1. Purpose and Scope
This document describes how Duneside accesses, uses, stores, and protects data from Meta (Facebook and Instagram) advertising accounts you choose to connect. Duneside is a read-only analytics and reporting platform for marketing agencies. We access Meta Ads insights solely to produce performance reports and consolidated cross-channel insights.
This policy supplements our Privacy Policy and Terms of Service.
2. User Authority and Account Ownership
You retain full ownership and authorityover your Meta advertising accounts and Business Manager assets at all times. Connecting an account to Duneside is entirely voluntary. By connecting, you confirm that you have lawful permission to grant read access to the account's performance data.
Duneside does not take ownership of, transfer, sublicense, or resell your Meta advertising accounts. You may revoke access at any time using the procedure in Section 9 of this document.
3. Meta Marketing API Access — Data We Retrieve
Our application uses the Meta Marketing API to retrieve read-only insights and performance data. Specifically, we access:
- Campaign-level performance metrics
- Account-level spend and delivery statistics
- Metrics including impressions, clicks, conversions, CTR, CPC, CPA, and ROAS
- Historical performance data for user-selected reporting periods
- Breakdowns and dimensions you configure for reporting (e.g., by campaign or date range)
We request only the permissions necessary to deliver the reporting features described above.
4. How We Use Meta Ads Data
Data retrieved from your Meta advertising accounts is used exclusively to:
- Generate advertising performance reports for your agency and clients
- Provide consolidated reporting across multiple marketing channels within Duneside
- Display analytics dashboards and exportable summaries you configure
We do not use Meta Ads data for ad delivery, audience building, campaign automation, or any purpose unrelated to analytics and reporting.
5. Read-Only Commitment
Duneside is a read-only platform. Through the Meta Marketing API, we do not perform:
- Ad, ad set, or campaign creation, editing, or deletion
- Audience or targeting modifications
- Budget or bid changes
- Creative uploads or modifications
- Any other campaign management or operational actions
All campaign management remains your responsibility and must be performed directly in Meta Ads Manager or through tools you separately authorize for that purpose.
6. Prohibited Business Activities
Duneside does not engage in, and does not permit use of our Platform for:
- Selling advertising inventory or media placements
- Generating clicks, impressions, or artificial traffic
- Creating or distributing invalid traffic
- Reselling, brokering, or transferring Meta advertising accounts
- Operating click arbitrage, traffic arbitrage, or similar business models
Our business model is limited to SaaS analytics and reporting services for agencies.
7. Authentication and Data Security
Access to Meta advertising accounts is established through Meta's official OAuth authorization flow within the Business Manager permissions model. Duneside does not collect or store your Meta login password. API tokens are stored securely and used only to retrieve authorized reporting data.
Data is transmitted over encrypted connections (TLS). We apply access controls and industry-standard security practices to protect stored performance data.
8. Data Retention and Deletion
Meta Ads performance data is retained only while your Meta integration remains connected and as needed to provide reporting for your selected date ranges. When you disconnect in Duneside, or when Meta authorization is revoked and our systems are notified, we delete the associated integration and stored Meta Ads performance data within a reasonable timeframe, subject to any legal retention obligations.
9. Account Removal Procedure
You may disconnect your Meta advertising accounts from Duneside at any time. Complete the steps below to stop future data access and remove data stored by Duneside.
- Disconnect in Duneside: Sign in to Duneside. Open Clients and select the client whose Meta account you connected. In the Integrations section, find Meta Ads and click Disconnect. When you disconnect, Duneside immediately stops retrieving new Meta Ads data for that connection, removes the stored integration connection from our systems, and deletes synced Meta campaign performance data associated with that integration. If you manage multiple clients, repeat this for each client where Meta Ads is connected.
- Revoke Meta authorization: After disconnecting in Duneside, revoke Duneside's access in Meta so no further API access is possible. If you connected via Meta Business Manager or Facebook Login for Business, go to business.facebook.com/settings, open Integrations → Connected apps, select Duneside, and choose Remove or Revoke access. If you connected via your personal Facebook account, go to Facebook Settings & privacy → Settings, open Security and login → Business integrations, select Duneside, and choose Remove.
- Review ad account assignments (recommended): In Meta Business Settings, open Accounts → Ad accounts, select each affected ad account, and confirm Duneside no longer appears under assigned partners, connected apps, or partner access. Remove any remaining Duneside assignments if present.
- If you cannot sign in to Duneside: You may complete Steps 2 and 3 in Meta. Revoking access in Meta is sufficient to immediately stop Duneside from retrieving new Meta Ads data. If you also need confirmation that stored data has been removed from Duneside, email support@useduneside.com with your agency or company name, the email address on your Duneside account (if known), and the Meta ad account ID(s) you disconnected. We will confirm removal and assist with any remaining data deletion requests within a reasonable timeframe.
- Automated removal via Meta: If you remove Duneside from your Meta account settings, Meta may notify us through their platform removal processes. When that happens, Duneside will delete the associated integration and stored Meta Ads performance data linked to that authorization.
10. Contact
For questions about Meta Ads data handling, API access scope, or account removal, contact support@useduneside.com.