Rubicon
Back to SiteRequest Demo

Legal

Privacy Policy

Last updated: August 6, 2026

1. What Rubicon Does

Rubicon is a campaign analytics, communications, and operations platform designed to help teams connect third-party platforms, review advertising and engagement performance, manage contact records, and coordinate campaign-related workflows.

2. Information We Collect

We may collect information you provide directly, such as your name, email address, team name, company name, login credentials, support messages, and workspace or campaign information you choose to upload or configure.

We may also collect technical information such as IP address, browser type, device information, log data, and usage diagnostics when you access the website or Service.

  • Contact records uploaded, entered, or managed by an organization using Rubicon, which may include names, phone numbers, email addresses, tags, notes, outreach history, consent or opt-out status, and similar contact-management data.
  • Message-related records generated through Rubicon messaging workflows, such as message content, delivery metadata, timestamps, response data, and related audit or compliance logs where available.

3. Contact Data and Messaging Data

An organization using Rubicon may manage its own contact database inside the platform and may use Rubicon to prepare, send, track, or administer communications to those contacts through supported communication channels and integrated service providers.

Rubicon acts as the platform provider for these workflows. The organization using Rubicon is responsible for the contact list it uploads or maintains, the lawfulness of the communication, and any required consent, notice, opt-out, or suppression handling under applicable law.

4. Information Collected Through Connected Meta Accounts

If you connect a Meta ad account or Facebook Page to Rubicon, we may access and store information made available through the permissions you authorize.

  • Meta ad account identifiers and ad account names.
  • Campaign, ad set, ad, and creative metadata.
  • Ad performance and reporting data such as impressions, clicks, spend, reach, engagement, conversions, demographics, and geographic breakdowns.
  • Facebook Page identifiers and Page names.
  • Facebook Page insights data for connected Pages, such as reach, impressions, engagement, audience, and other Page-level reporting metrics made available by Meta.
  • Post and comment data associated with connected Pages and Page-backed ads, including post IDs, comment IDs, message text, author display names, timestamps, and related engagement data where available.
  • Access tokens and related connection metadata needed to maintain the integration.
  • Rubicon uses ads_read to read advertising account, campaign, creative, and reporting data for connected Meta ad accounts.
  • Rubicon uses pages_show_list to list Facebook Pages the authorized user manages and connect the selected Page to the workspace.
  • Rubicon uses pages_read_engagement to read Page-backed post, comment, and engagement data needed for analytics and comment workflows.
  • Rubicon uses pages_read_user_content to read user-created content on connected Pages, such as posts and comments, so authorized users can review and analyze Page conversations and engagement inside Rubicon.
  • Rubicon uses read_insights to read analytics insights for connected Facebook Pages so authorized users can view Page-level performance in Rubicon dashboards and reports.

5. Information Collected Through Connected Google Ads Accounts

If you connect a Google Ads account to Rubicon, we may access and store information made available through the Google Ads API and the authorization you grant.

  • Google Ads customer account identifiers and related account-access metadata.
  • Campaign, ad group, ad, and creative metadata.
  • Advertising performance data such as impressions, clicks, spend, interactions, conversions, conversion value, video views, demographic breakdowns, and geographic breakdowns.
  • OAuth credentials and related connection metadata needed to maintain the integration, including refresh tokens used for background synchronization.
  • Rubicon currently uses the Google Ads OAuth scope https://www.googleapis.com/auth/adwords.

6. Information Collected Through Connected Google Analytics Accounts

If you connect a Google Analytics account or GA4 property to Rubicon, we may access and store information made available through the Google Analytics APIs and the authorization you grant.

  • Google Analytics account, property, and stream identifiers and display names.
  • Website and digital-channel analytics data such as users, sessions, page views, engagement, traffic acquisition, referral sources, geography, demographics, device categories, conversion activity, and related reporting metrics.
  • OAuth credentials and related connection metadata needed to maintain the integration, including refresh tokens used for background synchronization.
  • Rubicon uses the Google Analytics OAuth scope https://www.googleapis.com/auth/analytics.readonly to read Google Analytics and GA4 reporting data for authorized users.

7. How We Use Information

  • Provide, operate, secure, and improve the Service.
  • Connect and maintain authorized integrations with Meta, Google, and other third-party platforms.
  • Retrieve, display, process, and analyze campaign and engagement data for authorized users.
  • Generate dashboards, reports, and performance summaries.
  • Store, organize, and manage contact records and communication activity on behalf of an authorized organization.
  • Facilitate delivery, tracking, and administration of communications initiated by an authorized organization through integrated messaging channels and service providers.
  • Support comment analysis, sentiment workflows, troubleshooting, and customer support.
  • Detect abuse, secure accounts, enforce our terms, and comply with legal obligations.
  • Communicate with you about the Service, account activity, product updates, and support matters.

