Privacy Policy
Last updated: September 22, 2026
This page describes how MIXEL Marketing (the product) handles personal and account data in connection with our SaaS workspace and third-party social integrations, including TikTok. It is product policy text for customers and platform reviewers. It is not a substitute for legal advice. Mixel’s counsel should review this text before relying on it for formal regulatory filings.
Google Ads, Data Manager, Search Console and Business Profile
Connecting Google is optional. Search Console read-only access retrieves verified website properties and search-performance samples, including page URLs, search queries, dates, clicks, impressions, click-through rates and average positions. We use these to report website performance and suggest content reviews. Google Ads access retrieves accessible advertiser accounts, currency, time zone, campaigns, search terms, budgets, bids, targeting, costs, clicks and conversions for account selection, reporting and reviewed recommendations. Campaign creation, pausing, activation and every optimisation change require explicit approval; activation also requires an approved budget.
For an explicitly approved, eligible CRM conversion, Google Data Manager receives the selected Google destination, Google click identifier, event time, consent status and event identifier, plus the evidenced value and currency where applicable. Approved refund or reversal corrections are sent to Google Ads. An explicitly approved optimisation can pause a managed campaign, add one exact-match negative keyword, or lower one current bid or unshared daily budget after fresh evidence and exact before/after review. Copy and targeting suggestions are recorded handoffs and require manual selection in Google Ads. We store receipts to prevent duplicate submissions and show status. Receipt acceptance does not establish that Google matched a conversion. Test enquiries and events without the required consent are not eligible. Google connections do not authorize automatic advertising spend or automatic budget increases.
Business Profile connection requests Google's business.manage scope, which permits profile management. We read accessible account and location names and selected-location website clicks, call clicks and direction requests. Connecting alone does not publish. Selecting a location enables read-only measurement; only a separate activation permits weekly updates sending the latest published article summary and URL to that Google profile. We read recent reviews, including reviewer name, rating and comment, to prepare local reply drafts; a reply is sent only after owner approval. We store the encrypted refresh token, selected location, review drafts and delivery audit records in the tenant backend. Profile actions are not counted as article referrals, enquiries or revenue. Pausing stops future weekly posts while read-only measurement continues; disconnecting the integration removes its active token from the database. Google account revocation also stops future access. Previously published updates and replies remain at Google, while audit records and backups may remain under the retention practices described below.
Google OAuth tokens are encrypted before server-side storage. Selected account details, Search Console samples, delivery receipts and approval records are stored in the tenant-scoped backend and processed by our application hosting and database infrastructure to provide these features. Google data is not sold. Revoking access stops future authorized API access but does not automatically erase previously stored reports, CRM evidence or audit records. Contact info@mixel.ch to request access or deletion; applicable record-retention obligations and operational backups may affect what can be erased immediately.
You can revoke MIXEL Marketing access in your Google Account’s third-party connections settings. Search Console can also be disconnected in Integrations. Revocation does not delete information already delivered to Google or change campaigns already created there; manage those in Google Ads.
Manage Google Account connectionsOverview
MIXEL Marketing is a marketing automation and social publishing workspace operated by Mixel IT GmbH (Switzerland), available at marketing.mixel.ch and marketing.mixel.mu. The service helps authorized business users onboard websites, generate and edit content, and publish approved posts to connected platforms (including TikTok, LinkedIn, Facebook, YouTube, and CMS destinations). We process account credentials, media URLs, captions, schedules, and publishing metadata only as needed to operate that workspace.
Data we process
Depending on how you use the service, we may process: account email and authentication session data; tenant/organization and website identifiers; captions, hashtags, media URLs, schedules, and publish status; integration configuration and OAuth tokens for connected platforms; support communications; and basic technical logs (for example request timing and error diagnostics) needed to keep the service secure and reliable.
Consented website visit counts
If a website owner enables MIXEL measurement and a visitor explicitly consents on a MIXEL-hosted article or through the acquisition snippet on the customer's site, MIXEL counts one browser-reported visit per browser session on each origin. We keep only daily totals by website, channel and approved UTM source, medium and campaign ID. The analytics table does not store an IP address, user agent, visitor ID, click ID, page URL or referrer. A short-lived keyed hash of the IP limits abuse and is purged by daily cleanup once older than 48 hours. Daily totals are deleted after 13 months. Withdrawing consent stops future measurement; existing anonymous totals cannot be attributed to one visitor. Counts may be lower when scripts are blocked and do not represent Google impressions or search rank.
