Last updated: 7 July 2026. This Privacy Policy explains how Elevale (operated by Saint Financial Group Limited) collects, uses, stores, shares, and protects personal data when you use our platform, marketing website, and related services. It also describes your privacy rights and how to contact us.
Saint Financial Group Limited is the data controller for personal data described in this policy, except where we act as a processor on your instructions (for example, workspace content you upload) or where an agency or reseller acts as controller for their client workspaces. The Elevale platform infrastructure is operated by Saint Financial Group Limited (Elevale) as a data processor on our behalf under a Data Processing Agreement.
By creating an account, using Elevale, or submitting information through our marketing site, you acknowledge that you have read this Privacy Policy. Where required by law, we will obtain your consent before processing your data for specific purposes.
Scope
This policy applies to:
- The Elevale web application at elevale.app and related subdomains
- The elevale.com marketing website and documentation at /help
- Support, sales, and onboarding communications with Saint Financial Group Limited
- White-label or agency-branded experiences powered by Elevale, unless your agency publishes separate privacy terms that apply to your relationship with them
Third-party providers (for example Xero or Meta) also process data under their own privacy policies. Where Elevale accesses Google user data through Google OAuth APIs, we describe our practices in the Google user data section below.
Personal data we collect
We collect personal data that you provide directly, that we generate when you use the service, and that we receive from third parties where permitted.
Account and profile data
- Name, email address, and password (stored as a secure hash)
- Profile photo, job title, timezone, and notification preferences
- Multi-factor authentication settings and session metadata
- Organisation and workspace membership, roles, and permissions
Workspace and business content
- OKRs, KPIs, tasks, business briefs, wiki pages, process maps, and related files you upload
- Comments, mentions, assignments, and collaboration activity
- AI chat prompts, responses, and embeddings generated when you use AI features
- Voice session data when you use voice mode (where enabled)
Billing and commercial data
- Subscription plan, billing contact details, and invoice history
- Payment method metadata processed by Stripe (we do not store full card numbers)
- Tax identifiers and billing addresses where you provide them
Usage, technical, and security data
- IP address, browser type, device identifiers, and operating system
- Log data, error reports, performance metrics, and security events
- Audit log entries recording changes to workspace data, permissions, exports, and deletions
- Cookie and consent records (see our Cookie Policy)
Marketing and communications
- Contact form submissions, demo requests, and newsletter sign-ups on elevale.com
- Email open and click data for service and marketing messages (where permitted)
- Referral and partner programme information you choose to provide
Data from integrations
When you connect third-party integrations via OAuth or API keys, we receive data authorised by you and needed to deliver the integration (for example advertising metrics, accounting records, or CRM contacts). You control which integrations are enabled per workspace.
Google user data
This section thoroughly and clearly discloses how Elevale (developed by Saint Financial Group Limited) accesses, uses, stores, shares, and deletes Google user data obtained through Google OAuth APIs. It is intended to meet our disclosure obligations under the Google API Services User Data Policy and the Google APIs Terms of Service.
Elevale's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data.
Google user data is accessed only after a workspace admin or authorised user explicitly initiates an OAuth connection, reviews the requested scopes, and grants consent. We do not use Google Sign-In for Elevale account authentication.
Google OAuth integrations we offer
Google user data is accessed only when you connect one of these optional integrations:
- Google Analytics integration: syncs web analytics metrics from Google Analytics properties you authorise
- Google Ads integration: syncs advertising performance metrics from Google Ads customer accounts you authorise
We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or other Google account data. If we add integrations that request additional Google scopes, we will update this policy and request your consent before accessing new data types.
OAuth scopes requested
When you connect an integration, Elevale requests only the Google OAuth scopes needed for that integration:
- Google Analytics:
https://www.googleapis.com/auth/analytics.readonly(read-only access to Google Analytics reporting data for properties you select during setup) - Google Ads:
https://www.googleapis.com/auth/adwords(access to Google Ads account and campaign performance data for customer IDs you authorise)
Data accessed
The specific types of Google user data Elevale accesses, collects, or interacts with are limited to the OAuth scopes you approve during connection, and only for integrations you enable per workspace.
