COVID-19 Notice

View
site logo
Home
About
Services
Work
Careers
Sustainability
FAQ
Let's Talk

CreativeMITE · Social Media Tool

Social Media Tool Privacy Policy

What the social media management tool holds, who sees it, and how anyone at all can ask us to delete it.

In effect
21 August 2026
Applies to
The social media management tool
Data deletion
How to request it
Read with
Social Media Tool Terms of Use
Contents

Sections

    This policy covers the CreativeMITE social media management tool, the application CreativeMITE uses to connect to Facebook Pages, Instagram accounts and LinkedIn pages on behalf of the brands we look after. CreativeMITE is a Canadian marketing company, and the tool is ours: we built it, we run it, and we are answerable for what it holds.

    We have written this policy to be read rather than filed away. It is in plain words, it names the things it is talking about, and we would encourage you to read it. It sets out what the tool takes from those platforms, what we do with it, who else sees it, and how anyone at all can ask us to delete it.

    The standard this policy is written to is Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), together with Alberta's Personal Information Protection Act. Where the EU or UK GDPR reaches information we hold, we apply that standard as well rather than instead, and a section below sets out what that means in practice.

    Two things people usually come here for: the permissions we ask Facebook and Instagram for, and how to ask us to delete your data.

    Every request in this policy comes to one mailbox

    Questions about this policy, and every request described in it, go to hello@creativemite.com.

    CreativeMITE
    3003 43 Ave #115, Stony Plain, AB T7Z 0H4, Canada
    Email: hello@creativemite.com
    Phone: 780.963.9292

    The tool runs social media accounts for the brands we work with

    It is an internal platform our team uses, and it does the following:

    • publishes and schedules posts to connected Facebook Pages, Instagram business accounts and LinkedIn pages
    • keeps drafts, an approval workflow and an Instagram grid planner
    • collects performance figures for those accounts and their posts, and builds reports from them
    • reads advertising figures from Meta ad accounts a brand has connected
    • gathers comments, Facebook recommendations, mentions and, where that feature is enabled, direct messages into one inbox so our team can reply

    An account joins the tool only when its administrator grants us access

    Nothing is connected behind anyone's back. A Facebook Page, Instagram account or LinkedIn page reaches the tool only when somebody who administers it signs in to that platform and grants us access, and that access can be withdrawn again at any time, on the platform or in the tool.

    We hold an account record for every person who uses the tool

    The people who use the tool are our own team members and the client-side people we give access to. For each of them we hold:

    • name or username, email address, and a salted hash of the password, never the password itself
    • which brands they can see, and what they are allowed to do in each one
    • the time they last signed in
    • what they create in the tool: posts, drafts, comments on drafts, internal notes, assignments and grid plans
    • email addresses they enter as recipients of a scheduled report

    We rate-limit the password reset form, and we log our own errors

    The IP address a password-reset request arrives from is held in the web server's memory so that the form can be rate limited. It is not written to a database. Separately, when the application hits an error it writes a technical record to an error log database: the error message, the stack trace and the code that failed.

    We store the connected accounts and the figures we read for them

    For every connected Facebook Page, Instagram account, LinkedIn page and Meta ad account we store:

    • the platform's own id for the account, its name or @handle, and for a Facebook Page the Instagram account linked to it
    • the access token the platform issued, encrypted at rest
    • posts published or scheduled through the tool, with their text, their media and the result of publishing
    • posts already on the account, read back for reporting and the grid planner: the post id, caption, permalink, media type, thumbnail and posting time
    • daily figures for the account (views, reach, engagement, likes, comments, shares, saves and follower totals), and the same shape of figures for each individual post
    • daily advertising figures for connected Meta ad accounts: campaign and ad names, spend, currency, impressions, reach, clicks, engagement and results, all of them totals that contain nothing about the individual people who saw an ad
    • follower breakdowns by country, by city, and for Instagram by age band and by gender, which are counts per bucket (how many followers are in Canada, how many are 25–34), and no individual follower is named, identified or stored

    We import a brand's history from the tool it used before us

    Where a brand used another tool before us, somebody on our team can upload that tool's exported spreadsheets so the historical figures are not lost. The uploaded file is kept alongside the rows imported from it.

    We copy in the comments and messages sent to those accounts

    This part is about members of the public. If you commented on a post, left a Facebook recommendation, tagged or @mentioned one of these accounts, or sent it a direct message, this is the section that concerns you.

    When that happens the tool copies the conversation in, so our team can read it and answer. The record holds:

    • the platform's id for you, your name and your @handle, where the platform gives them to us
    • the text of your comment, recommendation, mention or message
    • a link to any image, video or file you attached
    • when it was sent, its like count, and whether it has since been hidden or deleted on the platform
    • the post it relates to, with that post's caption, thumbnail and link

    Alongside it we keep our own working state: whether the thread is open or done, who on our team it is assigned to, and internal notes. None of that is ever sent to the platform or shown to you.

