Allied Marketing Reputation Portal
Privacy Policy
This policy explains how Allied Marketing collects, uses, discloses, protects, and retains information when providing its email reputation, authentication, and inbox-placement services.
1. Scope and our role
This policy applies to the Allied Marketing Reputation Portal at reputation.allied.marketing and related inbox-monitoring and email-authentication services (the “Service”). Allied Marketing may act as a controller for portal account, security, and operational information and as a processor or service provider when handling customer data at a customer’s direction.
This policy does not govern a customer’s own email program, websites, or privacy practices. Customers are responsible for providing any notices and obtaining any permissions required for data they submit to the Service.
2. Information we process
Account and access information
We process names, business email addresses, password hashes for password-based customer accounts, Google identity identifiers for authorized Allied users, assigned customer domains, roles, sessions, and administrative audit records.
Sender reputation and deliverability information
We process reputation, compliance, delivery-error, feedback-loop, spam-rate, IP-status, volume, and related telemetry made available through Google Postmaster Tools, Microsoft SNDS, and other deliverability services configured by Allied Marketing or its customers.
Inbox-placement seed data
For an authorized Google, Microsoft, Outlook.com, Yahoo, or iCloud seed mailbox, the Service may process the mailbox address and limited metadata for test messages, such as sender, subject, Message-ID, received time, provider folder or category, and placement classification. The Service uses these fields to determine whether a test message reached the inbox, a category such as Promotions, spam or junk, or another location.
The seed-mailbox integration is designed not to download or store message bodies or attachments. It does not use mailbox access to send, modify, move, or delete messages.
Email-authentication tests
When a user sends a test message to a unique Allied testing address, we process message headers and technical delivery information needed to evaluate SPF, DKIM, DMARC, alignment, transport security, unsubscribe headers, and other deliverability signals. The inbound testing service is not intended for confidential message content.
Service and device information
We may process IP addresses, timestamps, request and error logs, browser or device information, security events, and session cookies necessary to operate, protect, and troubleshoot the Service.
3. How we use information
We use information to:
- provide reputation, compliance, inbox-placement, authentication, and diagnostic reports;
- correlate provider telemetry with sending domains and IP addresses;
- generate scores, summaries, recommendations, and customer-authorized shareable reports;
- authenticate users, administer accounts and domain assignments, and maintain security audit records;
- monitor, support, secure, and improve the Service; and
- comply with applicable law and enforce our agreements.
We do not sell mailbox data or use it for behavioral advertising, audience targeting, data brokerage, or unrelated monetization.
4. Connected email and reputation providers
Connections are initiated by an authorized administrator or mailbox owner using provider-approved credentials, delegated authorization, OAuth, or an access mechanism supplied by the provider. Provider tokens and credentials are encrypted at rest where stored by the Service. Users can revoke a provider connection through the Service or the provider’s account controls. When an authorized user requests an actual Gmail rendering, the Service temporarily imports a reconstructed copy of the selected preview into a dedicated rendering mailbox, captures the visual result, and deletes the Gmail copy immediately after capture.
The Service uses approved Google APIs for Google Postmaster data, account authentication, and Gmail metadata access. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft
The Service may use Microsoft Graph for authorized mailbox metadata and anti-spam classification headers and Microsoft SNDS for sender and IP reputation information.
Yahoo
For an individually authorized Yahoo seed mailbox, the Service requests the read-only mail-r scope and uses encrypted IMAP to read limited envelope metadata and Inbox or Spam/Bulk placement. It does not request Yahoo contacts or calendar access.
Apple iCloud Mail
For an administrator-connected iCloud seed mailbox, the Service uses encrypted IMAP and an Apple app-specific password to read limited envelope metadata and Inbox or Junk placement. The app-specific password is encrypted at rest, can be revoked through the Apple Account, and is not the user’s Apple Account password.
6. Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including providing historical reputation and placement reporting, maintaining account and security records, complying with legal obligations, and resolving disputes. Retention periods vary by data type, customer configuration, provider availability, and contractual requirements.
Inbound email-authentication test data is generally configured for limited operational retention. Expiring shared-report links are restricted to their stated access period and may be revoked earlier. Disconnecting a mailbox prevents future collection; existing operational records may remain until their applicable retention period ends or deletion is requested and legally permitted.
7. Security
We use administrative, technical, and organizational measures intended to protect information, including encrypted transport, encryption of stored provider credentials, access controls, domain-level authorization, audit logging, restricted service accounts, and limited mailbox permissions. No system is completely secure, and we cannot guarantee absolute security.
8. Your choices and privacy rights
Depending on your location and our relationship with you, you may have rights to request access, correction, deletion, or a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a response. You may also revoke mailbox authorization through the applicable provider and ask an Allied administrator to disconnect the mailbox.
Where Allied processes information on behalf of a customer, we may refer a request to that customer. We may verify the requester’s identity and retain information where required or permitted by law. We do not discriminate against individuals for exercising applicable privacy rights.
9. Cookies
The Service uses essential cookies and similar storage needed for authentication, OAuth security state, session continuity, and security. We do not use mailbox information for cross-context behavioral advertising.
10. Children
The Service is a business platform and is not directed to children. We do not knowingly collect personal information from children through the Service.
11. International processing
Information may be processed in the United States and other locations where Allied Marketing or its service providers operate. Where required, we use appropriate safeguards for cross-border transfers.
12. Changes to this policy
We may update this policy as the Service or legal requirements change. We will post the revised policy here and update the “Last updated” date. We may provide additional notice when a change is material.
13. Contact us
For questions, privacy requests, or concerns about this policy, contact Allied Marketing at privacy@allied.marketing or contact your Allied Marketing account representative.
Portal sign in