Google Analytics (when connected): Google Analytics account and property identifiers; aggregated web analytics metrics you map to KPIs, such as sessions, users, page views, traffic sources, conversion rates, channel performance, and related reporting dimensions and metrics; OAuth access and refresh tokens needed to maintain the connection.
Google Ads (when connected): Google Ads customer, campaign, and ad group identifiers; advertising performance metrics such as impressions, clicks, cost, click-through rate, average cost per click, conversions, conversion rate, conversion value, cost per conversion, and return on ad spend; OAuth access and refresh tokens needed to maintain the connection.
We do not collect Google account profile information (such as your Google name or email address) through these integrations beyond what is necessary to identify connected accounts and properties within the authorised API responses.
Data usage
How Elevale uses, processes, and handles Google user data, and the purpose for each use:
- Pull authorised Google Analytics and Google Ads metrics into KPIs, dashboards, health scores, OKR views, and related in-app reporting (purpose: provide the integration and reporting features you request)
- Refresh OAuth tokens and maintain integration connections you configured (purpose: keep authorised integrations working without repeated sign-in)
- Troubleshoot sync errors, display integration status, and maintain reliability of connected integrations (purpose: provide and improve the integration service)
We do not use Google user data obtained through Google OAuth APIs for:
- Advertising, retargeting, interest-based profiling, or personalised advertising
- Selling, renting, or licensing data to third parties
- Creditworthiness decisions or lending purposes
- Building unrelated marketing databases or audience segments
- Training, fine-tuning, or improving machine learning or artificial intelligence models
- Any purpose unrelated to providing or improving Elevale functionality you explicitly request
Raw Google Analytics and Google Ads API responses are not sent to AI providers (including Google Gemini). Synced metric values displayed in Elevale are stored as KPI and dashboard data; they are not automatically included in AI chat prompts.
Limited human access to Google-sourced integration data may occur only for user support, security investigation, compliance, or legal requirements, and not for unrelated marketing or research.
Data sharing
We do not sell Google user data. If and how we share Google user data with specific categories of third parties, and the purpose for that sharing:
- Google: Elevale calls Google APIs on your behalf using the OAuth tokens you authorised. Google processes those API requests under its own terms and privacy policy (purpose: retrieve the metrics you requested from your connected Google accounts)
- Platform subprocessors (infrastructure providers): Supabase (encrypted database storage), Fly.io (application hosting), and other providers listed at Subprocessors and integrations store or process integration data solely to operate Elevale on our instructions under contractual safeguards (purpose: host, secure, and deliver the service)
- Workspace members (your organisation): Users with permission in your workspace can view synced metrics and dashboards within that workspace (purpose: collaboration within your organisation; this is not a sale or disclosure to unrelated third parties)
- Legal and safety: Courts, regulators, or law enforcement when required by law, court order, or to protect rights, safety, and security (purpose: legal compliance and safety, as described elsewhere in this policy)
We do not share Google user data with advertising networks, data brokers, information resellers, or analytics resellers. We do not transfer Google user data to third parties for their own advertising, AI training, or unrelated commercial purposes.
Data storage and protection
Our practices for securely storing and protecting Google user data:
- Google OAuth access and refresh tokens are encrypted server-side before storage
- Synced metrics and related integration metadata are stored in our Supabase database with row-level security and role-based access controls
- Data in transit is protected with TLS 1.2+ encryption
- Access is limited to authenticated users with appropriate workspace permissions and to platform systems that need access to deliver the service
- API keys and OAuth encryption keys are managed using documented rotation practices
See Security and data protection for more detail.
Data retention and deletion
How long we retain Google user data and how you can request deletion:
- While connected: We retain OAuth tokens and synced Google metrics while the integration remains connected and your workspace is active, refreshing data on the sync schedule you configure
- Disconnect integration: When you disconnect Google Ads or Google Analytics in workspace integration settings, we revoke and delete stored OAuth tokens promptly (typically within 24 hours), stop new syncs, and no longer call Google APIs for that connection. Previously synced metric values may remain in KPIs and dashboards until you delete those records
- Workspace or account deletion: When you delete your account or a workspace is permanently deleted, Google integration data is removed according to our Data retention and deletion schedule (including anonymisation at 60 days and permanent deletion at 90 days after access ends)
How to request deletion of Google user data:
- Disconnect the Google integration in your workspace integration settings
- Delete synced KPIs or dashboards that contain Google data, if you no longer need them
- Use Profile → Security → Delete my account for full account erasure, or Profile → Privacy → Submit a request for targeted deletion
- Email contact form with the subject line "Google data deletion request"
We aim to respond to deletion requests within 30 days. If an agency controls your workspace, we may coordinate with them to fulfil your request.
