Skip to content
Coeff IQ
Legal

Privacy Policy

How Coefficients Co Ltd (Coeff IQ) handles personal information across the coeffiq.com website and the app.coeffiq.com platform.

Last updated: October 2, 2026

Overview

This Privacy Policy explains how Coefficients Co Ltd ("Coefficients Co Ltd", "Coeff IQ", "we", "us", or "our") collects, uses, shares, retains, and protects personal information. Coeff IQ is a product and business offering operated by Coefficients Co Ltd, a company based in the Philippines.

This policy covers:

  • The public website at coeffiq.com, including marketing pages, the blog, documentation, and the contact and demo request forms.
  • The authenticated platform at app.coeffiq.com, where customers create workspaces, connect data sources, and view analytics.

For personal information contained in the analytics and third-party platform data that a customer connects to their workspace ("Customer Data"), Coefficients Co Ltd acts as a processor (service provider) on behalf of the customer, who is the controller. See Controller and processor roles below. Our processing of Customer Data on a customer's behalf is also addressed in our Data Processing Addendum.

You can reach us about this policy at privacy@coeffiq.com. Our full contact details are in Contact us.

Effective date: October 2, 2026. The "Last updated" date above reflects the latest revision.

Controller and Processor Roles

Information Coefficients Co Ltd controls. For information we collect for our own purposes — account and profile details, billing records, website and support communications, security and log data, and website usage — Coefficients Co Ltd is the controller and this Privacy Policy governs that processing.

Customer Data we process for a customer. When a workspace connects a third-party account or otherwise brings data into the platform, Coefficients Co Ltd processes that data only to provide the service to that customer, on their instructions. The customer is responsible for the choice of what to connect, for having the authority to connect it, and for providing any notices or obtaining any consents their own end users or data subjects require.

If you are an employee, client, or contact of a Coeff IQ customer and have a question about how your personal information appears in their workspace, please contact that customer directly. We will refer such requests to the relevant customer and support them in responding.

Information We Collect and Its Sources

We collect the following categories of information, from the sources described.

  • Account and profile information — first and last name, work email address, phone number, password (stored only as a salted hash), and the company or team name that becomes your workspace name. After registration you may add a display name, job title, timezone, and locale. Source: you, at registration and in your profile settings.
  • Workspace, client, website, member, and invitation records — the workspaces, clients, and websites you create; team members you invite (their email address and assigned role); and pending invitations. Source: you and your workspace administrators.
  • Billing information — your plan, subscription status, billing country, and invoice or transaction records. Paid subscriptions are sold through Paddle.com as merchant of record; Paddle collects and processes your payment details (including card or wallet information) and calculates tax. Coefficients Co Ltd does not receive or store complete card numbers. Source: you and Paddle.
  • Contact, demo, and support information — your name, email, company, company size, the reason for contact, and the content of your message when you submit the contact or demo request form or email us for support. Source: you.
  • Device, log, and security information — IP address, browser and device type (user-agent), pages requested, timestamps, referring pages, and security events such as sign-in attempts, rate-limit events, and audit-log entries for significant account actions (for example, a member added, a plan changed, an integration connected). Source: automatically, when you use the website or platform.
  • Cookie and browser-storage information — a first-party record of your cookie preferences, and, only if you consent, analytics or marketing identifiers. See our Cookie Policy. Source: your browser.
  • Customer Data — the metrics, dashboards, reports, and other content created in, uploaded to, or generated within a workspace. This may include personal information that the customer chooses to include. Source: the customer and its authorized users.
  • Connected third-party platform data — analytics, search, advertising, social, and learning metrics retrieved from accounts a customer authorizes. See Connected data sources. Source: the third-party provider, using access the customer grants.

How We Use Information

We use the information above to:

  • Create and administer your account, workspace, and team membership.
  • Provide, operate, maintain, secure, and improve the website and the platform, including retrieving and displaying data from the sources you connect.
  • Set up and administer paid subscriptions and trials, and send billing and transactional messages. Paid subscriptions are processed by Paddle as merchant of record — see Subprocessors.
  • Respond to contact, demo, sales, and support requests.
  • Monitor for, investigate, and prevent fraud, abuse, security incidents, and violations of our Acceptable Use Policy or Terms of Service.
  • Understand aggregate website usage to improve content and navigation (only with your consent to analytics cookies).
  • Send product, security, and service announcements, and — only if you opt in — marketing communications, which you can unsubscribe from at any time.
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information, we do not "share" it for cross-context behavioral advertising, and we do not use Customer Data or connected third-party platform data for advertising or for unrelated purposes.

