Privacy Policy
Last updated: October 1, 2026
1. Who we are
Atribu (“we,” “us,” or “our”) operates a multi-tenant analytics platform that merges advertising spend with real business outcomes for performance agencies and brands. This Privacy Policy explains how we collect, use, store, and share information when you use our website, application, and related services (collectively, the “Service”).
2. Information we collect
Account information
When you create an account we collect your name, email address, and password. If you are invited to a workspace we also record the workspace and profile memberships associated with your account.
Workspace and profile data
To deliver the Service we process data you connect through third-party integrations, including but not limited to:
- Advertising platforms (e.g., Meta Ads) — campaign structure, spend, and delivery metrics.
- CRM and pipeline tools (e.g., GoHighLevel) — contacts, opportunity stages, and attribution fields.
- E-commerce platforms (e.g., Shopify) — orders, revenue, and customer history.
- Payment processors (e.g., Stripe) — payment event data related to cash collected.
- Messaging channels (e.g., Facebook Messenger, Instagram, WhatsApp) — the messages people send to a business’s connected Facebook Page or account, as described below.
All integration data is stored in a profile-scoped, isolated manner. Data from one profile is never mixed with or accessible from another profile.
Messages sent to a business’s connected Page or account
When a business connects a Facebook Page (Messenger), an Instagram account or a WhatsApp Business account, Meta delivers to Atribu the messages people send to it: the message text and attachments, the sender’s identifier on that channel (a Page-scoped ID on Messenger, an Instagram-scoped ID on Instagram, the phone number on WhatsApp), timestamps and, when the conversation started from an ad, the ad that referred the person. We also store the encrypted access token of the connected Page or account, so the business’s replies can be sent.
We use these messages to deliver them to the inbox the business chose, to send the replies the business’s team writes, and to show the business which ad or campaign started a conversation. For Instagram and WhatsApp conversations stored in a workspace, we also link the conversation to that person’s customer record in the same business’s workspace, including from an email address or a Chilean national ID number (RUT) the person writes in a WhatsApp message. For Messenger, Atribu does not keep a conversation history: each message is forwarded to the inbox application the business connected through Atribu (for example, Vitrina), which stores and displays the conversation.
Usage data
We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, operating system, IP address, and referring URLs.
Cookies and similar technologies
We use strictly necessary cookies to maintain your authenticated session. We may also use analytics cookies to improve the Service. You can manage cookie preferences through your browser settings.
3. How we use your information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Process and display analytics dashboards, reports, and attribution data within your profile scope.
- Authenticate your identity and enforce role-based access control at the workspace and profile level.
- Send transactional communications (e.g., invitations, security alerts, product updates).
- Improve and develop new features for the Service.
- Detect, prevent, and address security issues and fraud.
- Comply with legal obligations.
4. Data isolation and security
Atribu is built with an agency-first, multi-tenant architecture. Each workspace acts as a tenant boundary, and each profile within a workspace is fully isolated. We enforce isolation through application-level authorization checks and database-level policies (including PostgreSQL Row-Level Security where applicable).
We maintain audit logs for key security and trust events such as connection creation, attribution model changes, and report exports.
We use industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews.
5. Sharing and disclosure
We do not sell your personal information. We may share information in the following circumstances:
- Service providers — third-party vendors who assist us in operating the Service (e.g., hosting, analytics, email delivery), bound by confidentiality agreements.
- Inbox applications a business connects — when a business connects a messaging channel through an inbox application (for example, Vitrina), the messages people send to that channel are forwarded to that application, and the replies its team writes are sent through Atribu. The business chooses and can revoke that application’s access at any time.
- Within your workspace — workspace members with appropriate roles may access profile data they are authorized to view.
- Legal requirements — when required by law, regulation, legal process, or enforceable governmental request.
- Business transfers — in connection with a merger, acquisition, or sale of assets, in which case we will notify you.
6. Data retention
We retain your account information for as long as your account is active. Workspace and profile data is retained while the workspace remains active. Archived profiles may be retained for a reasonable period to allow reactivation. You may request deletion of your account and associated data at any time by contacting us.
Messages: for Facebook Messenger, Atribu keeps a copy of each message it forwards, including its text, in its delivery log for between three and four months so failed deliveries can be retried; a copy in its delivery queue has its content removed after 2 days and is deleted after 7 days; and receipts of the webhooks Meta sends us are kept for 30 days without message text. Instagram and WhatsApp conversations stored in a workspace are kept while the channel exists in the workspace. When an inbox application’s access to a messaging channel is revoked, Atribu deletes the stored access token and stops receiving and sending messages for it, but keeps the conversations already stored. When a business disconnects a messaging channel, Atribu deletes the stored access token for it, and the Instagram or WhatsApp conversations stored for that channel. Details, and how to request deletion, are on our Data Deletion page.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data, as well as the right to restrict or object to certain processing. To exercise these rights, contact us at the address below.
8. International transfers
Your information may be processed and stored in countries outside your country of residence. Where we transfer data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
10. Contact us
If you have questions about this Privacy Policy or our data practices, please contact us at [email protected].