Introduction
Scion Media, LLC ("Scion Media", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or engage our services. By using our website and services, you consent to the data practices described in this policy.
Scion Media is a digital marketing agency that helps local businesses grow their overall online visibility through managed local SEO, Google Business Profile management, website design, review management, and reporting services.
Legal entity: Scion Media, LLC
Location: Coral Springs, FL, United States
Privacy contact: privacy@scionmediadigital.com
Phone: 888-311-8950
Information We Collect
Personal Information
We collect personal information that you voluntarily provide to us when you:
- Fill out contact forms or request quotes and consultations
- Subscribe to our newsletter or marketing communications
- Engage our services and sign a service agreement
- Contact us for support
This information may include:
- Name, email address, phone number, and mailing address
- Business name, business address, industry, and service area
- Marketing goals, project requirements, and communication preferences
- Payment information (processed by our payment processor, Stripe — we never store full card details)
Automatically Collected Information
When you visit our website, we automatically collect certain information about your device, including:
- IP address and approximate geographic location
- Browser type, version, and operating system
- Pages visited, time on site, and referring website
- Device information and cookie identifiers
Google Business Profile Data
If you engage us for Google Business Profile management, we may access and process your Google Business Profile data only after you explicitly authorize us via Google's official OAuth 2.0 flow. The section below is the authoritative disclosure for how Scion Media handles Google user data.
Meta (Facebook and Instagram) Data
If you engage us for Facebook Page or Instagram Business Account management through our Sightline platform, we may access and process your Meta data only after you explicitly authorize us via Facebook Login for Business. The "Facebook and Instagram Data" section further down is the authoritative disclosure for how Scion Media handles Meta user data.
Google Business Profile Data and OAuth Access
Scion Media is a Google Business Profile management agency. To operate your profile on your behalf, we need access to your Google Business Profile data. That access is granted exclusively via Google's official OAuth 2.0 authorization flow — we cannot access your account without your explicit, real-time authorization.
Scopes we request
The OAuth scope we request is https://www.googleapis.com/auth/business.manage
(the Business Profile APIs family). This single scope authorizes the following specific
APIs used by Scion Media, each limited to the minimum functionality required to operate your profile on
your behalf:
- My Business Account Management API — View the Business Profile accounts and locations you have granted us access to.
- My Business Business Information API — Read and update your business information (name, address, phone, website, hours, categories, services, attributes).
- My Business Verifications API — Manage verification status for your locations.
- My Business Notifications API — Receive notifications about changes, reviews, and questions on your profile so we can respond promptly.
- Business Profile Performance API — Read profile insights (views, searches, clicks, calls, direction requests) to generate your monthly reports.
We do not request any additional Google scopes beyond business.manage. We do not access
Gmail, Drive, Contacts, Calendar, Photos, or any other Google product or user data.
How we use Google data
We use your Google Business Profile data exclusively to:
- Optimize your business profile for visibility across Google Search and Maps
- Post weekly Google Posts on your behalf to keep your profile active
- Monitor and respond to customer reviews (with your approval)
- Track profile insights (views, clicks, calls, direction requests) for reporting
- Generate monthly performance reports
- Maintain accurate, up-to-date business information
How we DO NOT use Google data
We will never:
- Sell your Google Business Profile data to any third party
- Share your data with anyone outside our service team
- Use your data for advertising purposes, retargeting, or interest-based advertising
- Use your data to train artificial intelligence or machine learning models
- Access more data than is necessary for the services you have hired us for
Granting and revoking access
You grant Scion Media access to your Google Business Profile during onboarding by completing Google's official OAuth consent flow. This requires you to actively click "Allow" on Google's consent screen. You can revoke this access at any time by:
- Visiting your Google Account permissions page at https://myaccount.google.com/permissions
- Finding "Scion Media" in the list of connected apps
- Clicking "Remove access"
You can also email privacy@scionmediadigital.com and we will revoke our access on your behalf within 24 hours.
Data retention
We retain Google Business Profile data only as long as your service agreement is active. Within 30 days of service termination, we permanently delete all stored Google data. Live access via OAuth is automatically revoked when your service ends.
Limited Use compliance
Scion Media's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Scion Media affirms that:
- Allowed use. We use Google user data only to provide or improve user-facing features that are prominent in Scion Media's services, as described in "How we use Google data" above. Any other use requires your additional explicit consent.
- Allowed transfer. We do not transfer Google user data to third parties except (a) as necessary to provide or improve user-facing features that are prominent in the requesting application's user interface, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets of Scion Media with notice to users.