    You did not sign up for anything, and you can still have it deleted

    You are not a user of ours. Your information reached us only because you interacted with an account we manage, and you can ask us to delete it without an account and without signing in to anything. See how to ask us to delete your data.

    We ask Facebook, Instagram and LinkedIn for these permissions

    When a Facebook Page or Instagram account is connected, Meta shows the person a list of permissions to approve. This is every permission we request and the job it does.

    To publish

    • pages_show_list: list the Pages the person administers, so they can pick which to connect.
    • pages_manage_posts: publish and schedule posts on a connected Page.
    • instagram_basic: read the connected Instagram account's profile and media.
    • instagram_content_publish: publish posts and reels to Instagram.
    • business_management: see which Pages, Instagram accounts and ad accounts in Business Manager the person is able to grant.

    To report

    • read_insights: Facebook Page and post performance figures.
    • pages_read_engagement: Page details and engagement figures.
    • pages_read_user_content: list the Page's own posts and their comments, for reporting.
    • instagram_manage_insights: Instagram account and media performance figures, and the aggregate follower breakdowns described above.
    • ads_read: read-only advertising figures for connected Meta ad accounts.

    To handle comments, reviews, mentions and messages

    • pages_manage_engagement: reply to, hide and delete comments on our Page posts.
    • instagram_manage_comments: read, reply to, hide and delete Instagram comments.
    • pages_manage_metadata: subscribe the Page to Meta's notifications so mentions reach the inbox. Requested only where that feature is switched on.
    • pages_messaging and instagram_manage_messages: read and answer direct messages. Requested only where the direct message feature is enabled.

    An Instagram account connected on its own, without a Facebook Page, grants a separate set that does the same jobs: instagram_business_basic (read the profile and media), instagram_business_content_publish (publish), instagram_business_manage_insights (performance figures), instagram_business_manage_comments (comments), and instagram_business_manage_messages where direct messages are enabled.

    LinkedIn uses its own permissions: w_member_social and w_organization_social to post as the person or as the organization, r_organization_social to read the organization's posts, and openid to identify who signed in.

    We use this information only for the jobs described above

    We do not sell it. We do not use it to target advertising of our own. We do not build profiles of individual people, and we pass it to no one except the service providers named below.

    Signing in sets a cookie, and the tool cannot work without it

    A forms-authentication cookie is what keeps you signed in from one page to the next. Most browsers let you block or delete cookies, but blocking this one will stop you signing in.

    Our public pages load analytics and anti-bot services

    The pages you can reach without signing in (the sign-in page, the password reset flow and this policy) also load:

    • Google Analytics 4 and Google Tag Manager, for visit statistics
    • Microsoft Clarity, for session and heatmap analytics
    • Google reCAPTCHA v3, which checks that the sign-in and password-reset forms are being used by a person

    On the marketing pages of creativemite.com, Google Maps is loaded as well. Each of those services sets its own cookies and receives your IP address and browser details, and their own policies govern that handling: Google and Microsoft.

    We are allowed to hold this information for a small number of reasons

    First, our clients instruct us to. A client decides which of its accounts are connected and what is done with them, and we carry that out. In data protection terms the client is the controller of that information and we are the processor. The one place that is reversed is our own users' accounts: there the decisions are ours, so we are the controller.

    Secondly, the access was granted and the service was asked for. Nothing is read from a platform until somebody who administers the account signs in and consents, and once they have, holding what this policy describes is what the service consists of: a post cannot be scheduled without being stored, a report cannot be built without figures behind it, and a comment cannot be answered without being read.

    Thirdly, and rarely, the law requires it. Where we are obliged to keep information or to produce it, that obligation is the basis we rely on.

    Where the GDPR reaches this information, we apply it as well

    Where the EU or UK GDPR applies, our lawful bases are performance of a contract (running the service) and legitimate interests (keeping it secure, and answering messages sent to accounts we manage). People covered by those laws have rights of access, correction, erasure, restriction, objection and portability, and can exercise any of them by writing to hello@creativemite.com.

    A small number of service providers handle this data for us

    These are the outside companies involved, and what each of them does:

    • Microsoft Azure: hosting, the SQL databases, Blob Storage for uploaded media, and Key Vault for application credentials
    • Microsoft Graph: sends the email the tool generates, from password resets to inbox notifications and scheduled reports
    • Meta Platforms, Facebook and Instagram: the source of most of the data described here, and the destination of everything we publish or reply
    • LinkedIn: the same, for LinkedIn pages
    • Google and Microsoft Clarity: the analytics and anti-bot services described above

    Media uploaded for a post sits in Azure Blob Storage and is moved to our own web server's disk once the post has gone out. Scheduled and background work runs inside our own database, so no outside service is involved in it.

