Nexus Hub Privacy Policy
Effective date: September 29, 2026
Last updated: September 29, 2026
This Privacy Policy explains how Nexus Creative LLC, a North Carolina limited liability company doing business as Nexus Creative Studio ("Nexus," "we," "us," or "our"), collects, uses, shares, and protects information in connection with Nexus Hub (the "Platform"), available at hub.nexusforyou.com, and the related websites, emails, and support we provide (together, the "Services").
Please read this Policy together with our Terms of Service and our Data Deletion Instructions.
1. Who we are and how to contact us
- Company: Nexus Creative LLC, doing business as Nexus Creative Studio
- Mailing address: 2409 Mason Wallace Dr, Charlotte, North Carolina 28212, United States
- Privacy contact: Ricardo Grauppe, help@nexusforyou.com
Ricardo Grauppe is also the person responsible for handling data protection requests, including requests under Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, "LGPD"), acting as our data protection contact (encarregado).
2. Scope of this Policy
This Policy applies to:
- People who create an account on or use the Platform ("Users"), including owners, managers, and agents of a business that uses the Platform, and members of the Nexus team.
- Businesses that use the Platform ("Customers").
- Visitors to our Platform pages, including sign-in pages and shared onboarding or file-sharing links.
- Information we receive from third-party services that a Customer or User chooses to connect, such as Google, Meta (Facebook, Instagram, Threads), and WhatsApp.
This Policy does not cover the privacy practices of third-party services you connect to the Platform. Their own privacy policies govern how they handle your information.
3. Our role: controller and processor
The Platform is a business tool. Different rules apply depending on whose information it is.
When Nexus is the controller. We decide how and why information is processed for account data about Users (for example, your name, email address, and sign-in information), for information about Customers as our business clients, for security and usage logs, and for communications you send to us. For this information, Nexus is the "controller" (or "business" under California law).
When Nexus is a processor or service provider. Customers use the Platform to store and manage information about their own customers, leads, prospects, and contacts, and to exchange messages with them ("Customer Data"). This includes leads and conversations from Google Local Services Ads, Google Ads, Meta lead forms, Facebook Pages, Instagram, and WhatsApp, as well as contacts, notes, tasks, files, contracts, and financial records the Customer adds. For Customer Data, the Customer is the controller and Nexus acts only as a "processor" or "service provider" on the Customer's behalf and under the Customer's instructions, as described in our Terms of Service and any agreement we have with the Customer.
If you are a person whose information was entered into the Platform by a business (for example, you requested a quote from a business that uses the Platform), please contact that business first about your information. If you contact us, we will forward your request to the relevant Customer and help them respond, as described in Section 13.
Agency services. Some Customers also hire Nexus to provide marketing agency services. In that case, authorized Nexus team members may access the Customer's workspace and connected accounts to perform those services, on the Customer's behalf and within the access the Customer grants.
4. Information we collect
4.1 Account and profile information
When a User is invited, signs up, or signs in, we collect:
- Name, email address, and password. Passwords are handled by our authentication provider (Supabase) and stored only in hashed form. We never see or store your password in plain text.
- If you use "Sign in with Google": your Google account name, email address, and basic profile information, and the Google account identifier needed to sign you in.
- Profile photo, if you upload one.
- Your workspace (company), your role (for example, owner, manager, or agent), and your permissions.
4.2 Customer business information
For Customers, we collect business details such as company name and legal name, contact names, business email and phone numbers, business address and service area, services offered, and the account identifiers the Customer links to the Platform (for example, a Google Ads customer ID or a Google Analytics property ID).
When a Customer completes our onboarding form, it may also provide its entity type, federal Employer Identification Number (optional), average ticket value, whether it has access to its digital accounts (the form asks only whether you have access, never for passwords), brand and tone-of-voice preferences, competitors and brands it admires, photos of completed projects, and logos.
