Privacy policy
Mississippi River Marketing LLC. Effective October 7, 2026.
The short version
- We collect what we need to answer you, run your marketing and show you your results. We do not sell personal information, and we never sell, rent or trade data from your connected accounts.
- In Bridge, you choose which accounts to connect. Each platform shows its own permission screen, and you can disconnect any of them at any time.
- Data from Google, Meta, TikTok, Microsoft and other platforms is used only to show you your reports and to carry out actions you confirm. It is never used for advertising, never used to train AI models and never shared with other clients.
- Report history from Google Analytics, Search Console, Bing and Instagram is kept while your workspace is open, so you can compare periods. Google Business Profile report copies are deleted after 30 days. Facebook Page statistics are read live and not saved at all.
- You can ask us for a copy of your data or to delete it. We finish deletions within 30 days, and within 7 days for YouTube data.
Who we are and what this policy covers
Mississippi River Marketing LLC (“MRM”, “we”, “us”) is a marketing company based in Southeast Missouri. This policy explains how we handle information on our website at mississippirivermarketing.com, in Bridge, our client reporting and publishing portal at portal.mississippirivermarketing.com, and in the marketing work we do for clients.
Bridge and its connections to Google, YouTube, Meta (Facebook and Instagram), TikTok and Microsoft (Bing) are operated by MRM. Questions about this policy go to mississippirivermarketing@gmail.com or 573-621-4337.
If you are a customer of one of our clients, that business's own privacy policy explains how it handles your information. We work on its behalf and follow its instructions.
Information from our website
Our website is hosted by Bluehost (Newfold Digital). Like every web host, it processes technical details needed to deliver and protect the site: your IP address, browser and device type, the pages requested and the time of each request. These server logs follow the host's own retention schedule.
We use Google Analytics 4 to understand which pages are read, but only after you allow it in “Privacy choices”, which is linked on every page. Until you choose, no analytics code runs. If your browser sends a Global Privacy Control signal, analytics stays off and we treat the signal as your choice.
- When allowed, Google Analytics uses cookies (named _ga and _ga_<ID>) and collects page addresses and titles, how you arrived, approximate location (city level) and device and browser information.
- We do not send names, email addresses, phone numbers, form entries or account identifiers to Google Analytics.
- Google signals, advertising features, ad personalization and enhanced measurement are turned off. There are no advertising pixels on our site.
- Detailed analytics data is kept for two months. Your choice is remembered in your browser for up to 90 days; analytics cookies expire after 90 days.
- You can change or withdraw your choice at any time in Privacy choices. Withdrawing stops future collection and removes the analytics cookies; it does not erase what Google already received.
Google explains how it handles this data in How Google uses information from sites or apps that use our services. You can also install the Google Analytics opt-out browser add-on.
Do Not Track: browsers' Do Not Track setting has no agreed meaning, so our site does not respond to it. We do honor Global Privacy Control, as described above. We do not let third parties track you across other websites from our site.
When you contact us
When you call, email or use a form on our website, we receive what you choose to send: usually your name, business name, email, phone number, website and what you need. Form entries are delivered to our business email inbox and handled like an email. Our business email is provided by Google (Gmail).
We use this information to reply, to prepare a consultation or quote and to do the work you hire us for. We do not add you to a newsletter or sell your details. Please do not send passwords, payment card numbers or other sensitive records in a first message.
When we work for you
To build and manage websites, listings, social media, content and ads, clients give us materials and access to accounts they own. We use that access only for the work agreed with the client and keep it within the people working on that account.
Where we manage a Google Business Profile for you: the profile is a free Google service and stays yours. We need your written authorization to manage it, you can remove our access at any time, and Google's notice Working with a third party explains your rights. Any fee we charge is for our work, not for the profile.
Where we manage advertising for you, platform spend and our fees are shown separately, and you can ask for your account's cost and performance data at any time.
