Privacy Policy
This Privacy Policy describes how The Aesthetic Generator LLC ("we," "us," or "our") collects, uses, shares, and protects information in connection with the Meta Ad Access Manager application (the "App"), available at https://aestheticgenerator.com. This policy is publicly accessible, non-geoblocked, and compliant with Meta Platform Terms Section 4.
Last updated: March 15, 2026
1. Overview
The Meta Ad Access Manager is a contracted marketing services tool operated by The Aesthetic Generator LLC, a Virginia limited liability company. The App enables businesses ("Clients") to grant The Aesthetic Generator LLC partner-level access to their Meta advertising accounts, and enables The Aesthetic Generator LLC to create, manage, and optimize Meta ad campaigns on behalf of those Clients.
By using this App — including by completing the onboarding flow at /connect, logging in via Facebook, or accessing the administrative dashboard — you agree to the practices described in this Privacy Policy.
This policy is designed to meet the requirements of the Meta Platform Terms (Section 4), the Meta Developer Policies, the Virginia Consumer Data Protection Act (VCDPA), and applicable provisions of the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR). In accordance with Meta Platform Terms Section 4.b, this policy clearly explains what data you are Processing, how you are Processing it, the purposes for which you are Processing it, and how Users may request deletion of that data.
2. Who We Are
The Aesthetic Generator LLC is a marketing services company incorporated in the Commonwealth of Virginia. We provide contracted digital advertising services to businesses in the aesthetics, wellness, and healthcare industries. All marketing content is ultimately approved by the Client and run in the Client's own advertising account.
Important: All marketing content is ultimately approved by the client and run in their advertising account. The Aesthetic Generator LLC does not own the creative, copy, automations, emails, or any content provided to the Client, and takes no liability for any marketing that the Client company decides to publish, whether B2B or B2C. Any "Partners" or Referral Partners referenced in our materials (such as LegitScript, Project Blue, TrueEval, or others) are independent third-party companies not owned by or affiliated with The Aesthetic Generator LLC. Any claims, fulfillment, or services rendered by those parties are their sole responsibility.
For privacy inquiries, contact us at: [email protected]
3. Data We Collect
We collect the following categories of information when you use the App. This includes data you provide directly, data collected automatically, and data obtained from Meta's Platform through permissions you grant.
3.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Business Information | Business name, website URL, industry, business type | To identify your business and set up the onboarding record |
| Contact Information | Name, email address, phone number | To communicate with you about your account and access status |
| Account Credentials (indirect) | Facebook User ID, Business Manager ID, Ad Account ID | Returned by Meta after you authorize the Facebook Login flow — we never collect your Facebook password |
3.2 Data Collected via Facebook Login (Meta Platform Data)
When you authenticate using Facebook Login, we receive the following Platform Data from Meta, subject to the permissions you grant:
| Category | Examples | Purpose |
|---|---|---|
| Public Profile | Name, profile picture, Facebook User ID | To identify you and associate your account with your business record |
| Email Address | Primary email on your Facebook account | To send you confirmations and updates about your onboarding |
| Business Accounts | Business Manager IDs, business names you manage | To display your businesses and allow you to select which account to connect |
| Ad Accounts | Ad account IDs, names, currency, status, spend limits | To allow you to select which ad account to grant partner access to |
| Access Token | Short-lived and long-lived Facebook User Access Token | To authenticate API calls on your behalf to grant partner access and manage campaigns |
3.3 Ad Account & Campaign Data (Marketing API)
Once partner access is granted, we access the following data through the Meta Marketing API on behalf of the Client:
| Category | Examples | Purpose |
|---|---|---|
| Campaign Data | Campaign names, objectives, status, budgets, schedules | To display, manage, and optimize your campaigns from the dashboard |
| Ad Set Data | Targeting parameters, audience settings, bid amounts | To create and optimize ad sets on your behalf |
| Ad Creative Data | Headlines, primary text, images, call-to-action types, destination URLs | To create and manage ad creatives on your behalf |
| Performance Insights | Spend, impressions, clicks, ROAS, CPM, CTR by campaign and date range | To analyze performance and provide optimization recommendations |
| Recommendations | Meta-generated optimization suggestions for your account | To surface actionable improvements to your campaigns |
3.4 Automatically Collected Technical Data
| Category | Examples | Purpose |
|---|---|---|
| Log Data | IP address, browser type, operating system, referring URL, pages visited, timestamps | Security, debugging, and fraud prevention |
| Session Data | Session cookies, authentication tokens (stored in secure HTTP-only cookies) | To maintain your login session |
| Usage Data | Features used, actions taken within the App, time spent | To improve the App and understand how it is used |
4. How We Use Your Data
We process your data only for the following legitimate purposes, as required by Meta Platform Terms Section 4.b and applicable law:
Providing the Service
To operate the onboarding flow, grant partner access to your Meta ad account, and manage campaigns on your behalf as a contracted marketing service provider.
