COVID-19 Notice
CreativeMITE · Social Media Tool
What the social media management tool holds, who sees it, and how anyone at all can ask us to delete it.
Sections
This policy covers the CreativeMITE social media management tool, the application CreativeMITE uses to connect to Facebook Pages, Instagram accounts and LinkedIn pages on behalf of the brands we look after. CreativeMITE is a Canadian marketing company, and the tool is ours: we built it, we run it, and we are answerable for what it holds.
We have written this policy to be read rather than filed away. It is in plain words, it names the things it is talking about, and we would encourage you to read it. It sets out what the tool takes from those platforms, what we do with it, who else sees it, and how anyone at all can ask us to delete it.
The standard this policy is written to is Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), together with Alberta's Personal Information Protection Act. Where the EU or UK GDPR reaches information we hold, we apply that standard as well rather than instead, and a section below sets out what that means in practice.
Two things people usually come here for: the permissions we ask Facebook and Instagram for, and how to ask us to delete your data.
Questions about this policy, and every request described in it, go to hello@creativemite.com.
CreativeMITE 3003 43 Ave #115, Stony Plain, AB T7Z 0H4, Canada Email: hello@creativemite.com Phone: 780.963.9292
It is an internal platform our team uses, and it does the following:
Nothing is connected behind anyone's back. A Facebook Page, Instagram account or LinkedIn page reaches the tool only when somebody who administers it signs in to that platform and grants us access, and that access can be withdrawn again at any time, on the platform or in the tool.
The people who use the tool are our own team members and the client-side people we give access to. For each of them we hold:
The IP address a password-reset request arrives from is held in the web server's memory so that the form can be rate limited. It is not written to a database. Separately, when the application hits an error it writes a technical record to an error log database: the error message, the stack trace and the code that failed.
For every connected Facebook Page, Instagram account, LinkedIn page and Meta ad account we store:
Where a brand used another tool before us, somebody on our team can upload that tool's exported spreadsheets so the historical figures are not lost. The uploaded file is kept alongside the rows imported from it.
This part is about members of the public. If you commented on a post, left a Facebook recommendation, tagged or @mentioned one of these accounts, or sent it a direct message, this is the section that concerns you.
When that happens the tool copies the conversation in, so our team can read it and answer. The record holds:
Alongside it we keep our own working state: whether the thread is open or done, who on our team it is assigned to, and internal notes. None of that is ever sent to the platform or shown to you.
You are not a user of ours. Your information reached us only because you interacted with an account we manage, and you can ask us to delete it without an account and without signing in to anything. See how to ask us to delete your data.
When a Facebook Page or Instagram account is connected, Meta shows the person a list of permissions to approve. This is every permission we request and the job it does.
To publish
To report
To handle comments, reviews, mentions and messages
An Instagram account connected on its own, without a Facebook Page, grants a separate set that does the same jobs: instagram_business_basic (read the profile and media), instagram_business_content_publish (publish), instagram_business_manage_insights (performance figures), instagram_business_manage_comments (comments), and instagram_business_manage_messages where direct messages are enabled.
LinkedIn uses its own permissions: w_member_social and w_organization_social to post as the person or as the organization, r_organization_social to read the organization's posts, and openid to identify who signed in.
We do not sell it. We do not use it to target advertising of our own. We do not build profiles of individual people, and we pass it to no one except the service providers named below.
A forms-authentication cookie is what keeps you signed in from one page to the next. Most browsers let you block or delete cookies, but blocking this one will stop you signing in.
The pages you can reach without signing in (the sign-in page, the password reset flow and this policy) also load:
On the marketing pages of creativemite.com, Google Maps is loaded as well. Each of those services sets its own cookies and receives your IP address and browser details, and their own policies govern that handling: Google and Microsoft.
First, our clients instruct us to. A client decides which of its accounts are connected and what is done with them, and we carry that out. In data protection terms the client is the controller of that information and we are the processor. The one place that is reversed is our own users' accounts: there the decisions are ours, so we are the controller.
