Who this notice covers
This notice covers the EvokeLoop public website and marketing workspace. The operating business and contact details appear in the Business information panel. When those details or approval of this notice are pending, the panel identifies the notice as a pre-release draft, not a completed verification declaration.
For account administration, security and website enquiries, EvokeLoop handles information to operate its service. For marketing information a business connects to its workspace, EvokeLoop acts on that business's instructions. That business is also responsible for the permissions, rights and notices needed for its own customers and team members.
Information we receive
Account and workspace information includes names, email addresses, sign-in identifiers, team roles, invitations and organization settings. Creative information includes uploaded images and videos, UGC, logos, product data, brand guidelines, prompts, generated outputs, captions, drafts and review comments.
When you authorize a Meta connection, EvokeLoop receives the account identity and authorization needed to discover and use the Pages or advertising accounts you select. Depending on permissions, this can include Page and account IDs and names, Page tasks, posts and aggregate engagement, campaigns, ad sets, ads, currency, time zone, spend, clicks and platform-reported conversions. Encrypted access credentials and connection metadata are stored separately for each workspace.
Website forms collect your name, email, request category, optional workspace reference and message. A private request reference allows you to check the status. Servers also process technical connection information, such as IP addresses and request details, for hosting, security and abuse prevention. Avoid submitting passwords, tokens, payment card details or unnecessary sensitive information.
How information is used
We use information to sign you in, organize your workspace, import authorized product information, generate requested creative work, preserve versions, manage reviews, schedule approved content, execute authorized delivery and display marketing reports. We also use it to answer enquiries, handle privacy requests, troubleshoot errors and record security and approval activity.
Connecting an account does not publish a post, activate an ad or authorize a budget change. Our initial Meta workflow supports Facebook Page posts and paused image ads in existing ad sets when required access and live delivery are enabled. We do not use the current integration to read personal messages, retrieve lead-form submissions, or manage Meta catalogs. Planned features require additional implementation and updated disclosures before use.
AI processing and service providers
When you deliberately use AI generation or copy assistance, the content needed for that task, such as prompts, selected images, product facts and brand instructions, is sent to the configured AI provider. The current implementation uses OpenAI for this processing. Do not include information you lack permission to share. Generated content may be inaccurate and needs human review.
EvokeLoop uses Render for application hosting and Supabase for account authentication, database and asset storage. Authentication email is handled by the configured email service. The public website and signed-in application load the Manrope typeface from Google Fonts, which receives the technical request information needed to deliver the font files. No advertising or analytics script is added to the public website by this font delivery.
Meta receives the API calls and approved content needed for the connection or publishing action you request. Authorized workspace members can access workspace information according to their roles; platform administrators can access data as needed for support, security and operation. Information may also be disclosed when legally required or necessary to protect the service. Vendor contractual terms and deployment settings govern their processing; this notice does not promise that all providers have zero retention.
Meta data and customer separation
Meta access is authorized by each customer for their own workspace. EvokeLoop is not a shared CLX or other advertiser account. Credentials are encrypted on the server and are not returned in ordinary connection responses. The current product does not sell Meta Platform Data or make a customer's account data available as a cross-customer data product.
Reports are based on the data the provider makes available. Platform-attributed conversions are not represented as independently deduplicated sales, and unique reach is not added across channels as though it were unique people. EvokeLoop does not claim Meta certification, partnership or completed review merely because a connection interface exists.
Cookies, storage and security
The public pages do not load advertising pixels or optional analytics scripts. The application uses session cookies for sign-in, a short-lived cookie for the Meta authorization flow, and local browser storage for interface preferences such as navigation and theme. Server logs and form abuse controls still process technical information even when no marketing cookie is set.
Implemented protections include workspace access checks, role-restricted approval actions, server-side credential encryption, private asset storage and checks against changed approvals. Public enquiries and deletion requests are accessible only to platform administrators, not ordinary workspace owners. No service can guarantee absolute security; see the Security page for the current scope rather than an unsupported certification claim.
Retention, deletion and your choices
Working assets, account records and activity history remain available while needed for the workspace and service. Disconnecting a Meta connection removes its stored credential in EvokeLoop and invalidates affected queued approvals, but does not automatically erase prior drafts, publications or audit records. OAuth selection sessions expire and are cleaned up as the connection flow runs.
You may request access, correction or deletion through the public Contact or Data deletion page without a EvokeLoop login. We need to verify identity and, for shared business data, authority before acting. A request receipt confirms receipt, not completed deletion. The platform team handles fulfillment; there is no instant workspace-erasure action in this release.
Deletion can require removing eligible active records and stored assets, restricting further use and coordinating with service providers. Limited records may need to remain for legal obligations, security or disputes; backup copies may persist until their applicable retention cycle expires. The team will explain relevant exceptions and timing when handling a verified request, within applicable legal requirements. We do not promise an unimplemented universal deletion deadline.
For data your employer or another business controls, identify the workspace or contact that business as well. Available privacy rights vary by location and may include access, correction, deletion and objection or restriction. Contact us to exercise a right or ask about a decision. You do not have to delete your Facebook account to make a EvokeLoop request.
Service location, audience and updates
EvokeLoop is a business marketing service, not a product directed to children. Do not upload sensitive personal information or children's data that is unnecessary to your task. Hosting and service providers may process information outside your location, including in the United States. Required contractual and transfer arrangements must be reviewed for the business and regions served before public launch.
We update this notice when the service, data use or providers materially change. The published update date identifies the version; important changes may also be communicated through the application or account contact. The current public-release readiness of this notice is stated below.