Security · Privacy · LGPD

Your ad and CRM data protected to the standard your IT team expects

LinkedScope connects to your ad accounts and your CRM. That is why this page explains, in plain terms, what we read, what we write, what we store, for how long and how we protect every piece of data. No fine print.
Last updated: October 2026 · Operated by LinkUpers Digital Business Ltda.
Technical sheetUpdated October 2026
Hosting
AWS, us-east-1 region (USA)
In transit
HTTPS / TLS
At rest
AES-256 for the database, files and queues
Tokens and API keys
AES-256-GCM with a segregated key
User passwords
Hash bcrypt
Connections
OAuth and official provider APIs
Contact lists
Hash SHA-256 in memory
Privacy
LGPD · data never sold
The short version

The essentials in eight points

For anyone who needs to approve LinkedScope quickly. Each point is detailed in the sections below.

Official APIs, no third-party passwords

Ad platforms and CRMs connect through OAuth or the provider’s own token. We never ask for your LinkedIn, Google, Meta or CRM password.

Encrypted credentials

Access tokens, refresh tokens and API keys are encrypted with AES-256-GCM. The key is kept outside the code and the database.

Encryption throughout

HTTPS for all traffic and AES-256 at rest for the database (rotating AWS KMS keys), files and processing queues.

Every customer isolated

Every read and write is scoped to the authenticated account. A user never reaches another company’s data.

Writes only with your permission

Conversions, audiences and CRM automations only write to your accounts after you turn the feature on. CRM automations ship disabled.

Hashed contacts

Emails and phone numbers sent to ad audiences are normalized and hashed with SHA-256 in memory, and the upload file is not kept.

Revoke access anytime

Disconnect any integration in LinkedScope or directly with the provider. Future access stops immediately.

Data is never sold

We do not sell or rent your data, and we do not use it to train general-purpose AI models or for third-party advertising.
What we read and write

Every permission has a reason

Some consent screens show broad labels because a single permission covers reading, conversions and audiences. Here is, platform by platform, what LinkedScope actually does with each one.

LinkedIn Ads

LinkedIn’s official Marketing API, authorized by the ad account administrator.

Scopesr_adsr_ads_reportingrw_adsrw_conversionsrw_dmp_segmentsr_ads_leadgen_automationr_marketing_leadgen_automationr_organization_adminrw_organization_adminr_organization_socialr_basicprofile
Data or resourceAccessWhen
Accounts, campaigns, ads and performance metricsReadWhenever the account is connected
Companies and job titles reached (aggregated LinkedIn data)ReadWhenever the account is connected
Lead Gen Forms and their leadsReadWhen you use lead management
Company page posts and engagementReadWhen you use organic signals
Conversion events (lead and qualified lead)WriteOnly when you turn on conversion sending
Target account, exclusion and CRM contact audiencesWriteOnly when you create or sync an audience
Bids and per-company impression capWriteOnly with the automation turned on for the campaign

Google Ads

Google Ads API and Google Data Manager API, through Google’s official consent screen.

Scopesadwordsdatamanager
Data or resourceAccessWhen
Accounts, campaigns, ad groups and metricsReadWhenever the account is connected
Google lead form submissionsReadWhen you use lead management
Conversion actions and eventsWriteOnly when you turn on conversion sending
Customer Match listsWriteOnly when you sync contacts

Meta Ads

Meta’s official Graph API, Marketing API and Conversions API.

Scopesads_readads_managementbusiness_managementpages_show_listpages_read_engagementpages_manage_adspages_manage_metadataleads_retrieval
Data or resourceAccessWhen
Accounts, campaigns, ad sets and metricsReadWhenever the account is connected
Pages and Lead Ads leadsReadWhen you use lead management
Lead and QualifiedLead events through the Conversions APIWriteOnly when you turn on conversion sending
Custom audiencesWriteOnly when you sync contacts

CRMs

HubSpot, Salesforce, Pipedrive, RD Station CRM and Clientify, through OAuth or an official token. Other CRMs can send data by webhook.

Data or resourceAccessWhen
Deals, companies, pipelines, stages and ownersReadAlways: it is the basis of pipeline attribution
ContactsReadWhen you use CRM contacts in ad audiences
Create contacts, companies or deals from leadsWriteOnly with the automation on and write permission granted in the CRM. Off by default
Temporary date filter (Pipedrive)WriteCreated and removed within the same query, to fetch only the requested period

Prospecting tools

Apollo, Snov.io and Walead, through OAuth or the provider’s own API key.

