Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Mythos Suite ("we," "us," or "our") collects, uses, stores, and protects personal data when operating the marketing tracking and analytics platform available at mythossuite.com. We comply with Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) and, where applicable, the European Union's General Data Protection Regulation (GDPR).

1. Data we collect

Account data

Our authentication service processes your name, email address, and access credentials for authentication, password recovery, and account security, including two-factor authentication when enabled.

Tracking data processed on behalf of customers

Our customers use Mythos Suite to receive conversion events from their own websites and campaigns, such as clicks, leads, and purchases. These events may contain identifiers such as email addresses, click identifiers, and campaign parameters. For this processing, the customer is the data controller and Mythos Suite acts as the data processor, processing data solely on the customer's instructions.

Platform usage data

We process audit records showing who performed an action and when within a workspace, along with technical logs and performance metrics used for security, support, and service improvement.

2. Google API and Google Ads data

When you connect a Google Ads account, Mythos Suite accesses only the data required to provide the integration features you enable. Authorization occurs directly through Google using OAuth 2.0; we do not receive or store your Google Account password.

Data accessed

  • identifiers, names, status, currency, and time zone of the Google Ads accounts you authorize, including manager account (MCC) hierarchy;
  • campaigns, costs, impressions, clicks, and performance metrics;
  • conversion actions required to configure the destination selected by the user;
  • OAuth access and refresh tokens required to maintain the authorized synchronization.

How we use this data

We use this data to display available accounts, synchronize campaigns and metrics with the workspace, generate reports, and send conversions configured by the user to the selected Google Ads account. We do not use data received from Google APIs to build advertising profiles, retarget users, or serve advertisements for our own benefit or for third parties.

Storage, retention, and deletion

OAuth tokens are encrypted before storage, transmitted only over TLS-protected connections, and isolated by workspace and access permissions. Tokens are retained while the integration remains connected. When you disconnect Google Ads, we attempt to revoke authorization with Google and remove locally stored tokens. Previously synchronized data may remain in workspace history until the account or workspace is deleted or a deletion request is fulfilled, subject to this Policy's retention rules.

You may also revoke access at any time from the connected applications page in your Google Account. To request deletion of data imported from Google, email support@mythossuite.com.

Sharing and Limited Use

We do not sell data obtained from Google APIs or transfer it to advertising networks, data brokers, or third parties for personalized advertising. Processing is limited to the visible integration features requested by the user and the infrastructure providers strictly necessary to operate the service.

Mythos Suite’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

See the Google API Services User Data Policy.

3. Legal bases and purposes

  • Contract performance: operating the contracted platform.
  • Legitimate interests: security, fraud prevention, and product improvement.
  • Consent: marketing communications when you choose to receive them.
  • Legal obligation: retaining records required by law.

4. Data sharing

We do not sell personal data. We share data only with infrastructure providers strictly necessary to operate the service, such as hosting, transactional email, and identity providers. These providers are contractually required to maintain confidentiality and protect the data.

5. Retention

Account data is retained while the account exists. Audit events follow the retention policy configured in the platform, which defaults to 365 days. Tracking data is retained according to the configuration of the data controller customer's workspace.

6. Your rights

You may request confirmation of processing, access, correction, portability, anonymization, or deletion of your data, and you may withdraw consent. Data subjects whose data we process on behalf of a customer should direct requests to that data controller; we will assist the customer in fulfilling them.

7. Security

We use encryption in transit (TLS), workspace isolation with roles and permissions, delegated authentication with MFA support, and a complete audit trail for administrative actions.

8. Cookies

We use cookies that are strictly necessary for authentication and sessions. We do not use third-party advertising cookies in the dashboard.

9. Contact

To exercise your rights or ask questions about this Policy, email support@mythossuite.com.

10. Changes to this Policy

We may update this Policy to reflect changes to the service or applicable law. The last updated date at the top of this page always identifies the current version.