4.3 Information from services you connect
Connecting a third-party service is always optional and is done by the Customer or User through an authorization screen of that service. We only receive the information that the service shares under the permissions you approve.
Google. If you connect a Google account, we may receive, depending on the permissions you grant:
- Basic profile (OpenID, email, profile): your Google email address and name, to identify the connected account.
- Google Calendar (calendar.events): events on your calendar, so you can view, create, update, and delete events from inside the Platform. Calendar events are displayed in your browser and are not stored in our database.
- Google Ads, including Local Services Ads (adwords): campaign, ad group, keyword, search term, device, budget, spend, and performance metrics; Local Services Ads leads, including the lead's name, phone number, and email address, service category, lead status and charge status, lead notes, conversation history (message text and the number of attachments), and phone call details such as duration and call recordings. When you choose to, the Platform also writes to Google Ads on your behalf: it submits lead feedback and ratings to Google and sends messages to a Local Services Ads lead.
- Google Analytics 4 (analytics.readonly): aggregated website analytics such as traffic channels, sources, pages, landing pages, events, cities, and devices. We only read this information.
- Google Business Profile (business.manage): information about the business locations you manage and the ability to manage posts and profile content you choose to publish.
Meta (Facebook, Instagram, Threads). Meta integrations are connected through "Facebook Login for Business." If you connect them, we may receive, depending on the permissions and assets you choose:
- Marketing API: your ad accounts, campaigns, ad sets, ads, and ad performance metrics; the ability to create and manage ads; and leads submitted through your Meta lead forms (for example, name, phone number, email address, and answers to your form questions).
- Facebook Pages and Messenger: the Pages you manage, Page posts and comments, and messages people send to your Page, so you can publish, moderate, and reply.
- Instagram: your Instagram professional account, media, comments, and direct messages, so you can publish content and reply to comments and messages.
- Threads: your Threads profile and posts, so you can publish and manage content.
- oEmbed: public post content used to display embedded Facebook or Instagram posts.
WhatsApp. A Customer may link its WhatsApp number to the Platform by scanning a QR code in the WhatsApp app, the same way you add a "linked device." Once linked, the Platform receives and stores, for that business number: messages sent and received (text, photos, videos, audio, documents, and other media), message status (sent, delivered, read), reactions, edits and deletions, the contact list and group information available to the linked device, contacts' WhatsApp profile names and profile photos, and presence information such as "online" or "typing" for open conversations. See Section 7.
4.4 Content Customers and Users add
Users can add content such as contacts, leads and prospects, sales pipeline stages, tasks and comments, notes and internal documents, meeting notes and transcripts, quick replies and automated message rules, files and videos stored in a Customer's file area ("Drive"), contracts and electronic signature information (signer names, email addresses, signing status, and audit events), finance entries (amounts in U.S. dollars, descriptions, categories, and payment status), and posts and reactions in the Platform's feed. Customers may also upload files through a shared upload link we provide to them.
4.5 Usage, device, and log information
When you use the Platform, our systems and hosting providers automatically record technical information such as IP address, browser type, device information, pages and API endpoints requested, date and time, and error logs. We use this information to operate, secure, and troubleshoot the Platform, including to apply rate limits against abuse. We also record certain actions for accountability, for example which User submitted feedback on or sent a message to a Local Services Ads lead.
4.6 Cookies and similar technologies
The Platform does not use advertising cookies or third-party analytics trackers. We use your browser's local storage for things the Platform needs to work:
- Sign-in session: a session token from our authentication provider, so you stay signed in.
- Preferences: interface choices, such as whether a contact panel is open, and whether you dismissed the prompt to enable desktop notifications.
- Form progress: on the onboarding form, your progress is saved in your browser so you do not lose it if you close the page.
Some third-party components load when you use certain features and may receive your IP address or set their own technical cookies: Google Fonts (typography), Google's sign-in and consent pages, the Bunny.net video player when you watch a video, and the OpenStreetMap Nominatim service when you search for an address on the onboarding form. You can clear local storage and cookies through your browser settings at any time, but you will be signed out.
