Legal

Privacy Policy

PortalIQ is a campaign planning, validation and publishing platform for marketing teams and agencies. This policy explains what personal data we handle, why we handle it, who we share it with, how long we keep it, and the choices you have — including the data we access on your behalf through Meta's APIs.

Effective: 14 August 2026 Last updated: 14 August 2026 Version: 1.0

Contents

  1. Who we are
  2. Scope of this policy
  3. Data we collect
  4. How we use data
  5. Legal bases
  6. Meta integration and API usage
  7. Sharing and subprocessors
  8. International transfers
  9. Data retention
  10. Security
  11. Your rights
  12. Deleting your data
  13. Cookies and local storage
  14. Children
  15. Changes to this policy
  16. Contact us

1. Who we are

PortalIQ ("PortalIQ", "we", "us") provides a web platform at portaliqio.com that connects a customer's media plan to advertising platforms — principally Meta — validates campaign setup through those platforms' APIs, routes approvals, and publishes signed-off campaigns.

For the account data of the people who sign in to PortalIQ, and for the operation of the platform itself, PortalIQ is the data controller. For the advertising, Page and lead data we access from a customer's connected Meta assets, PortalIQ acts as a data processor on that customer's instructions: the customer decides what campaigns run and what data is collected through them, and we process it only to deliver the features they have asked for.

Questions about this policy go to privacy@portaliqio.com.

2. Scope of this policy

This policy covers the PortalIQ website, the PortalIQ workspace application, and the PortalIQ integrations with third-party advertising platforms. It does not cover the practices of those third-party platforms themselves — when you authorise PortalIQ to act on your Meta ad account or Facebook Page, Meta's own Privacy Policy continues to govern what Meta does with your data on its own systems.

It also does not cover the marketing campaigns our customers run. If you filled in a lead form on a Facebook or Instagram ad, the advertiser named on that ad is the controller of your information; PortalIQ only routes it on their behalf, and requests about that data should go to the advertiser. We will help any customer respond to such a request.

3. Data we collect

We collect four categories of data, and no more than the platform needs to function.

Account and workspace data
Your name, email address, hashed password or single sign-on identifier, workspace membership, role and permissions, and your in-app activity — approvals given, comments posted, and changes made to a campaign. Authentication is handled by Supabase Auth; we never store your password in plain text.
Campaign and planning data
The content you put into the platform: briefs, media plans, budgets and cost assumptions, flight dates, audience definitions, creative assets and copy, tracking URLs and naming taxonomies, QA and validation results, approval packs, and the finance references recorded at handoff. This is business data, though it may incidentally contain personal data such as the names of team members and client-side approvers.
Connected platform data
Data retrieved from advertising platforms you connect. From Meta this includes ad account and Page identifiers and names, campaign, ad set and ad structures, budgets, delivery status, performance metrics, and the access tokens issued to us when you authorise the connection. Where you run Meta lead ads through PortalIQ, it also includes the responses submitted to those lead forms — which typically contain a prospect's name, email address and phone number.
Technical and usage data
Server logs recording IP address, browser and device type, pages and API routes requested, timestamps, referring page, and diagnostic information about errors. We use this to keep the service running, secure and debuggable.

We do not collect special category data (health, biometrics, political opinions, and the like), we do not buy personal data from data brokers, and we do not operate advertising trackers or third-party analytics pixels on this website.

4. How we use data

Every use of data falls under one of the following purposes.

  • Providing the platform — authenticating you, creating and running your workspace, and storing the campaign work you create in it.
  • Validating campaigns — reading your planned lines against the connected platform APIs to check naming, budgets, audiences, creative specifications and tracking before anything is published, and applying the fixes you authorise.
  • Routing approvals — assembling approval packs, notifying the people who need to sign off, and recording who approved what and when.
  • Publishing — creating and updating campaigns, ad sets, ads and Page posts on the platforms you have connected, only when a campaign has been signed off and only when you trigger it.
  • Delivering leads — forwarding lead form responses from Meta to the destination you configure, and recording the delivery status so a failure is visible and can be retried.
  • Support and communication — responding to your requests and sending service messages about outages, security and material changes. We do not send marketing email to workspace users who have not asked for it.
  • Security and abuse prevention — detecting, investigating and stopping unauthorised access, fraud and misuse.
  • Improving the service — diagnosing faults and understanding which features are used, using aggregated or de-identified data wherever that is sufficient.
  • Legal compliance — meeting our obligations and establishing, exercising or defending legal claims.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use data obtained from Meta's APIs to build advertising profiles, to train models, or for any purpose other than delivering the feature you asked for.

