Privacy Policy
Allocent (allocent.in) · Effective date: July 17, 2026
Allocent ("Allocent", "we", "us") is a marketing decision platform operated from Maharashtra, India. This policy explains what data we collect, how we use it, and the choices you have. It applies to allocent.in and all Allocent applications and services (the "Service").
1. Data We Collect
Account data: name, email address, password (stored hashed), and organization/brand name, collected when you create an account.
Business data you upload: order, sales, marketing, and operational data you provide via CSV/Excel upload or similar means. This data belongs to you and is processed solely to provide the Service to you.
Advertising account data (via OAuth): if you choose to connect a Meta (Facebook) or Google Ads account, we access campaign structure, spend, and performance data, and — only where you approve a specific action — make changes to campaigns on your behalf. Access is granted through the platform's official APIs using permissions you explicitly authorize (for Meta: ads_read, ads_management, business_management). We never receive or store your Meta or Google password.
Usage data: standard technical logs (IP address, browser type, pages viewed, timestamps) used for security and service operation.
2. How We Use Data
We use your data only to: (a) operate and provide the Service, including computing metrics, diagnostics, and marketing decision recommendations from your data; (b) execute campaign actions you explicitly approve; (c) secure the Service and prevent abuse; (d) communicate with you about the Service; and (e) comply with law. We do not sell your data, use it for third-party advertising, or use your identifiable business data to serve other customers.
3. Data Storage and Security
Data is stored with reputable cloud infrastructure providers with encryption in transit (TLS) and at rest. OAuth access tokens are stored encrypted. Access to customer data within Allocent is restricted and tenant-isolated: each customer's data is logically separated and protected by row-level security so no customer can access another customer's data.
4. Subprocessors
We use the following categories of service providers to operate the Service: cloud hosting and databases (Railway, Google Cloud Platform), authentication (Supabase), web hosting (Vercel), and AI inference for data cleaning and analysis (Groq). These providers process data only on our instructions.
5. Data Retention
We retain your data while your account is active. Upon account deletion or a verified deletion request, your data is deleted within 30 days, except where a longer retention period is required by law (e.g., billing records under Indian tax law).
6. Your Rights
Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you may access, correct, export, or delete your personal data, and withdraw consent for OAuth connections at any time. To disconnect an ad account, use the Connections page in the app or revoke access from your Meta or Google account settings. For deletion, see our Data Deletion Instructions.
7. Platform Terms
Our use of data received from Meta APIs adheres to the Meta Platform Terms and Developer Policies. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Children
The Service is a business tool and is not directed at individuals under 18. We do not knowingly collect data from minors.
9. Changes
We may update this policy; material changes will be notified via the Service or email. The effective date above reflects the latest version.
10. Contact
Privacy questions or requests: aditya@allocent.in
Allocent, Maharashtra, India.