Candango Logo
Agency Access Check Your Score

Candango Privacy Policy

Effective Date: June 1, 2026
Last Updated: June 1, 2026

Welcome to Candango. We take your privacy, data security, and compliance seriously. This Privacy Policy explains how Candango ("we," "our," or "us") collects, uses, stores, discloses, and safeguards your information when you use our website, platform, and services, including our integration with third-party APIs.

By accessing or using Candango, you explicitly agree to the collection, use, and disclosure practices outlined in this Privacy Policy. If you do not agree with any part of this policy, you must not authenticate your accounts or use our services.

1. Integration with YouTube API Services & Third-Party Terms

Candango relies on secure, automated integrations to verify creator metrics and calculate your Creator Integrity Index (CII) score.

  • YouTube API Services: Candango uses YouTube API Services to access your YouTube channel data and advanced analytics. By authenticating your channel via our platform, you explicitly agree to be bound by the YouTube Terms of Service.
  • Google Privacy Policy: Because we utilize Google OAuth and API services, your data is also subject to Google's data handling practices. We encourage you to review the Google Privacy Policy.
  • User Revocation: You can revoke Candango’s access to your data at any time via the Google Security Settings Page. Revoking permissions will immediately stop our platform from fetching updated data, and our system will automatically mark your account as unverified.

2. Google API Verbatim "Limited Use" Disclosure

Candango's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not under any circumstances transfer, sell, or disclose raw data received via Google APIs to third-party tools, advertising platforms, data brokers, or data marketplaces.

3. Information We Collect and Receive

We only request and collect data that is strictly necessary to calculate your CII score and generate your verified media kits. We collect information across the following categories:

A. Data Collected via YouTube API (With Your Consent)

  • Public Channel Metadata: Channel name, handle, creation date, profile imagery, video titles, descriptions, and thumbnails.
  • Public Statistics: Public subscriber counts, lifetime video view counts, comment counts, and like counts.
  • Private Channel Analytics (Restricted Scopes): Video-level watch time, real-time viewer engagement velocity, historical traffic sources, and audience retention metrics.

B. Account and Technical Data

  • Authentication Credentials: Google ID and secure OAuth 2.0 access tokens. We never see, access, or store your Google password.
  • User Profile Data: Your name, email address, corporate/agency affiliation (if applicable), and billing information (processed securely through our third-party PCI-compliant payment gateway).
  • Log and Usage Data: IP address, browser type, device information, and platform access logs to maintain platform security, prevent fraud, and optimize performance.

4. How We Use Your Data (Purpose Limitation)

We operate under a strict policy of purpose limitation. We use your collected YouTube data solely to:

  • Aggregate and calculate your baseline performance metrics (e.g., median views) to generate your standardized Creator Integrity Index (CII) Score.
  • Conduct automated integrity, authenticity, and engagement velocity tests to filter out artificial or inorganic audience spikes.
  • Populate your official Candango Verified Media Kit and user dashboard.
  • Maintain, secure, and improve the technical functionality of the Candango platform.

Data Exploitation Restrictions: We will not use your YouTube API data to display personalized advertisements, engage in profile targeting, or reverse-engineer user behavioral profiles for external marketing.

5. Data Sharing, Visibility, and Third Parties

Your privacy is foundational to our business model. We do not sell, rent, or trade your private analytics data.

  • Your Dashboard and Private Analytics: By default, your detailed private analytics and specific internal index breakdowns are completely private and visible only to you when logged into your secure Candango account.
  • CII Score and Media Kit Visibility: Your final calculated CII Score and verified media kit will only be made visible to third-party sponsors, brands, or agencies if you explicitly choose to generate and share your public dashboard link or change your account privacy settings to "Public" or "Visible to Agencies."
  • Service Providers: We may share basic account data (such as your email or billing details) with trusted cloud infrastructure providers (e.g., database hosting, payment processors) strictly to run the platform. These providers are contractually bound by strict confidentiality agreements.
  • Legal Requirements: We will only disclose your information if required to do so by law, subpoena, or a binding regulation from a governing authority.

6. Data Storage, Security, and Encryption Architecture

We implement rigorous technical and organizational security measures to protect your information from unauthorized access, loss, or alteration.

  • Encryption Standards: All data exchanged between your browser, Candango's servers, and the YouTube API endpoints is encrypted using Secure Socket Layer (SSL/TLS) protocols. Stored data is kept in an isolated, encrypted database environment at rest.
  • Token Isolation: Your API access and refresh tokens are encrypted using AES-256 cryptographic standards before being saved to our servers. These tokens are handled exclusively via server-to-server calls and are never exposed to the client-side browser interface.

7. Data Retention and Deletion Policy (The Right to be Forgotten)

We retain your historical performance data only as long as necessary to provide consistent trend analytics for your CII score.

  • Automatic Deletion upon Revocation: If you disconnect your YouTube channel or revoke permissions via Google Security Settings, Candango will immediately cease pulling data.
  • Account Deletion Requests: You have the right to request the permanent deletion of your Candango account and all associated historical data at any time. You may execute this via the "Delete Account" option in your dashboard settings or by emailing privacy@candango.com.
  • Processing Timeframes: Upon receiving a verified request, we will permanently purge all cached analytics, historical records, and metadata associated with your Google ID from our active production databases within thirty (30) days. Residual logs kept strictly for security auditable trails will be completely anonymized.

8. Compliance with Global Regulations (GDPR & CCPA)

While Candango is a business-to-business (B2B) utility platform matching creators with agencies, we comply with standard data rights:

  • Access and Portability: You may request a copy of the personal data we store about your account at any time.
  • Correction: You may update your account profile data directly via your dashboard.

9. Changes to This Privacy Policy

Candango reserves the right to modify or update this Privacy Policy at any time to reflect updates to our platform, changes in the YouTube API Developer Policies, or evolving legal regulations. We will notify you of any material changes by posting the new policy on this page with a revised "Last Updated" date and, where feasible, notifying you via email.

10. Contact Us

If you have any questions, concerns, or data deletion requests regarding this Privacy Policy or how Candango handles your information, please contact our data privacy team at:

Candango Privacy Team
Email: privacy@candango.com