Connected Data Sources

Customers connect third-party accounts to a workspace to bring reporting data into Coeff IQ. All connections are read-only: Coeff IQ retrieves reporting data and never creates, edits, publishes, or deletes content in your connected accounts.

When data is collected. On connection, Coeff IQ performs an initial import of the history the provider makes available (bounded by your plan). After that, data is synchronized automatically — hourly on paid plans, daily on the trial — and you can also trigger a manual refresh.

How it is stored and protected. OAuth access and refresh tokens, provider account identifiers, and API keys are encrypted at rest with AES-256 before they are written to our database. Retrieved data is stored in your workspace and isolated from other customers at both the application layer and the database layer. Data in transit is protected with TLS.

Disclosure. Connected data source data is disclosed only to the subprocessors listed in Subprocessors (for example, our database and hosting providers). It is never sold, never used for advertising, and never used to train generalized AI or machine-learning models.

Disconnecting and revoking. A workspace administrator can disconnect a provider from the client's Integrations page at any time. Disconnecting deletes the stored credential immediately; data already synced into your dashboards is not deleted automatically. To have already-synced provider data removed, submit a request to privacy@coeffiq.com (see Data Deletion). You can also revoke Coeff IQ's access from the provider's own security settings; Coeff IQ detects the revocation on its next sync attempt and marks the connection as needing reconnection.

What each provider family shares

  • Google Analytics 4 — authorized through a Google service account you add as a Viewer on your GA4 property. Coeff IQ reads aggregated reporting metrics and dimensions (sessions, users, engagement, conversions, revenue, traffic sources, landing pages). It does not read raw event-level data or individual user identities.
  • Google Search Console — authorized through Google OAuth with the webmasters.readonly scope. Coeff IQ reads search-performance data (clicks, impressions, click-through rate, average position) by query, page, and date.
  • YouTube — authorized through Google OAuth with the youtube.readonly and yt-analytics.readonly scopes. Coeff IQ reads channel-level analytics (views, watch time, subscriber changes) for a channel you own or manage.
  • Meta (Facebook Page Insights) — authorized through Meta OAuth. Coeff IQ reads Page-level insights (reach, impressions, engagement, follower counts) and per-post engagement for Pages you manage. It reads nothing from a personal Facebook profile.
  • Meta Ads — authorized through Meta OAuth with the ads_read scope. Coeff IQ reads ad-account performance (spend, clicks, CTR, CPM, CPC, conversion actions, ROAS), optionally broken down by campaign. It cannot create, edit, or pause campaigns.
  • Instagram — authorized through Meta OAuth, discovered via a linked Facebook Page. Coeff IQ reads account-level insights (reach, impressions, follower count) and per-media insights for an Instagram Business or Creator account. It reads nothing from a personal Instagram account.
  • TikTok — authorized through TikTok OAuth for read-only access to your basic profile information, account statistics (follower, following, likes, and video counts), and your list of public videos (up to 20 most recent per sync, with their view, like, comment, and share counts). Coeff IQ uses TikTok's Display API and does not access audience demographics or traffic sources.
  • X (Twitter) — authorized through X OAuth for read-only access to your account totals (followers, following, post count) and up to 20 of your most recent posts with their engagement counts.

Google API Services User Data Policy

Coeff IQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

  • Google user data we access: Google Analytics 4 reporting data (via a service account you authorize), Google Search Console search-performance data (webmasters.readonly), and YouTube channel data and analytics (youtube.readonly, yt-analytics.readonly).
  • How we use it: only to display the analytics, dashboards, and reports you request within your Coeff IQ workspace.
  • How we store and protect it: OAuth tokens and service-account keys are encrypted at rest with AES-256; retrieved data is tenant-isolated at the application and database layers; all transport uses TLS.
  • How we share it: only with the subprocessors listed below that host or process data to run the service. Google user data is never sold and is never used for advertising.
  • No AI or machine learning: Coeff IQ does not currently operate any AI or machine-learning feature, and does not use Google user data to develop or train machine-learning models. If Coeff IQ introduces such a feature, this Privacy Policy will be updated before it is offered.
  • Retention and deletion: Google user data is retained as described in Data retention and deletion and is deleted on disconnection of the credential and, on request, for data already synced. You can also revoke access at myaccount.google.com/permissions.

