Privacy Policy
Ad Launcher ("the App") is a business tool operated by maycol@olivinebeauty.com ("we", "us"). It lets a business build, launch and manage advertising for its own brand: connecting its own Meta ad account and Facebook Page, its own Shopify store, and preparing the ad creative it chooses to run. It is used by invited business operators — it has no consumer audience and no self-serve signup.
What we collect
Your App account. A name, an email address, and a password stored only as a salted scrypt hash. Signing in sets one session cookie (httpOnly, expires after 14 days). We use no analytics or advertising cookies.
Meta connection. When a business admin connects through Facebook Login for Business, the App receives — with Meta's permission dialog as the gate — the identifiers of the business assets that admin selects (an ad account ID, a Facebook Page ID, a pixel ID, and where linked an Instagram account), and a business integration access token scoped to those selections. Tokens are encrypted at rest, held server-side only, and never appear in a browser, an API response, or a log. The App requests no personal profile data — no friends, no feed, no personal timeline; the permissions used are business asset permissions only (ads_management, ads_read, business_management, pages_show_list, pages_read_engagement).
Shopify connection. A store domain and the credentials of a custom app that the business itself creates in its own store, used to read product titles and URLs so ads have a destination. Stored encrypted, server-side only.
Ad creative and sourcing. Video and image files uploaded or prepared for the business's ads, stored in private cloud storage. Public marketplace listing metadata (for example TikTok listing statistics) used to source creative ideas. Uploaded creative may be processed by AI services to tag and prepare it; no personal data of yours is sent for that purpose.
Operational records. An audit log of actions taken in the App (who, what, when, and for money-affecting actions the IP address), kept so that ad spend is attributable and reviewable.
How we use it
- To operate the App at the connected business's direction: listing its assets, building its ads in a paused state, and changing ad status only on an explicit operator action.
- To keep each business's workspace isolated — one business's data is never shown to, or used for, another.
- To secure the App and investigate misuse, using the audit log.
We do not sell data, share it for advertising, or use one business's data to benefit another. Data from Meta's platform is used only to provide the App's features to the business that granted it, per Meta's Platform Terms.
Where it lives
The App runs on Railway (hosting, United States) with data in a managed database, and stores creative files in Amazon S3. Requests the App makes to Meta, Shopify and other platforms go directly to those platforms at the connected business's instruction.
Retention and deletion
Connection credentials are kept while the workspace is active and removed when the connection is replaced or the workspace is closed. Ad creative and records are kept while the workspace is active. You can request deletion of your account or your business's data at any time — see Data deletion, or write to maycol@olivinebeauty.com. A business can also revoke the App's access in its own Meta Business settings or Shopify admin at any moment, which invalidates the tokens we hold.
Contact and changes
Questions and requests: maycol@olivinebeauty.com. If this policy changes, the new version is posted at this address with a new effective date.