    We protect this information with encryption, hashing and limited access

    • Traffic between your browser and the tool is encrypted with TLS.
    • Platform access tokens are encrypted at rest with AES-256 and carry an HMAC-SHA256 integrity check. The key lives in the server's environment, not in the database and not in our source code. Application credentials are held in Azure Key Vault.
    • Passwords are stored only as salted hashes. We cannot read them.
    • Access is granted per brand. Each user sees only the brands they have been added to, with individual permissions inside each one.
    • Sign-in attempts and password-reset requests are rate limited, and repeated failures lock the account.

    No system is perfectly secure, and we make no promises beyond the measures described here.

    We keep this information until it is deleted

    We will be plain about this: there is no automatic purge. Information stays until the brand or the connected account is deleted in the tool, or until we act on a deletion request.

    Disconnecting and deleting deactivate rather than erase

    Disconnecting an account, or deleting a brand, marks its records as deleted. The tool stops using them straight away and collects nothing further for them. But the underlying rows, including the stored access token, stay in the database until we erase them. If you want them actually erased rather than deactivated, ask us using the section below and we will do it.

    You can ask us to delete your data, whether or not you have an account

    Anyone can ask. Requests go to hello@creativemite.com. We acknowledge every request within 5 business days and complete it within 30 days.

    1. If you are a client, or you own the brand

    You can stop the collection yourself, immediately, inside the tool:

    • Open Brand Management and disconnect the Facebook Page, Instagram account, LinkedIn page or ad account. Nothing further is read or published for it.
    • Deleting the brand does the same for every account under it, and cancels its scheduled posts.

    That deactivates the records. To have them erased from our database, email us with the subject line Data deletion request and name the brand and the accounts.

    You should also remove our app on the platform itself, which revokes the token at Meta's end: on Facebook under Settings & Privacy → Settings → Business Integrations, and on Instagram under Settings → Website Permissions → Apps and Websites.

    2. If you use the tool

    Anyone who manages a brand can remove you from it under Brand Members, which ends your access to that brand's data. To have your user account and the record of it deleted altogether, email us with the subject line Data deletion request, from the address the account uses.

    3. If you commented on, reviewed, mentioned or messaged an account we manage

    You have no account with us and there is nothing to sign in to. Email hello@creativemite.com with this subject line:

    Data deletion request: social inbox

    Tell us:

    • the platform: Facebook or Instagram
    • the name or @handle of the account you interacted with
    • your own @handle, or the name shown on your comment or message
    • roughly when it was, if you remember

    We use those details only to find your records, and for nothing else. We then delete the text of your comment, recommendation, mention or message, your name, @handle and platform id, and any attachment link we stored. Once that is done we email you to confirm it.

    What we cannot do for you

    Deleting our copy does not remove anything from Facebook, Instagram or LinkedIn. Their copy is theirs, and their own policies govern it. To remove it there, delete it in the app, or contact the platform: Facebook, Instagram, LinkedIn. In the same way, once a post has been published to a platform it lives there under that platform's rules.

    You have rights over the information we hold about you

    Whether or not you use the tool:

    • You may ask us what personal information we hold about you, and we will tell you;
    • You may ask us to correct anything in it that is wrong or out of date;
    • You may ask us to delete it, by the routes set out above;
    • You may withdraw the access granted when an account was connected, either on the platform or in the tool; and
    • You may complain about the way we have handled any of it.

    We answer within 30 days, and we may check who you are first

    Write to hello@creativemite.com and we will answer within 30 days. We may need to confirm who you are before we do, and where we hold the information on a client's behalf we will pass the request to that client.

    You can complain to a privacy commissioner

    If our answer does not satisfy you, you can take it to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner of Alberta.

    We store this information on Microsoft Azure, and it may leave Canada

    Our databases, file storage and web servers run on Microsoft Azure. Meta, LinkedIn, Google and Microsoft all operate internationally, so information covered by this policy may be stored or processed outside Canada, and will be subject to the laws of the countries involved.

    This tool is not directed at children

    It is a business tool, and we do not knowingly collect information from anyone under 13. If a child's comment or message has reached us through an account we manage, tell us and we will delete it.

    This policy changes when the tool changes

    When a new feature reads or stores something this policy does not already describe, this page changes with it. The date at the top is the date of the current version, and material changes are posted here before they take effect.

    How to contact us about this policy

    CreativeMITE, 3003 43 Ave #115, Stony Plain, AB T7Z 0H4, Canada · hello@creativemite.com · 780.963.9292 · Contact us

    The same handling applies to everyone whose data reaches us

    There is one tool, one database and one set of practices behind it, so the handling described here is what everyone gets: our own team, our clients, and the members of the public who comment on a post or send a message. Which law brought you to this page changes what you can require of us. It does not change what we do.

    CreativeMITE

    780.963.9292

    hello@creativemite.com

    creativemite.com

    3003 43 Ave, #115

    Stony Plain, AB T7Z 0H4

    © 2026 CreativeMITE.
    All rights reserved.

    Terms of Use Privacy Policy Social Tool Privacy Policy Social Tool Terms of Use