Skip to content

Privacy Policy

This notice explains what personal data Medal Social collects, how we use and protect it, and the rights you have over it.

Last updated: 19 September 2026.

Introduction

This Privacy Policy explains how we collect, use, and protect your personal data when you interact with our platform.

Information Collection

We collect information that you provide directly to us, such as when you sign up or interact with our services.

Data Usage

We use personal data to provide and support the services you choose. Google user data is subject to the specific purposes and limits in the Google API Services section below.

This section explains how Medal Social AS accesses, uses, shares, protects, and retains Google user data, including sensitive Google Workspace directory data. These specific limits apply to Google data even where other sections of this policy describe broader uses of other service data.

Authorization and the integrations you choose

Medal Social offers optional Google sign-in, YouTube, Google Business Profile, Google Chat, Google Drive, Google Ads, and Google Workspace Directory Sync integrations. Each connection requires authorization through Google’s OAuth consent screen. Directory Sync is an Enterprise workspace feature that an authorized workspace administrator connects using a Google Workspace administrator account. We request only the permissions needed for the selected integration. Directory Sync is separate from Google sign-in and does not request Gmail, Drive, Calendar, YouTube, Chat, or Ads access.

Google data we access

Depending on which integrations you connect, we access your basic Google profile to identify the account; YouTube channel and content data; Google Business Profile locations, posts, and reviews; the Google Chat spaces you can post to and the reports you instruct Medal Social to deliver; the specific Google Drive files you select in Medal Social or that Medal Social creates for you; and Google Ads account data needed for campaigns you manage in Medal Social. We also process the OAuth credentials needed to maintain each authorized connection. The separate YouTube API Services section below provides additional YouTube-specific information.

For Google Workspace Directory Sync, we read the following data using four read-only Admin SDK permissions:

  • Users — admin.directory.user.readonly: Google user identifiers, names, primary work email addresses, and suspended or archived status, used to identify people and determine whether their workspace access should be active.
  • Domains — admin.directory.domain.readonly: company domain information, used to check that the connecting Google administrator manages the company domain verified for the Medal Social workspace.
  • Groups — admin.directory.group.readonly: group identifiers, names, and email addresses, used to display the groups an administrator can select for synchronization.
  • Group membership — admin.directory.group.member.readonly: membership information for a selected group, used to identify which users are included in that synchronization scope.

How Directory Sync uses this information

An administrator selects the verified company domain, a group of direct members, or a pilot of selected users, previews the imported people, and enables automatic synchronization. Medal Social uses the directory data to create or update workspace memberships and keep names, work emails, and access status aligned with the selected directory scope. This can provision membership before a person first signs in to Medal Social. Workspace administrators control local roles and whether inactive or out-of-scope managed users lose access to that workspace. Directory Sync does not modify Google users, groups, or domains, and does not delete a person’s Google account.

Permitted use and sharing

Google user data is used only to provide the features you authorize, such as account identification, publishing or importing content, replying to reviews, delivering reports, working with selected files, managing your campaigns, and synchronizing workspace membership. We do not sell Google user data, transfer it to data brokers, use it for credit assessment, or use it for targeted advertising or to build advertising profiles. Running campaigns that you explicitly manage through the Google Ads integration is separate from using your Google user data to target advertisements.

Directory profiles and membership information are available within the connected workspace according to the workspace’s access controls. Relevant Google data is processed by the infrastructure providers that operate Medal Social, such as our database and cloud-hosting providers, to deliver these features on our behalf under applicable data-processing obligations. We may also disclose information when required by law. Google data is not shared for third parties’ independent marketing or unrelated purposes.

How we protect Google user data

We protect Google user data, including sensitive directory information, using encryption in transit (HTTPS/TLS) and encryption at rest in our database infrastructure. Stored Directory Sync refresh tokens are additionally encrypted at the application layer using AES-256-GCM, with an encryption key supplied through protected server configuration. OAuth credentials are handled by the backend and are not displayed in the directory member list.

Authenticated, workspace-scoped authorization checks restrict access to directory configuration and data. Directory management operations require workspace administrator permissions, and the connected company domain must be verified. Directory requests to Google use read-only permissions. Disconnecting Directory Sync removes the saved connection credential and invalidates pending synchronization work. These controls reduce the risk of unauthorized access, alteration, and disclosure.

AI and machine learning

Google user data, including Google Workspace directory, Chat, and Drive data, is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models. We do not transfer this data to third-party AI services for model training. Directory Sync data is used for the directory and workspace membership functions described above.

Retention, disconnection, and deletion

We retain Google connection credentials only while needed to provide the authorized connection. For Directory Sync, disconnecting stops further synchronization and removes the saved refresh token. It does not automatically delete the workspace memberships already provisioned, imported directory profiles, or access-removal records: these remain associated with the workspace to preserve its membership and access controls. Pausing synchronization is also different from deleting data.

Directory records are retained while needed to administer the workspace or handle a verified deletion request. Deleting the workspace removes its directory profiles, connection records, credentials, pending authorization records, and access-removal records through the workspace deletion process. Removing access to one workspace does not delete a person’s separate account or memberships in other workspaces. To request access, correction, or deletion of your directory data without deleting the whole workspace, contact your workspace administrator or privacy@medalsocial.com. Any data we must retain to meet a legal obligation is limited to that purpose.

For other Google integrations, the applicable integration-specific deletion and retention information in this policy continues to apply. You can revoke Google authorization at any time through your Google Account connections page. Revocation prevents further authorized access to Google; it does not by itself delete data already held by Medal Social. Use the relevant Medal Social deletion controls or contact us to request deletion of that stored data.

Manage Medal Social access in your Google Account

Request access, correction, or deletion: privacy@medalsocial.com

Google API Services User Data Policy

Medal Social’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. These requirements also apply to raw or derived data received from Google Workspace APIs.

Read the Google API Services User Data Policy