Privacy Policy — Facebook Login & Marketing API

Last updated: 4/29/2025

This Privacy Policy describes how ScaleCommerce Inc., DBA Popsixle ("Popsixle", "we", "us") collects, uses, and shares information in connection with our website and software (the "Software"), including our use of Meta (Facebook) Login and the Marketing API. By accessing or using the Software, you consent to this policy.

Facebook Login and App Purpose

Popsixle uses Facebook Login for OAuth authentication to obtain a long‑lived User Access Token with Marketing API scopes. We use this token only to:

  • Authenticate you into the Popsixle app.
  • Discover assets you can access (ad accounts and pixels).
  • Read Ads Insights for a user‑selected ad account.
  • Send Conversions API (CAPI) events using a Pixel access token (recommended) or a system user token. We do not send CAPI using your user token.

Information We Collect

Account & App Information

  • Username and email you provide to Popsixle.
  • Facebook account identifiers and granted scopes necessary to access allowed assets.
  • Asset listings (ad accounts, pixels) and configuration metadata you select for use.

Website & Event Data

  • Hashed user information (e.g., name, email, phone) supplied by you or your site visitors (hashed with SHA‑256).
  • Non‑personal data (cookies, IP, device, browser/OS, referrers).
  • Non‑personal web events (clicks, page views, session data) for analytics and CAPI.

If non‑personal data becomes identifiable by combination, we treat it as Personal Information.

How We Use Information

  • Provide and improve the Software and related services.
  • Authenticate users and retrieve permitted assets (ad accounts, pixels).
  • Fetch Ads Insights for analysis and reporting you request.
  • Deliver compliant server‑side CAPI events via pixel access token (or system user token), not your user token.
  • Operate, secure, and research usage to enhance performance and reliability.

Sharing & Disclosure

  • We share data with your connected advertising accounts as needed to provide functionality (e.g., CAPI events to your pixel).
  • We may share limited data with service providers (hosting, storage, operations) to run the Software.
  • We may disclose information to comply with law or to protect rights, safety, or integrity.

Retention & Deletion

We retain information only as long as necessary to provide the Software and meet legal or operational requirements. You can request deletion of your Popsixle data or data obtained via Facebook Login by contacting success@popsixle.com. Include your account email and "Facebook Data Deletion" in the subject.

Security

We employ technical and organizational measures to protect information, but no method is 100% secure. Transmission and storage risks remain.

Children

We do not knowingly collect personal data from children under 13.

Territoriality

Data may be processed in the United States. By using the Software, you consent to such processing and U.S. law governing such processing.

Contact

Questions or requests (including data deletion): success@popsixle.com