Privacy Policy
Last updated: October 1, 2026
Bendrix Marketing ("Bendrix", "we") is an internal tool operated by Sociedad Gourmet to plan, schedule and publish social media content for the restaurant and hospitality brands of the group. This policy explains what data we handle when a team member connects a social media or advertising account, including TikTok and Google (YouTube, Google Business Profile and Google Ads).
Who can use Bendrix
Access is limited to invited members of our organization. Bendrix is not offered to the general public and does not collect data from the audiences of the connected accounts.
Data we collect from connected accounts
When an authorized user connects an account through the platform's official OAuth flow, we store:
- OAuth access and refresh tokens, encrypted at rest (AES-256-GCM).
- Basic profile information needed to identify the account inside Bendrix: account ID (for TikTok, the
open_id), display name and avatar. - Identifiers and status of the posts published through Bendrix (for example, the TikTok
publish_id).
For TikTok we request only the scopes user.info.basic, video.upload and video.publish. We do not read direct messages, followers, comments or any content not created through Bendrix.
Google user data
When an authorized team member connects a Google account, we ask only for the permission needed by the specific connection they choose, and we use it only for that purpose:
- YouTube (
youtube): to list the channels the user manages, upload the videos our team prepares and schedules, and delete a video we published if the team asks us to unpublish it. - Google Business Profile (
business.manage): to list the accounts and locations the user manages and to publish the local posts our team prepares and schedules. - Google Ads (
adwords): to read the campaigns, ads and performance metrics (impressions, clicks, spend) of the ad accounts the user selects, and to create or update the campaigns that our team explicitly configures in Bendrix. - Google Data Manager (
datamanager): to send to the user's own Google Ads account the reservations that originated from an ad click, so that the conversion is attributed to the right campaign. Each event contains only the ad click identifier (gclid, gbraid or wbraid), the conversion action, the value and the time; it does not contain the customer's name, email or phone number.
We store the OAuth tokens, the IDs and names of the selected channels, locations and ad accounts, and the post and campaign data and metrics returned by those APIs. We do not read your email, Drive, contacts or any other Google data, and we do not collect data from the viewers or customers of the connected accounts.
Bendrix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the user-facing features described above, which are visible in the Bendrix interface.
- We do not transfer Google user data to others, except as needed to provide those features, to comply with the law, or as part of a merger or sale with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized or interest-based advertising.
- We do not allow humans to read Google user data unless we have your consent for specific items, it is necessary for security or to investigate abuse, it is required by law, or the data has been aggregated and used internally.
- We do not use Google user data to develop, improve or train generalized AI or machine-learning models. Aggregated performance metrics of connected ad accounts may be sent to Google's Gemini API solely to generate suggestions shown inside Bendrix to our own team; they are not used to train models.
YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Bendrix's access to your Google account at any time at myaccount.google.com/permissions.
How we use the data
- To show which account is connected for each brand.
- To upload and publish the videos that our team prepares and explicitly schedules in Bendrix.
- To report whether each publication succeeded or failed.
We do not sell, rent or share this data with third parties, and we do not use it for advertising profiling.
Storage and security
Data is stored in our managed PostgreSQL database and cloud storage, accessible only to our backend services. Tokens are encrypted and never shown in the user interface.
Retention and deletion
Tokens are kept while the account remains connected. Disconnecting an account in Settings → Accounts deletes its tokens from our database (for TikTok it also revokes the token with the platform through the official revoke endpoint). You can also revoke access at any time from the platform's own settings; for Google, at myaccount.google.com/permissions. Data synced from Google APIs (such as campaign metrics) is deleted on request. To request deletion of any remaining data, write to gerencia@sociedadgourmet.com.
Changes
We will update this page if our data practices change.
Contact
Sociedad Gourmet — gerencia@sociedadgourmet.com