred from IP and connected-platform country or region dimensions

Browser, analytics provider, connected platform

Analytics/service providers; Customer users for connected reports

Professional or employment-related information

Business email, company, title or role if provided, organization membership

User, Customer, business sources

Customer users; Slate-controlled communications records; service providers

Inferences

Product-interest, feature-use, marketing engagement, or account-health inferences derived from Slate-controlled data

Slate-controlled activity

Slate service providers and authorized staff. No inferences from Customer Content or Google API Data for Slate advertising.

Sensitive personal information

Account authentication data and security information; payment credentials remain with Stripe or the authentication provider

User and Clerk

Necessary authentication, security, payment, and hosting providers only


17.1 Business purposes and categories of recipients

The business and commercial purposes are described in Section 6. Categories of recipients are described in Sections 9 and 11. Slate does not sell Personal Information and does not share it for cross-context behavioral advertising or process it for targeted advertising. Google Ads, Meta Ads, and comparable advertising tags are not enabled on Slate-controlled production sites as of the effective date.

17.2 Notice at collection

The categories collected at a particular interaction depend on the feature. Slate must link this Policy or a concise notice at or before registration, marketing forms, cookie collection, payment, support intake, and OAuth authorization. The notice must identify the relevant categories and purposes and must not rely on this long-form Policy when a timely contextual notice is required.

17.3 Minors

Slate has no actual knowledge that it sells or shares personal information of persons under 16 and does not intend to do so. The Service is for business users who are at least 18.

17.4 Appeals

Where a state law provides an appeal right, email legal@slatedata.app and identify the original request and decision. Slate targets a decision within 30 calendar days or sooner where applicable law requires and will provide the reason for its decision and any required attorney-general or regulator complaint route.

18. EEA, United Kingdom, and Switzerland disclosures

18.1 Controller and representative information

For Slate-controlled processing, Slate Data LLC is the controller. Slate Data LLC is a Massachusetts limited liability company with a business mailing address at 333 Ricciuti Drive #1404, Quincy, MA 02169, United States, and can be contacted at legal@slatedata.app. Slate currently offers the Service for United States business use. If an EU or UK representative or data protection officer becomes legally required, Slate will update this Policy with the applicable contact information.

18.2 Legal bases and rights

The legal bases are described in Section 6. Individuals may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal, and complaint to a supervisory authority. Individuals also may object to direct marketing at any time. Slate does not identify automated decision-making that produces legal or similarly significant effects as an active feature.

18.3 Customer-controlled data

When Slate acts as a processor, the Customer is responsible for the legal basis, transparency, data-subject response, and instructions. Slate will assist as required by the applicable data-processing agreement. A written Slate DPA, including processing details, confidentiality, security, subprocessors, deletion, audits, assistance, incident notice, and transfer terms, must be available before regulated Customer data is processed at scale.

18.4 Complaints

An individual may complain to the supervisory authority where the individual resides, works, or believes an infringement occurred. Slate requests an opportunity to address the concern through the published privacy contact first, but that request does not limit the right to contact a regulator.

19. Children and business use

Slate is a business-to-business service and is not directed to children. A User must be at least 18 and able to form a binding contract. Slate does not knowingly collect personal information directly from children under 13. A Customer must not upload, connect, or otherwise process children's personal information through Slate. If Slate learns that such information was collected without appropriate authorization, Slate will take reasonable steps to delete it and restrict the responsible account.

20. Changes to this Policy

Slate may update this Policy to reflect changes in law, platform requirements, providers, products, or processing. The updated version will state the new effective date and be posted at the public Privacy Policy URL. For a material change involving a new use of Google API Data or other information beyond the use originally disclosed and authorized, Slate will provide additional notice and obtain renewed consent or authorization when required before the new use begins.

A Customer is responsible for reviewing updates and maintaining its own notices. Continued use after an effective update constitutes acceptance only to the extent permitted by law and does not replace consent where consent is legally required.

21. Contact information

Slate Data LLC
333 Ricciuti Drive #1404
Quincy, MA 02169
United States

Email: legal@slatedata.app

Use this monitored address for privacy-rights requests, deletion requests, appeals, analytics or marketing opt-outs, platform-data deletion requests, security reports, legal notices, and regulator communications. The Founder and Managing Member monitors the inbox at least weekly and handles escalations.