- Prohibited use — advertising. We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- Prohibited use — human access. We do not, and do not permit any employee, contractor, or affiliate to, read Google user data except (a) with your affirmative agreement for specific data; (b) as necessary for security purposes such as investigating abuse or a security incident; (c) to comply with applicable law; or (d) where the data (including derivatives) has been aggregated and is used for internal operations in accordance with applicable privacy laws.
No human access to your data
Day-to-day operations on your Google Business Profile — content posting, review monitoring, insights aggregation, and profile updates — are performed by automated systems acting under the OAuth authorization you granted. Scion Media employees and contractors do not read, export, or otherwise access the individual contents of your Google user data except in the narrow circumstances listed in item (4) above.
When manual access is unavoidable (for example, to diagnose a production issue, to act on a specific support request you sent us, or to investigate a potential security incident), that access is:
- Authorized by a designated privileged-access role within Scion Media
- Logged with user identity, timestamp, scope of access, and business justification
- Time-limited and restricted to the minimum data necessary to resolve the issue
- Never used for advertising, model training, resale, or any purpose unrelated to the stated justification
Security for Google data
Google OAuth credentials are stored encrypted at rest and transmitted only over TLS 1.2 or higher. Access to Google API systems is restricted by role and protected by multi-factor authentication. Scion Media commits to an annual Cloud Application Security Assessment (CASA) appropriate to our scope tier, and will notify affected users of any security incident involving Google user data without undue delay and in any case consistent with applicable law.
Facebook and Instagram Data
Scion Media operates the Sightline platform as a Meta Tech Provider that helps local businesses manage their Facebook Pages and Instagram Business Accounts. To perform that work on your behalf, Sightline needs access to specific Meta data. Access is granted exclusively through Facebook Login for Business — a Page admin must explicitly authorize Sightline before any data is read, and access can be revoked at any time.
What data we access
When you connect a Facebook Page or Instagram Business Account through Sightline, we may access the following, limited to what the permissions you grant allow:
- Facebook Page profile information — name, address, phone number, hours, categories, website, cover and profile photos, and other public profile fields.
- Facebook Page posts and engagement metrics — your Page posts and their reach, impressions, likes, shares, and other engagement signals.
- Comments and reactions on Page posts — including the commenter's name and the text of their comment, so we can monitor and respond to customer engagement on your behalf.
- Page insights — audience demographics, post performance, follower counts, and other analytics provided by Meta.
- Linked Instagram Business Account — profile information, media (posts, reels, stories), comments on that media, and Instagram insights.
- Meta Business Manager assets — information about the Pages, Instagram accounts, and other business assets you grant Sightline access to.
The specific Meta permissions Sightline requests include pages_show_list,
pages_manage_metadata, pages_manage_posts, pages_read_engagement,
pages_read_user_content, pages_manage_engagement, read_insights,
business_management, instagram_basic,
instagram_content_publish, instagram_manage_insights, and
instagram_manage_comments. Each permission is requested only to deliver a feature that
appears in the Sightline product.
How we obtain it
We obtain Meta data exclusively through Facebook Login for Business. A Page admin or Business Manager user with the necessary role must complete Meta's official login flow and explicitly grant Sightline the listed permissions. Sightline cannot read any Meta data without that affirmative authorization, and cannot exceed the scope of the permissions granted.
Why we collect it
We use Meta data exclusively to provide the marketing services you have engaged us for, including:
- Maintaining accurate and consistent business listing information across your Facebook Page and Instagram profile
- Drafting, scheduling, and publishing posts, reels, and stories on your behalf
- Monitoring comments, reactions, and direct messages so we can respond to customer engagement
- Producing performance reporting (reach, impressions, follower growth, post performance) for your monthly review
- Surfacing recommendations to improve your social presence
How we DO NOT use Meta data
We will never:
- Sell your Facebook or Instagram data to any third party
- Share your Meta data with third-party advertisers or data brokers
- Use your Meta data for advertising, retargeting, or interest-based advertising outside the campaigns you explicitly direct us to run
- Use your Meta data to train artificial intelligence or machine learning models
- Use your Meta data for competitive research, benchmarking against other clients, or any purpose outside the marketing services agreement you signed
- Access more data than the permissions you granted require
Sub-processors
To deliver the service, Meta data may pass through the following vetted sub-processors, each bound by contractual data-protection requirements:
- Railway — application hosting and database infrastructure
- Cloudflare — content delivery network and edge security
- Anthropic — AI processing for content drafting and reply suggestions, where applicable to your plan; content sent to Anthropic is not used to train their models per Anthropic's API terms
We do not sell or share Facebook or Instagram data with third-party advertisers, marketing networks, or any party outside of these named sub-processors and Meta itself.
