Privacy Policy
How we collect, use, and protect information — including data we access through Google APIs on behalf of the businesses we manage.
Effective August 27, 2026
Who we are
Elevative Creative is a marketing agency based in Salt Lake City, UT. We provide local SEO, paid advertising, websites, reputation management, and content services to home-service businesses, and we operate software our clients use to manage that work.
This policy covers our website at elevativecreative.com, our client platform, and any connected integrations described below.
Information we collect
From website visitors
When you browse the site we collect standard technical information — pages viewed, referring site, approximate location, browser and device type — through analytics tooling. If you submit a form or book a call, we collect what you give us: name, business name, email address, phone number, and anything you write in a message.
From clients
For businesses we work with, we hold the information needed to deliver the service: contact details, business information, billing details, and the customer records they choose to store in our platform.
Data accessed through Google APIs
Where a business connects its Google account to our platform, we access only what that business explicitly consents to at the time of connection. Depending on which integrations they enable, that can include:
- Google Business Profile — business information (name, address, hours, categories, service areas), customer reviews, and profile performance metrics such as calls, direction requests, and searches. Where enabled, we reply to reviews on the business's behalf.
- Google Analytics — read-only reporting data, used to report on website performance alongside the rest of their marketing.
- Google Ads and conversion measurement — advertising performance reporting, and uploading offline conversion events the business has recorded, so their ad reporting reflects real outcomes.
- Gmail and Google Calendar — where a business connects them, so email and appointments can be sent and synced from within the platform.
We use this data solely to provide and improve the features the business connected it for. We do not sell it, we do not use it for advertising, and we do not use it to train generalized artificial-intelligence or machine-learning models.
Limited use
Elevative Creative's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect Google user data
Data obtained through Google APIs is treated as sensitive and is protected by the following measures:
- Encrypted in transit. Every connection — between a browser and our platform, between our platform and Google's APIs, and between our own services — uses HTTPS with TLS. We do not transmit Google user data over unencrypted channels.
- Encrypted at rest. OAuth access and refresh tokens are encrypted with AES-256-GCM using a key held outside the database, and are written to storage only in encrypted form. They are decrypted in memory at the moment a request to Google is made, and are never sent to the browser or exposed in any user interface, log, or export.
- Access is restricted and authenticated. Production access is limited to named administrators on the principle of least privilege, with no shared accounts. Sensitive administrative operations require two-factor authentication. Every request in the platform is authorised against the signed-in user's role and permissions before any Google data is read.
- Separated per business. Google connections are scoped to the business that authorised them, and every query is constrained to that business at the data layer. One client's Google data cannot be read by, or returned to, another client.
- Monitored and maintained. We log administrative and integration activity, run automated security monitoring and recurring audits of our infrastructure, and apply dependency and system security updates on an ongoing basis.
- Deleted when no longer needed. When a business disconnects its Google account, or revokes access at Google, the stored tokens are deleted and access stops. See Storage, security, and retention below for how long other data is kept.
- Incident response. If we became aware of unauthorised access to Google user data, we would investigate immediately, revoke and rotate the affected credentials, and notify the affected businesses without undue delay.
We do not sell Google user data, do not use it for advertising, do not transfer it to third parties except the service providers described below who are required to protect it, and do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
Revoking access
A business can disconnect its Google account from within our platform at any time, or revoke our access directly at myaccount.google.com/permissions. On disconnection we stop accessing the account and delete the stored access and refresh tokens.
How we use information
- To deliver the services a client has engaged us for.
- To respond to enquiries and provide support.
- To report on marketing performance.
- To bill for services and keep accurate financial records.
- To maintain the security and reliability of our systems.
- To meet legal and tax obligations.
How we share information
We do not sell personal information. We share it only with service providers who help us operate — hosting, email delivery, telephony, payment processing, and analytics — and only to the extent they need it to perform that function. We also disclose information where the law requires it.
Client data is kept separated between businesses. One client cannot access another client's records.
Storage, security, and retention
Data is stored with established cloud providers in the United States. The protections described under How we protect Google user data apply to personal and business data generally, not only to data obtained from Google:
- Traffic is encrypted in transit using HTTPS with TLS.
- Integration credentials and access tokens are encrypted at rest with AES-256-GCM, using a key held outside the database.
- Production access is limited to named administrators on a least-privilege basis, with two-factor authentication required for sensitive operations.
- Each business's records are separated from every other business's, and enforced on every query rather than by convention.
- Systems are monitored, administrative activity is logged, and security updates are applied on an ongoing basis.
- Data is backed up regularly so it can be restored after a failure.
We keep information for as long as a business is a client and for as long afterwards as we need it to meet legal, tax, and accounting obligations. After that it is deleted. A client may request earlier deletion of their data, subject to those obligations.
No system is perfectly secure. We work to protect information but cannot guarantee absolute security.
Your choices
You can ask us what personal information we hold about you, ask us to correct it, ask us to delete it, or ask us to stop sending marketing messages. Email [email protected] and we will respond.
You can opt out of marketing email using the unsubscribe link in any message, and out of text messages by replying STOP.
Cookies
We use cookies and similar technologies to run the site, remember preferences, and understand how the site is used. Most browsers let you refuse or delete cookies; some parts of the site may not work correctly if you do.
Children
Our services are for businesses. We do not knowingly collect personal information from anyone under 18. If you believe we have, contact us and we will delete it.
Changes to this policy
We may update this policy as our services change. The effective date at the top of this page shows when it was last revised. Material changes will be communicated to active clients.
Contact
Questions about this policy, or about the information we hold:
Elevative Creative
50 W Broadway Ste 333 PMB 878082
Salt Lake City, UT 84101-2027
[email protected]
+1-435-990-0171