Privacy Policy
Last updated: May 16, 2026
At Savage Solutions, we take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our website and services. We are committed to complying with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.
Information We Collect
Personal Information
We may collect personal information that you voluntarily provide to us when you:
- Fill out contact forms on our website
- Subscribe to our newsletter
- Request a consultation or quote
- Sign up for our services
- Communicate with us via email, phone, or SMS
Types of Personal Data
This information may include:
- Name, email address, and phone number
- Company name and business information
- Billing and payment information
- Project requirements and business needs
- Communication preferences
How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain our services
- Process transactions and send related information
- Send administrative information and updates
- Respond to inquiries and provide customer support
- Send marketing and promotional communications (with your consent)
- Improve our website and services
- Comply with legal obligations
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our website and store certain information.
Types of Cookies We Use
- Essential Cookies: Required for the website to function properly
- Analytics Cookies: Help us understand how visitors interact with our website
- Marketing Cookies: Used to deliver relevant advertisements
- Preference Cookies: Remember your settings and preferences
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, some parts of our website may not function properly without cookies.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information:
- Encryption of data in transit using SSL/TLS
- Secure data storage with access controls
- Regular security assessments and updates
- Employee training on data protection
- Incident response procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
Your Privacy Rights
GDPR Rights (EU Residents)
If you are a resident of the European Union, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive data in a structured format
- Right to Object: Object to processing of your personal data
CCPA Rights (California Residents)
If you are a California resident, you have the following rights:
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of sale of personal information
- Right to Non-Discrimination: Exercise rights without discrimination
To exercise these rights, please contact us using the information provided at the end of this policy.
Third-Party Platform Integrations (OAuth)
Our marketing automation platform integrates with third-party services on behalf of authorized users. When you connect a third-party account (such as LinkedIn, Meta/Facebook, Instagram, or Google Business Profile), you authorize us to act on your behalf within the specific scopes you approve during the OAuth consent flow.
Platforms We Integrate With
- LinkedIn (Community Management API) — publish posts to authorized organization pages using the w_organization_social scope
- Meta Graph API (Facebook & Instagram) — publish posts to authorized Pages and Instagram Business accounts
- Google Business Profile API — publish localPosts to authorized business locations
- Google Search Console API — read-only access to search performance data for client SEO reporting
- Google Analytics 4 API — read-only access to website analytics for client reporting
What We Store
For each connected third-party account, we store the minimum credentials required to operate the integration:
- OAuth refresh tokens, encrypted at rest using AES-256
- Account/organization identifiers (e.g., LinkedIn organization URN, Meta Page ID, GBP account ID)
- Scope grants and authorization timestamp
- Audit log of every publishing action (timestamp, platform, post ID, success/failure)
What We Do NOT Do
- We do NOT read your private messages, DMs, or inbox on any platform
- We do NOT sell, share, or transfer OAuth tokens or third-party data to other parties for marketing, advertising, or any other purpose
- We do NOT access platforms outside the explicit scope you granted during OAuth consent
- We do NOT use third-party platform data to enrich profiles, train AI models, or for any purpose unrelated to operating the integration you authorized
- We do NOT post content without an explicit publishing action initiated by an authorized user or scheduled rule the authorized user configured
Revoking Access
You can revoke our access to any connected third-party account at any time:
- From our portal at portal.savagesolutions.io: Settings → Integrations → Disconnect
- Directly from the third-party platform: LinkedIn (linkedin.com/psettings/permitted-services), Meta (facebook.com/settings/apps), Google (myaccount.google.com/permissions)
- By emailing privacy@savagesolutions.io with a deletion request
Data Retention for Integration Data
When you revoke access or close your account, we delete stored refresh tokens within 24 hours and purge associated audit logs within 30 days, except where retention is required to comply with legal obligations. Published posts remain on the third-party platform under that platform's own retention policies.
Compliance
Our integrations comply with each platform's developer terms:
- LinkedIn API Terms of Use and Professional Community Policies
- Meta Platform Terms and Developer Policies
- Google API Services User Data Policy (including the Limited Use requirements)
SMS Consent and Communications
Consent for SMS Communications
By providing your phone number and opting in, you consent to receive SMS messages from Savage Solutions.
Types of SMS Messages
- Appointment reminders and scheduling confirmations
- Project updates and status notifications
- Important account information
- Customer service communications
SMS Terms
- Message frequency varies based on your interactions with us
- Message and data rates may apply
- You can opt-out at any time by replying STOP
- For help, reply HELP or contact us directly
- We do not share SMS opt-in data with third parties for marketing purposes
Your mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Data Retention
We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your information to the extent necessary to:
- Comply with our legal obligations
- Resolve disputes
- Enforce our agreements
- Maintain business records
When we no longer need your personal information, we will securely delete or anonymize it.
Third-Party Services
We may use third-party service providers to help us operate our business and website, including:
- Payment processors (Stripe, PayPal)
- Email delivery (Nodemailer via SMTP, Resend, SendGrid)
- Analytics providers (Google Analytics 4, PostHog)
- CRM systems (GoHighLevel, HubSpot)
- Hosting and cloud services (Vercel, Cloudflare, AWS)
- Social platform APIs (LinkedIn, Meta/Facebook/Instagram, Google Business Profile, YouTube)
- Search and SEO tools (Google Search Console, DataForSEO)
These third parties have access to your personal information only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Children's Privacy
Our services are not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately. If we discover that we have collected personal information from a child under 13, we will promptly delete that information.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, or if you would like to exercise your privacy rights, please contact us:
Have Questions About Your Privacy?
We're here to help. Contact us to learn more about how we protect your data.
Contact Us