4.7 Communications
If you contact us by email or through the Platform, we keep your message, contact details, and our reply. We also send transactional emails, such as invitations, password reset emails, and signature requests.
5. How we use information
We use information to:
- Provide, operate, and maintain the Platform and the features you choose to use, including displaying reports, leads, conversations, and calendars; sending messages and publishing content you create; and storing your files.
- Create and manage accounts, authenticate Users, and enforce the roles and permissions a Customer sets.
- Provide agency services to Customers that have engaged Nexus for them.
- Send transactional and service communications, such as sign-in and password reset emails, notices about changes to the Services, and responses to support requests.
- Secure the Platform: detect, prevent, and respond to fraud, abuse, security incidents, and technical issues.
- Comply with law, respond to lawful requests, and enforce our Terms of Service.
- Improve the Platform's reliability and usability, using technical logs and feedback. We do not use Customer Data, Google user data, or Meta Platform Data for this purpose beyond what is necessary to provide the features you use.
We do not use Customer Data, data received from Google APIs, or Meta Platform Data for advertising, to build profiles of individuals, or to train generalized artificial intelligence or machine learning models. The Platform does not currently send Customer Data to any third-party artificial intelligence service. If we introduce such a feature, we will update this Policy before it is enabled and it will never use Google user data or Meta Platform Data in a way that violates the policies described in Sections 6 and 7.
6. Google user data and the Limited Use commitment
Nexus Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Limited to user-facing features. We use Google user data only to provide and improve the user-facing features you see in the Platform: signing in, showing and managing your calendar events, showing Google Ads, Local Services Ads, and Google Analytics reports, displaying and acting on Local Services Ads leads, and managing your Google Business Profile.
- No transfer except as allowed. We do not transfer Google user data to others except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- No advertising use. We do not use or transfer Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- No sale. We do not sell Google user data.
- No AI model training. We do not use Google user data, including data obtained through Google Workspace APIs such as Google Calendar, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
- Limited human access. No person reads Google user data unless: (a) we have your affirmative agreement for specific data (for example, a Customer has engaged Nexus to manage its Google Ads or Local Services Ads account, and authorized Nexus team members view that account's leads to perform the service, or you ask us for support on a specific item); (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymized and used for internal operations in accordance with applicable law.
How Google tokens are protected. When you connect Google, our server stores a refresh token encrypted with AES-256-GCM. Your browser never receives this refresh token. For calendar features, your browser receives only a short-lived access token limited to the calendar permission, which cannot be used for Google Ads or Google Analytics.
Revoking Google access. You can disconnect Google at any time in the Platform under Settings > Connections. When you do, we revoke the token with Google and delete it from our database. You can also remove access directly in your Google Account at myaccount.google.com/permissions.
Local Services Ads call recordings are streamed from Google to your browser when you choose to play them. We do not keep a copy of call recordings on our servers.
7. Meta Platform Data and WhatsApp data
7.1 Meta Platform Data (Facebook, Instagram, Threads)
"Meta Platform Data" means information we receive through Meta's APIs when a Customer connects its Meta business assets. For Meta Platform Data:
- We use it only to provide the features the Customer enabled, such as managing ads, receiving ad leads, replying to messages and comments, and publishing content, and only in accordance with the Meta Platform Terms and Developer Policies.
- We do not sell, license, or purchase Meta Platform Data.
- We do not use Meta Platform Data for advertising targeting, to build or augment user profiles, for surveillance, or to make eligibility decisions about people (for example, housing, employment, insurance, or credit).
- We do not transfer Meta Platform Data to third parties except to our service providers that help us operate the Platform (Section 8), as required by law, or as the Customer directs within the features of the Platform.
