Privacy Policy
SupaReach connects to your Meta advertising account to build, launch, and optimize ad campaigns. That means we handle data belonging to you and to the businesses you advertise for. This page explains exactly what we collect, why, where it goes, and how to get it deleted.
This document describes our actual data handling and is written to be accurate, but it has not been reviewed by a lawyer. Have counsel review it before relying on it for Meta App Review, GDPR, or CCPA compliance.
1. Who we are
SupaReach (“we”, “us”) provides software that manages advertising campaigns on Meta platforms. We act as adata processor for the advertising data you connect, and as a data controller for your own account details. We are not affiliated with, endorsed by, or operated by Meta Platforms, Inc.
2. What we collect
Account information
When you create an account we collect your name, email address, and organization membership. Authentication is handled by Clerk; we never receive or store your password.
Meta advertising data
When you connect an ad account, you grant permissions through Meta’s OAuth flow. We request only what the product needs:
| Permission | Why we need it |
|---|---|
| ads_read | Read campaign structure and performance metrics |
| ads_management | Create, pause, and adjust campaigns, ad sets, and ads |
| business_management | Identify which ad accounts you have a role on |
| pages_show_list | Let you choose the Page ads are published under |
Through those permissions we store ad account identifiers, campaign, ad set, and ad structure, creative content, and daily performance metrics such as spend, impressions, clicks, and conversions.We do not collect Custom Audience membership, customer lists, or any personal data about the people your ads reach.Metrics we receive from Meta are aggregate figures.
Product and campaign inputs
When you paste a product link we fetch that page to read its copy, images, and reviews so we can generate ad creative. We also store the campaign settings, budgets, and guardrails you configure, and an audit log of every change made in the product — by you or automatically.
3. Cookies and advertising tools
This marketing site carries the Meta pixel. We run ads on Facebook and Instagram to reach people who might use SupaReach, and the pixel is how we tell which of those ads actually work — without it we would be paying for traffic we cannot tell apart.
It sets two cookies in your browser:
_fbp— a random identifier for this browser, so a visit and a later signup can be recognised as the same person._fbc— set only if you arrived by clicking one of our ads, and it records which ad that was.
Two events are reported to Meta: a page view, and alead when you join the waitlist. The lead is sent twice — once from your browser and once from our servers — carrying one shared identifier so it is counted a single time. The server-side copy includes an irreversible SHA-256 hash of the email address you submitted, along with the cookies above, your IP address and your browser user agent. Your address itself is never sent to Meta in readable form.
That is the whole of it. We run no analytics suite, no session recording, no advertising cookies inside the product, and nothing here is shared with any other advertiser or data broker. Two other things this site stores are not tracking at all and never leave your device: your light or dark theme preference, and — if you are signed in — the fact that you asked to stay on the marketing site rather than be sent to the dashboard. Signing in sets session cookies belonging to Clerk, which are strictly necessary for the product to work.
You can switch the advertising tracking off:
- Block the cookies — your browser’s cookie or tracking-protection settings will do it, and several browsers block these by default. The site works exactly the same without them.
- Change what Meta does with it — Facebook Settings → Ads → Ad settings controls how your activity off Meta’s platforms is used, including data we send.
- Ask us to erase it — email[email protected].
We do not currently show a cookie consent banner. If you are somewhere that requires your consent before cookies like these are set, use your browser’s controls above — and tell us, because we would rather hear it than assume.
4. How we use it
- To create ad creative and campaign structures from your inputs.
- To publish and adjust campaigns on Meta on your behalf, within the budget caps and cost limits you set.
- To show you performance reporting and generate written summaries.
- To keep an audit trail of automated and manual actions.
- To operate, secure, and support the service.
We do not sell your data, and we do not use your advertising data to train machine learning models.
5. Who we share it with
We share data only with the providers needed to run the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Meta Platforms | Reading and managing your campaigns | Campaign structure, creative, budgets |
| Meta Platforms | Measuring which of our own ads brought you here | Hashed email address, ad click identifiers, IP address, browser user agent |
| Clerk | Authentication and organization management | Name, email, org membership |
| Neon | Database hosting | All stored application data |
| Google (Gemini), via OpenRouter | Generating ad copy, insights, and report summaries | Product descriptions and aggregate campaign metrics sent as prompts |
We may also disclose data where required by law, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different privacy policy.
6. How we protect it
- Meta access tokens are encrypted at rest using symmetric (Fernet) encryption, never stored in plain text.
- All traffic is served over TLS.
- Data is separated by workspace, so one organization cannot read another’s campaigns or reports.
- Automated changes run inside the budget caps, cost floors, and daily action limits you configure, and every one is written to an audit log you can review.
7. How long we keep it
We keep your data for as long as your account is active. If you disconnect an ad account, we delete its stored access token immediately. If you close your account, we delete your data within 30 days, except where we are required to retain records by law.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. To exercise any of these, email[email protected]. We respond within 30 days.
9. Deleting your data
You can remove your data at any time:
- Disconnect a Meta ad account — go to Settings → Connections and disconnect. The stored access token is deleted immediately.
- Revoke access from Meta — visit your Facebook Settings → Business Integrations and remove SupaReach.
- Delete your account and all associated data — email[email protected] and we will erase it within 30 days and confirm when done.
10. International transfers
Our providers may process data in the United States and other countries. Where data is transferred out of the UK or EEA, we rely on the transfer mechanisms offered by those providers, such as Standard Contractual Clauses.
11. Children
SupaReach is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
If we make material changes we will update the date at the top of this page and notify account holders by email before the changes take effect.
13. Contact
Privacy questions and data requests:[email protected]
Everything else: [email protected]