6. Meta integration and API usage

Connecting Meta is optional and always initiated by you. When you do connect, you authorise PortalIQ through Facebook Login for Business, and Meta — not PortalIQ — collects your credentials. PortalIQ never sees or stores your Facebook password.

Permissions we request, and what each one is for

ads_read
Reads the campaigns, ad sets, ads, budgets and delivery data in the ad accounts you select, so PortalIQ can compare what is live against the plan that was approved.
ads_management
Creates and updates campaigns, ad sets and ads in those ad accounts when you publish a signed-off plan. Without it the connection is read-only.
pages_show_list
Lists the Facebook Pages your login administers, so you can choose which Page a campaign publishes to.
pages_read_engagement
Reads back the content of the Pages you select, so PortalIQ can confirm that what was published matches what was approved.
pages_manage_posts
Creates and updates posts on the Pages you select. This is the permission that publishes; posts are created as drafts or scheduled items according to the plan you approved.

We request the narrowest set of permissions that lets the features you have enabled work, and we do not request a permission in order to hold it in reserve. If you decline a permission, the feature that depends on it is disabled rather than silently degraded.

How Meta data is handled

  • Tokens stay server-side. Access tokens issued by Meta are exchanged and stored on our servers and are never written into your browser, never included in client-side code, and never exposed through our API responses.
  • Reads are scoped to what you connected. PortalIQ queries only the ad accounts and Pages you explicitly selected, and only through Meta's official Marketing API and Graph API.
  • Writes are gated on approval. Nothing is created or changed on Meta until a campaign has passed validation and been approved inside PortalIQ, and until a person triggers the publish.
  • Lead data is routed, not mined. Where you use Meta lead ads, we receive the lead notification, record the delivery for auditing, and forward the response to the destination you configured. We do not use lead data for our own purposes.
  • Platform Terms. We use Meta Platform Data only to provide and improve the features described here, in line with Meta's Platform Terms and Developer Policies, and we do not transfer it to data brokers or advertising networks.

Disconnecting

You can disconnect Meta at any time from the Connected Accounts module in the PortalIQ workspace, which deletes the stored tokens for that connection immediately and stops all further API access. You can also revoke PortalIQ's access from Meta's side under Settings › Business Integrations. Revoking on either side stops the integration; see Deleting your data for removing the data already retrieved.

7. Sharing and subprocessors

We share personal data only with the service providers that run the platform, and only to the extent they need it. We do not sell data or disclose it for anyone else's marketing.

Netlify
Application hosting, serverless functions and the application database.
Supabase
Authentication, workspace records and the OAuth handshake with Meta.
Meta Platforms
The advertising platform you connect. Data flows to Meta when you publish, and from Meta when PortalIQ reads campaign state or receives a lead.
Other platforms you connect
Where you enable them, the equivalent integrations for other advertising, reporting and workflow tools, on the same basis.

We may also disclose data where we are legally required to, to enforce our Terms of Service, or to protect the rights and safety of our users. If PortalIQ is involved in a merger, acquisition or sale of assets, data may transfer to the successor entity; we will give notice before any such transfer changes how your data is handled.

8. International transfers

Our providers operate globally, so personal data may be processed outside the United Kingdom and the European Economic Area, including in the United States. Where data leaves the UK or EEA we rely on the transfer mechanisms our providers make available — principally the European Commission's Standard Contractual Clauses together with the UK Addendum, and adequacy decisions where one applies. You can request details of the safeguards in place by writing to us.

9. Data retention

We keep data for as long as it is needed for the purpose it was collected for, and then delete it. In practice:

Account data
For as long as your account is active. Deleted within 30 days of the account being closed.
Campaign and planning data
For as long as the workspace is active, because campaign history is what the platform is for. Deleted within 30 days of a workspace deletion request.
Approval records and approval packs
Retained for 24 months after a campaign closes, as the audit record of who approved what. Deletable on request where no legal or contractual obligation requires us to keep them.
Meta access tokens
Deleted immediately when you disconnect the account, when Meta revokes or expires the token, or when the workspace is deleted.
Meta campaign and Page data
Cached copies are refreshed on each sync and removed within 30 days of the connection being removed.
Lead form responses
Retained for 90 days so a failed delivery can be diagnosed and retried, then deleted. Shorter periods can be configured on request.
Server and security logs
Retained for up to 90 days, except where a specific security investigation requires longer.
Backups
Encrypted backups roll off within 35 days. Data deleted from the live system persists in backups until they expire, and is not restored into production.

Where the law requires a longer period — for example for tax or accounting records — we keep the minimum necessary for that purpose and nothing else.

