Legal
Privacy Policy
Last updated: May 25, 2026
1. Who We Are
BuzzMinter LLC ("BuzzMinter", "we", "us") is a Delaware limited liability company that designs, builds and operates industry-grade growth platforms across distinct B2B verticals (the "Platform"), available at buzzminter.com. The Platform is powered by a shared multi-tenant gateway that connects to third-party services on behalf of each vertical — including TikTok, YouTube, Google Ads, Google Analytics, Facebook, Instagram, LinkedIn, and X — so each vertical can run content generation, lead capture, nurturing and closing end-to-end. You can reach us at hello@buzzminter.com.
2. Information We Collect
We collect information you provide directly when you fill out our contact or booking form, or when you sign in to the BuzzMinter app: your name, email address, phone number, industry, and goals. We may also collect basic usage data (pages visited, browser type, IP address) through analytics tools for the purpose of improving the App and the Site.
3. How We Use Your Information
We use the information we collect to respond to your consultation requests, operate the BuzzMinter app, communicate with you about our services, and improve the App and the Site. We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Data Retention
We retain your contact information for as long as necessary to fulfill the purposes described above or as required by law. You may request deletion of your data at any time by contacting us.
5. Cookies
The BuzzMinter app and our website may use essential cookies to ensure proper functionality. We do not use tracking cookies for advertising purposes without your consent.
6. Third-Party Services
We use Amazon Web Services (AWS) to process and deliver emails. Your contact form data is transmitted securely via AWS Simple Email Service (SES). We use Supabase for backend infrastructure. These providers have their own privacy policies governing the data they process on our behalf.
7. Third-Party OAuth Integrations
BuzzMinter operates as a multi-tenant gateway that securely connects our customers' accounts to third-party platforms. When a customer authorizes a connection through our OAuth flow, we receive and store on their behalf the platform's display name, account identifier, and short-lived access and refresh tokens. These credentials are kept in our database under strict access controls (Supabase (managed Postgres) row-level security, service-role-only access from our backend), are isolated per customer, and are used solely to perform actions the customer has explicitly requested through the Platform — for example, publishing scheduled content or fetching analytics. We do not share, sell, or use these credentials for any purpose outside the scope of the customer's authorized usage, and we do not access platform content beyond what is necessary to deliver the requested action.
Scopes requested per integration:
• TikTok (Login Kit / Content Posting): user.info.basic, user.info.stats, video.publish
• TikTok For Business (Marketing API): Report, Ad Account Information, Lead Retrieval, Lead Test
• YouTube: youtube.upload, youtube.readonly, yt-analytics.readonly
• Google Ads: adwords
• Google Analytics: analytics.readonly
• Facebook: pages_manage_posts, pages_read_engagement, pages_show_list
• LinkedIn: w_organization_social, r_organization_admin
For TikTok specifically, the user.info.basic scope is used to retrieve the connected account's display name, open ID, and avatar; the user.info.stats scope is used to retrieve aggregated profile statistics (follower count, following count, total likes received, and total video count) which are displayed inside the Platform's analytics dashboard for the connected tenant; and the video.publish scope is used to publish videos that the tenant has explicitly submitted through the Platform.
For TikTok For Business (a separate TikTok app dedicated to advertiser data), we authorize each tenant's advertiser account through TikTok's Marketing API OAuth flow and store the resulting long-lived access token alongside the chosen advertiser ID. The Report permission is used to retrieve advertising performance metrics (spend, impressions, clicks, CTR, CPC, CPM, reach, conversions, cost-per-conversion) at the advertiser, campaign, and time-series level, displayed inside the tenant's analytics dashboard. The Ad Account Information permission is used to retrieve read-only metadata about the connected advertiser account (operating currency and account name) so monetary values can be labeled in the tenant's actual currency. The Lead Retrieval permission is used to fetch submissions from the tenant's own TikTok Lead Generation forms and surface them inside the tenant's leads dashboard alongside leads from other channels (Meta, Google, web forms); lead data is read-only on TikTok's side, stored encrypted in our database scoped per tenant, used solely to display leads to the tenant, and deleted within 30 days of disconnection or upon written request. The Lead Test permission is used exclusively in our development and staging environments to validate the Lead Retrieval integration against TikTok-provided sandbox lead data; no real end-user lead data is involved in Lead Test calls.
Tokens are retained as long as the connection is active. They are deleted when the customer disconnects the integration from inside the Platform, when their BuzzMinter account is terminated, or upon written request to hello@buzzminter.com. Customers can also revoke BuzzMinter's access at any time directly from the third-party platform's account settings.
Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (see Section 8 below for details).
8. Google API Services and Limited Use
BuzzMinter's integration with Google services — including YouTube (YouTube Data API and YouTube Analytics API), Google Ads, and Google Analytics — operates in compliance with the Google API Services User Data Policy, including the Limited Use requirements.
