Security and data handling
Last updated 17 September 2026
How MetricsGo connects to your clients' platforms, what it stores, who can see it, and how to take it back. Short on purpose.
Read-only, everywhere
Every connection asks for read scopes only. MetricsGo cannot edit a campaign, publish a post, change a property or touch an order. If a platform offered a write scope by default, we would not request it.
How you connect
- Meta: Facebook Login for Business. Meta issues the token; you pick the ad accounts and Pages; we never see a password.
- Google: Google sign-in with the Analytics and Search Console read-only scopes. You pick the properties and sites.
- Shopify: a custom app you create in your own store with read scopes; you paste its credentials, and you can revoke that app in Shopify at any time.
What is stored
- The performance data itself — spend, results, sessions, clicks, orders — synced hourly and kept so reports and comparisons work without calling the platform on every page view.
- The tokens the platforms issue, never shown in the app after connection.
- Your account: name, email and a salted password hash. Nothing from your inbox, calendar or drive.
Who can see what
- Every row belongs to one organisation. Nothing is shared across organisations unless you explicitly transfer a client.
- Inside an organisation, a member sees only the clients assigned to them; an admin sees all. A client viewer sees only their own numbers.
- API keys and assistant connections carry the same client visibility as the person who created them, and every one of them is read-only.
Where it runs
MetricsGo runs on a server operated by DigyGo with TLS on every connection, nightly database backups, and outbound email through Resend. No third-party analytics run inside the app.
Taking it back
- Disconnect a platform from Settings → Connections at any time; its data is removed with it.
- Revoke MetricsGo from the platform side too: Meta Business integrations, Google account permissions, or the Shopify app you created.
- Ask for your organisation to be deleted and everything goes. See the data-deletion page for the steps.
Reporting a problem
Found something? Write to support@digygo.com. Security reports are answered first.
