Privacy Policy
Last updated: October 8, 2026 • Effective Date: October 8, 2026
1. Overview & Commitment
PagePilot ("we", "us", or "our") is committed to protecting your privacy and ensuring transparency in how we collect, process, and safeguard your data. This Privacy Policy describes how we handle information when you use our multi-tenant SaaS platform, including when you connect your Facebook Pages via Meta Developer APIs.
2. Information We Collect
- Account Information: When you register, we collect your name, email address, and encrypted credentials (hashed using Argon2id).
- Workspace Data: Workspace titles, team member email invitations, role assignments, and audit events.
- Meta Platform Data: When you connect Facebook Pages (subject to Meta App Review), we collect Page identifiers, Page names, Page access tokens (encrypted at rest), and aggregate metric snapshots authorized through Meta permissions.
- Technical Information: IP address, browser type, and timestamp logs for security monitoring and rate limiting.
3. How We Use Information
We use collected data solely to deliver and secure our core services:
- Authenticate users and enforce strict multi-tenant workspace isolation.
- Publish approved content and retrieve scheduled insights from Facebook Pages.
- Protect against unauthorized access, credential stuffing, and session hijacking.
- Comply with Meta Platform Terms, Developer Policies, and applicable privacy regulations.
4. Meta API Data Handling & Security
In accordance with Meta Developer Policies:
- No Unauthorized Sharing: We do not sell, rent, or transfer Meta User Data or Page Data to third-party data brokers.
- Encryption at Rest: All sensitive access credentials, session refresh tokens, and Meta tokens are stored encrypted using industry-standard cryptography.
- Tenant Isolation: Data belonging to one workspace is strictly isolated from other tenants using PostgreSQL row-level and foreign-key constraints.
5. Data Retention & Deletion
We retain account data for as long as your workspace remains active. Users may request full account or workspace deletion at any time. Upon deletion, all associated authentication records, access tokens, and stored metric caches are permanently erased.
For Facebook platform data deletion instructions, visit our dedicated Data Deletion Instructions page.
6. Contact & Data Protection Officer
If you have questions regarding this Privacy Policy or wish to exercise your data subject rights under GDPR/CCPA, please contact us at:
privacy@pagepilot.app