Privacy Policy
Your Privacy Is Important
Oktos Consulting Group Effective: February 2026
This policy describes how Oktos Consulting Group ("Oktos," "we," "us") collects, uses, stores, and protects information when you use our website, engage our services, or connect your business systems to the Oktos Platform.
Information We Collect
When you contact us, request a consultation, or engage our services, we collect information necessary to deliver our work. This includes your name, email address, phone number, business name, and details relevant to the scope of our engagement.
Website Usage Data
We collect standard analytics data about how visitors interact with our website, including pages visited, time on site, referring sources, device type, and browser information. Our site uses cookies to support this analytics collection. You can disable cookies through your browser settings.
Business Data Accessed Through the Oktos Platform
When you authorize the Oktos Platform to connect to your business systems, we access operational data from those systems on your behalf. This is the core of our service. The specific data accessed depends on which platforms you connect, and is detailed in the Platform Integrations section below.
How We Use Your Information
We use information we collect for the following purposes:
To deliver business intelligence reports, diagnostic analysis, and strategic recommendations to your organization
To generate weekly, daily, and periodic performance reports based on your connected data sources
To identify trends, constraints, and opportunities in your business operations
To communicate with you about your engagement, reports, and findings
To improve and maintain the Oktos Platform and our analytical methodology
To analyze aggregate, anonymized usage patterns across our website
We do not use your business data for advertising, remarketing, profiling, or any purpose unrelated to delivering our services to you.
Platform Integrations
The Oktos Platform connects to third-party services you authorize to generate business performance reporting. Each integration is initiated by you and can be revoked at any time.
Google Analytics
What we access: Read-only analytics data including sessions, users, pageviews, traffic sources, geographic and device data, and conversion events. We request only the analytics.readonly permission.
What we do with it: Generate traffic trend reports, website-to-store attribution analysis, and audience behavior insights for your organization.
How to revoke access: Visit https://myaccount.google.com/permissions and remove "Oktos Platform."
Lightspeed POS (R-Series and E-Series)
What we access: Sales transactions, inventory records, customer contact information, product catalog data, vendor and purchase order data, employee records, and service or work order data.
What we do with it: Generate business performance reports covering sales trends, margin analysis, inventory health, service department metrics, cash flow patterns, and customer behavior.
How to revoke access: In your Lightspeed account, go to Settings > Client API Access, find Oktos Platform, and select "Revoke Access."
Shopify
What we access: Orders and transaction data, product and inventory information, customer records, discount and promotion usage, shipping and fulfillment data, and storefront analytics.
What we do with it: Generate ecommerce performance reports covering sales trends, product performance, customer acquisition and retention, average order value, and inventory sell-through rates.
How to revoke access: In your Shopify admin, go to Settings > Apps and sales channels, find Oktos Platform, and select "Remove app."
Klaviyo
What we access: Email and SMS campaign performance metrics, subscriber list data, flow and automation performance, revenue attribution data, and audience segment information.
What we do with it: Incorporate marketing channel performance into your business reports, including campaign ROI, subscriber growth, and marketing-attributed revenue.
How to revoke access: In your Klaviyo account, go to Settings > Integrations, find the Oktos Platform, and remove the integration.
Meta (Facebook and Instagram)
What we access: Ad campaign performance metrics, audience insights, pixel and conversion event data, ad spend, and engagement metrics.
What we do with it: Incorporate paid social performance into your business reports, including return on ad spend, customer acquisition cost, and campaign effectiveness.
What we do not access: Private messages, personal profile data, or any content unrelated to your business advertising accounts. We do not post, publish, or modify any content on your behalf.
How to revoke access: In Meta Business Settings, go to Business Integrations and remove the Oktos Platform.
As we expand platform support, this section will be updated to reflect any new integrations.
Data Security
Your data is protected by the following measures:
All API credentials and access tokens are encrypted at rest using industry-standard encryption (Fernet symmetric encryption)
Data is transmitted over HTTPS using TLS encryption
Database access is restricted to authenticated platform processes
Infrastructure is secured behind Cloudflare network protection
Access to client data is limited to authorized Oktos personnel involved in your engagement
Client data is logically separated at the database level. No client can access another client's data through the platform.
We treat your business data with the same care we would expect for our own. If you have specific security requirements, we are happy to discuss them as part of your engagement.
Data Sharing
We do not sell, rent, license, or share your personal information or business data with any third parties.
The only exceptions:
If required by law, regulation, or valid legal process
With your explicit written consent
With service providers who process data on our behalf under strict confidentiality agreements (for example, our hosting infrastructure)
Your data is yours. We access it to serve you. That is the only purpose.
Data Retention
We retain your business data for the duration of our service agreement. Upon termination:
You may request deletion of all stored data
Stored data will be deleted within 30 days of a deletion request
Encrypted credentials and access tokens are revoked and purged immediately upon disconnection
Your Rights
You have the right to:
Request a summary of what data we hold from your connected accounts
Request deletion of all stored data at any time
Revoke access to any connected platform at any time without affecting your relationship with Oktos
Opt out of marketing communications
Be notified of material changes to this policy
Contact us with any questions about your data
Google API Services User Data Policy
The Oktos Platform's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
We only use Google user data for the purposes described in this privacy policy
We do not transfer Google user data to third parties except as necessary to provide our services to you
We do not use Google user data for serving advertisements
We do not allow humans to read Google user data except with your explicit consent, for security purposes, to comply with applicable law, or for our internal operations where the data has been aggregated and anonymized
Changes to This Policy
We may update this Privacy Policy as our services and platform evolve. Material changes will be posted on this page with an updated effective date. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact
For questions about this Privacy Policy or how we handle your data:
Oktos Consulting Group
[email protected]
www.workwithoktos.com