- We delete Meta Platform Data when it is no longer needed to provide the features the Customer enabled, when a Customer disconnects the integration, when we receive a valid deletion request, or when Meta requires it, as described in Section 10 and in our Data Deletion Instructions.
7.2 WhatsApp connection
The WhatsApp connection works as a linked device on the Customer's own WhatsApp account, which the Customer links by scanning a QR code. It runs on WhatsApp gateway software hosted by Nexus on infrastructure we control. It is not a WhatsApp Business Platform (Cloud API) integration and is not provided, sponsored, or endorsed by WhatsApp or Meta.
We use WhatsApp data only to show the Customer's conversations in the Platform's inbox, send the messages and media the Customer's Users write, run the automated replies the Customer configures (such as welcome and away messages), and link conversations to the Customer's contacts. Each Customer's WhatsApp data is kept separate from every other Customer's data. The Customer can unlink the device at any time from the Platform or from WhatsApp (Settings > Linked devices).
7.3 Conversion data sent back to advertising platforms (optional feature)
The Platform may offer a feature that, when a Customer enables it, reports back to Google Ads or Meta (through Meta's Conversions API) which of the Customer's leads became qualified leads or customers, and the value of the sale in U.S. dollars. This helps the Customer's advertising campaigns learn which ads produce real customers. When enabled, the Platform may send click identifiers (such as Google's gclid, gbraid, or wbraid, and Meta's fbclid, fbc, or fbp values), the lead identifier assigned by the advertising platform, event names and times, the value of the sale, and email addresses and phone numbers that are hashed with SHA-256 before they are sent. The Platform may also submit lead quality ratings to Google Local Services Ads.
This feature is off unless the Customer turns it on. The Customer decides whether to use it and is responsible for providing any notices and obtaining any consents its own customers are entitled to under applicable law. Nexus sends this information only on the Customer's instructions, as its service provider.
8. How we share information
We share information only as described below.
8.1 Service providers (subprocessors)
We use the following providers to host and operate the Platform. They may process personal information only to provide their services to us, under contractual obligations of confidentiality and security.
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase, Inc. | Database, user authentication, and file storage for Platform files (profile photos and WhatsApp media) | Canada (Supabase region ca-central-1) |
| Vercel Inc. | Hosting of the Platform's web application and server functions | United States |
| Cloudflare, Inc. | Domain name system (DNS), secure file transfer proxy, secure tunnel and access control for self-hosted services | Global network |
| BunnyWay d.o.o. (Bunny.net) | Storage and delivery of Customer files and videos in the Drive | Bunny.net data centers selected for our storage |
| Resend | Delivery of transactional emails, such as password reset emails | United States |
| Autentique | Electronic signature of contracts: receives the contract document and signers' names and email addresses | Brazil |
| Google LLC (Google Workspace) | Our business email, used when you contact us | United States |
| Tailscale Inc. | Encrypted private network connecting our own servers | Global network |
In addition, self-hosted services (including the WhatsApp gateway) run on servers controlled by Nexus.
8.2 Third-party services you connect
When you connect Google, Meta, or WhatsApp, information flows between the Platform and that service as you direct. For example, when you send a message to a lead, publish a post, submit lead feedback, or enable conversion reporting, we transmit the content to that service. Their use of the information is governed by their own terms and privacy policies:
- Google: policies.google.com/privacy
- Meta: facebook.com/privacy/policy
- WhatsApp: whatsapp.com/legal/privacy-policy
8.3 Within a Customer's workspace
Information in a workspace is visible to the Customer's Users according to the roles the Customer sets. For example, an agent may see only the conversations and leads assigned to them. Authorized Nexus team members may access a Customer's workspace to provide support or agency services.
8.4 Legal reasons and protection
We may disclose information if we believe in good faith that it is required by law, subpoena, or other legal process; necessary to protect the rights, property, or safety of Nexus, our Users, or others; or necessary to investigate fraud, security issues, or violations of our Terms of Service.