Appendix A. Detailed data inventory

Record or field group

Examples

Purpose

Primary location or recipient

User record

User ID, email, name, avatar, user type, preferences, creation time

Account and experience administration

Clerk and Slate database on Neon

Organization record

Clerk organization ID, name, currency, time zone, fiscal year, date format, business type, settings

Workspace configuration and reporting context

Slate database on Neon

Membership

Organization ID, user ID, Admin/Editor/Viewer role, creation time

Authorization and organization governance

Clerk and Slate database on Neon

Billing

Plan, subscription status, trial, internal billing status, and billing period

Subscription administration

Slate database on Neon; no production payment processor identified as enabled

Integration connection

Provider, external account, encrypted access/refresh token, expiry, scopes, sync time, connecting user

Authorized platform access

Slate application and Neon; connected provider

Sync run

Provider, queued/running/succeeded/failed, summary, error, actor, timestamps

Reliability, audit, troubleshooting

Slate database and operational logs

Data source

Platform, provider, kind, owner, label, channel, notes, status, metadata

Source governance

Slate database

Source account

External account ID/name, currency, time zone, status, metadata

Account selection and attribution

Slate database

Raw metric fact

Date, grain, raw dimensions, raw metrics, raw payload, currency, time zone, idempotency key

Traceability, normalization, deduplication

Slate database

Normalized metric record

Source, medium, campaign, ad group, ad, creative, country, region, device, placement, metrics, tags, notes, edit status

Editable governed reporting record

Slate database and Customer-authorized exports

Rules and applications

Triggers, conditions, actions, run status, rows checked/matched/changed, old/new value

Automated governance and audit

Slate database

Audit and edit logs

Actor, action, before/after, reason, origin, timestamps, old/new amount

Accountability and change history

Slate database

Saved views and reports

Filters, columns, groupings, sorting, creator

User-facing reporting

Slate database

Google Sheets export

Spreadsheet ID/URL/name, export type, mode, schedule, filters, columns, status, row count

Customer-directed export and history

Slate database and Google Sheets

Alerts

Type, severity, status, title, message, metadata, email status

Operational and reporting notifications

Slate database and any configured email provider

Webhooks

Source, event ID, receipt time

Deduplication and event handling

Slate database and logs

Site/product analytics

Page, event, referrer, campaign, device, cookie, session, error

Slate-controlled analytics and improvement

Google Analytics and Heap only when configured and consented

Slate marketing profile

Business contact, subscription/consent, suppression, campaign engagement

Slate communications and marketing

Slate-controlled communications records; no production marketing automation vendor identified as enabled


Appendix B. Integration and provider matrix

Integration or provider

Status as of August 30, 2026

Access or role

Privacy treatment

Google Sign-In via Clerk

Identified for use

Authentication profile and session

Separate from data-source authorization

Google Ads

Active code-backed connector

`adwords` OAuth scope; reporting data

Google Limited Use; no Slate advertising use

Google Analytics 4 data source

Active code-backed connector

`analytics.readonly`

Customer-facing aggregate analytics reporting

Google Sheets

Active code-backed export destination

`spreadsheets` and `drive.file`

Customer-directed file creation/editing only

Google Docs

Not active in audited implementation

No active Docs scope identified

No current access; policy/consent update required before activation

Google Slides

Not active in audited implementation

No active Slides scope identified

No current access; policy/consent update required before activation

General Google Drive

Not active; `drive.file` only for Sheets workflow

No broad Drive scope identified

Do not claim access to all Drive files

Meta Ads

Active code-backed connector

`ads_read`, `business_management`

Customer-facing reporting; Meta terms apply

LinkedIn Ads

Active code-backed connector

`r_ads`, `r_ads_reporting`

Customer-facing reporting; program approval required

Microsoft Advertising

Active code-backed connector

`openid`, `offline_access`, `msads.manage`

Used for reporting; disclose broader permission accurately

TikTok Ads

Active code-backed connector

App-approved dynamic scopes

Customer-facing reporting; app approval and data terms apply

Reddit Ads

Active code-backed connector

`adsread`, `identity`

Customer-facing reporting; production user-agent and commercial approval review required

Shopify

Active code-backed connector

No universal required data scope; table-selected optional `read_orders`, `read_customers`, `read_products`, `read_inventory`, `read_locations`, and `read_marketing_events`; `read_all_orders` is used only if separately granted

Shop, orders/line items, limited customers, products/variants, inventory, locations, attribution visits, privacy webhooks, and derived reporting; Protected Customer Data review applies

