Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains how Mythos Suite ("we," "us," or "our") collects, uses, stores, and protects personal data when operating the marketing tracking and analytics platform available at mythossuite.com. We comply with Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) and, where applicable, the European Union's General Data Protection Regulation (GDPR).
1. Data we collect
Account data
Our authentication service processes your name, email address, and access credentials for authentication, password recovery, and account security, including two-factor authentication when enabled.
Tracking data processed on behalf of customers
Our customers use Mythos Suite to receive conversion events from their own websites and campaigns, such as clicks, leads, and purchases. These events may contain identifiers such as email addresses, click identifiers, and campaign parameters. For this processing, the customer is the data controller and Mythos Suite acts as the data processor, processing data solely on the customer's instructions.
Platform usage data
We process audit records showing who performed an action and when within a workspace, along with technical logs and performance metrics used for security, support, and service improvement.
2. Google API and Google Ads data
When you connect a Google Ads account, Mythos Suite accesses only the data required to provide the integration features you enable. Authorization occurs directly through Google using OAuth 2.0; we do not receive or store your Google Account password.
Data accessed
- identifiers, names, status, currency, and time zone of the Google Ads accounts you authorize, including manager account (MCC) hierarchy;
- campaigns, costs, impressions, clicks, and performance metrics;
- conversion actions required to configure the destination selected by the user;
- OAuth access and refresh tokens required to maintain the authorized synchronization.
How we use this data
We use this data to display available accounts, synchronize campaigns and metrics with the workspace, generate reports, and send conversions configured by the user to the selected Google Ads account. We do not use data received from Google APIs to build advertising profiles, retarget users, or serve advertisements for our own benefit or for third parties.
Storage, retention, and deletion
OAuth tokens are encrypted before storage, transmitted only over TLS-protected connections, and isolated by workspace and access permissions. Tokens are retained while the integration remains connected. When you disconnect Google Ads, we attempt to revoke authorization with Google and remove locally stored tokens. Previously synchronized data may remain in workspace history until the account or workspace is deleted or a deletion request is fulfilled, subject to this Policy's retention rules.
You may also revoke access at any time from the connected applications page in your Google Account. To request deletion of data imported from Google, email support@mythossuite.com.
Sharing and Limited Use
We do not sell data obtained from Google APIs or transfer it to advertising networks, data brokers, or third parties for personalized advertising. Processing is limited to the visible integration features requested by the user and the infrastructure providers strictly necessary to operate the service.
Mythos Suite’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
See the Google API Services User Data Policy.
3. Legal bases and purposes
- Contract performance: operating the contracted platform.
- Legitimate interests: security, fraud prevention, and product improvement.
- Consent: marketing communications when you choose to receive them.
- Legal obligation: retaining records required by law.
4. Data sharing
We do not sell personal data. We share data only with infrastructure providers strictly necessary to operate the service, such as hosting, transactional email, and identity providers. These providers are contractually required to maintain confidentiality and protect the data.
5. Retention
Account data is retained while the account exists. Audit events follow the retention policy configured in the platform, which defaults to 365 days. Tracking data is retained according to the configuration of the data controller customer's workspace.
6. Your rights
You may request confirmation of processing, access, correction, portability, anonymization, or deletion of your data, and you may withdraw consent. Data subjects whose data we process on behalf of a customer should direct requests to that data controller; we will assist the customer in fulfilling them.
7. Security
We use encryption in transit (TLS), workspace isolation with roles and permissions, delegated authentication with MFA support, and a complete audit trail for administrative actions.
8. Cookies
We use cookies that are strictly necessary for authentication and sessions. We do not use third-party advertising cookies in the dashboard.
9. Contact
To exercise your rights or ask questions about this Policy, email support@mythossuite.com.
10. Changes to this Policy
We may update this Policy to reflect changes to the service or applicable law. The last updated date at the top of this page always identifies the current version.
