Privacy Policy
Version 1 · Effective date: 26 September 2026
1. Who we are
This policy explains the processing of personal data on TACT Grow · tactgrow.com and in the TACT Grow panel. The data controller under Türkiye's KVKK is Tactfair Organizasyon A.Ş. Tax details: Bornova V.D. 8151144050. Address: Alsancak Mah. Atatürk Cad. Gündoğdu No: 244 İç Kapı No: 4, Konak / İzmir. Our contact address for privacy requests is support@tactlabs.dev.
This text covers account registration, business information, readings from accounts you connect, the First Check scan, cookies and data deletion requests. The data processed varies according to the features you use and the connection permissions you grant for your own account.
2. Data we collect
User registration collects only an email address and password; first and last names are not collected. Email verification is mandatory. Passwords are hashed with Argon2id.
During business setup, account type, legal name, country and contact number are required. The business step collects the business display name, industry, description and contact number. Website, Facebook, Instagram, Google Business, TikTok, YouTube, LinkedIn and X links and a WhatsApp number are optional. These fields are used to create the account and business record.
Account identifiers, connection permissions and access credentials for the advertising accounts you connect are processed. The fields read for Meta and Google are described in their respective sections below.
Session information is held in the database. Identity and membership events are recorded in database audit tables. Server request logs include the client IP address; their retention limits appear in section 8. Application log entries contain no email address, IP address or user identifier.
3. How we collect data
Account and business information is collected through the forms you complete. The registration form uses Cloudflare Turnstile for bot checks. Verification and password emails are sent through Google Workspace SMTP. When you sign in with Google, Facebook or Microsoft, these services are used only for sign-in identity; social sign-in access tokens are not stored.
Advertising account data is read from the provider's API for accounts you connect yourself. When you connect your Google Ads account, the scope used and the fields read are subject to the limits in section 5.
First Check collects signals from public pages at the website and social profile links supplied. Request logs are generated on the server; identity and membership events are written to audit records in the application's database. For creative text tasks, only brief fields written by the customer are sent to OpenAI; advertising API data is not sent.
4. Meta connection
When you connect your Meta advertising account, the account directory provides `id`, `account_id`, account name, currency and account status. The page list provides page identifiers and names. The connection requests `ads_management`; `pages_show_list` is added when page selection is used. Granted permissions are read back from Meta for verification.
First Check's Meta reading is limited to four GET operations: advertising account identity, account access capability, Facebook page identity and Instagram professional account identity. Response fields at this stage are limited to provider identifiers; a response contains at most four fields.
First Check uses `ads_read` for advertising account identity; `pages_read_engagement` and `pages_show_list` for Facebook page identity; and `ads_read`, `instagram_basic` and `pages_read_engagement` for Instagram professional identity. The `ads_management` permission can technically carry write capability; the First Check operations described here only read data.
You can remove the Meta connection from the panel. You can separately request deletion of your account and personal data at support@tactlabs.dev.
5. Google connection
Google sign-in uses only the `openid` and `email` scopes. These scopes concern sign-in identity. Social sign-in access tokens are not stored; sign-in and advertising account connections are authorised separately.
When you connect your Google Ads account, the `https://www.googleapis.com/auth/adwords` scope is used for advertising access. Reading covers only the account you connect yourself. First Check queries are limited to customer identity (`customer.id`), whether the account is a manager account (`customer.manager`), account status (`customer.status`) and conversion action identity (`conversion_action.id`). Each query retrieves at most one row, with at most three fields in the response.
TACT Grow complies with the Limited Use requirements of the Google API Services User Data Policy in its use of information received from Google APIs. This commitment covers only the `openid` and `email` scopes for sign-in and the limited reading described above from the user's own connected advertising account. Google data is not used for advertising, sold or transferred to third parties. Humans do not read this data except where legally required, for a security investigation or with the user's explicit permission.
You can send requests concerning your Google connection or deletion of Google data to support@tactlabs.dev.
6. First Check scan
First Check scans only public pages. A scan follows at most three pages and at most three redirects; only HTML and XHTML content is processed. Requests to private network and loopback addresses are rejected. Social profile links are restricted to permitted HTTPS domains.
The scan extracts a page title of at most 300 characters, call-to-action counts and categories, form counts and form destination categories, whether a Meta pixel is present, and external reference counts. These signals evaluate page structure; email addresses, contact numbers and personal names are not extracted. Checking whether a page contains a pixel does not mean that TACT Grow uses advertising cookies.
Query parameters resembling confidential information, such as API keys, tokens, secrets or passwords, are removed from links.