Secondly, the access was granted and the service was asked for. Nothing is read from a platform until somebody who administers the account signs in and consents, and once they have, holding what this policy describes is what the service consists of: a post cannot be scheduled without being stored, a report cannot be built without figures behind it, and a comment cannot be answered without being read.
Thirdly, and rarely, the law requires it. Where we are obliged to keep information or to produce it, that obligation is the basis we rely on.
Where the EU or UK GDPR applies, our lawful bases are performance of a contract (running the service) and legitimate interests (keeping it secure, and answering messages sent to accounts we manage). People covered by those laws have rights of access, correction, erasure, restriction, objection and portability, and can exercise any of them by writing to hello@creativemite.com.
These are the outside companies involved, and what each of them does:
Media uploaded for a post sits in Azure Blob Storage and is moved to our own web server's disk once the post has gone out. Scheduled and background work runs inside our own database, so no outside service is involved in it.
No system is perfectly secure, and we make no promises beyond the measures described here.
We will be plain about this: there is no automatic purge. Information stays until the brand or the connected account is deleted in the tool, or until we act on a deletion request.
Disconnecting an account, or deleting a brand, marks its records as deleted. The tool stops using them straight away and collects nothing further for them. But the underlying rows, including the stored access token, stay in the database until we erase them. If you want them actually erased rather than deactivated, ask us using the section below and we will do it.
Anyone can ask. Requests go to hello@creativemite.com. We acknowledge every request within 5 business days and complete it within 30 days.
1. If you are a client, or you own the brand
You can stop the collection yourself, immediately, inside the tool:
That deactivates the records. To have them erased from our database, email us with the subject line Data deletion request and name the brand and the accounts.
You should also remove our app on the platform itself, which revokes the token at Meta's end: on Facebook under Settings & Privacy → Settings → Business Integrations, and on Instagram under Settings → Website Permissions → Apps and Websites.
2. If you use the tool
Anyone who manages a brand can remove you from it under Brand Members, which ends your access to that brand's data. To have your user account and the record of it deleted altogether, email us with the subject line Data deletion request, from the address the account uses.
3. If you commented on, reviewed, mentioned or messaged an account we manage
You have no account with us and there is nothing to sign in to. Email hello@creativemite.com with this subject line:
Data deletion request: social inbox
Tell us:
We use those details only to find your records, and for nothing else. We then delete the text of your comment, recommendation, mention or message, your name, @handle and platform id, and any attachment link we stored. Once that is done we email you to confirm it.
What we cannot do for you
Deleting our copy does not remove anything from Facebook, Instagram or LinkedIn. Their copy is theirs, and their own policies govern it. To remove it there, delete it in the app, or contact the platform: Facebook, Instagram, LinkedIn. In the same way, once a post has been published to a platform it lives there under that platform's rules.
Whether or not you use the tool:
Write to hello@creativemite.com and we will answer within 30 days. We may need to confirm who you are before we do, and where we hold the information on a client's behalf we will pass the request to that client.
If our answer does not satisfy you, you can take it to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner of Alberta.
Our databases, file storage and web servers run on Microsoft Azure. Meta, LinkedIn, Google and Microsoft all operate internationally, so information covered by this policy may be stored or processed outside Canada, and will be subject to the laws of the countries involved.
It is a business tool, and we do not knowingly collect information from anyone under 13. If a child's comment or message has reached us through an account we manage, tell us and we will delete it.
When a new feature reads or stores something this policy does not already describe, this page changes with it. The date at the top is the date of the current version, and material changes are posted here before they take effect.
CreativeMITE, 3003 43 Ave #115, Stony Plain, AB T7Z 0H4, Canada · hello@creativemite.com · 780.963.9292 · Contact us
There is one tool, one database and one set of practices behind it, so the handling described here is what everyone gets: our own team, our clients, and the members of the public who comment on a post or send a message. Which law brought you to this page changes what you can require of us. It does not change what we do.