Legal
Privacy Policy
Last updated: June 21, 2025
Panomara (panomara.io) · Operated by Sazid Abdullah Farhan
1. Overview
This policy explains what data Panomara collects, why, how it is used, and your rights. Panomara is a white-label client reporting platform for digital marketing agencies.
2. Who This Policy Applies To
This policy applies to:
- Agency users — people who sign up for a Panomara account
- Client users — end users who access branded portals created by agencies
3. Data We Collect
Agency Users
- Name, email address, and password (on signup)
- Agency name and branding settings (logo, colour, domain)
- Billing information — processed and stored by Paddle, not by us
- OAuth tokens for connected integrations (Google, Meta) — stored encrypted in our database, server-side only
- Usage data (report views, login timestamps, activity log)
Client Users (Portal Visitors)
- Email address (used to log into the client portal)
- Session data (IP address, user agent, login timestamp) for security and audit purposes
- No passwords are stored for client users — access is managed via secure cookies
Marketing Data (via Integrations)
Data fetched from Google Analytics 4, Google Ads, Google Search Console, and Meta Ads is done on behalf of agencies. This data belongs to the agency and their clients. We do not use it for any purpose other than displaying it in your portal. Our use of Google API data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Data
- To operate and deliver the Panomara service
- To send transactional emails (account confirmation, report notifications, billing receipts) via Resend
- To display analytics data in agency dashboards and client portals
- To handle billing and subscription management via Paddle
- To investigate abuse or security incidents
- To improve and optimise the platform (using aggregated, anonymised usage data only)
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in this policy.
5. Data Storage and Security
- All data is stored in secure cloud infrastructure in the USA
- Agency data is strictly isolated — no agency can access another's data
- Integration tokens are stored securely server-side and never exposed to end users
- Passwords are hashed and never stored in plain text
- All data in transit is encrypted via HTTPS
6. Subprocessors
We share data with the following third parties to operate the service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | USA |
| Vercel | Web hosting and CDN | USA / Global |
| Paddle | Payment processing (Merchant of Record) | UK |
| Resend | Transactional email delivery | USA |
| API integrations (GA4, Ads, Search Console) | Global | |
| Meta | API integration (Meta Ads) | USA |
8. Your Rights (GDPR)
If you are located in the UK or EU, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to processing
- Withdraw consent at any time
- Export your data in a portable format
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email: hello@panomara.io. We will respond within 30 days.
9. Data Retention
- Active account data is retained while your account is open
- On cancellation, your data is retained for 90 days to allow reactivation, then permanently deleted
- You may request immediate deletion at any time by emailing hello@panomara.io
- Billing records may be retained longer as required by law (Paddle handles this)
- Portal session logs are retained for 90 days then deleted
10. International Transfers
Your data may be stored and processed in the USA (Supabase, Vercel) and UK (Paddle). When transferring data outside the UK/EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements.
11. Children
Panomara is not intended for users under 18. We do not knowingly collect data from minors.
12. Changes to This Policy
We will notify you by email at least 14 days before any material changes to this policy take effect.
13. Contact
For privacy questions or data requests: