Nexus Hub

Nexus Hub Privacy Policy

Effective date: September 29, 2026
Last updated: September 29, 2026

This Privacy Policy explains how Nexus Creative LLC, a North Carolina limited liability company doing business as Nexus Creative Studio ("Nexus," "we," "us," or "our"), collects, uses, shares, and protects information in connection with Nexus Hub (the "Platform"), available at hub.nexusforyou.com, and the related websites, emails, and support we provide (together, the "Services").

Please read this Policy together with our Terms of Service and our Data Deletion Instructions.

1. Who we are and how to contact us

Ricardo Grauppe is also the person responsible for handling data protection requests, including requests under Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, "LGPD"), acting as our data protection contact (encarregado).

2. Scope of this Policy

This Policy applies to:

  1. People who create an account on or use the Platform ("Users"), including owners, managers, and agents of a business that uses the Platform, and members of the Nexus team.
  2. Businesses that use the Platform ("Customers").
  3. Visitors to our Platform pages, including sign-in pages and shared onboarding or file-sharing links.
  4. Information we receive from third-party services that a Customer or User chooses to connect, such as Google, Meta (Facebook, Instagram, Threads), and WhatsApp.

This Policy does not cover the privacy practices of third-party services you connect to the Platform. Their own privacy policies govern how they handle your information.

3. Our role: controller and processor

The Platform is a business tool. Different rules apply depending on whose information it is.

When Nexus is the controller. We decide how and why information is processed for account data about Users (for example, your name, email address, and sign-in information), for information about Customers as our business clients, for security and usage logs, and for communications you send to us. For this information, Nexus is the "controller" (or "business" under California law).

When Nexus is a processor or service provider. Customers use the Platform to store and manage information about their own customers, leads, prospects, and contacts, and to exchange messages with them ("Customer Data"). This includes leads and conversations from Google Local Services Ads, Google Ads, Meta lead forms, Facebook Pages, Instagram, and WhatsApp, as well as contacts, notes, tasks, files, contracts, and financial records the Customer adds. For Customer Data, the Customer is the controller and Nexus acts only as a "processor" or "service provider" on the Customer's behalf and under the Customer's instructions, as described in our Terms of Service and any agreement we have with the Customer.

If you are a person whose information was entered into the Platform by a business (for example, you requested a quote from a business that uses the Platform), please contact that business first about your information. If you contact us, we will forward your request to the relevant Customer and help them respond, as described in Section 13.

Agency services. Some Customers also hire Nexus to provide marketing agency services. In that case, authorized Nexus team members may access the Customer's workspace and connected accounts to perform those services, on the Customer's behalf and within the access the Customer grants.

4. Information we collect

4.1 Account and profile information

When a User is invited, signs up, or signs in, we collect:

4.2 Customer business information

For Customers, we collect business details such as company name and legal name, contact names, business email and phone numbers, business address and service area, services offered, and the account identifiers the Customer links to the Platform (for example, a Google Ads customer ID or a Google Analytics property ID).

When a Customer completes our onboarding form, it may also provide its entity type, federal Employer Identification Number (optional), average ticket value, whether it has access to its digital accounts (the form asks only whether you have access, never for passwords), brand and tone-of-voice preferences, competitors and brands it admires, photos of completed projects, and logos.

4.3 Information from services you connect

Connecting a third-party service is always optional and is done by the Customer or User through an authorization screen of that service. We only receive the information that the service shares under the permissions you approve.

Google. If you connect a Google account, we may receive, depending on the permissions you grant:

Meta (Facebook, Instagram, Threads). Meta integrations are connected through "Facebook Login for Business." If you connect them, we may receive, depending on the permissions and assets you choose:

WhatsApp. A Customer may link its WhatsApp number to the Platform by scanning a QR code in the WhatsApp app, the same way you add a "linked device." Once linked, the Platform receives and stores, for that business number: messages sent and received (text, photos, videos, audio, documents, and other media), message status (sent, delivered, read), reactions, edits and deletions, the contact list and group information available to the linked device, contacts' WhatsApp profile names and profile photos, and presence information such as "online" or "typing" for open conversations. See Section 7.

4.4 Content Customers and Users add

Users can add content such as contacts, leads and prospects, sales pipeline stages, tasks and comments, notes and internal documents, meeting notes and transcripts, quick replies and automated message rules, files and videos stored in a Customer's file area ("Drive"), contracts and electronic signature information (signer names, email addresses, signing status, and audit events), finance entries (amounts in U.S. dollars, descriptions, categories, and payment status), and posts and reactions in the Platform's feed. Customers may also upload files through a shared upload link we provide to them.