Bridge, our client portal
Bridge is available only to people invited by MRM or by a client workspace. It shows each business its own website, search, local and social performance, and lets authorized people plan and approve posts. These are the kinds of information Bridge handles:
- Account details: your name, email address, role, the workspaces you belong to and, for MRM staff, a two-step verification factor. Passwords are handled by our authentication provider (Supabase) and are never visible to us.
- Security records: sign-ins, connection changes, approvals and other important actions, with the time and the person who acted. Our authentication provider records sign-in events, which can include IP address and browser details.
- Connected-platform data: described in the next section, platform by platform.
- Content you upload: photos, videos, file names, captions, planned dates and approval decisions, stored privately for your workspace.
- Email preferences and delivery records for Bridge emails (invitations, sign-in help, approval requests and the weekly summary).
Bridge uses only essential cookies: a secure sign-in session cookie and short-lived cookies that protect a connection while you are on a platform's permission screen. Bridge has no analytics or advertising trackers.
Bridge's written summaries are produced by fixed rules from your report values. Your data is not sent to an AI service to write them.
Connected platforms in Bridge
Nothing is connected automatically. An authorized person in your workspace chooses a platform, signs in on that platform's own page and approves the permissions listed below. We never see or store your platform passwords. Bridge stores the access credentials each platform issues, encrypted with AES-256-GCM, and uses them only from our server.
| Platform | Permission requested | What Bridge reads or does | What is stored |
|---|---|---|---|
| Google Analytics | analytics.readonly (read only) | Lists the properties you can access and reads totals for visits, people, views, engagement, tracked key events, traffic channels, landing pages, device types and the number of people active in the last 30 minutes. These are totals; Google does not give Bridge data about individual visitors. | Report totals, kept while the workspace is open so you can compare periods. Live “active right now” counts are deleted within 2 days. |
| Google Search Console | webmasters.readonly (read only) | Lists your verified sites and reads search clicks, impressions, click-through rate, average position, and the top search terms, pages, countries and devices. | Report totals, kept while the workspace is open so you can compare periods. |
| Google Business Profile | business.manage | Lists your business locations and reads performance (calls, direction requests, website clicks, search and Maps views). When an authorized person reviews and confirms it, Bridge sends business-detail changes or a Google post to the location shown. Google requires this one permission for both reading and editing; Bridge never edits on its own. | Report copies for no more than 30 days, then deleted; a record of each change you submitted and its status. |
| YouTube | youtube.readonly, youtube.upload | Identifies the channel you authorized. When you confirm an upload, sends the selected video with the title, description, visibility and audience setting you chose. | Channel name and ID, re-checked with YouTube every 7 days; each upload's status and YouTube video ID. |
| Facebook Pages | public_profile, pages_show_list, pages_read_engagement, read_insights | Confirms who authorized the connection, lists the Pages they manage, and reads the chosen Page's content views, post engagements and follows. | The Page name and ID you selected. Page statistics are read live each time and not saved. |
| Instagram (professional accounts) | instagram_basic, instagram_manage_insights, with the Page permissions above | Reads the linked account's username, follower count, number of posts and accounts reached. | Account name and ID; report totals, kept while the workspace is open. |
| TikTok | user.info.basic, video.upload; video.publish only if direct posting is enabled | Reads your TikTok display name and an app-specific account ID. When you choose Send to TikTok, the video you selected goes to your TikTok inbox as a draft for you to finish in TikTok. Direct posting, when enabled, sends the media, caption, privacy and interaction settings you chose, after you confirm. | Display name and app-specific ID; each transfer's status, so nothing is sent twice. |
| Bing Webmaster Tools (Microsoft) | webmaster.read (read only) | Lists your verified sites and reads Bing search clicks and impressions. It does not change Bing listings. | Report totals, kept while the workspace is open so you can compare periods. |
Bridge connects one platform at a time. Disconnecting a platform in Bridge deletes its stored credentials straight away and stops collection. Report history already collected stays in your workspace until you ask us to delete it or the workspace closes; Google Business Profile copies are still deleted 30 days after they were fetched.
