Legal
Privacy Policy
Last updated August 12, 2026
This policy explains how Prysmatic handles information when you use our website, work with our team, or authorize a reporting connection through Prysmatic Connections.
Information we collect
We collect information you provide directly, including contact details, project information, and messages submitted through our website or client-service process. We also collect limited technical information needed to operate and secure our services.
Connected reporting services
When an authorized client representative connects a reporting service, Prysmatic may access and store the following information:
- Google Analytics 4: the authorizing Google account’s identifier, email address, granted scopes, selected account and property metadata, and read-only analytics reports such as users, sessions, acquisition, landing pages, engagement, and key events.
- Google Search Console: the authorizing Google account’s identifier, email address, granted scopes, selected verified site metadata, and read-only search-performance reports such as clicks, impressions, queries, pages, click-through rate, and average position.
- Microsoft Clarity: the client-confirmed project ID, encrypted Data Export API token, and read-only exported reporting data such as sessions, engagement, scroll depth, interaction signals, devices, browsers, operating systems, and URLs.
How we use information
Prysmatic uses connected data to provide the reporting, analytics, conversion optimization, and client-support services requested by the applicable client. We also use limited operational information to verify access, maintain synchronization, troubleshoot failures, secure the service, and comply with legal obligations.
Prysmatic requests separate, read-only Google scopes for Google Analytics and Search Console. We do not use connected Google or Microsoft reporting data for advertising, credit decisions, or sale to data brokers.
Google API Services data
Prysmatic’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Prysmatic limits use of Google user data to providing and improving the client-facing reporting services that the user authorized.
Authorized Prysmatic personnel may access connected reporting data when needed to deliver the client’s requested services, respond to support requests, investigate security or technical issues, or comply with law. Prysmatic requires personnel and service providers with access to protect the data and use it only for those purposes.
Storage and security
Prysmatic encrypts provider credentials before storing them. Secure connection links use one-time random tokens; Prysmatic stores only a cryptographic hash of each raw invitation token. We use access controls, encrypted transport, limited internal access, audit records, and reasonable administrative and technical safeguards designed to protect information.
No method of storage or transmission can guarantee absolute security. Please contact us promptly if you believe a connection or credential has been compromised.
Sharing and service providers
Prysmatic may share information with infrastructure, database, security, and other service providers that process data on our behalf to operate the requested services. We may also disclose information when required by law, to protect rights and security, or as part of a corporate transaction subject to applicable notice and consent requirements.
Prysmatic does not sell connected Google or Microsoft reporting data. We do not transfer it to advertising platforms, data brokers, or information resellers for their own use.
Retention, disconnection, and deletion
Prysmatic retains connected reporting data for the client-service relationship and any agreed reporting or legal retention period. Disconnecting a client-owned connection removes its locally stored provider credential when no other source references it. Historical reporting facts and sync records remain available so the client’s reporting history stays intact, subject to the applicable service agreement and deletion requests.
You can revoke Google access through your Google Account security settings and revoke Microsoft Clarity access by deleting the relevant Data Export token in Clarity. Revocation may prevent future imports. To request access, correction, or deletion, email info@prysmaticagency.com. Prysmatic will verify the requester’s authority before acting on client data.
Changes and contact
We may update this policy as our services or legal obligations change. We will update the date above and provide additional notice when required. Questions about this policy or Prysmatic’s data practices may be sent to info@prysmaticagency.com.