Privacy Policy
Last updated: August 2026
1. About t2ó ONE
t2ó ONE is a private, invitation-only analytics platform operated by t2ó North America ("t2ó", "we", "us"). It is used internally by t2ó staff and by named client stakeholders explicitly invited to access dashboards for their engagement. This platform is not a public-facing service and is not available for self-registration.
2. What information we collect
When you sign in and use the platform, we collect and process the following personal data:
- Identity information from Google OAuth: your name, email address, and Google profile picture (URL). We use this to authenticate you and to display your identity within the app.
- Authorization records stored in Clerk (our authentication provider): your permitted roles, entitlements, and metadata that determine which dashboards you can view.
- Application usage logs such as pages visited, actions performed, timestamps, IP address, and browser user agent. Retained for a maximum of 90 days for security auditing.
- Session cookies required for authentication and remembering your session.
We do not sell your personal data, and we do not use it for advertising or marketing purposes.
3. Client data displayed in the platform
The dashboards shown in t2ó ONE present marketing performance data belonging to t2ó's clients (for example, campaign spend, conversions, and customer segment aggregates). Access to any specific client's data is restricted to authorized staff at t2ó and authorized stakeholders at that client. Client data is processed under the terms of the underlying service agreement between t2ó and each client.
4. Google OAuth data usage
We use Google OAuth 2.0 to verify your identity. We request only the following minimum scopes:
openid— to identify youemail— to associate your account with your email addressprofile— to display your name and profile picture
We do not request access to your Gmail, Drive, Calendar, contacts, or any other Google Workspace service. Your Google OAuth tokens are used solely for authentication and are not shared with third parties.
5. How we store and protect your data
Personal data is stored on encrypted infrastructure operated by our authentication provider (Clerk) and application hosts (Vercel, AWS). All data in transit is protected by TLS 1.2 or higher. Application access is protected by role-based authorization checks enforced server-side.
6. Your rights
You have the right to access, correct, or delete the personal information we hold about you. To exercise any of these rights, or to request that your account be removed from the platform, email us at alejandro.ramirez@t2o.com. We will respond within 30 days.
7. Data sharing
We do not sell, rent, or share your personal data with third parties for their independent use. We may share limited data with the service providers listed above (Clerk, Vercel, AWS, Google) strictly to operate the platform. These providers process data under their own privacy commitments and applicable data-processing agreements.
8. Data retention
Identity data is retained as long as you have an active account plus 30 days after deactivation. Application logs are retained for 90 days. On request, we will delete your personal data within 30 days, subject to any legal retention requirements.
9. Children
t2ó ONE is not intended for and is not directed at children under 16. We do not knowingly collect data from anyone in that age group.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page. Continued use of the platform after an update indicates acceptance of the revised policy.
11. Contact
Questions about this privacy policy or our data practices can be sent to: alejandro.ramirez@t2o.com.