4.5 Usage, device, and log information

When you use the Platform, our systems and hosting providers automatically record technical information such as IP address, browser type, device information, pages and API endpoints requested, date and time, and error logs. We use this information to operate, secure, and troubleshoot the Platform, including to apply rate limits against abuse. We also record certain actions for accountability, for example which User submitted feedback on or sent a message to a Local Services Ads lead.

4.6 Cookies and similar technologies

The Platform does not use advertising cookies or third-party analytics trackers. We use your browser's local storage for things the Platform needs to work:

Some third-party components load when you use certain features and may receive your IP address or set their own technical cookies: Google Fonts (typography), Google's sign-in and consent pages, the Bunny.net video player when you watch a video, and the OpenStreetMap Nominatim service when you search for an address on the onboarding form. You can clear local storage and cookies through your browser settings at any time, but you will be signed out.

4.7 Communications

If you contact us by email or through the Platform, we keep your message, contact details, and our reply. We also send transactional emails, such as invitations, password reset emails, and signature requests.

5. How we use information

We use information to:

  1. Provide, operate, and maintain the Platform and the features you choose to use, including displaying reports, leads, conversations, and calendars; sending messages and publishing content you create; and storing your files.
  2. Create and manage accounts, authenticate Users, and enforce the roles and permissions a Customer sets.
  3. Provide agency services to Customers that have engaged Nexus for them.
  4. Send transactional and service communications, such as sign-in and password reset emails, notices about changes to the Services, and responses to support requests.
  5. Secure the Platform: detect, prevent, and respond to fraud, abuse, security incidents, and technical issues.
  6. Comply with law, respond to lawful requests, and enforce our Terms of Service.
  7. Improve the Platform's reliability and usability, using technical logs and feedback. We do not use Customer Data, Google user data, or Meta Platform Data for this purpose beyond what is necessary to provide the features you use.

We do not use Customer Data, data received from Google APIs, or Meta Platform Data for advertising, to build profiles of individuals, or to train generalized artificial intelligence or machine learning models. The Platform does not currently send Customer Data to any third-party artificial intelligence service. If we introduce such a feature, we will update this Policy before it is enabled and it will never use Google user data or Meta Platform Data in a way that violates the policies described in Sections 6 and 7.

6. Google user data and the Limited Use commitment

Nexus Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  1. Limited to user-facing features. We use Google user data only to provide and improve the user-facing features you see in the Platform: signing in, showing and managing your calendar events, showing Google Ads, Local Services Ads, and Google Analytics reports, displaying and acting on Local Services Ads leads, and managing your Google Business Profile.
  2. No transfer except as allowed. We do not transfer Google user data to others except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  3. No advertising use. We do not use or transfer Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
  4. No sale. We do not sell Google user data.
  5. No AI model training. We do not use Google user data, including data obtained through Google Workspace APIs such as Google Calendar, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
  6. Limited human access. No person reads Google user data unless: (a) we have your affirmative agreement for specific data (for example, a Customer has engaged Nexus to manage its Google Ads or Local Services Ads account, and authorized Nexus team members view that account's leads to perform the service, or you ask us for support on a specific item); (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymized and used for internal operations in accordance with applicable law.

How Google tokens are protected. When you connect Google, our server stores a refresh token encrypted with AES-256-GCM. Your browser never receives this refresh token. For calendar features, your browser receives only a short-lived access token limited to the calendar permission, which cannot be used for Google Ads or Google Analytics.

Revoking Google access. You can disconnect Google at any time in the Platform under Settings > Connections. When you do, we revoke the token with Google and delete it from our database. You can also remove access directly in your Google Account at myaccount.google.com/permissions.

Local Services Ads call recordings are streamed from Google to your browser when you choose to play them. We do not keep a copy of call recordings on our servers.

