Meta apps covered by this document
This document applies to the following apps operated by Halis Sarıca – Ninja Agency on the Meta developer platform:
| App | Meta App ID | Purpose and data used |
|---|---|---|
| Ninja Panel | 764342293314597 | Lets our agency team and our clients manage Meta ad accounts, campaigns, audiences, instant-form leads and reports for the Business assets connected to them, through the official Meta APIs. Access tokens are stored encrypted; data is never sold. |
01Who we are
The controller for the processing described in this policy is:
Halis Sarıca – Ninja Agency
Horozluhan Mah. Günpınar Sk. No: 33 İç Kapı No: 1, Selçuklu / Konya, Türkiye
Email: [email protected]
Phone: +90 535 308 52 78
If you have any question about this policy or your data, contact us at [email protected]. Data protection contact: [email protected].
02Scope
This policy covers:
- our website https://ninjagency.com;
- our advertising and consulting services;
- Ninja Panel, our web application for managing Meta advertising (Meta App ID: 764342293314597), available at https://app.ninjagency.com.
When we process data on behalf of a business client (for example the leads of an advertiser or the content of their ad accounts), we act as that client’s processor or service provider, and the client is the controller. In that case the client’s own privacy policy also applies.
03Data we process when you visit the website
- Technical data: IP address, date and time of the request, pages visited, browser and device information. Our servers keep this in access logs for security and error analysis. IP addresses we store in our own database for abuse prevention are pseudonymised (hashed).
- Cookies and similar technologies: necessary cookies, and — only with your consent — analytics (Google Analytics) and marketing (Meta Pixel) cookies. Details are in our cookie policy.
- Contact form: name, email, phone, company, the service and budget you select, your message and the time of your consent.
- Data deletion requests: name, email, your Facebook name or ID if you provide it, the details of your request and its status.
04Data we process in Ninja Panel
Account data of platform users: name, email address, password (stored only as a salted hash), role and access assignments, login times and an audit log of actions.
Platform Data received from Meta. When a business connects to Ninja Panel through Facebook Login for Business or grants access to its Business Manager, we receive through the official Meta APIs — and only for the assets that business shares with us:
- the Meta user ID and name of the person who authorised the connection, and the access token issued by Meta (stored encrypted);
- Business Manager information: business IDs and names, and which people and system users have access to shared assets;
- ad account information: IDs, names, status, currency, time zone, spending limits, amounts spent and the payment method description shown by Meta (for example card type and last four digits — never full card numbers);
- campaigns, ad sets, ads and creatives: their settings, budgets, schedules, targeting and status, and the images, videos and texts used in ads;
- performance insights: aggregated metrics such as impressions, reach, clicks, spend and conversions;
- Facebook Pages and Instagram business accounts: IDs, names, usernames, profile pictures, follower counts, posts selected for ads, and Page access tokens (stored encrypted);
- pixels/datasets and product catalogs: IDs, names, settings and aggregated event statistics;
- custom audiences: names, sizes and settings. Customer lists are hashed in your browser (SHA-256) before they are sent to Meta; we do not store raw lists;
- leads submitted to the advertiser’s instant forms: the answers to the form questions (for example name, email, phone) and form metadata. Lead answers are stored encrypted and are only available to the advertiser who owns the form and the people they authorise;
- notifications that Meta sends to our webhook about changes to these assets.
We do not ask for, receive or store Facebook passwords or browser cookies, and we do not use browser automation.
05Why we process your data and on what legal basis
- To provide Ninja Panel and our services (managing ad accounts, creating and editing campaigns, reporting, delivering leads to the advertiser, controlling access): performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)), and — where we act for a client — on the client’s documented instructions.
- To answer your enquiries and requests: steps prior to a contract or our legitimate interest in responding (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)).
- To keep our systems secure and prevent abuse: legitimate interest (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Analytics and marketing cookies: your consent (GDPR Art. 6(1)(a); KVKK Art. 5(1); ePrivacy rules), which you can withdraw at any time.
- Legal obligations such as accounting and tax records and responding to lawful requests: GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç).
We use Platform Data from Meta only to provide Ninja Panel to the business that shared it, in line with the Meta Platform Terms. We do not sell, license or purchase Platform Data; we do not use it to build profiles for other purposes, to target people outside the advertiser’s own campaigns, or to provide services to anyone else; and we do not share it with data brokers or advertising networks.
07International transfers
Our servers are located in Amsterdam (NL). Meta, Google and some service providers may process data outside your country, including outside the European Economic Area and Türkiye. Where this happens we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, adequacy decisions, and — for transfers from Türkiye — the safeguards required by Article 9 of KVKK.
08How long we keep data
- Contact form messages: up to 24 months after our last contact, unless they lead to a contract.
- Data deletion requests: up to 3 years, as proof that we handled the request.
- Consent records: up to 3 years after your last choice.
- Server logs: up to 30 days, unless needed to investigate a security incident.
- Platform user accounts: while the account is active; deleted or anonymised within 30 days after it is closed.
- Platform Data from Meta: while the business keeps Ninja Panel connected and our service is active. We delete it as soon as reasonably possible and no later than 30 days after the business disconnects Ninja Panel, the contract ends, the data is no longer needed for the service, or a verified deletion request is received — unless the law requires us to keep it. Access tokens are deleted immediately when a connection is removed.
- Invoices and contract records: for the period required by tax and commercial law.
09How to request deletion of your data
You can ask us to delete your data at any time:
- follow the steps on our data deletion page and submit the form there;
- or email [email protected] with the subject “Data deletion request”.
If you connected a business to Ninja Panel, you can also remove the app in Facebook under Settings & privacy → Settings → Business integrations (or Apps and websites). This stops our access immediately; send us a deletion request as well so we delete the data we already hold. We confirm every request with a reference code and complete it within 30 days.
10Your rights
Depending on the law that applies to you, you have the right to:
- access your data and receive a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing, including processing based on our legitimate interests;
- data portability;
- withdraw your consent at any time, without affecting earlier processing;
- lodge a complaint with a supervisory authority — for example the authority in your EU country of residence, the Dutch Autoriteit Persoonsgegevens, a German data protection authority, or the Turkish Personal Data Protection Authority (KVKK).
If you are in Türkiye, you also have the rights listed in Article 11 of KVKK; see our KVKK information notice. To exercise your rights, email [email protected]. We will answer within one month (within 30 days under KVKK) and may ask you to verify your identity.
11Security
We use administrative, technical and physical safeguards designed to protect personal data against unauthorised access, loss, alteration or disclosure, including encrypted connections (HTTPS), encryption of access tokens and secrets at rest, hashed passwords, role-based access control, separation of each client’s data, audit logs and regular updates. If a security incident affects your data or Platform Data, we will notify you, the competent authorities and Meta as required by law and by the Meta Platform Terms.
12Children
Our website and Ninja Panel are intended for businesses and are not directed at children under 16. We do not knowingly collect data from children.
13Changes to this policy
We may update this policy when our services or the law change. The effective date at the top shows the latest version. We will inform platform users of material changes in advance.