Legal
Privacy Policy
Last updated August 9, 2026
On The Go is an agency operating platform operated by Above The Fold. This policy explains what we collect, why, how long we keep it, and the choices you have. It covers agencies who work in our studio and the clients they serve through branded portals.
Who we are
On The Go (“On The Go”, “we”, “us”) is operated by Above The Fold, a digital agency based in India. We are the data controller for account data, and a data processor for the brand and platform data an agency brings into the product on behalf of its own clients.
For any privacy question or request, email privacy@onthego.agency.
Information we collect
Account data. Names, email addresses and passwords for agency team members and client users. Passwords are stored only as bcrypt hashes; we never hold or can recover the plaintext.
Agency and brand content. The work an agency puts into the platform: content items, captions, media links, reports, meeting notes, campaigns, tasks, leads and client requests.
Connected platform data. When an agency connects a Meta or Google account, we receive the data described in the next two sections, strictly to deliver the features that agency asked for.
Usage data. Activity records of who did what and when, used to power the audit trail inside each agency’s own studio. We do not use third-party advertising or tracking cookies on the product.
Data we access through Meta
Agencies connect their Meta accounts using Facebook Login for Business. We request only the permissions needed for the features we provide, and we use each one for a single, specific purpose:
pages_show_list— to list the Facebook Pages you manage, so you can choose which ones to link to a brand.pages_read_engagement— to read Page and post engagement metrics for the reports and analytics we show you.pages_manage_posts— to publish and schedule the posts you create and approve inside On The Go.instagram_basic— to identify the Instagram business accounts linked to your Pages and read their basic profile and media data.instagram_manage_comments— to show Instagram comments in your reputation inbox and to post the replies you write there.business_management— to discover the Pages, Instagram accounts and ad accounts held in your Business Manager, so you can select the ones a brand should use.ads_read— to read ad account performance (spend, reach, results) for the performance dashboards. This permission is read-only; we do not create, edit or spend on your campaigns.
The data we retrieve through these permissions includes Page and Instagram profile information, published posts and their engagement metrics, comments and direct messages on the assets you connect, and ad account performance figures. We use it only to operate the scheduling, publishing, reputation-management and reporting features you have asked for.
We do not sell platform data, we do not share it with any third party for their own purposes, and we do not use it to target advertising. It is used solely to render the product to the agency that connected the account and the client that agency has bound to that brand.
Data we access through Google
Where an agency connects a Google account, we request access through Google’s OAuth consent screen. We ask only for the scopes a feature needs, we use each one for a single, specific purpose, and the connection is optional and can be revoked at any time. The Google scopes we may request are:
calendar.readonly— read-only access to your Google Calendar events, to show your availability and upcoming events in the team scheduling view. We never create, edit or delete events.webmasters.readonly— read-only access to Google Search Console, to populate the SEO reporting surfaces (impressions, clicks, queries and page performance).analytics.readonly— read-only access to Google Analytics (GA4), to show traffic and engagement reporting.adwords— access to Google Ads, to read campaign performance (spend, reach, results) for the performance dashboards. We do not create, edit or spend on your campaigns.business.manage— access to your Google Business Profile, to read and manage the locations, posts and reviews you choose to link, for the local-presence and reputation features.
The data we retrieve through these scopes includes calendar event times, Search Console and Analytics reporting metrics, Google Ads performance figures, and Google Business Profile location, post and review data. It is used only to render the scheduling, reporting and local-presence features the connecting agency has asked for.
On The Go’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it or transfer it to any third party for their own purposes, and we do not let humans read it except with your consent for support, where required for security or by law, or on data that has been aggregated and anonymised.
As the platform grows we will request only the additional Google scopes a new feature requires, and we will describe any new sensitive scope in this section before it is used.
How we store and secure your data
Tokens are encrypted at rest. Access and refresh tokens from connected accounts are encrypted with AES-256-GCM before being written to our database. Encrypted token material is never returned in an API response and never rendered in any interface. Where a shorter-lived token is derived from a stored one, it is held in memory for the life of the process and never written to disk.
Every agency is a separate tenant. Users see only their own agency’s brands, team, content and connections, and each client sees only the brand they are bound to. That boundary is enforced on the server on every request, not in the browser.
Support access is consented and time-boxed. Our staff cannot enter an agency’s workspace to help without that agency granting access, either with a single-use code they generate or by approving a request in the product. Access expires on its own, can be revoked mid-session, and every such session is recorded.
Connections are held at the agency level. Only members of the agency that created a connection can view, manage or disconnect it. Clients never see or manage provider connections.
How long we keep it
Account and brand data is retained for as long as the account is active, and is deleted when the account is closed or on a verified deletion request. Tokens for a connected account are deleted immediately when that account is disconnected. Backups are retained on a rolling basis and age out on their normal rotation.
Who we share it with
We do not sell personal data. We share data only with the infrastructure providers needed to run the service — our hosting provider, and the platforms you have chosen to connect (Meta, Google) when we make a request on your behalf. We disclose data to authorities only where we are legally required to.
Your rights and choices
You may request access to, correction of, or deletion of your personal data at any time by emailing privacy@onthego.agency. Agency administrators can also correct or remove team and client users directly in the studio.
You can disconnect any Meta or Google account at any time from Settings › Connections in the studio, which deletes the stored tokens for that connection. Full instructions, including how to request deletion of an account and its data, are on our Data Deletion page.
Changes to this policy
We may update this policy as the product changes. The “last updated” date at the top of this page always reflects the current version.