How long we retain it
Meta data is retained only as long as your connection to Sightline is active and your service agreement is in force. Specifically:
- While your account is connected, we retain the operational data needed to deliver the service (your most recent posts, comments, insights, and audience metrics).
- If you disconnect your Facebook Page or Instagram account from Sightline, we purge the associated data from our active systems within 90 days.
- You can request immediate deletion at any time by contacting us at privacy@scionmediadigital.com or through the Data Deletion process described below.
- Aggregated, fully anonymized statistics that cannot be traced back to you may be retained for internal product analytics.
User rights
You can manage your Meta data in Sightline at any time by:
- Disconnecting your account — go to Sightline → Settings → Connected Accounts and click "Disconnect" for the Facebook Page or Instagram account in question. This revokes our access immediately and triggers data purge.
- Removing the app from Facebook — visit Facebook Settings → Business Integrations (or Settings → Apps and Websites), find Sightline, and remove it. Meta will notify our endpoint and we will delete the associated data per the Data Deletion process below.
- Contacting us directly — email privacy@scionmediadigital.com or marc@scionmediadigital.com for any data access, correction, or deletion request.
Compliance with Meta Platform Terms
Sightline's use of information received from Meta APIs adheres to the Meta Platform Terms and the Meta Developer Policies, including all data-handling, retention, and use restrictions stated in those documents. Specifically, Sightline affirms that it uses Meta data solely to provide the marketing features described above, does not transfer Meta data to any party other than the sub-processors listed, does not use Meta data for advertising outside the campaigns clients direct, and does not use Meta data to train AI models.
Our automated Data Deletion Callback endpoint, which Meta calls when a user removes Sightline from
their Facebook account, is published at:
https://app.scionmediadigital.com/api/meta/data-deletion.
Data Deletion process
You can request deletion of all Meta data we hold about you at any time. There are three paths:
- In Sightline — disconnect your Facebook Page or Instagram account in Sightline → Settings → Connected Accounts. Disconnect immediately revokes our API access and queues purge of all associated data.
- Via Facebook — remove Sightline from Facebook Settings → Business Integrations. Meta will send a deletion callback to our endpoint and we will purge the associated data and return a confirmation code per Meta's specification.
- By email — write to privacy@scionmediadigital.com with the subject line "Meta Data Deletion Request" and identify the Facebook Page or Instagram account in question.
Service-level commitment: deletion requests are processed within 30 days and typically within 24 hours. After deletion, only minimal records required for legal compliance (such as audit logs of the deletion event itself) are retained, and those are kept for the shortest period applicable law permits.
Security for Meta data
Meta access tokens are stored encrypted at rest and transmitted only over TLS 1.2 or higher. Access to Meta API systems is restricted by role and protected by multi-factor authentication. We will notify affected users of any security incident involving Meta user data without undue delay and in any case consistent with applicable law and Meta's incident-reporting requirements.
SMS / Text Messaging
Scion Media Digital may send and receive SMS text messages as part of providing services. This section describes how SMS works on our platform — what we send, how you opt in, how you opt out, and how we handle the data associated with text messaging.
Types of SMS we send
- Transactional and account-care messages to existing clients — appointment reminders, account confirmations, service updates, document-ready notifications, and replies to your inbound questions. These are sent to clients who have opted in during onboarding by checking a dedicated SMS consent box on our intake form.
- Initial business-to-business outreach to business owners whose business phone numbers are publicly listed for commercial inquiry on Google Business Profile, Yelp, Better Business Bureau, and the business's own website. The outreach is addressed to the business by name, relates only to legitimate commercial services we offer, and is sent under the business-to-business provisions of federal communications law. Every recipient may reply STOP at any time to opt out permanently.
Opting in
For client/account messages, opt-in is collected on our intake form (scionmediadigital.com/contact) via a dedicated checkbox that reads: "I agree to receive SMS text messages from Scion Media Digital about my account, appointments, and the services I have requested. Message and data rates may apply. Reply STOP at any time to opt out. Message frequency varies."
Opting out
You can opt out at any time by replying STOP, UNSUBSCRIBE, END, QUIT, or CANCEL to any message we send. Our system immediately and permanently records your opt-out across all of our numbers and sends a confirmation reply: "You're unsubscribed from Scion Media texts. Reply START to resubscribe." We will not send you further SMS unless you explicitly opt back in by replying START.
Help
Reply HELP or INFO to any message for assistance, or email hello@scionmediadigital.com.
