SupaReach
LEGAL

Privacy Policy

Last updated 11 September 2026

SupaReach connects to your Meta advertising account to build, launch, and optimize ad campaigns. That means we handle data belonging to you and to the businesses you advertise for. This page explains exactly what we collect, why, where it goes, and how to get it deleted.

This document describes our actual data handling and is written to be accurate, but it has not been reviewed by a lawyer. Have counsel review it before relying on it for Meta App Review, GDPR, or CCPA compliance.

1. Who we are

SupaReach (“we”, “us”) provides software that manages advertising campaigns on Meta platforms. We act as adata processor for the advertising data you connect, and as a data controller for your own account details. We are not affiliated with, endorsed by, or operated by Meta Platforms, Inc.

2. What we collect

Account information

When you create an account we collect your name, email address, and organization membership. Authentication is handled by Clerk; we never receive or store your password.

Meta advertising data

When you connect an ad account, you grant permissions through Meta’s OAuth flow. We request only what the product needs:

PermissionWhy we need it
ads_readRead campaign structure and performance metrics
ads_managementCreate, pause, and adjust campaigns, ad sets, and ads
business_managementIdentify which ad accounts you have a role on
pages_show_listLet you choose the Page ads are published under

Through those permissions we store ad account identifiers, campaign, ad set, and ad structure, creative content, and daily performance metrics such as spend, impressions, clicks, and conversions.We do not collect Custom Audience membership, customer lists, or any personal data about the people your ads reach.Metrics we receive from Meta are aggregate figures.

Product and campaign inputs

When you paste a product link we fetch that page to read its copy, images, and reviews so we can generate ad creative. We also store the campaign settings, budgets, and guardrails you configure, and an audit log of every change made in the product — by you or automatically.

3. Cookies and advertising tools

This marketing site carries the Meta pixel. We run ads on Facebook and Instagram to reach people who might use SupaReach, and the pixel is how we tell which of those ads actually work — without it we would be paying for traffic we cannot tell apart.

It sets two cookies in your browser:

Two events are reported to Meta: a page view, and alead when you join the waitlist. The lead is sent twice — once from your browser and once from our servers — carrying one shared identifier so it is counted a single time. The server-side copy includes an irreversible SHA-256 hash of the email address you submitted, along with the cookies above, your IP address and your browser user agent. Your address itself is never sent to Meta in readable form.

That is the whole of it. We run no analytics suite, no session recording, no advertising cookies inside the product, and nothing here is shared with any other advertiser or data broker. Two other things this site stores are not tracking at all and never leave your device: your light or dark theme preference, and — if you are signed in — the fact that you asked to stay on the marketing site rather than be sent to the dashboard. Signing in sets session cookies belonging to Clerk, which are strictly necessary for the product to work.

You can switch the advertising tracking off:

We do not currently show a cookie consent banner. If you are somewhere that requires your consent before cookies like these are set, use your browser’s controls above — and tell us, because we would rather hear it than assume.

4. How we use it

We do not sell your data, and we do not use your advertising data to train machine learning models.

5. Who we share it with

We share data only with the providers needed to run the service:

ProviderPurposeData involved
Meta PlatformsReading and managing your campaignsCampaign structure, creative, budgets
Meta PlatformsMeasuring which of our own ads brought you hereHashed email address, ad click identifiers, IP address, browser user agent
ClerkAuthentication and organization managementName, email, org membership
NeonDatabase hostingAll stored application data
Google (Gemini), via OpenRouterGenerating ad copy, insights, and report summariesProduct descriptions and aggregate campaign metrics sent as prompts

We may also disclose data where required by law, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different privacy policy.

6. How we protect it

7. How long we keep it

We keep your data for as long as your account is active. If you disconnect an ad account, we delete its stored access token immediately. If you close your account, we delete your data within 30 days, except where we are required to retain records by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. To exercise any of these, email[email protected]. We respond within 30 days.

9. Deleting your data

You can remove your data at any time:

10. International transfers

Our providers may process data in the United States and other countries. Where data is transferred out of the UK or EEA, we rely on the transfer mechanisms offered by those providers, such as Standard Contractual Clauses.

11. Children

SupaReach is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

12. Changes to this policy

If we make material changes we will update the date at the top of this page and notify account holders by email before the changes take effect.

13. Contact

Privacy questions and data requests:[email protected]
Everything else: [email protected]