8. Google API Services User Data

Rubicon uses Google user data only to provide and improve the Google Ads and Google Analytics integrations that authorized users choose to connect.

Rubicon does not sell Google user data. Rubicon does not use Google user data for advertising, does not transfer Google user data to third parties except as necessary to provide or secure the Service, comply with law, or as directed by an authorized user, and does not use Google user data to develop, improve, or train generalized AI or machine learning models.

Rubicon's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9. Artificial Intelligence Services

Rubicon uses third-party artificial intelligence integrations to support product features such as analysis, summarization, drafting assistance, and campaign intelligence workflows.

Rubicon currently uses OpenAI models provided through Microsoft Azure. Rubicon does not operate its own foundation AI model for these features.

Rubicon has a Microsoft Customer Agreement with Azure to help protect customer data processed through Azure services. Customer data is handled according to Rubicon's published privacy disclosures and applicable contractual protections with Microsoft Azure.

10. Legal Basis and Authorization

Where required by applicable law, we process personal information based on your consent, the performance of a contract with you or your organization, our legitimate interests in operating and improving the Service, and compliance with legal obligations.

When you connect a Meta account, Facebook Page, Google Ads account, or Google Analytics account or property, you represent that you are authorized to grant Rubicon access to that data on behalf of yourself or the relevant organization.

When an organization uses Rubicon to store or message its own contacts, that organization represents that it has an appropriate legal basis to collect, upload, use, and communicate with those contacts.

11. How We Share Information

We do not sell personal information.

  • With service providers and infrastructure vendors that help us operate the Service.
  • With integrated communications or delivery providers to the extent necessary to transmit, route, deliver, or track messages initiated through the platform.
  • With third-party platforms when required to provide the integration you requested.
  • Within your team or organization, according to your workspace permissions.
  • If required by law, legal process, or to protect rights, safety, security, or the integrity of the Service.
  • In connection with a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.

12. Data Retention

We retain information for as long as reasonably necessary to provide the Service, maintain security and auditability, comply with legal obligations, resolve disputes, and enforce agreements.

For platform integrations specifically, access tokens, refresh tokens, and connection credentials are stored so the integration can function. If a Meta, Google Ads, or Google Analytics connection is disconnected in Rubicon, stored connection credentials are removed from the active connection record. Historical analytics and reporting data previously synced into the workspace may remain available after a connection is disconnected unless a separate deletion request is made.

Contact records, communication activity, and messaging logs may remain in the workspace until deleted by the customer organization, removed in accordance with workspace retention settings or policies, or deleted following a valid request.

If you want Rubicon to delete previously synced Meta-related, Google Ads-related, or Google Analytics-related workspace data, please follow the instructions on the Data Deletion page or contact us at info@crossrubicon.com.

13. Security

We use reasonable administrative, technical, and organizational measures to protect information. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.

14. Your Choices and Rights

Depending on your location and applicable law, you may also have rights to request access, correction, deletion, restriction, or objection regarding certain personal information. We may need to verify your identity and authority before fulfilling certain requests.

If you are a contact of an organization that uses Rubicon, your first point of contact regarding outreach, contact records, or opt-out requests should generally be the organization that collected your information, unless applicable law requires otherwise.

  • Disconnect Meta integrations from within Rubicon, if you are an authorized workspace manager.
  • Disconnect Google Ads integrations from within Rubicon, if you are an authorized workspace manager.
  • Disconnect Google Analytics integrations from within Rubicon, if you are an authorized workspace manager.
  • Remove Rubicon from your Meta Apps and Websites settings.
  • Revoke Rubicon access from your Google account settings.
  • Contact us to request deletion of data associated with your use of the Service.

15. Data Deletion Instructions

You may request deletion of Meta-related, Google Ads-related, or Google Analytics-related data by removing the Rubicon app from Meta/Facebook, revoking Rubicon access from your Google account settings, disconnecting the integration in Rubicon, or emailing info@crossrubicon.com with your name, account email, organization or team name, relevant account IDs, Google Ads customer IDs, Google Analytics property IDs, and a clear statement describing what you want deleted.

Requests relating to organization-managed contact records or campaign communications may require coordination with the relevant organization that controls that contact data.

16. International Transfers

Your information may be processed and stored in countries other than your own. Where required, we take reasonable steps to provide appropriate safeguards for cross-border transfers.

17. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version at the relevant public URL and revise the last updated date above.

19. Contact Us

DFS AI Global d.o.o. za usluge

Petrova ulica 133, 10123 Zagreb, Croatia

info@crossrubicon.com

Rubicon

The AI-powered command center for modern political campaigns.

info@crossrubicon.com

Legal
  • Privacy Policy
  • Terms of Use
  • Data Deletion
© 2026 Rubicon. All rights reserved.