Privacy Policy
Last updated: July 30, 2026
At Rocket Hub we take privacy seriously. This policy explains what personal data we process, for what purpose, and the rights available to you, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable data protection law.
1. Data controller
Controller: RocketROI SL, Tax ID B-65986465, registered at the Registro Mercantil de Barcelona, with address at Paseo de Gracia 88, Ático, 08008 Barcelona.
Data protection contact: protecciondedatos@rocketroi.com · Phone +34 933 283 127.
2. Who this applies to
Rocket Hub is a restricted-access professional platform intended for the agency and its clients. This policy applies to users with access to the platform and to visitors of the public pages (sign-in, sharing portals and legal information).
3. Data we process
- Account data: name, email address, role and the organization (client) you belong to.
- Authentication data: your corporate Google account identifier or sign-in credentials.
- Usage and technical data: activity logs, IP address, device and browser type, and technical identifiers needed for your session.
- Work content: creatives, campaigns, reports and metrics from connected platforms that are managed on the platform on behalf of the client.
4. Purposes and legal basis
- Provide and maintain the service and manage your account — performance of a contract or pre-contractual measures.
- Ensure security, prevent fraud and audit access — legitimate interest.
- Comply with applicable legal obligations — compliance with a legal obligation.
- Operational communications about the service (notices, changes, support) — performance of the contract and legitimate interest.
5. Dual role: controller and processor
With respect to users' account data, Rocket Hub acts as data controller.
With respect to the content and metrics each client uploads or connects (for example, campaign or sales data), the agency acts as processor on behalf of that client, who is the controller. Such processing is governed by the relevant data processing agreement (DPA).
6. Third-party integrations
Using the authorized credentials of the agency or the client, the platform connects to third-party services through their official APIs to import the data it centralizes.
For Google, access is read-only and limited to the following scopes, each with its purpose: Google Ads (advertising metrics), Google Analytics 4 (sessions and attribution), Search Console (organic performance), Merchant Center (catalog and feeds), Tag Manager (tag configuration) and Google Drive (importing creatives into the DAM). We also use openid and email to identify the authorizing account.
The use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. We do not use this data for advertising purposes nor sell it, and it is used solely to provide and improve the user-facing features.
Other integrations (Meta, TikTok, Shopify, BigQuery, among others) are likewise limited to the necessary data and governed by the policies of their source platform.
7. Recipients and processors
We do not sell your data. We may rely on providers acting as processors under contract, primarily cloud infrastructure providers (Google Cloud Platform) for hosting, storage and databases.
We may also disclose data where legally required or upon request from a competent authority.
8. Retention
We keep data while the account is active and a service relationship exists. After it ends, data is kept blocked for legally required periods and deleted when no longer necessary.
9. International transfers
Infrastructure is operated preferably within the European region. If any provider involves an international transfer, it will be covered by the safeguards provided under the GDPR (for example, standard contractual clauses).
10. Security
We apply appropriate technical and organizational measures: strict per-client data isolation, role-based access control, encryption in transit, secure secret and credential management (Secret Manager) and audit logging.
11. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to protecciondedatos@rocketroi.com. If you believe the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
Where data is processed on behalf of a client (controller), we will forward your request to that client or handle it following their instructions.
12. Cookies and local storage
The public pages and the application use only strictly necessary technical storage (for example, to keep your session signed in and remember your language). We do not use advertising or profiling cookies.
13. Minors
The platform is intended for professionals, not minors. We do not knowingly collect data from minors.
14. Changes to this policy
We may update this policy to reflect legal or service changes. We will publish the current version on this page, indicating its update date.