1. Introduction
This Privacy Policy describes how Connect Social, LLC ("Company," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, and protects information through Nucleus ("the Platform"), our internal business command center accessible at nucleus.connectsocial.co.
Nucleus is not a public-facing application. It is an internal tool used by Connect Social employees, contractors, and authorized clients with portal access. This policy applies to all authorized users of the Platform.
2. Information We Collect
2.1 Account Information
When you are invited to and access the Platform, we collect:
- Full name
- Email address
- Role and department assignment
- Profile information provided through Clerk (our authentication provider)
2.2 Business Data
Depending on your role and permissions, you may enter or access the following types of data within the Platform:
- Financial data (revenue, expenses, bank and credit card balances)
- Advertising campaign data (spend, conversions, ROAS)
- Client information and contract details
- Employee compensation and HR data
- Business development pipeline and deal information
- Invoices and reconciliation records
2.3 Usage Data
We automatically collect:
- Login timestamps and session information
- Pages and features accessed
- Actions performed within the Platform (audit trail)
- Browser type, device information, and IP address
3. Authentication and Third-Party Services
3.1 Clerk (Authentication)
We use Clerk as our authentication provider. Clerk processes your email address, name, and authentication credentials (including multi-factor authentication data) to verify your identity. Clerk's handling of your data is governed by Clerk's Privacy Policy.
3.2 Integrated Services
The Platform integrates with the following third-party services. Data flows between these services and the Platform as described:
- QuickBooks Online — Financial data including bank balances, credit card balances, and accounting records are synced into the Platform via OAuth 2.0
- Meta Marketing API — Advertising spend data and credit line information are imported for campaign tracking and ROAS calculations
- Everflow — Campaign revenue, conversion, and performance data are imported for reporting and analytics
- Google Drive — Contract documents (PDFs) are accessed for AI-powered data extraction to populate contract records
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption at rest: Sensitive data, including employee salary information, is encrypted using AES-256-GCM with dedicated encryption keys. OAuth tokens for third-party integrations are encrypted separately with their own keys.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS/HTTPS
- Access controls: Role-based access control (RBAC) with field-level enforcement ensures users can only access data appropriate to their role
- Audit logging: All create, update, and delete operations are recorded in an immutable audit log
- Multi-factor authentication: Supported and encouraged for all user accounts via Clerk
5. Data Storage
Platform data is stored on DigitalOcean managed infrastructure, including:
- PostgreSQL (managed) — Primary database for all application data
- Redis (managed) — Caching, session management, and background job queues
All infrastructure is hosted in DigitalOcean data centers with encryption at rest enabled at the infrastructure level.
6. How We Use Your Data
We use the information collected through the Platform to:
- Authenticate and authorize your access to the Platform
- Provide business intelligence, reporting, and analytics features
- Manage financial operations, invoicing, and reconciliation
- Track advertising campaign performance and return on ad spend
- Manage employee records, compensation, and HR functions
- Maintain an audit trail for compliance and security purposes
- Improve and maintain the Platform
7. Data Sharing
We do not sell your personal data to third parties.
Access to data within the Platform is restricted to authorized Connect Social personnel on a need-to-know basis, determined by their assigned role and permissions. We may share data with third parties only in the following circumstances:
- With service providers who assist in operating the Platform (as listed in Section 3), under appropriate data protection agreements
- When required by law, regulation, or legal process
- To protect the rights, property, or safety of Connect Social, its users, or others
8. Data Retention
We retain your data for as long as your account remains active and you are authorized to use the Platform. Upon termination of your access:
- Your authentication credentials are deactivated through Clerk
- Business data you entered or managed remains in the Platform as part of Connect Social's business records
- Audit log entries related to your activities are retained indefinitely for compliance purposes
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- The right to access the personal data we hold about you
- The right to request correction of inaccurate data
- The right to request deletion of your personal data, subject to legal and business retention requirements
- The right to know what personal information is collected and how it is used
To exercise any of these rights, please contact us at jake@connectsocial.co.
10. California Privacy Rights (CCPA)
While Connect Social, LLC is a Wyoming entity, we recognize that some authorized users may be California residents. If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information is collected about you
- The right to request deletion of your personal information
- The right to opt out of the sale of personal information (note: we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To submit a CCPA request, contact jake@connectsocial.co. We will respond within 45 days as required by law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the Platform following any changes constitutes acceptance of the updated policy.
12. Contact
For questions about this Privacy Policy or to make a data-related request, please contact:
Connect Social, LLC
981 Joseph E Lowery Blvd NW, Suite 108
Atlanta, GA 30318
Email: jake@connectsocial.co
© 2026 Connect Social, LLC. All rights reserved.