Privacy
Privacy Policy
How XPLENDOR handles personal data and advertising data of its customers, including the data received from Meta (Facebook and Instagram).
On this page
- 1. Data controller
- 2. Who this policy applies to
- 3. Account and Platform usage data
- 4. Data received from Meta (Facebook and Instagram)
- 5. Where Meta data is stored, for how long and how it is deleted
- 6. Measurement on customer websites
- 7. Sharing with third parties
- 8. Security
- 9. Your rights (GDPR)
- 10. Changes to this policy
1. Data controller
The controller of the data described in this policy is:
- Entity: SIMON COSTA, UNIPESSOAL LDA, which operates the XPLENDOR brand
- Tax number (NIF): 517343355
- Address: Rua Camilo de Oliveira, 101, 4.º Esq., Rio Tinto, Gondomar
- Privacy contact: xplendorcar@gmail.com
XPLENDOR is the business management and marketing analytics platform available at xplendor.pt and in the related web application (the "Platform").
2. Who this policy applies to
This policy applies to:
- visitors of this website;
- companies that are customers of the Platform and the users they authorise;
- visitors of customer websites that installed the XPLENDOR measurement script (section 6).
3. Account and Platform usage data
- Account data: name, email address and password (stored only as an irreversible hash).
- Company data: legal name, company tax number, contacts and other data the customer enters.
- Business data the customer enters or imports (for example vehicles, sales, expenses, aggregated bookings).
- Server technical logs (for example requests, errors and synchronisation dates).
Purpose: to provide the contracted service. Legal basis: performance of the contract with the customer (Article 6(1)(b) GDPR).
Contact form on this website: name, email and message, sent through the Formspree service so that we can reply. Legal basis: steps taken at the request of the data subject prior to entering into a contract.
4. Data received from Meta (Facebook and Instagram)
This section specifically describes the data XPLENDOR receives when a customer connects their Meta ad account to the Platform through Facebook Login. The connection is always started by the customer and can be disconnected at any time.
4.1 Permission requested
XPLENDOR requests only the ads_read permission, to read the performance data of the ad account selected by the customer.
XPLENDOR only reads data. It does not create, edit, pause or delete campaigns, ads, audiences or any other content on Meta.
4.2 What we collect and why
- Access token: the long-lived token issued by Meta and its expiry date. It is used only so that the Platform can request the data below on the customer's behalf. It is stored encrypted (AES-256-CBC) in the database and is never shown in the browser.
- The ID of the ad account chosen by the customer.
- Campaign structure: IDs and names of campaigns, ad sets and ads, and the status of each ad (active, paused, etc.).
- Daily performance metrics: spend, impressions, clicks, reach, frequency, CPM, CTR and CPC, per account, campaign and ad.
- Metrics aggregated by age range and gender (impressions, clicks, spend and reach). These are statistical totals provided by Meta and do not identify individuals.
- Ad set targeting settings (for example the ages, locations and interests chosen by the advertiser), and interest searches in Meta's targeting catalogue.
- Custom audience metadata: ID, name, type, approximate size, delivery status and last update date. XPLENDOR does not receive or store the list of people in those audiences.
Purpose: to show the customer how much they spent on advertising, what results they obtained, which ads relate to each product (for example each vehicle), and to relate that spend to the sales the customer records in the Platform. From this data the Platform calculates indicators such as cost per contact and records Meta spend as a marketing expense of the customer.
Legal basis: performance of the contract with the customer, who expressly authorises the connection.
4.3 What we do not collect
- Data about individual Facebook or Instagram users (profiles, contacts, messages, comments or audience member lists).
- Meta lead form data, Pixel data or Conversions API data.
- Posts, Pages or Instagram accounts, or ad account billing data.
4.4 Limited use
Data received from Meta is used only to provide the Platform to the customer who authorised it. It is not sold, not used for third party advertising, not shared with other customers and not used to train artificial intelligence models.
5. Where Meta data is stored, for how long and how it is deleted
Where: in the Platform database, on servers hosted by [FORNECEDOR DE ALOJAMENTO E PAÍS], separated by customer company. Each company can access only its own data.
How long: campaign performance and structure data is kept while the customer's Platform account is active, to allow historical comparisons. There is currently no automatic deletion based on age.
When the customer disconnects the integration in the Platform:
- XPLENDOR asks Meta to remove the app authorisation from the customer's account and then deletes the access token; the integration stops requesting data from Meta;
- if Meta does not accept the request (for example because the token has already expired), the disconnection still completes and the customer can remove XPLENDOR in their Facebook settings (Settings and privacy, Business integrations);
- the customer chooses what happens to the data already received: by default, the history (metrics, campaign structure, audience metadata and calculated expenses) is kept in the account for reference; alternatively, the customer can immediately delete all data received from Meta, after explicit confirmation;
- when deleting, the sales recorded by the customer are kept, without any link to campaigns or ads.
When the customer switches to a different ad account, the metrics and ads of the previous account are deleted.
When the customer's Platform account is closed, all company data, including the data received from Meta, is deleted from the database.
Later deletion: if the history was kept, the customer can delete it later in the Platform (Integrations) or request deletion by email, without closing the account. Instructions and timeframes are on the Data Deletion page (/en/data-deletion/).
Technical logs: server logs may contain account and campaign IDs and error messages returned by Meta; they do not contain access tokens. They are kept for 14 days and then deleted automatically.
Backups: [DESCREVER CÓPIAS DE SEGURANÇA E PRAZO].
6. Measurement on customer websites
Customers may install an XPLENDOR script on their own website to record visits coming from ads. The script stores a random visitor and session ID, the page visited, the campaign parameters in the URL (UTM), the ad ID and the advertising platform click ID (for example fbclid or gclid), and interactions such as clicks on phone, WhatsApp or form.
In that case the customer is the controller towards the visitors of their website, and XPLENDOR acts as a processor on the customer's behalf. The customer is responsible for informing its visitors and obtaining any required consent.
8. Security
Access tokens for external platforms are stored encrypted. The Meta app secret exists only on the server. Access to the Platform requires authentication and every request is checked so that a user can only access the data of their own company. Communications use an encrypted connection (HTTPS).
9. Your rights (GDPR)
Under the General Data Protection Regulation you may, at any time, exercise:
- the right of access to your data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure (deletion) of your data;
- the right to restriction of processing and the right to object;
- the right to data portability for the data you provided;
- the right to withdraw an authorisation you gave, for example by disconnecting the Meta integration, without affecting processing carried out before that.
To exercise these rights, write to xplendorcar@gmail.com. We reply within one month of receiving the request, extendable in the cases provided for in the GDPR, and we may ask the requester to confirm their identity.
You also have the right to lodge a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.
10. Changes to this policy
This policy may be updated to reflect changes to the Platform or to the law. The date of the last update is shown at the top of the page. Relevant changes are communicated to customers by email or in the Platform.

