Legal
Privacy Policy
Last updated
This policy explains what information CrossLion collects, why we collect it, how we store it, and how you can control it.
1.Scope
This policy applies to the CrossLion website, the ads management dashboard, and the ad account resources and managed media buying services that go with them.
It does not apply to how third-party platforms such as Meta (Facebook, Instagram) handle your data themselves. To understand how your data is used on those platforms, read their own privacy policies.
2.Information obtained through Facebook authorization
After you sign in with Facebook and complete authorization, we obtain and store the following through Meta's official APIs:
- Public profile — your name and Facebook user ID
- Business Manager (BM) — the names and IDs of the BMs you have access to
- Ad accounts — basic information about the ad accounts you have access to, such as name, ID, currency, and account status
- Pages — the names and IDs of the Pages you have access to, used to choose which Page an ad runs under
- Access token — the long-lived credential we use to call Meta's APIs on your behalf, together with the list of permissions you actually granted
We do not obtain your Facebook password, messages, friend list, or photo albums, and we do not read personal information unrelated to running ads.
3.Your platform account information
The platform has its own account system, separate from Facebook. The related information includes:
- Username, account type (admin / staff), and account status
- Password — stored as a bcrypt hash; we cannot recover your original password
- Notes and other supporting details entered by an admin
4.Usage and security logs
For account security, troubleshooting, and traceable team collaboration, the platform records:
- Sign-in records — sign-in time, last active time, source IP, User-Agent, and a device summary (for example Chrome / macOS)
- Session records — the devices currently signed in, so you can review them in the dashboard and revoke the ones you no longer use
- Audit logs — for every write operation: the event type, who performed it, what it acted on, the time, the source IP, and the User-Agent
Admins' own actions are logged in the same way, and the logs cannot be edited from anywhere in the product.
5.How we use this information
We use the information above only for the following purposes:
- Creating and managing campaigns, ad sets, and ads on Meta on your behalf
- Uploading ad creatives and creating dark posts on your behalf
- Reading performance data and reports and showing them to you
- Syncing changes to the Business Managers and ad accounts under your control
- Keeping accounts secure, investigating faults, and meeting our legal obligations
We do not use this information for user profiling or targeted marketing, and we do not use it to train any model.
6.What we will never do
- Sell your personal information or business data to any third party
- Share your Facebook authorization data for any purpose other than running ads
- Ask for or store your Facebook password
- Access advertising assets you have not authorized us to access
7.Sharing and disclosure
Your information leaves our systems only in the following situations:
- Submitted to Meta — to carry out the ad operations you request, the relevant data is submitted through Meta's official APIs (Graph API / Marketing API) and is then governed by Meta's data policy
- Legal requirements — when a competent authority makes a lawful request through due process, we will cooperate to the extent the law requires
- Business changes — in a merger, acquisition, or transfer of assets, we will notify you before any transfer and require the receiving party to maintain protection standards no lower than those in this policy
8.Storage and security
- Data is stored in a PostgreSQL database on our own servers; we do not use any third-party data platform
- Facebook access tokens are stored encrypted and decrypted only when calling Meta's APIs
- Platform account passwords are stored as bcrypt hashes; we never keep them in plain text
- All traffic to the website and the dashboard is encrypted over HTTPS
No system can guarantee absolute security. If a data security incident occurs that could affect your interests, we will notify the affected users as soon as we have established what happened.
9.Retention
We keep data for "the shortest period necessary to achieve the purpose it was collected for".
Facebook authorization data — once you remove the authorization on Facebook, or send us a deletion request, the corresponding access token and advertising asset information are erased.
Platform accounts and logs — when an account is closed, the account information and the associated authorization data are deleted. For security auditing and legal obligations, some audit logs may be retained for a period after identifying information has been stripped out. We will publish the specific retention periods on this page once they are settled.
10.Your rights
At any time, you can:
- Review — see your account information, signed-in devices, and audit logs in the dashboard
- Correct — contact us to fix inaccurate account information
- Revoke — remove this app on Facebook under Settings → Business Integrations
- Delete — ask us to delete all of the data we hold about you
See our Data Deletion Instructions for how deletion works and how long it takes.
11.Cookies and local storage
The website carries no ads and includes no third-party analytics or tracking scripts, and it does not use tracking Cookies.
The ads management dashboard stores your sign-in token in your browser's localStorage to keep you signed in. Clearing your browser data signs you out.
12.Minors
Our services are built for businesses and professional media buyers, not for individuals under 18. If we find that we have collected a minor's information, we will delete it promptly.
13.Cross-border data transfers
Using the platform to run ads on Meta on your behalf necessarily involves transferring data to Meta's global infrastructure, where it is governed by Meta's data policy.
If your region imposes specific requirements on transferring personal information abroad, please confirm that this arrangement complies with local law before you use the services.
14.Changes to this policy and how to reach us
We may update this policy as our business and the applicable regulations change. When we do, the date at the top of this page changes with it, and we will give separate notice of significant changes.
If you have questions about this policy, or want to exercise any of the rights above, contact us through the channels listed in the footer.