Data we access from Google APIs. When a customer connects a Google account to BuzzMinter, we access on their behalf:
• YouTube channel and video metadata (channel name, channel ID, video IDs, titles, descriptions, thumbnails)
• The ability to upload new videos to the connected YouTube channel
• YouTube Analytics performance reports for the connected channel (daily views, watch time, average view duration, subscribers gained). We do not access monetization or revenue data.
• Google Ads campaign- and ad-group-level performance metrics (impressions, clicks, conversions, cost) for the connected ad account, read-only. We never create, edit, pause, or delete campaigns, ad groups, ads, or keywords — the broader write capabilities described in Google's consent screen for the adwords scope are not exercised by our Platform.
• Google Analytics 4 property reports for the connected property (sessions, users, pageviews, top pages, conversion events), read-only
How we use Google user data. The data we access through Google APIs is used solely to provide the user-facing features of the Platform that the customer has explicitly requested — for example, scheduling a video upload, displaying analytics in their dashboard, or generating campaign performance reports. We do not derive secondary insights, train machine learning models on this data, or use it for any purpose outside the scope of the customer's authorized usage.
Limited Use commitments. Data obtained through Google APIs is:
• Not transferred to third parties except (i) to infrastructure providers strictly necessary to provide the Platform (e.g., our database, hosting), (ii) to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with the same data protection commitments.
• Not used to serve advertisements, including retargeting, personalized, or interest-based advertising.
• Not read by humans except (i) with the customer's explicit prior consent, (ii) for security purposes (such as investigating abuse), (iii) to comply with applicable law, or (iv) in aggregated/anonymized form for internal operations.
Token storage and revocation. Google OAuth access tokens and refresh tokens are stored in our Supabase (managed Postgres) database under strict service-role access controls and are isolated per customer. They are deleted when the customer disconnects the corresponding integration from inside BuzzMinter, when their account is terminated, or upon written request. Customers can also revoke BuzzMinter's access at any time from their Google Account permissions page.
9. Data Security and Protection Mechanisms
We take the protection of personal data and sensitive data — in particular OAuth credentials and data obtained from Google APIs and other third-party platforms — seriously, and we apply the following technical and organizational safeguards:
Encryption in transit. All traffic to and from the Platform, including OAuth handshakes, API gateway calls, and dashboard access, is served exclusively over HTTPS using TLS 1.2 or higher. Server-to-server calls to third-party providers (Google, TikTok, Facebook, LinkedIn, X, AWS, Supabase) are also performed over TLS.
Encryption at rest. The underlying Supabase (managed Postgres) database (managed by Supabase) and our object storage are encrypted at rest using AES-256. Database backups inherit the same encryption.
Credential storage. Third-party OAuth access tokens and refresh tokens (including Google, YouTube, Google Ads, Google Analytics, TikTok, Facebook, LinkedIn, X) are stored in dedicated per-integration tables, isolated per customer (tenant). BuzzMinter API keys issued to customers are never stored in plaintext — only a SHA-256 hash and a short non-secret prefix are persisted, so a database snapshot cannot be used to impersonate a customer.
Access controls. Tables holding sensitive data have Supabase (managed Postgres) Row-Level Security (RLS) enabled with no public policy, meaning they are unreachable through the public anon key and can only be queried by our backend using the service role. The service-role secret is stored as an encrypted environment variable on our hosting provider (AWS Amplify) and is never exposed to the browser or to client code. Administrative access to production infrastructure (AWS, Supabase, hosting) is restricted to a minimal number of authorized engineers and protected by individual accounts, strong passwords, and multi-factor authentication.
Tenant isolation. Every row of customer data carries a tenant_id, and all gateway endpoints authenticate the caller via a Bearer API key tied to a specific tenant before any read or write — preventing one customer from ever accessing another customer's connections, tokens, or analytics.
Limited human access. Data obtained from Google APIs (and other third-party APIs) is not read by humans, except (i) with the customer's explicit prior consent, (ii) for security purposes such as investigating abuse or a security incident, (iii) to comply with applicable law, or (iv) in aggregated and anonymized form for internal operations and capacity planning.
Network and platform hardening. The Platform runs on managed cloud providers (AWS, Supabase) that maintain SOC 2 / ISO 27001 compliance for their underlying infrastructure. Dependencies are kept up to date and monitored for known vulnerabilities; secrets are never committed to source control.
Incident response. In the event of a confirmed security incident affecting personal data or third-party credentials, we will notify affected customers without undue delay at the email address associated with their account, describe the nature of the incident and the data involved, and detail the remediation steps taken — including, where applicable, revoking and rotating impacted tokens and API keys.
Data deletion. When a customer disconnects an integration, terminates their account, or submits a written deletion request to hello@buzzminter.com, the associated tokens and personal data are deleted from our production database; residual copies in encrypted backups are purged according to our backup rotation (maximum 30 days).
10. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise any of these rights, please contact us at hello@buzzminter.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the date at the top of this page.
12. Contact
For any privacy-related questions, contact us at:
Buzzminter LLC — 8 The Green #21902, Dover, Delaware 19901, USA
hello@buzzminter.com