Privacy Policy
Version 1.0.0-draft · drafted 2026-08-16
This is a working draft. It has not been reviewed or approved by a lawyer, and it does not yet name a contracting entity or a governing law. 8 questions in it are still open for legal review, and each one is marked in the text below.
# Privacy Policy > **DRAFT — NOT LEGALLY REVIEWED.** > Prepared from the product's actual data model. Not reviewed or approved by a > lawyer, and not a statement of compliance with any regime. ## 1. Who is responsible **[LEGAL REVIEW REQUIRED — contracting entity and registered address]** **[LEGAL REVIEW REQUIRED — controller / processor characterisation]** The answer differs between account data (which the operator holds for its own purposes) and advertising data synced on your behalf (which is yours). That distinction drives most of this document and the DPA. ## 2. What is collected, and why Each category below corresponds to real tables in the system. Nothing is listed because it might be collected one day. ### Account and identity Your name, email address and password hash; email verification and password reset tokens; sessions. Used to sign you in and to keep your account secure. ### Workspace and membership Workspaces, members and their roles, invitations (which contain the invited email address), and workspace settings. Used to decide who may see what. ### Advertising platform connections The authorisation you grant, and access tokens for the platforms you connect. **Tokens are encrypted at rest and are never returned by any API, never written to logs, and never included in a data export.** ### Advertising data Advertising accounts, campaigns, ad sets, ads, creatives and daily performance metrics read from platforms you connect. This is your business data, held on your behalf. ### Commerce data Stores, products, orders and order lines from a commerce store you connect. > **Order customer identity is reduced to a one-way hash at the point of > ingest.** No customer email address, name or postal address from your store is > stored. The hash is salted with a secret that is not exported, so it cannot be > reversed. It exists only to count repeat purchases. ### AI usage Records of AI analyses run, the tokens consumed and the cost. Analysis input is redacted before it is sent, and the AI provider does not receive account credentials or store-customer identifiers. ### Uploaded files Creative assets you upload, and metadata about them. ### Audit and security records An append-only record of security-relevant actions: sign-in, permission changes, integration connects and disconnects, and data deletions. **This record is kept even when other data is deleted**, because it is the evidence that the deletion happened. ### Operational records Rate-limit counters, job records, and receipts used to recognise a repeated webhook delivery. Webhook message bodies are not stored — only a hash. ### Billing No payment is processed and no payment data is held. Billing is not enabled. ## 3. Who it is shared with The current sub-processor list is maintained separately and is part of these documents. Providers a customer's data can actually reach today are the AI provider that produces analysis and the advertising and commerce platforms you choose to connect. **[LEGAL REVIEW REQUIRED — sub-processor characterisation]** Data from advertising and commerce platforms flows *to* the service on your authorisation, which is not the usual sub-processor direction. ## 4. International transfers **[LEGAL REVIEW REQUIRED — international transfers and transfer mechanism]** Unanswerable until a hosting provider and its regions are chosen. None has been. ## 5. How long it is kept An engineering retention inventory exists and covers every table. The periods themselves are unresolved. **[LEGAL REVIEW REQUIRED — retention periods]** for audit records, accounting records, webhook receipts, AI usage records, performance metrics, and backups. What is settled today: expired sessions and expired verification tokens are deleted automatically because they are already unusable; nothing else is deleted on a timer. ## 6. Your rights You can request an export of a workspace's data, and you can request deletion of a workspace or of your own account. Deletion marks the subject immediately — access stops at once — and a staged purge then erases the data. **Three limits, stated plainly:** - **Deletion does not reach database backups.** Data already deleted from the live system remains in backups taken before the deletion, until those backups age out. **[LEGAL REVIEW REQUIRED — how this is described, and backup retention.]** - **Deletion does not reach the advertising platforms.** Your campaigns and their data remain in your own platform accounts, which are yours. - **Deleting your own account does not delete a workspace's files.** Deleting your account removes your account, your sign-in credentials and your access, including your membership of every workspace. Files you uploaded — creative assets, product images and exports — are held as workspace records rather than personal ones: they stay with the workspace and remain available to its other members. We record who uploaded a file so the workspace knows where it came from, and that record alone does not make the file yours to remove. Deleting the **workspace** is what erases its files. **[LEGAL REVIEW REQUIRED — whether workspace files should be treated as the workspace's records rather than the uploader's personal data, and how that is described here.]** Some records are deliberately retained: the audit trail, and accounting records if any exist. **[LEGAL REVIEW REQUIRED — the legal basis and period for each.]** **[LEGAL REVIEW REQUIRED — jurisdiction-specific rights]** including obligations under Moroccan Law 09-08 / CNDP and, for EU customers, the GDPR. ## 7. Security Tenant data is isolated at the database level as well as in the application. Platform tokens are encrypted at rest. Passwords are hashed. Access to credential tables is withheld from the application's own database role. **This describes controls that exist. It is not a certification, and no compliance claim is made.** ## 8. Contact **[LEGAL REVIEW REQUIRED — privacy contact, and whether a data protection officer or representative is required.]**