How We Share Information

We share information only in these circumstances:

  • Service providers and subprocessors that host, store, secure, or process data to operate the website and platform, under contracts that require confidentiality and appropriate safeguards. See Subprocessors.
  • Within your organization — other authorized members of your workspace can see workspace content according to their assigned role.
  • Legal and safety — to comply with law, respond to lawful requests, enforce our terms, or protect the rights, property, or safety of Coefficients Co Ltd, our customers, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy's commitments.

We do not sell personal information, and we do not disclose it for cross-context behavioral advertising.

Subprocessors

Coefficients Co Ltd engages the following subprocessors to provide the platform. Each is bound by a data processing agreement with confidentiality and security obligations. Our Data Processing Addendum describes how we notify customers of changes.

  • Cloudflare — content delivery, DNS, web application firewall, application compute (Workers and Containers), queues, and object storage. Global infrastructure; requests are processed at locations close to the user.
  • Neon — managed PostgreSQL database (primary system of record). Production region: Singapore.
  • Upstash — Redis for caching, rate limiting, and short-lived coordination. Not used as a durable system of record. Production region: Singapore.
  • Paddle (Paddle.com Market Limited and affiliates) — our merchant of record for paid subscriptions. Paddle processes information necessary for checkout, payment processing, fraud prevention, tax calculation and compliance, receipts and invoices, subscription administration, and refunds and disputes. Paddle acts as an independent controller for that payment processing under its own privacy notice and buyer terms. Global infrastructure, including the United States and the United Kingdom.
  • Amazon Web Services (AWS) — transactional email delivery (Amazon SES). Singapore region where supported.

The third-party platforms a customer independently authorizes (Google, Meta, YouTube, Instagram, TikTok, and X) are data sources chosen and controlled by the customer, not Coeff IQ subprocessors. Their handling of your data is governed by their own terms and privacy policies.

Data Retention and Deletion

  • Account information and Customer Data are retained while your account is active or as needed to provide the service.
  • The end of a free trial or the cancellation of a subscription does not automatically delete your account or Customer Data. Your access changes, but your data remains until you ask us to delete it or the account is closed.
  • Following a verified account or workspace deletion request, active Customer Data and provider-derived data are deleted or irreversibly anonymized within 30 days. Stored OAuth credentials and API keys are revoked or deleted as soon as the request is validated.
  • Deleted information may persist temporarily in encrypted, access-restricted disaster-recovery backups until those backups expire on their ordinary schedule — no later than 30 days after deletion from active systems. Backups are restored only for legitimate disaster-recovery or security purposes, and a deletion request is re-applied if a restore occurs.
  • We retain limited billing, tax, fraud-prevention, dispute, audit, and legal-compliance records for as long as applicable law requires. Records kept for these purposes, or under a legal hold or active investigation, are not reused for analytics, advertising, or ordinary product functionality.
  • Inactive accounts may be deleted after reasonable advance notice.

Your Choices and Controls

  • Account or workspace deletion — there is no self-service deletion action in the app today. Submit a request to privacy@coeffiq.com or support@coeffiq.com, or use the contact form. See Data Deletion for what is deleted, how we verify your request, and the timeframe.
  • Integration disconnection — disconnect any connected provider from the client's Integrations page. This deletes the stored credential immediately; email privacy@coeffiq.com to remove data already synced.
  • OAuth revocation — revoke Coeff IQ's access directly in the provider's account settings (for Google, at myaccount.google.com/permissions).
  • Cookie preferences — set, change, or withdraw your Analytics and Marketing cookie choices at any time using the Privacy Settings link in the site footer, or the cookie banner on your first visit; see the Cookie Policy.
  • Marketing email — opt out with the unsubscribe link in any marketing message, or by emailing support@coeffiq.com. Service and security notifications will still be sent.

