Data Security Policy
Last Updated: 8/14/2025
Scope
This policy applies to all data we handle, including:
- User-provided personal information (e.g., name, email address)
- Meta Platform Data received through the Meta Marketing API (e.g., ad account IDs, campaign and ad performance metrics, audience insights)
Encryption & Storage Security
- In Transit: All data is encrypted using TLS 1.2 or higher when transmitted.
- At Rest: All stored data is encrypted using AES-256 or equivalent standards.
- Hosting Security: Stored on secure, access-controlled servers with SOC 2 / ISO 27001 certifications.
Access Control
- Restricted to authorized personnel only, following least privilege.
- Strong credentials & MFA used for authentication.
- Access permissions reviewed at least quarterly.
Data Retention & Deletion
- Meta Platform Data retained only as long as necessary.
- Deleted within 30 days of account deletion or revocation.
- No unnecessary backups of personal or Meta data are stored.
Data Sharing & Processors
- Never sell personal data or Meta Platform Data.
- Shared only with approved providers:
- Supabase – hosting & database services
- OpenAI – analytics on aggregated, non-identifiable data
- All processors are bound by data protection agreements.
Incident Response
We investigate immediately, notify affected parties and authorities within 72 hours when required, and log all incidents for audit.
User Rights & Control
- Users may request access, correction, or deletion anytime.
- Meta users can revoke access via Meta settings.
- Revoked data deleted within 30 days.
Policy Updates
We may update this policy periodically. Significant changes will be communicated via email or in-app notification.
Purpose Limitation
- Request only minimum Meta permissions needed.
- Data used solely as described in our Privacy Policy.
- No automated decision-making without explicit consent.
User Consent & Control
- Users can view/manage granted permissions anytime.
- Revoked permissions trigger immediate data deletion within 30 days.
- For ads_management, actions only performed if explicitly initiated.
Audit & Logging
All API calls that modify campaigns, ads, or assets are logged with details and retained for 12 months, then securely deleted.
Change Management
- Update policies when new Meta permissions are required.
- Request user consent before enabling new permissions.
- Notify users in advance of impactful changes.
Testing & QA
We maintain a staging environment for testing with test accounts only — never live user data — unless explicitly authorized for troubleshooting.
Contact: privacy@alace.ai