Privacy Policy

Last updated: February 25, 2026

1. Data Controller

This privacy policy describes how Calimatic Technologies ("we," "us," or "our") collects, uses, and protects personal data through the Calimatic Meta Leads Integration service ("Service").

Contact: support@calimatic.com

2. Data We Collect

We collect the following data through our integration with Facebook and Meta Lead Ads:

  • Lead information submitted through Meta (Facebook) Lead Ad forms, including: name, email address, phone number, company name, and any other fields configured in the Lead Ad form
  • Meta Lead Ad identifiers: form ID, ad ID, lead ID, page ID
  • Facebook Page information: Page name and Page ID for pages you connect to the Service
  • OAuth tokens: access tokens issued by Meta to authenticate API requests on your behalf

3. How We Use Your Data

Lead data collected via Facebook Lead Ads is used solely to:

  • Retrieve lead submissions from Meta's API in real-time via webhooks
  • Transfer lead information to the advertiser's configured CRM system
  • Enable the advertiser to follow up on inquiries submitted through their Lead Ad forms

We do not use lead data for any purpose other than providing the Service. We do not use lead data for advertising, profiling, or analytics beyond what is necessary to deliver leads to your CRM.

4. Meta-Specific Data Practices

Our integration with Facebook and Meta platforms involves the following data practices:

  • Token storage: OAuth access tokens (user tokens and page tokens) are encrypted at rest using AES-256-GCM encryption. Tokens are used solely to authenticate API requests to Meta's Graph API.
  • Webhook data: We receive real-time lead notifications via Meta's webhook system. Webhook payloads are verified using HMAC-SHA256 signatures to ensure authenticity.
  • Scopes: We request only the permissions necessary to retrieve leads and manage webhook subscriptions:
    • leads_retrieval — Read lead data submitted through Lead Ad forms
    • pages_manage_ads — Access Lead Ad forms associated with your Pages
    • pages_manage_metadata — Subscribe Pages to webhook notifications for real-time lead delivery
    • pages_show_list — List Pages you manage so you can select which to connect
    • pages_read_engagement — Read Page engagement data required by the Leads API
  • Token refresh: Long-lived user tokens are refreshed before expiration to maintain uninterrupted service. Expired or revoked tokens are marked invalid and are not retained.

5. Data Storage & Security

All data is stored securely with encryption at rest. Access tokens and API keys are encrypted using AES-256-GCM encryption. Data is hosted on secure, SOC 2 compliant infrastructure. Access to production systems is restricted to authorized personnel only.

6. Data Retention

Lead data is retained for the duration specified by the advertiser's data retention policy. OAuth tokens are retained only while the integration is active and are invalidated upon disconnection or deauthorization. Data deletion requests are processed within 30 days.

7. Data Deletion

You can request deletion of your data in the following ways:

  • Email: Send a deletion request to support@calimatic.com with the subject line "Data Deletion Request"
  • Meta's data deletion callback: When you remove our app from your Facebook settings, Meta automatically sends a deletion request to our callback URL at https://connect.calimatic.com/compliance/data-deletion
  • Deauthorization: Revoking the app's access via Facebook settings triggers automatic token invalidation

Upon receiving a deletion request, we will invalidate all associated access tokens and anonymize lead data linked to your account. You will receive a confirmation code and a status URL to track the progress of your deletion request.

8. Third-Party Sharing

We do not sell, rent, or share your personal data with any third parties. Lead data is only transferred to the advertiser's designated CRM system as configured by the account administrator. We do not share data with data brokers or advertising networks.

9. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

  • Lawful basis: We process personal data based on legitimate interest (providing the Service as requested) and, where applicable, your consent provided through Meta's Lead Ad forms.
  • Right of access: You may request a copy of the personal data we hold about you.
  • Right to rectification: You may request correction of inaccurate personal data.
  • Right to erasure: You may request deletion of your personal data.
  • Right to restrict processing: You may request that we limit how we use your data.
  • Right to data portability: You may request your data in a structured, machine-readable format.
  • Right to object: You may object to the processing of your personal data.

Data controller: Calimatic Technologies acts as a data processor on behalf of the advertiser (data controller) for lead data. For data related to your use of the Service (account information, tokens), Calimatic Technologies is the data controller.

To exercise any of these rights, contact us at support@calimatic.com.

10. Your Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information.
  • Right to opt-out of sale: We do not sell personal information. No opt-out is necessary.
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to correct: You may request correction of inaccurate personal information.

To exercise any of these rights, contact us at support@calimatic.com.

11. Contact

For privacy inquiries, data requests, or concerns, please contact us at:

Calimatic Technologies
Email: support@calimatic.com