Local content-integrity review
When an authorized user runs the local content-integrity review, MIXEL checks the saved article title, metadata and body on its own infrastructure. A MIXEL-hosted language model may select verbatim excerpts when available; a deterministic check works without it. No article text is sent to Gemini, DataForSEO or another paid fact-check provider by this action. MIXEL does not independently verify external factual claims: every report requires human review of the full article and a documented evidence note before approval. MIXEL stores the content hash, candidate excerpts, writing-quality signals, review note and reviewer identity as tenant-scoped approval evidence. An unchanged report is valid for 24 hours; audit records may remain under our retention practices. Writing signals do not prove human or AI authorship. Previously created third-party-provider reports may remain in historical audit records.
TikTok and other social integrations
When you connect TikTok (or another social platform) via OAuth, you authorize MIXEL Marketing to act on your behalf for the scopes you approve. For TikTok Content Posting / Direct Post we request: user.info.basic (account identity such as open_id and, where TikTok provides them, display name and avatar URL), video.upload (upload video bytes for a publish attempt), and video.publish (complete Direct Post so the video can go live on the connected TikTok account rather than remaining only as an inbox draft). We receive from TikTok the OAuth tokens and open_id required to publish, plus any basic profile fields TikTok returns under user.info.basic. We use that data solely to identify the connected account and to publish or schedule customer-approved video content that you (or your authorized users) submit in MIXEL Marketing. We do not use TikTok profile data for advertising, profiling unrelated to publishing, or sale to third parties.
Why we process TikTok data
Purpose is limited to: connecting your TikTok creator account; storing encrypted credentials so the workspace can publish on your instruction; uploading and publishing video content you supply (caption/title and public HTTPS video URL); showing connection status in Integrations; refreshing tokens when TikTok requires it; and troubleshooting failed publishes with tenant-scoped audit metadata.
Storage and security
OAuth access and refresh tokens are stored server-side and encrypted at rest before persistence. Publishing runs on our application infrastructure (Cloudflare Workers) with tenant-scoped backend storage (self-hosted Supabase/Postgres). Access to service-role systems is restricted to server routes that re-check session and website ownership. We apply industry-standard transport encryption (HTTPS/TLS) for data in transit.
Retention
We retain operational and integration data for as long as the connection or account remains active and as needed to provide the service, maintain security, resolve disputes, and meet legal record-keeping obligations. If you disconnect TikTok (or delete the integration), we remove or deactivate the stored TikTok tokens and open_id for that website so further publishes cannot use that connection. Residual encrypted backups and audit logs may persist for a limited operational period consistent with security and Swiss commercial record practices, then are purged according to our retention cycle.
Sharing; we do not sell your data
We do not sell personal data. We share data only with processors and platforms required to deliver the features you request: hosting and database providers; and the social or CMS APIs you connect (TikTok receives the video and caption you choose to publish). Subprocessors act under our instructions. Platform APIs remain subject to those platforms’ own privacy policies.
Your rights
Depending on your location (including Switzerland and the EEA/UK), you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. You may also lodge a complaint with a competent supervisory authority. To exercise rights related to MIXEL Marketing account or integration data, contact us using the details below. For data TikTok holds independently on your creator account, use TikTok’s own settings and privacy tools.
How to disconnect or revoke TikTok access
In MIXEL Marketing: open Integrations, select the website, and use Disconnect on the TikTok card (or delete the TikTok integration). That removes our stored tokens for that website. Separately, revoke the app in TikTok’s account / connected apps settings so TikTok stops issuing access to MIXEL Marketing. After disconnect or revoke, new publishes to that TikTok account will fail until you reconnect.
Children
MIXEL Marketing is a business SaaS product. It is not directed at children, and we do not knowingly collect personal data from children for this service.
Changes
We may update this policy when the product, integrations, or legal requirements change. The “Last updated” date at the top will change when we do. Material changes affecting TikTok or other OAuth integrations will be reflected on this page.
Contact
For privacy questions, contact info@mixel.ch.