Campaign Management & Optimization
To create, read, update, and manage Meta ad campaigns, ad sets, and ad creatives through the Meta Marketing API on behalf of Clients who have granted us access.
Performance Reporting
To retrieve and display ad performance insights (spend, impressions, clicks, ROAS) so that both you and our team can monitor campaign results.
Account Administration
To maintain your client record, track access status, and manage the partner relationship between your ad account and our Business Manager (ID: 2581418418854646).
Communication
To send you confirmation emails, status updates, and operational notifications related to your account and campaigns.
Security & Compliance
To detect fraud, prevent unauthorized access, comply with legal obligations, and enforce our terms of service.
Service Improvement
To analyze aggregated, de-identified usage patterns to improve the App's features and user experience.
Meta Platform Terms Compliance: We process Platform Data only as described in this privacy policy and only for the purposes for which it was collected, in accordance with Meta Platform Terms Section 3 (Data Use) and Section 4 (Privacy Policy). We do not sell, license, or purchase Platform Data. We do not use Platform Data to build user profiles for advertising targeting, make eligibility determinations, or perform surveillance.
5. Meta Platform Data — Special Disclosures
Because this App integrates with Meta's Platform (Facebook Login, Graph API, and Marketing API), the following additional disclosures are required under the Meta Platform Terms and Meta Developer Policies.
5.1 Permitted Use of Platform Data
We access Meta Platform Data solely to provide the contracted marketing services described in this policy. Specifically, we use Platform Data to: (a) authenticate users via Facebook Login; (b) display your businesses and ad accounts for selection during onboarding; (c) send a partner access request to your ad account on behalf of The Aesthetic Generator LLC's Business Manager; and (d) create and manage Meta ad campaigns, ad sets, and creatives on your behalf.
5.2 Prohibited Uses
We will never use your Meta Platform Data to:
- ✗Sell, license, or transfer your data to third parties for their own use
- ✗Build advertising profiles about you or your users
- ✗Make eligibility determinations (housing, employment, credit, insurance, etc.)
- ✗Perform surveillance or law enforcement functions
- ✗Discriminate based on protected characteristics
- ✗Re-identify anonymized or aggregated data
- ✗Use data for purposes materially different from those described here without re-obtaining your consent
5.3 Access Token Handling
Facebook User Access Tokens obtained during the onboarding flow are used solely to make authorized API calls on your behalf. Long-lived tokens are stored securely in our database with encryption at rest. Tokens are never logged, exposed in URLs, or transmitted to unauthorized third parties. You may revoke access at any time through your Facebook App Settings .
6. Data Sharing & Disclosure
We do not sell your personal information. We share your data only in the following limited circumstances:
6.1 Meta Platforms, Inc.
By using Facebook Login and granting partner access, you authorize us to interact with Meta's APIs on your behalf. Meta processes data in accordance with its own Privacy Policy and Platform Terms .
6.2 Service Providers
We may share data with trusted service providers who assist in operating the App (e.g., cloud hosting, database services, email delivery). All service providers are contractually required to: (a) use data only to provide services to us; (b) maintain appropriate security safeguards; and (c) comply with Meta Platform Terms as if they were in our place, per Meta Platform Terms Section 5.a.
6.3 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website prior to your information being transferred and becoming subject to a different privacy policy.