8.5 Business transfers
If Nexus is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a policy that is at least as protective, and with notice to you.
8.6 No sale or sharing for cross-context behavioral advertising
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state laws. We have not done so in the preceding 12 months.
9. Legal bases for processing
Where laws such as the LGPD or similar laws require a legal basis, we rely on:
- Performance of a contract with the Customer or User, to provide the Platform and agency services.
- Legitimate interests, such as keeping the Platform secure, preventing abuse, and communicating with Users about the Services, balanced against your rights.
- Compliance with legal obligations, such as tax and accounting records and responding to lawful requests.
- Consent, where required, such as when you authorize a Google or Meta integration or allow desktop notifications. You may withdraw consent at any time, which does not affect processing that already took place.
For Customer Data, the Customer as controller is responsible for having a valid legal basis, and for giving any required notices and obtaining any required consents, for the information it collects and processes through the Platform.
10. Data retention
We keep information only as long as necessary for the purposes described in this Policy:
- Account information: for as long as the account is active. When an account is closed, we delete or anonymize it within 30 days, except where we must keep certain records to comply with law.
- Customer Data: for the duration of the Customer's subscription or service agreement, or until the Customer deletes it. After the agreement ends, the Customer may request an export within 30 days; we then delete Customer Data within 60 days after the end of the agreement, unless the law requires us to keep it.
- Connection tokens: Google and Meta tokens are kept only while the connection is active and are deleted immediately when the integration is disconnected. The WhatsApp linked-device session is ended when the Customer unlinks it.
- Data obtained from connected services: kept while needed to provide the features the Customer uses. When a Customer disconnects an integration, we stop collecting data from it immediately. Data that is displayed from the service in real time (such as Google Ads and Google Analytics reports, calendar events, and call recordings) is not stored. Records that were saved into the Customer's workspace (for example, a lead or conversation that became a contact) remain part of the Customer's records until the Customer deletes them or asks us to delete them, which we complete within 30 days of the request.
- Logs: technical and security logs are kept for a limited period, generally no longer than 90 days, unless needed to investigate an incident.
- Backups: deleted information may remain in encrypted backups for up to 30 days, after which it is overwritten in the normal backup cycle. Backups are not used for any other purpose.
- Business records: invoices, contracts, and financial records about our own relationship with Customers are kept as long as required by tax, accounting, and legal obligations.
11. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information, including:
- Encryption in transit using TLS (HTTPS) for all connections to the Platform.
- Encryption of stored Google OAuth refresh tokens with AES-256-GCM, with the encryption key kept only on the server. Our database and storage providers also encrypt data at rest.
- Secrets and API keys kept on the server and never sent to the browser.
- Role-based access control inside each workspace, database row-level security, and separation of each Customer's data.
- Short-lived, signed links for accessing stored media and files.
- Shared secrets for incoming webhooks, and access controls on our self-hosted services, which are reachable only through an authenticated tunnel or our private network.
- Rate limiting to protect against abuse and automated attacks.
- Access to production systems limited to authorized Nexus personnel who need it.
Some links are designed to work without signing in, such as a Customer's onboarding form link, a shared upload link, and the address of a profile photo. These use long, random addresses, but anyone who has the link can open it, so please keep them private.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify affected Customers, Users, and authorities as required by law.
12. International data transfers
Nexus is based in the United States. The Platform is used by people in the United States and in Brazil, among other places. Information is processed in the United States and in Canada (where our main database and platform file storage are hosted), and may be processed in other countries where our service providers operate (see Section 8.1). These countries may have data protection laws that differ from those in your country.
When we transfer personal information from Brazil or other jurisdictions with transfer rules, we rely on mechanisms permitted by applicable law, such as contractual commitments with our service providers, the performance of a contract with you, or your consent.
13. Your rights and choices
13.1 Rights available to everyone
Regardless of where you live, you can:
- Access and correct your account information in the Platform under Settings, or by contacting us.