10. Security

These are the controls we operate today:

  • Encryption in transit. All traffic to and from PortalIQ is served over HTTPS with TLS, and HTTPS is enforced.
  • Encryption at rest. Databases and object storage are encrypted at rest by our infrastructure providers.
  • Credential isolation. Platform access tokens and API secrets are held in server-side environment configuration and server-side storage. They are never sent to the browser and never written into the client bundle.
  • Tenant isolation. Workspace records are protected by row-level security, so a signed-in user reaches only the workspaces they belong to.
  • Least privilege. Integrations request the narrowest permission set that makes the feature work, and internal access to production data is limited to the people who need it to run the service.
  • Managed infrastructure. We build on Netlify and Supabase and inherit their patching, network isolation and backup practices rather than running our own servers.

PortalIQ is an early-stage platform. We do not currently hold a SOC 2 or ISO 27001 certification, and we say so plainly rather than implying assurances we have not been audited against. No system can be guaranteed completely secure. If we become aware of a personal data breach affecting you, we will notify the relevant supervisory authority and affected users without undue delay, and within 72 hours where the law requires it.

If you believe you have found a security vulnerability, please report it to security@portaliqio.com rather than disclosing it publicly. We will acknowledge your report and keep you updated while we fix it.

11. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of data that is inaccurate or incomplete.
  • Erasure — deletion of your data where we have no overriding basis to keep it.
  • Portability — a copy of the data you gave us, in a structured, machine-readable format.
  • Restriction and objection — to stop or limit processing we carry out on the basis of legitimate interests.
  • Withdrawal of consent — at any time, without affecting processing already carried out. Disconnecting a platform integration withdraws the consent given for it.
  • Non-discrimination — under the CCPA/CPRA, we will not deny you service or offer you different terms because you exercised a privacy right. We do not sell or share personal information as those terms are defined.
  • Complaint — to your local supervisory authority. In the UK that is the Information Commissioner's Office. We would appreciate the chance to address it first.

To exercise a right, email privacy@portaliqio.com from the address on your account. We respond within 30 days, and will tell you if we need longer because a request is complex. We may need to verify your identity before acting. Requests are free unless they are manifestly unfounded or excessive.

If your data reached us through a customer's campaign — for example you submitted a lead form on their ad — we will forward your request to that customer and support them in answering it, because the data is theirs to control.

12. Deleting your data

You can have your data deleted in either of the following ways.

From inside PortalIQ

  • Open the PortalIQ workspace and go to the Connected Accounts module.
  • Disconnect the Meta account. Its stored access tokens are deleted immediately and API access stops.
  • To remove everything, email us to request deletion of the workspace and account.

By email

  • Write to privacy@portaliqio.com with the subject "Data deletion request", from the email address on the account, telling us whether you want a specific integration's data removed or the entire account.
  • We confirm receipt within 5 working days and complete the deletion within 30 days, then confirm in writing.
  • Encrypted backups expire on their own schedule within 35 days; deleted data is never restored into production from them.

From Meta

Data we are required to keep by law — for example invoicing records — is retained for the minimum period required and deleted afterwards. We will tell you if anything falls into that category.

13. Cookies and local storage

PortalIQ uses only what it needs to work. We set a session cookie and store an authentication token in your browser's local storage to keep you signed in, and we store interface preferences locally so the workspace opens the way you left it. If you connect Meta by pasting an access token rather than through the OAuth flow, that token is held in your browser's session storage for that tab only — it is cleared when the tab closes, when you sign out and when you disconnect. Connecting through OAuth stores nothing of the kind in your browser. There are no advertising cookies, no third-party analytics trackers, and no cross-site tracking on this site.

Clearing your browser storage signs you out. Both the marketing site and the signed-in workspace load fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com) and JavaScript libraries from public CDNs (esm.sh, cdn.tailwindcss.com), which receive your IP address as part of serving those files. Those four are the only third-party hosts either page contacts; no images, fonts or scripts are loaded from anywhere else.

14. Children

PortalIQ is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this policy

We update this policy when the platform changes or the law does. The effective date and version at the top of this page always reflect the current text. For material changes — a new category of data, a new purpose, a new class of recipient — we will notify account holders by email or through an in-app notice at least 14 days before the change takes effect, so you have time to object or close your account. Continued use after the effective date means you accept the updated policy. Previous versions are available on request.

16. Contact us

Reach us at any of the following, and we will respond within 30 days:

Privacy and data rights
privacy@portaliqio.com
Security reports
security@portaliqio.com
General support
support@portaliqio.com
Website
portaliqio.com

See also our Terms of Service.