Your Privacy Rights

Depending on where you are located, you may have some or all of the following rights regarding personal information for which Coefficients Co Ltd is the controller:

  • Philippines (Data Privacy Act of 2012) — the rights to be informed, to access, to object, to rectification, to erasure or blocking, to data portability, to damages, and to lodge a complaint with the National Privacy Commission.
  • European Union / United Kingdom (GDPR / UK GDPR) — the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right to complain to your supervisory authority.
  • Canada — the rights to access your personal information and to request correction, and to raise concerns with the Office of the Privacy Commissioner of Canada or a provincial regulator.
  • United States (state privacy laws) — where applicable, the rights to know, access, correct, and delete personal information, to obtain a portable copy, and to opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising.

The exact rights available to you, and any exceptions, depend on your location and the applicable law. To exercise a right, email privacy@coeffiq.com. We will acknowledge your request promptly and aim to complete a verified request within 30 days. If the law that applies to you allows a different timeframe or an extension for a complex request, we will follow that law and tell you the reason and expected completion date. We may need to verify your identity and, for a workspace-level request, your authority to act, before we proceed. You will not be discriminated against for exercising a right.

Cookies and Similar Technologies

The website uses a small number of strictly necessary cookies and browser-storage entries to function and to remember your cookie choices. We use Google Analytics 4 to understand aggregate usage; it, and any marketing technology, loads only after you opt in through the cookie banner, and remains off until then. We use Google Consent Mode in its Basic form, meaning Google Analytics is not loaded and sends no request of any kind before you consent — Google's advertising signals (ad_storage, ad_user_data, ad_personalization) are permanently denied, as this site runs no advertising campaigns through Google and uses no remarketing feature. You can change or withdraw your choice at any time using the Privacy Settings link in the site footer; withdrawing Analytics consent after granting it reloads the page and clears Google Analytics' cookies, since an already-running Google Analytics cannot be reliably stopped from script alone. Full details, including categories and named providers, are in our Cookie Policy.

Security

We use administrative, technical, and organizational measures designed to protect personal information, including:

  • Encryption in transit (TLS) and AES-256 encryption at rest for stored integration credentials.
  • Multi-tenant isolation enforced at both the application layer and the database layer (PostgreSQL row-level security).
  • Role-based access controls within the platform and least-privilege database roles.
  • Hashed password storage, rate limiting, and lockout on repeated failed sign-ins.
  • Logging of significant account activity and access to production systems.
  • Redaction of known-sensitive values from logs.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach affecting your information, we will notify you and any regulator as required by applicable law.

International Data Transfers

Coefficients Co Ltd is based in the Philippines, and our subprocessors operate in several countries. Our primary production region for persistent platform data (database, cache, and email) is Singapore (AWS ap-southeast-1) where the provider supports it. Cloudflare operates a global network and may process requests near the user. Paddle, our merchant of record, operates globally, including in the United States and the United Kingdom.

When we transfer personal information across borders and the law requires a safeguard, we use an appropriate mechanism, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another valid UK mechanism, data processing agreements with our vendors, and other measures required by applicable privacy law.

Children's Privacy

Coeff IQ is a business-to-business service intended for organizations and working professionals. It is not directed to children, and you must be at least 18 years old and able to enter into a binding contract to use it. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact privacy@coeffiq.com and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If a change is material, we will provide additional notice, such as an email to your account address or a notice in the platform, before it takes effect. Your continued use of the website or platform after an update takes effect means you accept the revised policy.

Contact Us

For privacy questions or to exercise a right, contact us at:

Coefficients Co Ltd
2nd Floor, Coefficients Building
Peridot corner Aquamarine Street, Pleasantville
Ilayang Iyam, Lucena City
Quezon Province 4301, Philippines

If you are in the EU or UK and believe we have not resolved your concern, you may contact your local data protection authority. If you are in the Philippines, you may contact the National Privacy Commission.

We use necessary cookies to run this site, and — only with your consent — Google Analytics 4 to understand aggregate usage. See our Privacy Policy and Cookie Policy.