Privacy policy
Agency Client Onboarding · last updated September 28, 2026
Agency Client Onboarding helps marketing agencies get access to their clients' advertising and analytics accounts. It is operated by Kitchn Venture GmbH, Französische Straße 12, 10117 Berlin, Germany (imprint). This page says what Agency Client Onboarding stores, why, for how long, and how to have it deleted.
Agencies
For an agency's account we store the agency's name and colour, its users' names, email addresses and passwords (as a hash, never in readable form), the agency's recipients (its Meta Business ID, Google Ads manager account ID and Google email), its templates and its requests. We keep this while the account exists.
Clients who open a request link
- We never ask for passwords. You sign in on Meta's and Google's own pages.
- When you sign in, Meta or Google gives Agency Client Onboarding an access token for the permissions you approved, and your account's ID and name. We use it only to list the accounts you can share, to share the ones you choose with the agency, and to check that they were shared. Tokens are stored encrypted and deleted one day after the request is completed, cancelled or expired.
- For each account you share we store its ID, its name, the access level and what we observed (for example “verified on 28 September”). The agency sees this, because it is what the agency needs to start work.
- If you enter a Shopify collaborator code, it is stored encrypted, shown only to the agency, and deleted a week after the item is done.
- We do not read or store your campaigns, audiences, customer data, orders or reports.
Information from Meta and Google
Agency Client Onboarding's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this information, use it for advertising, or give it to anyone other than the agency that sent the request, and only as described above.
Visitors of this website
We count visits without cookies: a daily changing, salted hash of the address and browser, which cannot be linked across days. The address and browser string go to our own analytics service, datalove, which turns them into country, region, city, browser and device type when it receives them and does not store them. If you join the early-access list, we keep your email, agency and answers to contact you about Agency Client Onboarding until you ask us to remove them.
Agencies using the app
When you are signed in, our server records which pages you open (the kind of page, not its address) and what you change, with your user and your agency, to improve the product. A script from datalove also records what the app shows you and what you do in it (pages, clicks, scrolling), so we can see where people get stuck. Form fields are always masked, and on pages that show your clients (requests, recipients, team) their content is masked too, so client names, emails and accounts never leave your browser. Recordings are kept 30 days. You can object at any time by writing to us; we then stop both for you. Clients who open a request link are never recorded.
Service providers
- Hosting: Hetzner Online GmbH, Germany.
- Email: Postmark (ActiveCampaign, LLC), for the emails Agency Client Onboarding sends.
- Usage analytics: datalove, our own first-party analytics, hosted in Germany.
- Meta Platforms and Google, when you choose to sign in with them.
Legal basis
We process agency data to provide the service (Art. 6 (1) (b) GDPR), a client's data because the client asks us to share access with their agency (Art. 6 (1) (b) and (a) GDPR), and website statistics on the basis of our legitimate interest in understanding how Agency Client Onboarding is used (Art. 6 (1) (f) GDPR).
Your rights and deletion
You can ask for access to, correction or deletion of your data, restrict or object to processing, and complain to a supervisory authority. How to have Agency Client Onboarding's data about you deleted is on the data deletion page. Access you gave an agency lives in Meta and Google and is removed there; deleting Agency Client Onboarding's data does not remove it.