Back to homepage

Privacy Policy

Effective date:

This policy explains how StillMetrics, available at https://stillmetrics.com, handles information when you visit the site, create an account, join a workspace, connect a data source or use reporting tools. StillMetrics is a platform in development. Meta Ads is integrated; Salla functionality is still being developed, and other integrations are upcoming. This policy covers features actually used, not a promise that every integration is available.

1. Information we process

  • Account and authentication information: email address, user identifier, profile information supplied at registration or sign-in, authentication/session information and account-related communications. If you choose Google sign-in, we receive the identity information Google provides for login, such as your email, name and profile image where supplied. StillMetrics does not receive your Google password.
  • Workspace information: workspace names, settings, membership, roles, invitations and connected-source information.
  • Authorized Meta Ads information: ad account identifiers, names and currencies; campaign, ad set, ad and creative metadata; advertising performance, spend, impressions, clicks, reach, frequency, conversion actions, values and attribution information where made available by Meta and retrieved by the service. Advertising reports are not a list of individual people who viewed or clicked an ad.
  • Authorized Salla information: merchant/store information and order, product and customer information made available through an authorized connection and used by the enabled commerce functionality. This can include order identifiers, dates, statuses, amounts and customer-related fields contained in returned records. Availability depends on the integration and permissions.
  • Connection and reporting information: source authorization tokens, permissions, expiry information, reporting API-key records and usage needed to authenticate data access.
  • Operational information: request and error logs, synchronization history, timestamps and technical information such as browser/device information and IP addresses where recorded by our infrastructure. We also process information you send when requesting support.

2. Why we use information

We use information to sign you in, manage workspaces and permissions, retrieve and organize authorized source data, produce analytics and reports, support exports and reporting connections, diagnose failures, protect the service against misuse and respond to requests. Connections are opt-in: you or an authorized workspace user choose to connect a source and grant the permissions requested by that source.

Where applicable law requires a legal basis, processing may be necessary to provide the service you request, support legitimate interests in operating and securing the service, comply with legal obligations, or rely on consent where required. Your organization's own responsibilities for merchant and customer information remain separate from StillMetrics' account and service administration.

3. Google login and reporting access

Google authentication is used for account login when you choose it. Current Looker Studio access to StillMetrics reporting uses a workspace reporting API key; it does not use Google OAuth to authorize access to StillMetrics data. The Meta Ads Community Connector handoff is a Beta / Test option, not approved production onboarding.

If you use Looker Studio, Google Sheets or a connector, the data you request is made available to that tool and may be accessible to people with whom you share the resulting data source, sheet or report. Those tools apply their own terms, privacy practices and access controls. Do not place reporting keys in publicly shared reports, documents or URLs.

4. Who can access information

Workspace members can access workspace information according to their roles and the service's access controls. Workspace administrators are responsible for choosing members and managing shared reporting access. Anyone holding a valid reporting key may be able to read the workspace data exposed by that key's reporting endpoints.

We use service providers, including Lovable Cloud and supporting hosting, authentication, database, cloud and operational platforms, to run the service. They process information as needed to provide their services. Authorized support or operational personnel may access information where needed to troubleshoot, secure or administer StillMetrics. Connected platforms such as Meta, Salla and Google also process information under their own policies.

We may disclose information when required by law or reasonably necessary to address fraud, security incidents or legal claims. If the service changes ownership, information may be transferred as part of that change, subject to applicable law and appropriate notice.

5. Security and browser storage

StillMetrics uses access controls, workspace isolation and restricted handling of source tokens to reduce unauthorized access. No online service can guarantee absolute security. Keep your login, reporting keys and source credentials confidential, review workspace membership and notify us if you suspect unauthorized access.

The application and authentication providers use browser storage and/or cookies as needed to maintain sessions and operate the service. Third-party pages you choose to open may use their own cookies. Clearing browser storage can sign you out; it does not delete server-side records.

6. Retention, disconnection and deletion

Information is retained as needed to provide reporting, maintain account and workspace records, troubleshoot issues and meet applicable legal or security requirements. There is no universal fixed retention period promised by this policy.

Disconnecting a source or revoking its authorization does not necessarily delete previously imported data, cached reports, logs or exports. To request deletion of an account, workspace or connected-source data, email ziadelamary@gmail.com. We may need to verify your identity and authority over a workspace before acting. Requests are reviewed and handled subject to applicable law, technical constraints and legitimate retention obligations; backups may remain until their normal lifecycle ends. Copies already exported to third-party tools must be managed in those tools.

7. Your choices and privacy rights

You can choose not to connect a source, manage workspace access where your role allows, revoke reporting keys through the available key controls, and revoke source permissions in the relevant platform's account settings. Google sign-in access can be revoked in your Google Account settings. Revoking Google access does not itself delete your StillMetrics account or imported reports, and existing sessions may need to be signed out separately.

Depending on your location, you may have rights to access, correct, delete or receive a copy of your personal information, restrict or object to processing, or withdraw consent. Send requests to ziadelamary@gmail.com. You may also have the right to complain to your local data protection authority. If your information appears in a merchant's workspace, contact that merchant as well; we may need its instructions to handle the request.

8. Children and international processing

StillMetrics is a business reporting service, not intended for children. Do not submit children's personal information unnecessarily. If you believe a child has provided personal information directly to us, contact us.

Service providers and connected platforms may process information in countries other than yours. This policy does not promise a particular data residency location. Where legally required, applicable protections must be considered for international transfers.

9. Changes and contact

We may update this policy as the service develops or legal requirements change. Updates will appear here with a revised effective date; material changes will be communicated where required by law.

For privacy, deletion or support requests, contact StillMetrics at ziadelamary@gmail.com. Please identify the relevant account or workspace, but do not email passwords, API keys or source tokens. See also our Terms of Service.