7. Meta Platform Data and WhatsApp data

7.1 Meta Platform Data (Facebook, Instagram, Threads)

"Meta Platform Data" means information we receive through Meta's APIs when a Customer connects its Meta business assets. For Meta Platform Data:

  1. We use it only to provide the features the Customer enabled, such as managing ads, receiving ad leads, replying to messages and comments, and publishing content, and only in accordance with the Meta Platform Terms and Developer Policies.
  2. We do not sell, license, or purchase Meta Platform Data.
  3. We do not use Meta Platform Data for advertising targeting, to build or augment user profiles, for surveillance, or to make eligibility decisions about people (for example, housing, employment, insurance, or credit).
  4. We do not transfer Meta Platform Data to third parties except to our service providers that help us operate the Platform (Section 8), as required by law, or as the Customer directs within the features of the Platform.
  5. We delete Meta Platform Data when it is no longer needed to provide the features the Customer enabled, when a Customer disconnects the integration, when we receive a valid deletion request, or when Meta requires it, as described in Section 10 and in our Data Deletion Instructions.

7.2 WhatsApp connection

The WhatsApp connection works as a linked device on the Customer's own WhatsApp account, which the Customer links by scanning a QR code. It runs on WhatsApp gateway software hosted by Nexus on infrastructure we control. It is not a WhatsApp Business Platform (Cloud API) integration and is not provided, sponsored, or endorsed by WhatsApp or Meta.

We use WhatsApp data only to show the Customer's conversations in the Platform's inbox, send the messages and media the Customer's Users write, run the automated replies the Customer configures (such as welcome and away messages), and link conversations to the Customer's contacts. Each Customer's WhatsApp data is kept separate from every other Customer's data. The Customer can unlink the device at any time from the Platform or from WhatsApp (Settings > Linked devices).

7.3 Conversion data sent back to advertising platforms (optional feature)

The Platform may offer a feature that, when a Customer enables it, reports back to Google Ads or Meta (through Meta's Conversions API) which of the Customer's leads became qualified leads or customers, and the value of the sale in U.S. dollars. This helps the Customer's advertising campaigns learn which ads produce real customers. When enabled, the Platform may send click identifiers (such as Google's gclid, gbraid, or wbraid, and Meta's fbclid, fbc, or fbp values), the lead identifier assigned by the advertising platform, event names and times, the value of the sale, and email addresses and phone numbers that are hashed with SHA-256 before they are sent. The Platform may also submit lead quality ratings to Google Local Services Ads.

This feature is off unless the Customer turns it on. The Customer decides whether to use it and is responsible for providing any notices and obtaining any consents its own customers are entitled to under applicable law. Nexus sends this information only on the Customer's instructions, as its service provider.

8. How we share information

We share information only as described below.

8.1 Service providers (subprocessors)

We use the following providers to host and operate the Platform. They may process personal information only to provide their services to us, under contractual obligations of confidentiality and security.

Provider Purpose Location of processing
Supabase, Inc. Database, user authentication, and file storage for Platform files (profile photos and WhatsApp media) Canada (Supabase region ca-central-1)
Vercel Inc. Hosting of the Platform's web application and server functions United States
Cloudflare, Inc. Domain name system (DNS), secure file transfer proxy, secure tunnel and access control for self-hosted services Global network
BunnyWay d.o.o. (Bunny.net) Storage and delivery of Customer files and videos in the Drive Bunny.net data centers selected for our storage
Resend Delivery of transactional emails, such as password reset emails United States
Autentique Electronic signature of contracts: receives the contract document and signers' names and email addresses Brazil
Google LLC (Google Workspace) Our business email, used when you contact us United States
Tailscale Inc. Encrypted private network connecting our own servers Global network

In addition, self-hosted services (including the WhatsApp gateway) run on servers controlled by Nexus.

8.2 Third-party services you connect

When you connect Google, Meta, or WhatsApp, information flows between the Platform and that service as you direct. For example, when you send a message to a lead, publish a post, submit lead feedback, or enable conversion reporting, we transmit the content to that service. Their use of the information is governed by their own terms and privacy policies:

8.3 Within a Customer's workspace

Information in a workspace is visible to the Customer's Users according to the roles the Customer sets. For example, an agent may see only the conversations and leads assigned to them. Authorized Nexus team members may access a Customer's workspace to provide support or agency services.

8.4 Legal reasons and protection

We may disclose information if we believe in good faith that it is required by law, subpoena, or other legal process; necessary to protect the rights, property, or safety of Nexus, our Users, or others; or necessary to investigate fraud, security issues, or violations of our Terms of Service.

8.5 Business transfers

If Nexus is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a policy that is at least as protective, and with notice to you.

8.6 No sale or sharing for cross-context behavioral advertising

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state laws. We have not done so in the preceding 12 months.