Limited Use commitments
For Google user data obtained through Google OAuth APIs, we commit to the following Limited Use requirements:
- Use data only to provide or improve user-facing Elevale features that you request
- Not use Google OAuth data to serve advertisements, including retargeting or interest-based advertising
- Not allow humans to read Google OAuth data except with your consent, for security or compliance needs, or when data is aggregated and anonymised for internal operations
- Not use Google OAuth data to train, fine-tune, or improve general machine learning or artificial intelligence models
- Not transfer Google OAuth data except to provide or improve user-facing features, comply with applicable law, or as part of a merger or acquisition with equivalent protections
How we use personal data
We use personal data only where we have a lawful basis under UK GDPR, EU GDPR, or equivalent laws.
- Provide the service: Create and manage your account, authenticate you, store workspace content, and deliver features you request (contractual necessity)
- Billing and administration: Process subscriptions, send invoices, prevent fraud, and comply with tax obligations (contractual necessity and legal obligation)
- Security and abuse prevention: Monitor for unauthorised access, enforce MFA, maintain audit logs, and protect the platform (legitimate interests)
- Product improvement: Analyse aggregated usage to fix bugs, improve performance, and develop features (legitimate interests; analytics cookies only with consent on the marketing site)
- AI features: Process prompts and workspace context you submit to generate responses, summaries, and embeddings when you use AI tools (contractual necessity or legitimate interests, depending on the feature)
- Communications: Send service messages, security alerts, and (with consent or soft opt-in where allowed) product updates and marketing (contractual necessity, legitimate interests, or consent)
- Legal compliance: Respond to lawful requests, enforce our terms, and maintain records required by law (legal obligation)
We do not sell your personal data. We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review.
How we share personal data
We share personal data only as described below.
Subprocessors and infrastructure providers
We use trusted subprocessors to host, secure, and deliver Elevale. They process data on our instructions and under contractual safeguards. Our current platform subprocessors include:
- Supabase: Database, authentication, and file storage
- Fly.io: Application hosting
- Stripe: Payment processing
- OpenAI and Google Gemini: AI chat and embeddings (when enabled; separate from Google OAuth integration data, see AI and automated processing)
- ElevenLabs: Voice mode (when enabled)
- AWS SES: Transactional email
The authoritative subprocessor list is published at Subprocessors and integrations. We provide at least 30 days notice before adding subprocessors that process personal data, where required by our Data Processing Agreement.
Agencies, resellers, and workspace members
Workspace admins and members with appropriate permissions can access data within that workspace. Agencies using white-label branding may act as controller for client workspace data. See Agency and reseller data responsibilities.
Professional advisers and authorities
We may disclose data to lawyers, accountants, insurers, or regulators when required by law, court order, or to protect rights, safety, and security.
Business transfers
If Saint Financial Group Limited is involved in a merger, acquisition, or asset sale, personal data may transfer to the successor entity subject to equivalent protections. We will notify you where required by law.
International transfers
Elevale may process and store data in the United Kingdom, European Economic Area, United States, and other countries where our subprocessors operate. Where personal data is transferred outside the UK or EEA to countries without an adequacy decision, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, and supplementary measures where needed. Details are set out in our Data Processing Agreement.
Data retention
We retain personal data only as long as necessary for the purposes described in this policy.
- Active accounts and workspaces: Retained while your subscription or account is active
- Cancelled workspaces: Grace period until the end of the billing period, then soft anonymisation at 60 days and permanent deletion at 90 days after access ends
- Audit logs: 2 years, then automatically purged
- Cookie consent records: 1 year
- Privacy requests: 3 years after completion (compliance evidence)
- Billing and tax records: Typically 6 to 7 years, as required by law
- Backups: Encrypted point-in-time recovery on a rolling schedule, independent of application deletion timelines
Full retention schedules are documented at Data retention and deletion. You can delete your account at any time from Profile → Security.