Google, including YouTube
Bridge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- We use Google data only to show you your reports and to carry out actions you confirm in Bridge.
- We do not sell it, use it for advertising or retargeting, use it to judge credit or lending, or transfer it to data brokers or information resellers.
- We do not use it to train AI or machine-learning models, and we do not build databases from it beyond what Bridge needs to show your reports.
- People at MRM see your Google data only with your agreement as part of the services you hired us for (for example, reviewing your reports with you), when needed for security or to investigate abuse, or to comply with the law.
YouTube features in Bridge use YouTube API Services. By using them you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
You can remove Bridge's access to your Google account, including YouTube, at any time on Google's security settings page, as well as by disconnecting in Bridge. If you disconnect YouTube in Bridge, the stored credentials are deleted straight away and the channel details within 7 days. If you remove access on Google's page instead, Bridge finds out at its weekly check of each channel and deletes the credentials and channel details then. Either way, channel details Bridge can no longer confirm with YouTube are never kept longer than 30 days.
When Bridge changes your Google Business Profile at your request, the person who confirmed it sees the result in Bridge, and we notify the workspace by email within 48 hours, separately from any notice Google sends.
Meta (Facebook and Instagram)
We process Meta Platform Data only as described in this policy: to show your Page and Instagram performance in Bridge. We do not sell or license it, use it for advertising, profiling or eligibility decisions, or share it with anyone except the service providers listed below, who act only for us, or where the law requires.
You can request deletion of your Meta data at any time by following our data deletion instructions, and you can remove Bridge from your account in Facebook's Settings under Business integrations. Data deletion requests are open to everyone who has used Bridge, not only clients.
TikTok
Bridge uses TikTok's Login Kit and Content Posting API so you can send your own videos to your own TikTok account. Nothing is sent until you choose the video and confirm. By posting you agree to TikTok's Music Usage Confirmation. We do not sell TikTok data or use it for cross-context behavioral advertising. You can remove Bridge's access in TikTok's settings under Security and permissions, or by disconnecting in Bridge.
Microsoft (Bing Webmaster Tools)
Bing data is used only to show your search performance in Bridge. It is never used for advertising or marketing. You can remove Bridge's access at account.live.com/consent/Manage or by disconnecting in Bridge.
Platforms we plan to add
We list these now so you know what may come. None of them is active, and Bridge does not request any of their permissions today. Before one is switched on we will update this policy with exactly what it reads, why and for how long, and each one will ask for your permission separately on the platform's own screen.
| Platform | What it would do | Rules it would follow |
|---|---|---|
| Google Ads | Read-only campaign reporting (clicks, impressions, cost, conversions). | Google Ads Developer Policies and the Google API Services User Data Policy: Google Ads data shown separately from other platforms, costs shown without our fees, nothing shared without your written consent, access removed within 3 business days of disconnecting. |
| Meta publishing and ads reporting | Publish posts you approve to your Page or Instagram account; read ad results for your own ad accounts. | Meta Platform Terms: publish only what you confirm; ad data used only to measure your own campaigns, never for targeting. |
| Company page statistics and posting posts you approve. | LinkedIn API terms, including their storage limits: page statistics kept no longer than LinkedIn allows, and your data deleted within 10 days of leaving. | |
| Pin performance and scheduling Pins you choose. | Pinterest Developer Guidelines: no storage beyond what they allow, no AI training, no sharing. | |
| X (Twitter) | Post performance and posting what you confirm. | X Developer Agreement: explicit consent for each post, deletions honored within 24 hours. |
| Yelp | Your business page's metrics, through a Yelp partner arrangement. | Yelp's partner and display terms: metrics shown only to your workspace and deleted when you leave. |
| Nextdoor and Apple Business | Business page information and performance. | Each platform's partner terms, once approved. |
| Microsoft Advertising | Read-only reporting for Bing ads. | Microsoft's advertising and API terms: no use of data for other advertising. |
| Email marketing (such as Mailchimp) | Campaign results (sends, opens, clicks). | The provider's API terms: no access to your subscriber list beyond what reporting needs, deletion on request. |
| Call tracking (such as CallRail) | Counts of calls by source. | The provider's terms and call-recording laws; caller details would not be stored in Bridge. |
How we use information, and what we never do
- To reply to you and provide the services and Bridge features you ask for.
