Security & data

What we access, and why

Relay connects to your Meta ad accounts to read performance and lead data on your behalf. This page explains what that means in practice, kept factual rather than a marketing pitch.

What Meta Platform Data we access

We request only the Meta permissions needed to read your ad performance and leads, and to send conversion events you configure.

Read-only ad performance

Campaign, ad set and ad-level spend and results from the ad accounts you connect. We do not modify your campaigns unless you explicitly use a feature that does (like the campaign planner).

Leads you authorise

Instant Form and other lead data from accounts you connect, so it can appear in your CRM pipeline. We only import what your connection grants access to.

Conversions API, on your instruction

We send conversion events to Meta only for the pipeline stages you map to an event. Email and phone are SHA-256 hashed on the server before anything is sent.

Nothing beyond that

We do not request permissions to post on your behalf, manage your Page, or access data outside the ad accounts and leads you connect.

Hosting & data handling

Supabase & AWS, hosted in Mumbai

Your data is stored in Supabase (PostgreSQL) with the application running on AWS, both in the Mumbai (ap-south-1) region.

Encryption in transit

All traffic between your browser, Relay and Meta's APIs is encrypted in transit (HTTPS/TLS).

Role-based, per-agency access

Every workspace is scoped to its own agency. Team roles (owner, manager, rep) further limit which clients and leads a team member can see.

Hashed identifiers, not raw PII, to Meta

Personal identifiers sent for conversion tracking are hashed (SHA-256) server-side before transmission, in line with Meta's Conversions API requirements.

Data deletion

Meta data-deletion requests

If you remove Relay from your Facebook or Instagram account, Meta notifies us through a signed data-deletion callback. You can check the status of a request at /data-deletion using the confirmation code Meta provides.

Your own export & deletion controls

You can request export or deletion of your account and lead data at any time by emailing [email protected]. For lead data you imported, you act as the controller and Relay assists as your processor.

No selling your data

We do not sell your personal data or your leads' personal data. Data is shared only with the sub-processors needed to run the Service (cloud hosting, payment processing, email delivery, and Meta itself for the permissions you grant), as detailed in our Privacy Policy.

Questions about security or data handling?

Email [email protected], we usually reply within a day.

Contact us