Last updated June 25, 2026
Volume Creatives (“Company,” “we,” “us,” or “our”) operates the platform at volumecreatives.com (the “Service”). This Privacy Policy explains what personal data we collect, how we use and share it, your rights, and how to contact us. By using the Service, you agree to the collection and use of information in accordance with this Policy.
When you connect a Meta account, we receive and process the following data strictly to provide the Service:
We do not receive or store payment card numbers, personal financial data of your customers, or Meta user data beyond what is necessary to operate the Service features you use.
Images and videos you upload or import are stored temporarily in our systems solely to facilitate ad creation via the Meta Marketing API. Assets are uploaded to Meta on your behalf and may be retained in our storage for a period to support retry, re-use, and audit features.
Data received through the Meta Marketing API is used exclusively to:
We do not use Meta data for our own advertising purposes. We do not sell, rent, or share Meta data with third parties for their own marketing or advertising purposes. We do not use Meta data to build profiles about Meta users other than you (the account operator). We do not transfer Meta data to data brokers. Our use of Meta Platform Data is subject to Meta’s Platform Terms and Developer Policies.
We do not sell your personal data. We share data only in the following circumstances:
We use the following third-party service providers to operate the Service:
Each sub-processor is bound by contractual obligations to protect your data and use it only to provide services to us on your behalf.
We may disclose your information if required to do so by law or in good-faith belief that such disclosure is necessary to comply with a legal obligation, protect our rights or property, prevent fraud or illegal activity, or protect the safety of users or the public.
In the event of a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice in the Service before your data is transferred and becomes subject to a different privacy policy.
We may share your data with third parties when you have given us explicit consent to do so.
Meta access tokens and refresh tokens are encrypted at rest using AES-256 encryption and stored in our secure database infrastructure via Supabase Vault. All data in transit is protected by TLS 1.2 or higher. We implement access controls, authentication requirements, and audit logging to restrict access to sensitive data.
You may revoke the Service’s access to your Meta accounts at any time through Meta’s Business Settings (“Disconnect” in our Settings → Connections also triggers token revocation). Upon disconnection, we delete the stored token from our systems within 30 days.
Despite our security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security and disclaim liability for unauthorized access beyond our reasonable control.
We retain your personal data for as long as your account is active or as necessary to provide the Service. Specifically:
We use the following types of cookies and similar technologies:
We do not use advertising or cross-site tracking cookies. You may control cookies through your browser settings, but disabling strictly necessary cookies may impair Service functionality.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent laws, including the right to restrict processing, object to processing based on legitimate interests, and lodge a complaint with your local supervisory authority. Our legal bases for processing include: performance of our contract with you (providing the Service), compliance with legal obligations, legitimate interests (security, fraud prevention, service improvement), and consent (marketing communications).
For cross-border transfers of personal data from the EEA/UK to the United States, we rely on Standard Contractual Clauses approved by the European Commission or equivalent transfer mechanisms.
California residents have the right to know what personal information we collect and how it is used, the right to delete personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information), and the right not to be discriminated against for exercising these rights. To submit a verifiable consumer request, contact us at the email below. We will respond within 45 days.
The Service is not directed to children under the age of 18, and we do not knowingly collect personal data from anyone under 18. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete that information promptly. If you believe a child has provided us with their personal data, contact us at support@volumecreatives.com.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies. This Privacy Policy applies only to information collected by our Service.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at the address associated with your account and/or by posting a prominent notice in the Service at least 14 days before the effective date. Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
For privacy questions, access requests, deletion requests, or complaints:
We will respond to all requests within 30 days. For unresolved complaints, EEA/UK residents may contact their local data protection authority.