- Delete your account and personal information by contacting us (see our Data Deletion Instructions).
- Export your information in a portable format by contacting us.
- Withdraw consent and disconnect integrations at any time in Settings > Connections.
- Revoke access directly with the connected service:
- Google: myaccount.google.com/permissions
- Facebook: Settings & privacy > Settings > Business integrations (facebook.com/settings?tab=business_tools)
- Instagram: Settings > Website permissions > Apps and websites
- Threads: remove Nexus Hub from your Threads account's app permissions
- WhatsApp: Settings > Linked devices > select the device > Log out
- Opt out of non-essential emails. We only send service and transactional emails, which are necessary to operate your account.
13.2 U.S. state privacy rights (including California)
Depending on your state of residence (for example, California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws), and to the extent those laws apply to Nexus, you may have the right to:
- Know what personal information we collect, use, and disclose, including the categories and specific pieces of personal information.
- Access and receive a portable copy of your personal information.
- Correct inaccurate personal information.
- Delete personal information, subject to legal exceptions.
- Opt out of the sale or sharing of personal information for cross-context behavioral advertising, targeted advertising, and certain profiling. We do not sell or share personal information for these purposes.
- Limit the use of sensitive personal information. We use sensitive personal information (such as account login credentials) only for purposes permitted by law, such as providing the Services and security.
- Not be discriminated against for exercising these rights.
- Appeal our decision on your request, by replying to our decision and explaining why. If we deny the appeal, you may contact your state Attorney General.
Categories of personal information (California disclosure). In the past 12 months we have collected: identifiers (name, email address, phone number, IP address, account identifiers); customer records (business contact details, contracts, payment status); commercial information (services purchased, finance records a Customer enters); internet or network activity (logs of use of the Platform); audio, electronic, and visual information (profile photos, WhatsApp media, Local Services Ads call recordings streamed from Google); professional information (business role and company); and account login credentials (sensitive personal information). Sources, purposes, and recipients are described in Sections 4, 5, and 8. Retention is described in Section 10.
Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof of authorization and ask you to verify your identity.
13.3 Rights under Brazil's LGPD
If you are in Brazil, under Article 18 of the LGPD you have the right to: confirmation that we process your data; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of the LGPD; portability to another service provider; deletion of data processed based on consent; information about the public and private entities with which we share data; information about the possibility of not giving consent and its consequences; and withdrawal of consent. You may also file a complaint with Brazil's National Data Protection Authority (Autoridade Nacional de Proteção de Dados, "ANPD").
13.4 How to exercise your rights
Email help@nexusforyou.com with the subject "Privacy Request," and tell us what you would like us to do. We will verify your identity, generally by confirming control of the email address associated with your account, and respond within 45 days (or within 15 days for LGPD requests, when applicable), or tell you if we need more time as permitted by law.
If your request concerns Customer Data (information a business stored about you in the Platform), we will forward it to that business, which is the controller, and assist it in responding.
14. Children's privacy
The Platform is a business tool intended for adults. It is not directed to children under 13 (or under 16 in jurisdictions where that age applies), and Users must be at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
15. Do Not Track and Global Privacy Control
Because we do not track Users across third-party websites or use personal information for targeted advertising, the Platform does not change its behavior in response to "Do Not Track" browser signals. Where required by law, we treat a Global Privacy Control signal as a valid request to opt out of the sale or sharing of personal information, which we already do not engage in.
16. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the "Last updated" date above. If the changes are material, we will notify Customers and Users by email or through the Platform before the changes take effect. Your continued use of the Platform after the effective date means you accept the updated Policy.
17. Contact us
If you have questions or complaints about this Policy or our privacy practices, contact:
Ricardo Grauppe
Nexus Creative LLC (doing business as Nexus Creative Studio)
2409 Mason Wallace Dr, Charlotte, North Carolina 28212, United States
help@nexusforyou.com