1. Introduction
Meta to Sheets ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
2.1 Information You Provide
- Google account information (name, email) when you sign in
- Meta (Facebook) Ads account credentials and access tokens
- Import configuration data (metrics, date ranges, spreadsheet IDs)
- Payment information (processed securely by Stripe)
2.2 Automatically Collected Information
- Usage data (features used, import frequency)
- Device information (browser type, operating system)
- Log data (IP address, timestamps, error logs)
- Analytics data via Google Analytics 4 (with user consent)
- Conversion tracking via Meta Pixel (with user consent)
2.3 Third-Party Data
- Meta Ads performance data via Meta Marketing API
- Google Sheets metadata via Google Sheets API
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Service
- Process your imports from Meta Ads to Google Sheets
- Manage your account and subscription
- Send you service-related notifications (import status, payment reminders)
- Improve and optimize the Service
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
4.1 Service Providers
- Google (Google Sheets API): To write data to your spreadsheets
- Google Analytics: To analyze usage and improve our service (with consent)
- Meta (Marketing API): To fetch your advertising data
- Meta Pixel: To measure conversions and optimize marketing (with consent)
- Stripe: To process payments securely
- Vercel / Railway: To host our application and workers
- Sentry: To monitor errors and improve service reliability
- Resend: To send transactional emails
4.2 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, government regulations).
5. Data Security
We implement appropriate technical and organizational security measures to protect your personal information, including:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- OAuth 2.0 for secure authentication
- Regular security audits and updates
- Access controls and authentication
However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your personal information only for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy. Import logs are retained for 90 days. You can request deletion of your account and data at any time.
7. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data
- Portability: Request transfer of your data
- Objection: Object to processing of your data
- Withdraw Consent: Revoke OAuth permissions at any time
To exercise these rights, contact us at support@example.com
8. Data Deletion
8.1 How to Delete Your Data
You can request deletion of your data through any of the following methods:
- Account Settings: Log in to your account, go to Settings, and click "Delete Account"
- Email Request: Send a deletion request to support@metatosheets.com
- Meta Account: Remove the app from your Facebook settings (triggers automatic deletion)
- Google Account: Revoke access from your Google Account settings
8.2 What Gets Deleted
When you request data deletion, we permanently remove:
- Your account information (name, email)
- Meta Ads account connections and OAuth tokens
- Google Sheets access tokens and refresh tokens
- Saved import configurations
- Scheduled jobs and automation settings
- Import history and logs
- Billing information (except what Stripe must retain for compliance)
8.3 Deletion Timeline
- Immediate: OAuth tokens are revoked and access is disabled
- Within 24 hours: Account data is marked for deletion
- Within 30 days: All personal data is permanently deleted from our systems
- Backup retention: Data in backups is purged within 90 days
8.4 Data We Cannot Delete
For legal and compliance reasons, we may retain certain data:
- Transaction records required by financial regulations (via Stripe)
- Anonymized analytics data that cannot be linked back to you
- Data required for ongoing legal proceedings
- Aggregate usage statistics (anonymized)
8.5 Deletion Confirmation
After deletion, you will receive a confirmation code that you can save for your records. If you initiated deletion through Meta or Google, you'll be redirected to a confirmation page with details of what was deleted.
9. Meta (Facebook) Data Usage
9.1 What Meta Data We Access
When you connect your Meta Ads account, we access:
- Your advertising account information (account ID, name, currency)
- Campaign, Ad Set, and Ad data (names, IDs, statuses)
- Performance metrics (spend, impressions, clicks, conversions, ROAS)
- Creative information (ad images, copy) for Pro and Enterprise users
- Date-range filtered insights as specified in your import configuration
9.2 How We Use Meta Data
We use your Meta Ads data solely to:
- Fetch advertising performance metrics via Meta Marketing API
- Export the data to your chosen Google Sheet
- Display import history and status in your dashboard
- Execute scheduled automatic exports
We do NOT:
- Create, modify, or delete any ads, campaigns, or ad sets
- Share your Meta Ads data with third parties
- Store your ad performance data permanently (only import logs)
- Use your data for advertising or marketing purposes
9.3 Meta Data Storage
- OAuth Tokens: Encrypted and stored in PostgreSQL database
- Account Information: Account ID, name, and currency (metadata only)
- Performance Data: NOT stored permanently, only used during export
- Import Logs: Metadata about imports (date, row count, status) kept for 90 days
9.4 Disconnecting Meta Account
You can disconnect your Meta Ads account at any time from Settings. This will:
- Immediately revoke our access to your Meta Ads data
- Delete all OAuth tokens from our system
- Disable any scheduled imports using that account
- You can also revoke access directly from your Facebook settings
10. Cookies and Tracking
We use cookies and similar tracking technologies to improve your experience and understand how you use our service. We comply with GDPR and implement Google Consent Mode v2.
10.1 Essential Cookies
These cookies are necessary for the service to function and cannot be disabled:
- Authentication cookies: To keep you logged in
- Session cookies: To maintain your session state
- Security cookies: To prevent fraud and abuse
10.2 Analytics Cookies (Optional)
With your consent, we use analytics cookies to understand how users interact with our service:
- Google Analytics 4: Tracks page views, events, and user behavior
- Data collected: Pages visited, features used, time spent, device info
- Anonymization: IP addresses are anonymized
- Retention: Data is retained for 26 months
10.3 Marketing Cookies (Optional)
With your consent, we use marketing cookies to measure ad performance:
- Meta Pixel: Tracks conversions and optimizes ad campaigns
- Data collected: Sign-ups, subscription purchases, page views
- Purpose: To measure ROI and improve our marketing
10.4 Your Consent Choices
You have full control over optional cookies:
- When you first visit, a banner will ask for your consent
- You can accept or reject analytics and marketing cookies
- Your choice is saved for future visits
- You can change your preferences at any time by clearing your browser cookies
- Rejecting cookies will not affect core functionality
10.5 Google Consent Mode v2
We implement Google Consent Mode v2, which means:
- No cookies are set until you provide consent
- Analytics data is sent cookieless if you decline
- Your privacy choices are respected across all Google services
11. Third-Party Links
Our Service may contain links to third-party websites (e.g., Meta, Google). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
12. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
Email: support@example.com