9. Legal bases for processing

Where laws such as the LGPD or similar laws require a legal basis, we rely on:

For Customer Data, the Customer as controller is responsible for having a valid legal basis, and for giving any required notices and obtaining any required consents, for the information it collects and processes through the Platform.

10. Data retention

We keep information only as long as necessary for the purposes described in this Policy:

11. Security

We use administrative, technical, and physical safeguards appropriate to the nature of the information, including:

Some links are designed to work without signing in, such as a Customer's onboarding form link, a shared upload link, and the address of a profile photo. These use long, random addresses, but anyone who has the link can open it, so please keep them private.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify affected Customers, Users, and authorities as required by law.

12. International data transfers

Nexus is based in the United States. The Platform is used by people in the United States and in Brazil, among other places. Information is processed in the United States and in Canada (where our main database and platform file storage are hosted), and may be processed in other countries where our service providers operate (see Section 8.1). These countries may have data protection laws that differ from those in your country.

When we transfer personal information from Brazil or other jurisdictions with transfer rules, we rely on mechanisms permitted by applicable law, such as contractual commitments with our service providers, the performance of a contract with you, or your consent.

13. Your rights and choices

13.1 Rights available to everyone

Regardless of where you live, you can:

13.2 U.S. state privacy rights (including California)

Depending on your state of residence (for example, California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws), and to the extent those laws apply to Nexus, you may have the right to:

  1. Know what personal information we collect, use, and disclose, including the categories and specific pieces of personal information.
  2. Access and receive a portable copy of your personal information.
  3. Correct inaccurate personal information.
  4. Delete personal information, subject to legal exceptions.
  5. Opt out of the sale or sharing of personal information for cross-context behavioral advertising, targeted advertising, and certain profiling. We do not sell or share personal information for these purposes.
  6. Limit the use of sensitive personal information. We use sensitive personal information (such as account login credentials) only for purposes permitted by law, such as providing the Services and security.
  7. Not be discriminated against for exercising these rights.
  8. Appeal our decision on your request, by replying to our decision and explaining why. If we deny the appeal, you may contact your state Attorney General.

Categories of personal information (California disclosure). In the past 12 months we have collected: identifiers (name, email address, phone number, IP address, account identifiers); customer records (business contact details, contracts, payment status); commercial information (services purchased, finance records a Customer enters); internet or network activity (logs of use of the Platform); audio, electronic, and visual information (profile photos, WhatsApp media, Local Services Ads call recordings streamed from Google); professional information (business role and company); and account login credentials (sensitive personal information). Sources, purposes, and recipients are described in Sections 4, 5, and 8. Retention is described in Section 10.

Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof of authorization and ask you to verify your identity.

13.3 Rights under Brazil's LGPD

If you are in Brazil, under Article 18 of the LGPD you have the right to: confirmation that we process your data; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of the LGPD; portability to another service provider; deletion of data processed based on consent; information about the public and private entities with which we share data; information about the possibility of not giving consent and its consequences; and withdrawal of consent. You may also file a complaint with Brazil's National Data Protection Authority (Autoridade Nacional de Proteção de Dados, "ANPD").

13.4 How to exercise your rights

Email help@nexusforyou.com with the subject "Privacy Request," and tell us what you would like us to do. We will verify your identity, generally by confirming control of the email address associated with your account, and respond within 45 days (or within 15 days for LGPD requests, when applicable), or tell you if we need more time as permitted by law.

If your request concerns Customer Data (information a business stored about you in the Platform), we will forward it to that business, which is the controller, and assist it in responding.

14. Children's privacy

The Platform is a business tool intended for adults. It is not directed to children under 13 (or under 16 in jurisdictions where that age applies), and Users must be at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

15. Do Not Track and Global Privacy Control

Because we do not track Users across third-party websites or use personal information for targeted advertising, the Platform does not change its behavior in response to "Do Not Track" browser signals. Where required by law, we treat a Global Privacy Control signal as a valid request to opt out of the sale or sharing of personal information, which we already do not engage in.

16. Changes to this Policy

We may update this Policy from time to time. When we do, we will change the "Last updated" date above. If the changes are material, we will notify Customers and Users by email or through the Platform before the changes take effect. Your continued use of the Platform after the effective date means you accept the updated Policy.

17. Contact us

If you have questions or complaints about this Policy or our privacy practices, contact:

Ricardo Grauppe
Nexus Creative LLC (doing business as Nexus Creative Studio)
2409 Mason Wallace Dr, Charlotte, North Carolina 28212, United States
help@nexusforyou.com