Privacy Policy — Cuevas Media Group
LEGAL NODE · DATA PROTECTION

Privacy Policy.

LAST UPDATED · JANUARY 9, 2026

Cuevas Media Group (“we,” “us,” or “our”) is committed to protecting your privacy.

By accessing or using the App, you agree to the practices described below. If you do not agree, please do not use the App.

SECTION 01Information We Collect

1.1 Personal Data

Information you provide directly, such as:

  • Name, email address, phone number, and company name.
  • Authentication credentials, which are stored in hashed form.
  • Billing-related information handled by our payment processor.

1.2 Usage Data

Automatically collected technical data may include IP address, browser type, device identifiers, referring URLs, pages viewed, date and time stamps, error logs, and similar diagnostics.

1.3 Cookies & Similar Technologies

We use session, preference, and security cookies to operate and improve the App. You can disable cookies through your browser, but parts of the App may not function properly without them.

1.4 Facebook & Instagram Advertising Data

When you connect a Facebook or Instagram account, we request the following Meta permissions:

PermissionLevelWhy We Request It
ads_managementAdvancedCreate, edit, pause, or delete campaigns, ad sets, and ads you explicitly authorize.
ads_readAdvancedPull ad-performance metrics, including impressions, spend, and conversions, for dashboards and exports.
business_managementAdvancedList Ad Accounts, Pages, and Custom Audiences belonging to your Business Manager so you can select assets.
pages_show_listStandardDisplay the Pages you manage so you can choose one for boosted-post campaigns.

We do not request or receive your friend lists, private messages, personal posts, or special-category data such as health, financial, political, religious, or biometric information.

SECTION 02How We Use Information

We process data to:

  • Provide, operate, and maintain the App.
  • Execute advertising actions you initiate, such as creating a campaign.
  • Display real-time analytics and generate aggregate benchmarks.
  • Send transactional messages, including password resets and invoices.
  • Detect, prevent, and address technical issues or fraud.
  • Comply with legal obligations.

Legal bases under GDPR/UK-GDPR: performance of contract, legitimate interests, consent where obtained, and compliance with law.

SECTION 03Data Retention

Data TypeRetention Period
Meta advertising objects & insights24 months from the last successful token refresh or 48 hours after you disconnect your account—whichever occurs first.
Personal & billing dataFor as long as you maintain an account and up to 7 years thereafter to meet bookkeeping and compliance duties.
Cookies & logsUp to 26 months unless a shorter period is sufficient.

SECTION 04Your Choices & Data Deletion

Delete Your Meta Data

  • Disconnect in Facebook → Settings → Business Integrations to trigger our Facebook Data Deletion Callback and an automatic purge within 48 hours.
  • Email [email protected] with the subject “Delete my Meta data”. We will honor verified requests within 72 hours.

You may also exercise rights of access, rectification, objection, restriction, portability, and complaint under GDPR/CCPA by contacting us.

SECTION 05Sharing & Disclosure

We never sell or rent any Meta advertising data. We share data only with:

  • Sub-processors that perform services on our behalf, including hosting, payment, and customer support, under executed DPA and confidentiality terms.
  • Authorities or successors when required by law or during a business transfer.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use-case categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.

5.1 Sub-processors & Vendors

The following third-party service providers may process data on our behalf:

CategoryLegal Entity ExampleTypical Data Touched
Hosting / InfrastructureAmazon Web Services, Inc.Servers, file storage, and backups.
Serverless / FrontendVercel Inc.Edge functions, static assets, and build logs.
CDN / SecurityCloudflare, Inc.TLS termination, WAF logs, and cached API traffic.
DatabaseSupabase, Inc.Database tables, campaign metadata, and insight caches.
Payments & BillingStripe, Inc.Customer name, email, card last four digits, and invoices.
Transactional EmailResend, Inc.Password-reset links and system notifications.
CRM / AutomationHighLevel Inc.Client contact records, funnels, and campaign assets.

SECTION 06International Transfers

We operate in the United States. Where we transfer data from the EEA or UK, we rely on Standard Contractual Clauses or an adequacy decision.

SECTION 07Security

We employ encryption in transit and at rest, role-based access controls, two-factor authentication for internal accounts, regular penetration testing, and vendor risk assessments. No method is 100% secure, and we cannot guarantee absolute security.

SECTION 08Children

The App is not directed to, and we do not knowingly collect information from, anyone under 18.

SECTION 09Changes

Material changes will be announced 30 days in advance through email or an in-App notice. The “Last updated” date reflects the current version.

SECTION 10Contact

For privacy questions, rights requests, or data-deletion requests, contact Cuevas Media Group:

ADDRESS2611 Teeside Ct
Kissimmee, FL 34746
EMAIL[email protected] PHONE(904) 351-6305