7. Cookies
TACT Grow uses the following three cookies. No analytics or advertising cookies are used. No cookie that creates a requirement for a cookie banner is used.
| Cookie | Purpose | Duration |
|---|---|---|
| `__Host-tactgrow_django` | Maintain the user session | 8 hours; deleted when the browser closes |
| `__Host-tactgrow_csrf` | Protect against cross-site request forgery | 1 year |
| `django_language` | Retain your selected interface language | Session |
Session and CSRF cookies have the Secure, HttpOnly and SameSite=Lax attributes. The language cookie contains only the language code.
8. Retention and backups
Servers, the database, media bucket, logs and backups are in Germany on Hetzner's Nuremberg infrastructure. Hetzner Object Storage is used for media. Logs and database backups are held on the same server.
A database dump is made with `pg_dump` every night at 02:00. These backups remain on the same server for 7 days and do not leave the server. A restore drill is performed every Sunday at 03:30. A record deleted from the database can remain in nightly dumps for at most another 7 days; it then automatically leaves the backup cycle.
The 30-day deletion period for data covered by deletion includes this backup cycle; no additional 7-day period is added to the 30 days for backup removal. Requests are answered as soon as possible and within 30 days at the latest. Records subject to statutory retention obligations remain subject to the retention requirements of the applicable legislation.
Server logs are kept in persistent journald records, limited to at most 1 GB and at most 30 days. Caddy request logs include the client IP address. Gunicorn also records requests; query strings are excluded from these records. Your IP address is therefore retained in server logs for at most 30 days.
9. Security and access
TLS is used for data in transit. The database and Redis are not exposed externally; they are accessible only on the internal network. Passwords are hashed with Argon2id; user sessions are held in the database and associated with the session cookie.
Access credentials for advertising accounts connected by the customer are encrypted at the application level using AES-256-GCM and bound to the tenant.
Data separation between businesses is implemented through database row-level security policies and a tenant context verified for each transaction. The application's runtime roles cannot bypass these row-level security rules.
SSH access to the server uses two keys and is allowed only from trusted IP addresses. Administrative access is limited to the CTO and a restricted CI user able to run only a single deployment command. System secrets are protected with SOPS+age and decrypted on the server only in RAM. Application logs contain no personal data; framework logs use the route name instead of the request path.
10. Third parties
The third parties used and their roles are listed below.
| Third party | Role and data scope |
|---|---|
| Hetzner | Server and media bucket hosting in Germany |
| Google Workspace SMTP | Verification and password emails |
| Telegram | Server monitoring messages only; no application data is sent |
| OpenAI | Creative text tasks; only brief fields written by the customer, with no advertising API data sent |
| Cloudflare Turnstile | Bot checks on the registration form |
| Google / Facebook / Microsoft | Sign-in identity only |
| GitHub / GHCR | Code and image hosting; no customer data |
| Tailscale | Administrative network |
| Meta and Google advertising APIs | Accounts connected by the customer themselves |
11. Your rights: KVKK Article 11 and GDPR
Under Article 11 of KVKK No. 6698, subject to the applicable legal conditions, you have the right to:
- Learn whether your personal data is processed and request information if it is.
- Learn the purpose of processing and whether the data is used for that purpose.
- Know the third parties to whom data is transferred in Türkiye or abroad.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction when the legal conditions are met.
- Request notification of correction, deletion or destruction to third parties that received the data.
- Object to an adverse outcome arising from analysis solely by automated systems.
- Seek compensation for damage caused by unlawful processing.
Where the European Union's General Data Protection Regulation (GDPR) applies, subject to the relevant conditions, you have rights of access and obtaining a copy, rectification, erasure, restriction of processing, objection and data portability. Where processing relies on consent, you can withdraw it without affecting the lawfulness of processing before withdrawal. You can object to processing for direct marketing. Subject to applicable exceptions, you have the right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects, to request human intervention and to challenge a decision, and to complain to the competent data protection supervisory authority.
You can send rights and deletion requests to support@tactlabs.dev, including the email address registered to your account. The data deletion request page is tactgrow.com/legal/data-deletion-request/. There is no user-facing account deletion button in the panel; the process is handled through support. You may be asked to verify your identity. You can confirm receipt and the stage of your request through support's written response. Requests are answered as soon as possible and within 30 days at the latest; deletion and the backup cycle are described in section 8. This request does not automatically delete your Meta or Google accounts on third-party platforms.
12. Contact and changes
For privacy, disconnection and data deletion requests, you can contact Tactfair Organizasyon A.Ş. at support@tactlabs.dev.
Changes are published on this page; the version number and effective date are updated.