Privacy Policy
This Privacy Policy describes how the Spend Stats team ("we", "us", "our") collects, uses, stores and shares information when you use the Spend Stats application ("Spend Stats", the "Service"), available at meta-tool.top. By connecting your Facebook account to the Service you agree to the practices described here.
In short: Spend Stats reads spending statistics of the advertising accounts you choose to connect and delivers them to your team's reporting. We collect only what is needed for that purpose, we never sell your data, and you can disconnect and request deletion at any time.
1. Who we are
Spend Stats is operated by the Spend Stats team. We act as the data controller for the personal data described in this Policy. Contact: [email protected].
2. What the Service does
Spend Stats is an internal reporting tool for media buying teams that work with the Spend Stats team. After a team member signs in with Facebook Login and grants permission, the Service uses the Meta Marketing API to read daily performance metrics of the advertising accounts that member manages, and aggregates those metrics in the team's reporting system. The Service has read-only access and does not modify ads, campaigns or accounts.
3. Information we collect
3.1 Information received from Meta Platforms
When you connect your Facebook account, we receive the following data through Facebook Login and the Meta Marketing API, subject to the permissions you grant:
| Data | Permission | Purpose |
|---|---|---|
| Your Facebook user ID, name and email address | public_profile, email | Identify who connected which accounts; contact you about the connection |
| List of advertising accounts you have access to: account ID, name, currency, time zone, status | ads_read | Know which accounts to report on |
| Business Manager (business portfolio) IDs and names you belong to | business_management | Discover advertising accounts owned by or shared with your businesses; group accounts by business |
| Aggregated daily performance metrics per advertising account: amount spent, impressions, clicks, reach and similar insight fields | ads_read | Produce spend reports for your team |
| An access token issued by Meta | — | Make API requests on your behalf while the connection is active |
We do not collect the content of your ads, your audiences, your personal posts, messages, friends list, or data about people who interact with your ads.
3.2 Information collected automatically
Our servers record standard technical logs: IP address, browser user agent, requested URL, timestamp and response status. Logs are used for security and troubleshooting and are retained for up to 30 days.
3.3 Cookies
The Service uses only strictly necessary cookies to keep you signed in during the connection process. We do not use advertising or analytics cookies.
4. How we use the information
- To authenticate you and link the advertising accounts you connect to your team.
- To retrieve and aggregate daily spend metrics and deliver them to the team's internal reporting system.
- To notify you when your connection needs to be renewed (Meta access tokens expire) or when an account becomes unavailable.
- To maintain the security, stability and integrity of the Service.
- To comply with legal obligations and Meta Platform Terms.
We do not use the information to build advertising profiles, to target advertising, or for any purpose unrelated to reporting on the advertising accounts you connected.
5. Legal basis
Where the GDPR or similar laws apply, we process your data on the basis of the performance of our agreement with you or your team (Art. 6(1)(b) GDPR), our legitimate interest in operating internal reporting for advertising activities we are engaged in (Art. 6(1)(f) GDPR), and, for the connection itself, your consent given through the Facebook Login dialog (Art. 6(1)(a) GDPR), which you may withdraw at any time by disconnecting the application.
6. How we share the information
We do not sell personal data. We share information only as follows:
- Within your team and the Spend Stats team. Spend metrics and the identity of the person who connected an account are visible to that team's leads and our staff responsible for reporting.
- Service providers. We use hosting providers and Cloudflare, Inc. for content delivery and security. These providers process data on our behalf under contractual obligations and may not use it for their own purposes.
- Meta Platforms. API requests are sent to Meta to retrieve the data described above, under Meta Platform Terms and Developer Policies.
- Legal requirements. We may disclose information when required by law, regulation or a valid legal request, or to protect our rights and the safety of others.
7. Data retention
| Data | Retention |
|---|---|
| Access tokens | Until you disconnect the application, the token expires, or you request deletion, whichever comes first. Expired tokens are removed within 30 days. |
| Your user ID, name, email | While your connection is active, and up to 30 days after disconnection or deletion request. |
| Advertising account list | While the connection is active. Removed within 30 days after deletion request. |
| Aggregated daily spend metrics | Retained as business records for financial reporting for as long as we work with the team and as required by accounting law. These records are business metrics of an advertising account, not personal data about you, and are kept in a form that does not identify you after your personal data is deleted. |
| Technical logs | Up to 30 days. |
8. Data security
Access tokens and personal data are stored encrypted at rest and transmitted only over HTTPS. Access to production systems is restricted to authorised staff using key-based authentication. We log access to tokens and never write tokens to application logs. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
9. International transfers
Our servers and service providers may be located outside your country. Where data is transferred from the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Your rights
Depending on your location, you may have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to lodge a complaint with a supervisory authority. To exercise these rights, email [email protected]. We respond within 30 days.
11. Disconnecting and deleting your data
You can disconnect Spend Stats at any time from your Facebook settings under Settings & Privacy → Settings → Apps and Websites. Disconnecting revokes our access token. To have your stored data deleted, follow the instructions on our Data Deletion page or email us. When Meta notifies us that you removed the application, we process the deletion request automatically.
12. Children
The Service is intended for business use by adults. We do not knowingly collect data from anyone under 18.
13. Compliance with Meta Platform Terms
Our use of data received from Meta complies with the Meta Platform Terms and Developer Policies. We use Platform Data only to provide the Service described here, we do not sell or license it, we do not use it for surveillance or for building user profiles, and we delete it when required by those terms or when you request it.
14. Changes to this Policy
We may update this Policy from time to time. The effective date at the top indicates the current version. Material changes will be communicated to connected users by email before they take effect.
15. Contact
Spend Stats
Email: [email protected]