Privacy Policy
This policy explains what data Freshlytics collects, why, how long we keep it and what you can ask us to do with it.
1. Who we are
Freshlytics is a campaign optimization and reporting platform for TikTok Ads, operated by Noa Digital ("Freshlytics", "we", "us"). For personal data described in this policy, Noa Digital is the controller unless stated otherwise. You can reach us at privacy@freshlytics.site.
2. Scope of this policy
This policy covers the Freshlytics website at freshlytics.site, the Freshlytics web application, and the communications we send to customers and people who contact us. It does not cover TikTok's own processing of your data — see the TikTok Privacy Policy and the terms of your TikTok advertiser account for that.
3. Data we collect
3.1 Data you give us
- Account data: name, work email address, company name, role, and a password hash or single sign-on identifier.
- Workspace configuration: target CPA and ROAS values, alert routing, saved views, automation rules and similar settings you create.
- Communications: the content of emails, beta access requests and support messages you send us, including anything you choose to include in them.
- Advertising assets and inputs: the videos, images, product feeds, audience lists and event data you upload or connect so that Freshlytics can publish them to TikTok on your behalf.
3.2 Data we receive from TikTok on your instruction
When you authorize Freshlytics for one or more TikTok ad accounts, we receive advertising data through the TikTok Marketing API. This is described in section 4.
3.3 Data collected automatically
- Application logs: IP address, browser user agent, timestamps and the requests made to our application, used for security, debugging and abuse prevention.
- Website server logs: standard access logs kept by our hosting and CDN providers.
We do not use advertising trackers, third-party analytics scripts, session recording or fingerprinting on this website.
4. TikTok advertising data
Freshlytics accesses TikTok data only through the official TikTok Marketing API, only for ad accounts you explicitly authorize, and only with the permissions listed on our how it works page. We never scrape TikTok, never use unofficial endpoints or browser automation, and never ask for your TikTok password.
4.1 What we read from your ad accounts
- Ad account details: name, ID, currency, time zone, status and Business Center relationships
- Campaign, ad group and ad structure: objectives, budgets, bid strategies, schedules, placements, targeting summary and delivery status
- Performance reporting: spend, impressions, clicks, conversions, video engagement and cost metrics, by day and by hour
- Creative metadata: creative IDs, names, formats and thumbnails
- Catalogs and products: catalog structure, product attributes, availability, review status and rejection reasons
- Pixels, custom conversions and audience lists that exist in your account — their names, IDs and configuration, so they can be selected when building a campaign
- Delivery diagnostics, rejection reasons and, where you use Spark Ads, the posts you have authorized for advertising
- Comments on your own ads, where you enable comment moderation
4.2 What we write, and only on your instruction
Freshlytics creates and updates objects in your ad accounts when you publish a launch batch, approve a recommendation or enable an automation rule: campaigns, ad groups and ads; uploaded videos and images; catalogs, feeds and product updates; audiences; custom conversions; budget, bid, schedule and status changes; and comment moderation actions on your own ads. Every write is recorded in an audit log with the user, the source and the values behind it.
4.3 Data you provide for advertising purposes
Some features involve personal data that belongs to you and your customers rather than to TikTok:
- Custom audiences. Customer identifiers you upload or connect for audience building. Identifiers are hashed before transmission where TikTok requires it, are used solely to create or update the audience you asked for, and are deleted from our systems once the audience has been delivered or on your request.
- Server-side conversion events. Event data you send from your own systems, including hashed identifiers used for matching, forwarded to TikTok for optimization and measurement of your campaigns.
- Lead form submissions. Where you run lead generation ads, the submissions from your own ads — which contain personal data provided by the person filling in your form. We retrieve them and deliver them to the CRM or webhook you configure. We store them only as long as needed to deliver them and, by default, for no more than 30 days.
For all of this data you are the controller and Freshlytics is your processor. We use it only to provide the feature you enabled, never for any other customer, never to enrich profiles, never for our own marketing, and we do not sell or share it. A Data Processing Agreement is available on request.