Security
We implement technical and organisational measures to protect personal data, including:
- TLS 1.2+ encryption in transit and encrypted storage at rest
- Multi-factor authentication required after signup for platform accounts
- Row Level Security and role-based access controls on tenant data
- Server-side encryption for OAuth tokens and hashed storage for API keys
- Immutable audit logging for key workspace and admin actions
See Security and data protection and Audit logging for more detail. No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately.
Your rights
Depending on your location, you may have the following rights over your personal data:
- Access: Know what personal data we hold about you and receive a copy
- Portability: Receive your data in a structured, commonly used format (JSON export available in-app)
- Rectification: Correct inaccurate or incomplete data in Profile settings or by contacting us
- Erasure: Request deletion of your personal data, subject to legal retention requirements
- Restriction: Ask us to limit how we use your data in certain circumstances
- Objection: Object to processing based on legitimate interests, including direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing
- Complaint: Lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk)
How to exercise your rights
- Self-service export: Profile → Privacy → Download my data
- Self-service erasure: Profile → Security → Delete my account
- Privacy request: Profile → Privacy → Submit a request (we aim to respond within 30 days)
- Contact us: contact form with the subject line "Privacy request"
We may need to verify your identity before fulfilling a request. If an agency controls your workspace, some requests may need to be coordinated with them. We do not charge a fee unless a request is manifestly unfounded or excessive.
US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, and other US states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, and opt out of certain processing.
- Sale or sharing: Elevale does not sell personal data and does not share personal data for cross-context behavioural advertising
- Sensitive data: We process account credentials and workspace content only as needed to provide the service
- Authorised agent: You may use an authorised agent to submit a request where permitted by law; we may require proof of authorisation
Submit US privacy requests via the in-app Privacy Center or contact form. We will not discriminate against you for exercising your rights.
Other regions
Residents of Canada (PIPEDA and provincial laws, including Quebec Law 25), Brazil (LGPD), Australia (Privacy Act and APPs), and other jurisdictions may have additional rights to access, correct, delete, or restrict processing of personal data, and to withdraw consent where applicable.
We handle these requests through the same channels described in How to exercise your rights above: self-service tools in Profile → Privacy, or contact form. We aim to respond within 30 days.
For a summary of global rights by region, see Compliance overview → Global privacy rights.
Cookies and similar technologies
We use cookies and similar technologies on the marketing site and platform. Essential cookies are required for sign-in and security. Optional analytics cookies on the marketing site are used only with your consent. Full details are in our Cookie Policy.
Children
Elevale is a business software service not directed at children under 16 (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
AI and automated processing
When you use optional AI features, the prompts and workspace context you explicitly submit may be sent to AI subprocessors (such as OpenAI or Google Gemini via a separate server-side API) to generate responses. This AI processing is separate from Google Ads and Google Analytics OAuth integration data: we do not automatically send raw Google API responses to AI providers.
We configure AI providers not to use your content to train their public models for Elevale API usage, subject to each provider's terms. AI outputs may be inaccurate: review important decisions before relying on them. You can limit AI usage by disabling AI features in workspace settings where available.
Marketing communications
We may send product updates, onboarding tips, and promotional emails where permitted by law. You can unsubscribe using the link in any marketing email or by contacting us. Service and security messages (for example password resets, billing notices, and incident alerts) are not marketing and cannot be opted out of while you maintain an account.
Data breaches
If a personal data breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required and contact affected users without undue delay when the breach poses a high risk. Report suspected security issues via contact form. See Incident response and data breaches.
Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or business changes. We will post the revised policy on this page and update the "Last updated" date. For material changes that affect how we process personal data, we will provide additional notice (for example by email or in-app notification) where required by law. Continued use of Elevale after the effective date constitutes acceptance of the updated policy where permitted.
Contact us
Data controller: Saint Financial Group Limited
Data Protection Officer: Dylan O'Rourke
Privacy enquiries: contact form
Security issues: contact form
General contact: contact form
Company identification: Legal notice
For platform infrastructure questions, Elevale (Saint Financial Group Limited) acts as processor on our instructions.