6.5 Third-Party Partners (Referral Partners)
Any "Partners" or Referral Partners referenced in our marketing materials (such as LegitScript, Project Blue, TrueEval, or others) are independent third-party companies. We do not share your personal data with these partners without your explicit consent. These parties have their own privacy policies and are solely responsible for their own data practices and any claims or services they provide.
7. Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Category | Examples | Purpose |
|---|---|---|
| Client Business Records | Business name, contact info, onboarding status | Retained for the duration of the service relationship plus 3 years for legal/accounting purposes |
| Facebook Access Tokens | Long-lived user access tokens | Retained until revoked by the user or until the service relationship ends, whichever is earlier |
| Ad Account IDs & Campaign Data | Account IDs, campaign names, performance metrics | Retained for the duration of the service relationship; deleted within 30 days of account termination |
| Log & Technical Data | IP addresses, session logs | Retained for up to 90 days for security and debugging purposes |
| Aggregated Analytics | De-identified usage statistics | May be retained indefinitely as they cannot be associated with any individual |
In accordance with Meta Platform Terms Section 3.d, we will delete Platform Data promptly upon receiving a deletion request from you or from Meta, when retaining the data is no longer necessary for a legitimate business purpose, or when required by applicable law.
8. Your Rights & Data Deletion Requests
You have the following rights regarding your personal data. These rights apply to all users who can access the App, as required by Meta Platform Terms Section 4.b.
Right to Access
Request a copy of the personal data we hold about you.
Right to Deletion
Request that we delete your personal data from our systems.
Right to Correction
Request correction of inaccurate or incomplete data.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Restrict Processing
Ask us to limit how we use your data in certain circumstances.
Right to Object
Object to our processing of your data for certain purposes.
Right to Revoke Consent
Revoke your Facebook Login authorization at any time via Facebook App Settings.
Right to Withdraw Partner Access
Remove our Business Manager's access to your ad account at any time via Meta Business Manager.
How to Submit a Data Deletion Request
To exercise any of the above rights, or to request deletion of your data, please contact us using one of the following methods. We will respond within 30 days of receiving your request.
You may also revoke our access to your Meta ad account directly through Meta Business Manager → Partners , or revoke Facebook Login authorization through Facebook App Settings .
9. Security
We implement administrative, physical, and technical safeguards designed to protect your information against unauthorized access, disclosure, alteration, and destruction, in accordance with Meta Platform Terms Section 6 (Data Security).
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
Encryption at Rest
Sensitive data including access tokens and personal information is encrypted at rest in our database.
Access Controls
Access to client data is restricted to authorized personnel only, using role-based access controls.
Session Security
Authentication sessions use secure, HTTP-only, SameSite cookies with short expiration windows.
No Password Collection
We never collect or store your Facebook password. Authentication is handled entirely by Meta's OAuth system.
Vulnerability Reporting
To report a security vulnerability, email us at [email protected]. We will acknowledge and address reports promptly.
While we implement industry-standard security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data.
10. Facebook Login
This App uses Facebook Login (a Meta product) to authenticate users. When you click "Continue with Facebook," you are redirected to Meta's login interface. We never see or store your Facebook password.
During the Facebook Login flow, we request the following permissions:
| Category | Examples | Purpose |
|---|---|---|
| public_profile | Name, profile picture, Facebook User ID | Required to identify you and associate your session with your business record |
| Primary email address on your Facebook account | To send you account-related communications and confirmations | |
| business_management | Business Manager accounts you manage, Business IDs | To list your businesses so you can select which one to connect |
| ads_management | Ad account IDs, campaign data, ad sets, creatives, insights | To grant partner access and manage campaigns on your behalf as a contracted service provider |
| ads_read | Ad account performance data, insights, recommendations | To retrieve and display campaign performance metrics in the dashboard |
You can review and revoke these permissions at any time by visiting Facebook Settings → Apps and Websites . Revoking permissions will prevent us from managing your campaigns but will not automatically remove our Business Manager's existing partner access to your ad account (which must be removed separately via Meta Business Manager).