Amazon Ads

Provider enum only; no live connector established

None confirmed

Do not claim active access

Klaviyo data source

Planned/desired; not active in audited connector registry

None confirmed

Separate from Slate marketing Klaviyo account

Pinterest / Spotify

Inactive or placeholder concepts only

None confirmed

Do not claim active access

Clerk

Active dependency

Authentication and organization management

Processor/service provider plus independent-controller account data

Neon Postgres

Active infrastructure

Primary application database

Databricks/Neon processor in AWS us-east-1; six-hour recovery history; SCCs and UK Addendum for restricted transfers

Vercel

Active infrastructure

Hosting, execution, deployment, logs, jobs

Vercel processor in iad1 / AWS us-east-1; global CDN; one-day runtime logs; SCCs and UK IDTA

Stripe

Production enablement not established

Subscription and payment administration

Excluded from the verified production-provider list as of the effective date

Google Analytics for Slate

Enabled through the published production GTM container

Slate website/product analytics

GA4 page-view measurement only; 14-month user/event retention; reset off; Signals, advertising, enhanced measurement, and User-ID disabled

Heap

Enabled on Slate-controlled production surfaces through the shared production environment

Product and website analytics, interactions, and Heap-generated pseudonymous user and session identifiers; no Slate identity calls

US Product Analytics region; 37-month retention; replay, target text, IP, and geolocation capture disabled

Google Ads / Meta Ads for Slate

Not enabled in production

Slate advertising and measurement

No advertising pixel, retargeting, enhanced matching, audience, or conversion tag enabled

Klaviyo for Slate marketing

Not enabled in production

Marketing profiles, consent, suppression, message events

Excluded from the verified production-provider list as of the effective date

GitHub

Active private source-control repositories

Code and development history

Not a production Customer-data store; no secrets or live data

Svix hosted service

Not established by dependency alone

Possible webhook service only if separately configured

Hosted service not established and excluded from the production-provider list


Appendix C. Official platform notices reviewed

The following official materials informed the platform-specific disclosures as of the effective date. Slate reviews applicable terms and notices when adding scopes or materially changing a connector.

  •   Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
  •   Google Workspace API User Data and Developer Policy: https://developers.google.com/workspace/workspace-api-user-data-developer-policy
  •   Google Ads API Required Minimum Functionality: https://developers.google.com/google-ads/api/docs/api-policy/rmf
  •   Google Ads API Terms and Policies: https://developers.google.com/google-ads/api/terms
  •   Google Analytics Terms: https://www.google.com/analytics/terms/
  •   Google EU User Consent Policy: https://www.google.com/about/company/user-consent-policy/
  •   Meta Platform Terms: https://developers.facebook.com/terms/
  •   Meta Developer Policies: https://developers.facebook.com/devpolicy/
  •   LinkedIn Marketing Developer Terms: https://www.linkedin.com/legal/l/marketing-api-terms
  •   Microsoft Advertising Policies: https://about.ads.microsoft.com/en-us/resources/policies
  •   TikTok Business Products Data Terms: https://ads.tiktok.com/i18n/official/policy/controller-to-controller/privacy
  •   Reddit Data API Terms: https://redditinc.com/policies/data-api-terms
  •   Shopify API License and Terms of Use: https://www.shopify.com/legal/api-terms
  •   Shopify Protected Customer Data Requirements: https://shopify.dev/docs/apps/launch/protected-customer-data
  •   Amazon Ads API documentation: https://advertising.amazon.com/API/docs/en-us/info/api-overview
  •   Clerk Privacy Policy and DPA: https://clerk.com/legal/privacy
  •   Vercel DPA: https://vercel.com/legal/dpa
  •   Neon Privacy and DPA resources: https://neon.com/privacy-policy
  •   Stripe Privacy Center: https://stripe.com/legal/privacy-center
  •   Heap Privacy and Session Replay guidance: https://help.heap.io/hc/en-us/sections/36055200771601-Session-Replay-Data-Privacy
  •   Klaviyo Privacy Center: https://privacy.klaviyo.com/
  •   California CCPA and Global Privacy Control guidance: https://oag.ca.gov/privacy/ccpa
  •   FTC privacy and security guidance: https://www.ftc.gov/business-guidance/privacy-security
Slate

Trusted marketing data, without a data team.

Product

Product OverviewData SourcesManual DataGovernance & Audit TrailExports

Solutions

Marketing TeamsAgenciesFinance Teams

Use Cases

Monthly ReportingManual Vendor SpendExecutive Budget ReviewsAgency Client Reporting

Resources

BlogDocsAbout SlateSecurity

Get Started

Sign inStart with your first source
Terms of ServicePrivacy PolicyData Processing Agreement