Legal
Privacy Policy
Last updated: 8 October 2026
This policy explains what PromReach collects, why, who we share it with and the choices you have. We collect only what we need to run the service, and we never sell your data.
1. Who we are
PromReach (promreach.com) is a marketing platform for businesses, agencies and creators. This policy covers our website, web app, mobile apps and API. If you have questions, email support@promreach.com.
When a business uses PromReach to manage its own customers' messages or comments, that business decides what happens to that data and we process it on its behalf.
2. What we collect
Information you give us
- Account details: name, email address, password (stored only as a secure hash), optional phone number and profile photo.
- Workspace details: organization name, team members and their roles, brand kit, billing details.
- Content you create or upload: posts, captions, images and videos, campaigns, links, bio pages, reports, AI Studio prompts and saved results.
- Marketplace and creator data: service listings, creator profiles, portfolios, briefs, orders, deliverables and messages about them.
- Support tickets and messages you send through the contact form.
Information from connected platforms
When you connect Facebook, Instagram, TikTok, YouTube or LinkedIn, you sign in on that platform and choose what to share. We never see your password. Depending on the permissions you grant, we receive:
- Your profile, Page or channel name, handle, picture and IDs, and the ad accounts you manage.
- Posts, comments, direct messages and mentions on the Pages and accounts you connect, so you can publish, reply and see them in one inbox.
- Insights the platform reports: followers, reach, impressions, engagement, video views, ad spend and results, and audience breakdowns where the platform provides them.
- Access tokens, which we store encrypted and use only to perform the actions you ask for.
We use data from YouTube API Services only to show your channel's statistics and content inside PromReach. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's use of your data is covered by the Google Privacy Policy. You can revoke our access at any time from Google security settings.
Payments
Card and mobile-wallet payments are handled by our payment providers (EPS and Stripe). We never receive or store full card numbers. We keep a record of each payment, refund, withdrawal and wallet movement, because we are required to keep accurate financial records.
Information collected automatically
- Session data: IP address, browser or device type (user agent) and sign-in times, to keep your account secure and let you see and end active sessions.
- Smart link and bio page visits: the referring website, an approximate country and the device type. We do not store visitors' IP addresses for link analytics.
- Push notification tokens, if you turn on notifications in the browser or mobile app.
- Logs and error reports that help us find and fix problems.
3. How we use it
- To provide the service: publish and schedule content, run campaigns, show analytics, run the inbox, marketplace and wallet.
- To generate AI suggestions when you use AI Studio or the AI agent. AI never publishes on its own; you approve every action.
- To process payments, prevent fraud and abuse, and keep financial records.
- To send account emails (verification, password reset, receipts, important changes) and the notifications you choose.
- To secure the service, debug problems and improve features.
- To meet legal obligations.
4. Legal bases
We process your data to perform our contract with you (running the service you signed up for), to meet legal obligations (for example financial record keeping), for our legitimate interests (security, fraud prevention, improving the product) and, where required, with your consent (for example push notifications). You can withdraw consent at any time.
6. How long we keep it
- Account and workspace data: while your account is active. When you delete your account, we delete or anonymize it after a 14-day grace period.
- Platform tokens: deleted as soon as you disconnect a platform or delete your account.
- Payment, wallet and invoice records: kept as long as the law requires for financial records, linked to an anonymized account after deletion.
- Session records and logs: kept for a limited time for security and debugging.
- Backups: overwritten on a rolling schedule of up to six months.
7. Security
We encrypt data in transit (HTTPS) and encrypt platform access tokens at rest. Passwords are hashed. You can turn on two-factor authentication and review active sessions in your settings. Access to production systems is limited to people who need it. No system is perfectly secure, so please tell us at support@promreach.com if you find a problem.
8. Your choices and rights
- Access and update your profile in Settings.
- Disconnect any platform at any time in Settings → Social accounts. You can also remove PromReach from the platform's own app settings.
- Export reports and lists as CSV or PDF.
- Delete your account: see how to delete your account.
- Ask for a copy of your data, a correction or a deletion by emailing support@promreach.com. We answer within 30 days.
If you signed in to a platform through PromReach and want that platform's data removed, see data deletion instructions.
10. Children
PromReach is for people aged 18 and over. We do not knowingly collect data from children.
11. International transfers
Our servers and some of our providers are outside Bangladesh. When data moves between countries we rely on our providers' contractual safeguards to protect it.
12. Changes to this policy
We will post any changes on this page and update the date above. If a change is significant, we will tell you by email or in the app before it takes effect.
13. Contact
Email support@promreach.com or use the contact form.