11. Meta Marketing API
This App uses the Meta Marketing API (part of the Meta Graph API) to create, manage, and optimize Meta ad campaigns on behalf of Clients. We access this API using the ads_management and ads_read permissions granted by the Client during onboarding.
All Marketing API access is governed by the Meta Platform Terms and the Meta Developer Policies . We use Marketing API data exclusively to provide the contracted advertising management services described in this policy and for no other purpose.
Our Meta App (App ID: 1493540405531418) has been registered with Meta and is subject to Meta's App Review process for advanced permissions. We operate as a Tech Provider under Meta Platform Terms Section 5.b, accessing Platform Data on behalf of and at the direction of our Clients.
12. Partner Access to Ad Accounts
The core function of this App is to facilitate the granting of Meta Business Partner Access from a Client's Meta ad account to The Aesthetic Generator LLC's Business Manager (Business Portfolio ID: 2581418418854646).
When you complete the onboarding flow and grant partner access:
- →We send a partner access request to your selected ad account via the Meta Graph API using your authorized access token.
- →This grants our Business Manager the ability to create, manage, and run ads within your ad account.
- →All ad spend remains in your ad account and is billed to your payment method on file with Meta.
- →We do not transfer funds, access your payment information, or make financial decisions on your behalf.
- →All marketing content is ultimately approved by you (the Client) and run in your advertising account.
- →You retain full ownership and control of your ad account at all times.
You may revoke partner access at any time by navigating to Meta Business Manager → Settings → Partners and removing The Aesthetic Generator LLC from your account.
14. Children's Privacy
This App is intended for use by business owners and marketing professionals who are at least 18 years of age. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete such information as soon as possible. If you believe we may have collected information from a child under 13, please contact us at [email protected].
15. Virginia Consumer Data Protection Act (VCDPA)
As a Virginia company, The Aesthetic Generator LLC is subject to the Virginia Consumer Data Protection Act (Va. Code § 59.1-571 et seq.). Virginia residents have the following rights with respect to their personal data:
Right to Know
Confirm whether we process your personal data and access such data.
Right to Correct
Correct inaccuracies in your personal data.
Right to Delete
Delete personal data you have provided to us or that we have obtained about you.
Right to Data Portability
Obtain a copy of your personal data in a portable format.
Right to Opt Out
Opt out of the processing of your personal data for targeted advertising, sale, or profiling. (We do not engage in these activities.)
Right to Appeal
If we decline to act on your request, you may appeal our decision by contacting us at the email below.
To exercise any of these rights, submit a request to [email protected]. We will respond within 45 days, with a possible 45-day extension where reasonably necessary. We will not discriminate against you for exercising your rights.
Note on CCPA (California): California residents may have similar rights under the California Consumer Privacy Act (CCPA/CPRA). We do not sell personal information as defined under the CCPA. To submit a CCPA request, use the same contact information above.
16. International Data Transfers
The Aesthetic Generator LLC is based in the United States. If you are accessing the App from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated.
By using the App and providing us with your information, you consent to the transfer of your information to the United States and to the processing of your information in the United States in accordance with this Privacy Policy.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland: We process your data on the legal basis of your consent (given when you authorize Facebook Login and grant partner access) and on the basis of our legitimate interests in providing contracted marketing services. You have the right to withdraw consent at any time and to lodge a complaint with your local data protection authority.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- •Update the "Last Updated" date at the top of this policy
- •Post the revised policy at this URL
- •Notify registered users via email if the changes are material
- •Re-submit our App for Meta App Review if changes affect how we process Platform Data
Your continued use of the App after any changes to this Privacy Policy constitutes your acceptance of the revised policy. If you do not agree to the revised policy, please discontinue use of the App and contact us to request deletion of your data.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
The Aesthetic Generator LLC
Commonwealth of Virginia, United States
We will respond to all privacy requests within 30 days. For urgent security issues, please include "URGENT" in the subject line.
This privacy policy is publicly accessible, non-geoblocked, and compliant with Meta Platform Terms Section 4, Meta Developer Policies, and Virginia VCDPA requirements.
© 2026 The Aesthetic Generator LLC. All rights reserved.