Message frequency and rates
Message frequency varies based on your relationship with us and the services you've requested. Transactional messages (appointment reminders, account updates) typically occur 1–5 times per month per active service. Standard message and data rates from your wireless carrier may apply. Scion Media Digital does not charge you for SMS — but your carrier's plan does.
Sharing of SMS opt-in / contact data — explicit statement required by carrier policy
We do not share your mobile phone number, SMS opt-in status, or any data collected through SMS with any third party for marketing purposes. Mobile data is used solely for our own communication with you about your account, services, and (where applicable) initial business inquiries. No third party — including affiliates and marketing partners — has access to this data for the purpose of contacting you.
SMS carrier compliance
Scion Media Digital is registered with The Campaign Registry (TCR) for application-to-person (A2P) 10-digit long-code (10DLC) SMS messaging. Our brand and campaigns are filed with TCR through Twilio (our messaging provider) under the LOW_VOLUME and MIXED use case categories. We honor all federal Telephone Consumer Protection Act (TCPA), CAN-SPAM, and state mini-TCPA requirements applicable to our outbound messaging.
SMS data retention
Inbound and outbound SMS messages are retained in our customer relationship management system for as long as your account is active or as needed to provide services and comply with legal obligations. Opt-out records are retained permanently to honor your STOP request across future messaging.
How We Use Your Information
We use the information we collect to:
- Deliver our services (manage your profile, perform SEO work, build and host websites, manage reviews, generate reports)
- Respond to your inquiries, support requests, and communications
- Process payments via our payment processor
- Send you marketing communications, where you have consented and subject to your right to opt out at any time
- Analyze website usage and improve our services based on what works for our clients
- Personalize your experience on our website and in our communications
- Comply with legal obligations and enforce our Terms of Service
- Detect, prevent, and investigate fraud, abuse, or security incidents
Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties for their own marketing purposes. We share information only in the following circumstances:
- Service providers: We use trusted third parties to deliver our services — including Google (for Business Profile API access), Meta (for Facebook Page and Instagram API access), Stripe (payments), Railway (hosting and database), Cloudflare (CDN and edge security), and Anthropic (AI processing for content drafting). Each is bound by contractual data protection requirements.
- Legal compliance: We may disclose information when required by law, court order, subpoena, or valid government request.
- Business transfers: If Scion Media is acquired, merged, or sells substantially all of its assets, your information may transfer to the successor entity, subject to this Privacy Policy or a policy offering equivalent protection.
- With your consent: We may share information with additional parties when you explicitly authorize us to do so.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include:
- Encryption in transit via HTTPS/TLS 1.2 or higher
- Encryption at rest for sensitive data and OAuth credentials in our databases
- Access controls and authentication — employee and contractor access is role-based and protected by multi-factor authentication
- Regular security assessments of our systems, processes, and third-party integrations
- Secure servers and data centers operated by vetted infrastructure providers
- Employee and contractor training on data protection and incident response
No system is 100% secure, but we follow industry best practices to protect your information.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and analyze our website. You can control cookie settings through your browser preferences; note that some site features may not function properly if cookies are disabled.
Types of cookies we use:
- Essential cookies required for core site functionality and session management
- Analytics cookies (including Google Analytics) to understand aggregate site usage
- Preference cookies that remember your settings
We do not use advertising cookies, tracking pixels, or third-party retargeting on our own website.
Your Rights and Choices
Subject to applicable law, you have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you
- Correction — ask us to correct information that is inaccurate or incomplete
- Deletion — request that we delete your personal information, subject to legal retention requirements
- Portability — receive your data in a machine-readable format
- Opt-out — unsubscribe from marketing communications at any time
- Restriction — request that we restrict processing based on consent or legitimate interest
- Withdraw consent — withdraw any consent you previously gave for processing
To exercise any of these rights, email privacy@scionmediadigital.com. We respond within 30 days.
Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party site before providing personal information.
Children's Privacy
Our services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will delete it.
International Data Transfers
Scion Media operates from the United States. If you access our services from outside the United States, your information may be transferred to, stored, and processed in the United States or in other jurisdictions where our service providers are located. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to our active clients and posted prominently on this page. The "Last Updated" date at the top of this page reflects the most recent version. Your continued use of our services after such changes constitutes acceptance of the updated policy.
Contact Us
For questions about this Privacy Policy or our data practices:
Email: privacy@scionmediadigital.com
Phone: 888-311-8950
Mail: Scion Media, LLC, Coral Springs, FL, United States
For data subject requests, please use privacy@scionmediadigital.com with the subject line "Data Subject Request".