4.4 What we never receive or request
- Personal data about the TikTok users who saw or clicked your ads — TikTok's reporting is aggregated and we do not attempt to de-aggregate it
- Organic account content, followers, direct messages, or any TikTok user's profile data
- Creator Marketplace or creator personal data
- Your TikTok password — authorization happens entirely inside TikTok's OAuth flow
- Any permission that would let Freshlytics post organic content, follow accounts or interact outside your own ads
4.5 Deletion
You can disconnect an ad account at any time, which stops all further collection. On request we delete the associated data as described in section 9 and on our data deletion page. We also honour the deletion and retention requirements imposed by TikTok's developer terms.
5. How we use data
- To provide, operate and secure the Freshlytics service
- To sync, normalize, analyse and display your advertising data
- To send you the alerts, reports and notifications you configure
- To answer support requests and beta access enquiries
- To monitor for abuse, debug problems and improve reliability
- To send occasional service messages, such as changes to this policy or to pricing
- To comply with legal obligations
We do not use your data for behavioural advertising, and we do not sell or share personal data as those terms are defined under the CCPA/CPRA.
6. Legal bases (GDPR)
- Contract: providing the service to you and your workspace.
- Legitimate interests: securing the service, preventing abuse, improving reliability, and responding to your enquiries — balanced against your rights.
- Consent: where required, for example optional product update emails, which you can withdraw at any time.
- Legal obligation: for accounting, tax and lawful requests.
7. Sharing and sub-processors
We share data only with the service providers needed to run Freshlytics, under contracts that restrict their use of it. The current list is published on our Security & data page and includes our hosting provider, our CDN provider and our transactional email provider.
We may also disclose data if required by law, to protect our rights or the safety of others, or as part of a merger or acquisition — in which case we will notify affected customers in advance and the acquirer will remain bound by this policy.
We do not sell personal data. We do not disclose your advertising data to other customers.
8. International transfers
Our servers are located in the European Union. Where a sub-processor is outside the EEA or the UK, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism. A copy of the relevant safeguards is available on request.
9. Retention
- Account data: for as long as your account exists, then deleted within 30 days of a deletion request.
- TikTok authorization tokens: until you disconnect the ad account or revoke access in TikTok Business Center, then deleted promptly.
- Advertising data: rolling 13 months, so year-on-year comparisons work; deleted earlier on request.
- Uploaded creatives and catalog data: for as long as the ad account is connected, then deleted with the workspace.
- Audience source data and server-side event payloads: deleted once delivered to TikTok, and in any case within 30 days.
- Lead form submissions: deleted once delivered to your CRM or webhook, and in any case within 30 days.
- Application and access logs: 30 days.
- Business records: invoices and similar records for as long as tax law requires.
- Backups: encrypted backups roll over within 14 days, after which deleted data no longer exists in them.
10. Security
We use TLS for data in transit, AES-256 encryption at rest, encrypted storage of OAuth tokens, role-based access control, mandatory two-factor authentication for staff with production access, and audit logging. Details are on the Security & data page. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant supervisory authority as required by law, without undue delay and within 72 hours of becoming aware.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you
- correct inaccurate data
- delete your data ("right to be forgotten")
- restrict or object to processing, including profiling
- receive your data in a portable, machine-readable format
- withdraw consent at any time, without affecting prior processing
- not be discriminated against for exercising CCPA/CPRA rights
- lodge a complaint with your data protection authority
To exercise any of these, email privacy@freshlytics.site. We answer within 30 days and may ask you to verify your identity first. If you are an end user of one of our customers, please contact that customer — we will forward your request to them and assist as their processor.
12. Cookies
This marketing website sets no cookies and loads no third-party trackers. The Freshlytics web application uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or analytics cookies in the application. If that ever changes, we will ask for consent first and update this section.
13. Children
Freshlytics is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the product changes. The "last updated" date at the top always reflects the current version, and we notify workspace owners by email before any material change takes effect.
15. Contact
Noa Digital — Freshlytics
Privacy and data requests: privacy@freshlytics.site
General enquiries: support@freshlytics.site
Website: freshlytics.site