- To keep accounts and data secure, prevent misuse and fix problems.
- To send service emails: invitations, sign-in help, approval requests and decisions, and a weekly summary you can turn off with the link in each email or in Bridge settings.
- To meet legal, tax and accounting obligations.
We never sell personal information or connected-platform data. We never use connected-platform data for advertising, to build profiles of people, or to train AI or machine-learning models. We never show one client's data to another client.
How long we keep information
| Information | How long |
|---|---|
| Platform credentials (access and refresh tokens) | Until you disconnect, the platform revokes access or the workspace closes. Deleted straight away on disconnect. |
| Google Analytics, Search Console, Bing and Instagram report history | While the workspace is open, so you can compare periods. Deleted when you ask or when the workspace closes. |
| Google Business Profile report copies | No more than 30 days after they were fetched, then deleted. Bridge fetches fresh data from Google when you open the report. |
| Facebook Page statistics | Not stored; read live each time. |
| Live “active right now” counts | Shown for a few minutes; the saved count is deleted within 2 days. |
| YouTube channel details | Re-checked with YouTube every 7 days. Deleted within 7 days of disconnecting in Bridge, at the next weekly check after access is removed at Google, and never kept unconfirmed for more than 30 days. |
| Uploaded photos and videos | Until you move them to Trash. Trash can be restored for 7 days, then the file and captions are deleted. Unfinished uploads are deleted after 48 hours. |
| Records of posts, uploads and listing changes you made | While the workspace is open; deleted when it closes. |
| Accounts and security records | While the account is active, then up to 12 months for security and legal needs. |
| Emails and business records about client work | As long as needed for the work and for tax and legal records. |
| Backups | Our database provider keeps short rolling backups; deleted data leaves them as they expire. |
Your choices and requests
- Disconnect a platform: open Connections in Bridge and choose Disconnect, or remove Bridge on the platform's own settings page (links in the platform sections above).
- Delete data: follow the data deletion instructions or email us with “Data deletion” in the subject. We confirm who you are and that you have authority over the workspace, then finish within 30 days (7 days for YouTube data) and tell you what was deleted and anything we must keep by law.
- Get a copy: ask and we will send the data Bridge stores for your workspace in a common format (CSV or JSON) within 30 days.
- Correct information or stop emails: update it in Bridge, use the link in any Bridge email, or ask us.
- Website analytics: change your choice in Privacy choices on any page of our website.
Deleting data in Bridge does not delete what is held by the platforms themselves (for example, a video already on YouTube). Manage that on the platform.
How we protect information
- All connections to our website and Bridge use HTTPS.
- Platform credentials are encrypted before storage, with the key kept separately from the database, and are never sent to your browser.
- Database access rules keep each workspace's data to the people allowed to see it. MRM staff accounts require two-step verification.
- Uploaded files are stored privately, and preview links expire after five minutes.
No system is perfectly secure. If a security incident affects your information, we will tell you and the affected platforms as the law and their terms require. To report a security problem, email us with “Security” in the subject.
Children, location and your state's laws
Our website and Bridge are for businesses and adults. They are not directed to children under 13, and we do not knowingly collect children's information. If you believe a child has sent us information, contact us and we will delete it.
We serve businesses in the United States and store information in the United States. Some states give residents rights to access, correct or delete personal information. Wherever you live, you can use the requests above, and we will not treat you differently for using them.
Changes and contact
When we change this policy we update the date at the top. If a change affects how we use connected-platform data, we will tell Bridge users by email or in Bridge before it takes effect, and ask for permission again where a platform requires it.
Mississippi River Marketing LLC · mississippirivermarketing@gmail.com · 573-621-4337