Security

How we treat access to your org.

You are granting API access to a production marketing org. That deserves a page, not a sentence. Everything below is what re:target does today — not what it intends to do.

Write scopes requested
0
Subscriber data read
Never
Metadata retention
The engagement
Hosting region
EU (Frankfurt)

The four scopes we request

All four are read-only. re:target has no write scope in its installed package, so there is no code path by which it could modify an asset even if it tried.

Read-only scopes on the installed package
ScopeWhat it readsWhy we need it
documentAndImages_readContent Builder assets, templates, imagesCounts and categorises email and content assets
automations_readAutomation Studio definitions and activitiesFinds automations and the activities they depend on
list_and_subscribers_readData extension and list definitionsInventories data extensions — schema only, never rows
journeys_readJourney Builder definitions and entry sourcesInventories journeys and detects unsupported entry sources
What is not in the list
No *_write scope. No tracking_events. No contact or subscriber read beyond the definitions that describe a data extension. If you audit the package after connecting, these four are all you will find: documentAndImages_read, automations_read, list_and_subscribers_read, journeys_read.

What we store, and for how long

Metadata only

We store asset names, types, counts, folder paths, dependency edges and the definitions that describe them. We do not store subscriber records, email content bodies, send results or tracking data.

The life of the engagement

Inventory data and the report are kept while the work is live, so you can go back to them. When the engagement ends we delete both. Ask us sooner and we delete them sooner — there is no retention period we are holding you to.

Credentials

Client ID and secret are encrypted at rest and used only to mint short-lived access tokens against your tenant's auth endpoint. Revoke the installed package in Marketing Cloud and our access ends at that moment — there is nothing on our side to wait for.

EU hosting

Everything runs in the EU, in Frankfurt. Nothing about an assessment leaves the region. Private hosting puts it on infrastructure dedicated to you, in a region you pick.

Sub-processors

The third parties that can touch assessment data. This list is part of the contract: we give notice before adding to it.

Current sub-processors
Sub-processorPurposeRegion
Google CloudApplication hosting and databaseEU (Frankfurt)
Google WorkspaceEmail notifications and support correspondenceEU

Have a security review to run? Send it over.

We answer questionnaires. If your org cannot send metadata through shared infrastructure at all, private hosting exists for exactly that conversation.

Contact sales