Data or resourceAccessWhen
Campaigns, lists and sequencesReadWhen the tool is connected
Sending contacts to lists or sequencesWriteOnly when you trigger the send
The platforms you connect are data sources you choose, not LinkedScope sub-processors. Access is granted through each platform’s official flow and can be revoked at any time.
What we store

Only what the product needs to work

LinkedScope is not a permanent copy of your CRM or your ad accounts. We store what operating the service requires, and nothing more.

What we store

What we do not store

For how long

While the account is active

We keep data for as long as needed to provide the service, maintain security and meet legal and contractual obligations.

When you disconnect an integration

Future access stops immediately. Data already stored in LinkedScope stays until you request deletion, which is a separate request.

When you close the account

We delete or anonymize the data, except what the law requires us to keep, such as billing, audit and fraud-prevention records.
Data lifecycle

You are in control from start to finish

  1. 1AuthorizationYou start the connection and approve the scopes on the provider’s official screen.
  2. 2SelectionYou choose the ad accounts, the CRM and which features to turn on.
  3. 3ProcessingBackground jobs query the official APIs and build dashboards, reports and syncs.
  4. 4Revocation and deletionYou disconnect whenever you want and request deletion of what was stored.
How we protect it

Technical and organizational measures

The measures that protect your accounts, your credentials and the data that flows through LinkedScope.

Encryption

Integration credentials

Platform access

Tenant isolation

Webhooks and events

Infrastructure

Secure development

Operations

LGPD

Clear roles and guaranteed rights

LinkedScope is operated by LINKUPERS DIGITAL BUSINESS LTDA (Brazilian tax ID 50.667.466/0001-13) and follows Brazil’s General Data Protection Law (LGPD).

Your company is the controller

For contacts, leads and lists you upload or sync, the purpose and legal basis are your decision. LinkedScope acts as the processor and handles that data only to deliver the feature you requested.

LinkedScope controls the account data

For platform users’ data, such as name, email and billing details, LinkedScope is the controller, as set out in the Privacy Policy.

Data subject rights

To exercise any of these rights, use the contact form.
International transfer: platform data is stored on AWS in the us-east-1 region (Virginia, USA), under the provider’s contractual safeguards.
Sub-processors

Who processes data on our behalf

Vendors with access to customer data to operate LinkedScope. All of them work under contractual confidentiality and data protection obligations.
VendorPurposeLocation
Amazon Web ServicesHosting, database, queues, file storage and logsUSA (us-east-1)
StripeSubscription billing with international cardsUSA
AsaasSubscription billing in Brazil (boleto, Pix and card)Brazil
BrevoTransactional emails, such as account activation and password resetFrance (EU)
Relevant changes to this list are published on this page, with the update date.
For your security team

Documents and direct contact

Contracts can include confidentiality, privacy and information security clauses, depending on scope.

Privacy Policy

Data categories, purposes, retention and rights.

Terms of Use

Responsibilities, integrations, automations and acceptable use.

What we do not offer yet

We would rather be upfront about our limits than let your team find out later.
If any of these is a requirement for your company, talk to us: we assess it case by case in the contract.
Responsible disclosure

Found a vulnerability?

Let us know through the contact form with the subject “Security”. Your report goes straight to the people responsible for the product. Please do not access other customers’ data or disclose the issue before it is fixed.
FAQ

Questions IT teams usually ask

Where is the data stored?

On Amazon Web Services, in the us-east-1 region (Virginia, USA), with AES-256 encryption at rest for the database, files and queues.

No. Connections use OAuth or each provider’s official token. You approve the scopes on the LinkedIn, Google, Meta or CRM screen itself.

Because sending conversion events and syncing audiences requires writing to the platform. These actions only happen when you turn the feature on. Otherwise, access is read-only.

Not by default: the CRM is read for pipeline attribution. Contacts, companies or deals are only created if you turn on the automation and grant write permission in the CRM. It ships disabled.

Account users’ profiles, deal owners in the CRM and, when you use those features, leads and contacts. In those cases, your company is the controller and LinkedScope acts as the processor.

No. The data is used only to deliver LinkedScope to your company. We do not sell or rent it, and we do not use it to train general-purpose AI models.

Disconnect the integration in LinkedScope settings or revoke it directly with the provider. To erase what was already stored, send a deletion request through the contact form.

When you close the account, we delete or anonymize the data, except what the law requires us to keep, such as billing and audit records.

The warning is part of Google’s own app verification process. It does not mean passwords are collected or that access happens without consent: the connection is still official, revocable OAuth.

Need more detail to approve LinkedScope?

Talk to the team. We answer your IT team’s questions directly.