Last Updated: 19 Aug 2026

This Privacy Policy explains how Waterbe.,Co.,Ltd collects, uses, and protects personal data when you use our Service.


1. Data Controller

Waterbe.,Co.,Ltd (operating the Spool platform — referred to in this policy as “Spool”, “we”, “us”, or “our”)
Registered Address: 524, Bongeunsa-ro, Gangnam-Gu, Seoul, South Korea
Email: privacy@spool.marketing


2-A. Information We Collect

We may collect:


2-B. Information We Collect


When you choose to connect a third-party advertising account (such as
Google Ads, Meta Ads, Naver Search Ads, or Kakao Ads) to Spool, we
access certain data on your behalf to provide our analytics features.

For Google Ads specifically, we access:

We request the following Google OAuth scopes:

We never modify, create, pause, or delete your Google Ads campaigns. Spool’s access is read-only for the purpose of analytics and reporting.


OAuth refresh tokens received from Google are stored encrypted at rest in our database. Tokens are used only by Spool’s backend systems to fetch your campaign data on schedule and on demand from within your
Spool dashboard.

For Meta Ads (Facebook and Instagram) specifically, we access :

We request the following Meta permissions:

For YouTube specifically, we access:

We request the following Google OAuth scopes:


3. Purpose of Processing

We process personal data to:


4. Legal Basis (GDPR)

Processing is based on:


5. Data Sharing

We may share data with:

We do not sell personal data.


6. Data Retention

We retain personal data only as long as necessary to fulfill contractual and legal obligations.


7. Data Security

We apply technical and organizational measures to protect all personal data, and we apply them specifically to the sensitive data we access through Google APIs — including YouTube channel metadata and YouTube Analytics reports — as well as the advertising data accessed through Meta, Naver, and Kakao.

Encryption in transit: All data exchanged between your browser, our servers, and third-party APIs — including all Google and YouTube API data — is encrypted using TLS 1.2 or higher (HTTPS).

Encryption at rest: OAuth tokens, refresh tokens, and connected-account credentials are protected with application-level field encryption using Fernet (AES-128 in CBC mode with HMAC-SHA256 authentication); plaintext tokens are never written to disk or to application logs. All stored data — including the YouTube channel and analytics data and the advertising performance data we retrieve on your behalf — is held in managed PostgreSQL databases (AWS RDS) with encryption at rest enabled.

Access controls: Access to the Service requires authentication through our identity provider, and all connected-account data and sensitive Google user data is scoped to your organization. Internal access to production systems and stored data is limited to authorized personnel on a need-to-know basis.

Data minimization: We request only read-only scopes and access only the data required to provide analytics and reporting features.

Retention and deletion: Sensitive Google API data is retained only as long as necessary to provide the reporting features you use. When you disconnect an account or request deletion, we delete stored OAuth tokens immediately and remove the associated stored data as described in Sections 10 and 11.


8. Your Rights

Depending on your jurisdiction, you may have rights to:

Requests may be submitted to privacy@spool.marketing.


9. International Transfers

If data is transferred outside the EEA, appropriate safeguards (such as standard contractual clauses) are applied.


10. Google API Services User Data Policy (Google API Services User Data Policy Compliance)

Spool’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data we access from Google APIs is :


11. Data Deletion

You can delete the data Spool holds from your connected advertising accounts at any time: Click “Disconnect” on the Integrations page within your Spool account. This immediately deletes the stored OAuth access tokens for that account and stops Spool from fetching any further data from it.

To request deletion of your entire Spool account and all associated data, email privacy@spool.marketing. We will process verified deletion requests within 30 days.

For Meta (Facebook and Instagram), you can also remove Spool directly from your Facebook settings at https://www.facebook.com/settings?tab=business_tools, which revokes Spool’s access to your Meta data.
For Google, you can also remove Spool at https://myaccount.google.com/permissions.
When you disconnect or request deletion, we stop fetching new data and delete the stored OAuth tokens. Historical analytics already saved in your Spool account remain available until you delete the relevant campaigns or close your Spool account.


12. Updates

We may update this Privacy Policy from time to time. Continued use of the Service constitutes acceptance of the updated policy.