Last updated May 13, 2026 · Effective May 13, 2026
This Privacy Policy explains what information HydraScale collects, why we collect it, how we use it, and the rights you have over it. It applies to the HydraScale dashboard at hydrascale.io and any related services.
HydraScale is an operations dashboard for multi-store DTC brands. To do its job, it connects to the third-party services you already use — Shopify, Meta Ads, Google Ads, Google Drive, Gmail, Triple Whale, euShipments, Brevo and others — and consolidates the data into one tenant-scoped workspace.
We are committed to handling your data responsibly and transparently. This policy is written in plain English; if anything is unclear, email privacy@hydrascale.io.
When you create an account we collect your name, email address, a hashed password (we never see the plaintext), and the organisation you belong to. If you sign in with Google, we additionally store your Google account email and a Google-issued user identifier.
When you authorise an integration, HydraScale retrieves only the data needed to run the features you've enabled. Specifically:
We log basic request data (timestamp, route, response code, anonymised IP) and product analytics (which pages you visit, which features you use) so we can keep the service reliable and improve it. We do not run third-party advertising trackers.
When billing is enabled we store the last four digits and brand of your card, your billing address, and a token issued by our payment processor. We never store full card numbers; they are held by our PCI-DSS-compliant payment processor.
We use the information described above to:
We do not sell your personal data. We do not use your data to train generative AI models for third parties. When we use AI features (anomaly explanations, support-email triage), we send only the minimum context needed, using providers that contractually do not use the data to train their own models.
Compliance disclosure
HydraScale's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data to third parties.
We do not use Google user data for advertising, and we do not allow humans to read your Google user data except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
Google Ads (adwords + userinfo.email + userinfo.profile)
Why: Read daily spend, impressions, clicks, conversions per ad account so the dashboard can show real margin and ROAS. userinfo lets us display 'Connected as ...' on the integration card so you can confirm the right Google account was linked.
What we keep: Daily aggregates only — no creative content, no audience PII. Email + display name shown on the integration card only.
Sign in with Google (openid + email + profile)
Why: Lets you create an account or sign in with one click. We receive only your Google account email, display name, and profile picture URL.
What we keep: Email + name attached to your user record so you can sign back in. We do not store profile picture URLs.
Encrypted in transit + at rest
All Google data is fetched over TLS and stored encrypted at rest in our database.
Strict tenant isolation
Your Google data is only readable by users in your organisation. Cross-tenant access is blocked at the database layer and audited.
Revoke any time
Disconnect a Google integration in Settings → Integrations, or revoke at myaccount.google.com/permissions.
No advertising use
Google user data is never used to personalise, target, or measure advertising.
Questions about our Google API usage? Email privacy@hydrascale.io.
We keep your data only as long as needed:
See Data Deletion Instructions for step-by-step guidance.
Regardless of where you live, you have the following rights over your personal data:
For CCPA / CPRA residents specifically: we do not sell or share personal information as those terms are defined under California law. You may exercise your rights by emailing privacy@hydrascale.io. We will respond within 45 days.
We follow industry-standard practices to protect your data:
Full detail at /security. To report a vulnerability, email security@hydrascale.io.
Your data may be processed in the country where our cloud provider operates and where our team works. We rely on Standard Contractual Clauses (where applicable) and provider-level safeguards to ensure equivalent protection regardless of where the data is stored.
HydraScale is a B2B product not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us information, email privacy@hydrascale.io and we will delete it.
We'll update this policy as the product evolves. Material changes will be announced in-app and by email to the account owner at least 14 days before they take effect. The "Last updated" date at the top reflects the current version.
For any privacy question or request:
We respond to privacy requests within 1 business day on business days, and formal data-rights requests within the timeframes required by applicable law.