Last updated: September 4, 2026
Creative Augmentation ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website creativeaugmentation.in, including any other media form, media channel, mobile website, or mobile application related or connected thereto, and when you interact with us through Instagram or Facebook messaging. Please read this privacy policy carefully.
We may collect information about you in a variety of ways. The information we may collect via the website includes:
We are an Amazon advertising agency. On behalf of our clients, and only with their explicit authorisation, we access data through the Amazon Advertising API and the Amazon Selling Partner API ("Amazon SP-API"). This section specifically addresses how we handle data obtained through Amazon's APIs.
We also manage Facebook and Instagram advertising for our clients through the Creativ Ads Console (ads.creativeaugmentation.com), using Meta's Marketing API. This section explains what data we access through Meta on our clients' behalf, how we use and protect it, and how it can be deleted.
How access is granted. A client grants us access to their Meta ad account by sharing it with our Meta Business portfolio (Creative Augmentation, Business ID 1396739397786188) in Meta Business Settings, or by having us create and manage an ad account on their behalf. Our access runs through a Meta System User whose permissions the client controls. The client can revoke that access at any time in Meta Business Settings, without contacting us.
What we access. For each ad account shared with us — using the ads_read, ads_management and business_management permissions:
We do not access Facebook or Instagram user profiles, messages, posts, comments, Pages content, or pixel/browser-level data of end users through the console. We hold no names, email addresses, phone numbers or other personal data of the people who see or interact with a client's ads.
How we use it.
We never sell advertising data, never combine one client's data with another's, and never use a client's data to advertise to anyone.
Where it is stored and for how long. Data is stored on Google Cloud in the Mumbai (asia-south1) region, isolated per client. We keep campaign- and ad-set-level daily performance for up to 730 days, ad-level daily performance and audience snapshots for up to 180 days, and a technical log of our API calls (endpoint, timing, outcome — no advertising data) for operational monitoring. Data is deleted on request at any time (see our Data Deletion page) and when a client relationship ends.
Who we share it with. Only the sub-processors needed to run the service — Google Cloud (hosting, storage, AI models) and the client's own Meta platform. We do not transfer Meta platform data to data brokers, advertising networks or any other third party.
How we protect it. Encryption in transit and at rest; a dedicated, least-privilege service identity for the Meta integration; API credentials held in a managed secret store, never in code or logs; the console reachable only through our web application firewall; per-user sign-in with named, revocable accounts and role-based access to each client; and an audit trail of every read and change. We comply with Meta's Platform Terms and Developer Policies.
Your rights. A client may ask us at any time to show, correct or delete the advertising data we hold for their ad account — see our Data Deletion page. Revoking our access is done by the client directly in Meta Business Settings; we then stop collecting new data immediately and delete what we hold on request.
We use large language models to help deliver our service. Specifically:
What the models see. Only your own Amazon advertising data — never another client's. We do not use your data to train AI models, and our AI providers do not train on it.
Accuracy. AI-generated classifications, insights and recommendations are estimates, not guarantees. They can be wrong. Any classification can be reviewed and overridden by a human, and we apply automated validation checks and guardrails before any change reaches your Amazon account.
Automated changes. Where you have enabled automation, we may adjust bids and budgets on your behalf. Every automated change is bounded by limits you configure (minimum and maximum bid, maximum budget), is subject to cooldown periods, and is logged.
Data freshness. Reporting data is refreshed at least daily. Amazon itself restates advertising figures for up to 14 days after the fact, so recent numbers may change.
We provide an AI messaging assistant and a shared team Inbox that answer customer messages across Meta's messaging platforms — Instagram Direct, Facebook Messenger, and WhatsApp. We operate this both on our own business accounts and, as a service (our "Chat Studio" product), on the accounts of business clients who authorise us to act on their behalf. This section explains how we handle data obtained through Meta's platforms when you message a business we serve.
Creativ Chat (Android/iOS) is the companion app to Creativ Chat Studio, for businesses and their team members. When you use the app we process: your name and email address (from your Google or Microsoft sign-in — we never receive your password), the Instagram Direct Message conversations of your business's connected account (to show the inbox and let authorised team members reply), saved replies and chat-assignment records you create, a push-notification token for your device (only if you allow notifications, used to tell you a conversation was assigned to you), and basic service logs.
This data is stored on Google Cloud Platform (Mumbai, India); conversation threads and service logs are automatically deleted after at most 90 days. It is shared only with the processors that make the service work — Meta Platforms (Instagram messaging), Google Cloud (hosting), Google/Microsoft (sign-in), and Expo (notification delivery) — and is never sold or used for advertising. The app contains no ads and no third-party tracking. All data is encrypted in transit.
You may sign out at any time (removing the token from your device), disable notifications in system settings, and request access, correction, or deletion of your data by emailing mail@creativeaugmentation.in. The app is intended for business users aged 18 and over.
When a merchant installs our Shopify app, we access their store's product catalog to power automated chat replies. Where the merchant enables order tracking, we also access order details (order number, fulfillment status, and the phone number on the order) solely to answer that customer's own order-status questions after identity verification in chat. We store the merchant's store connection credentials securely, never process or store customer payment information, and delete all store data automatically when the app is uninstalled or upon request at hello@creativeaugmentation.in.
Creativ Outreach (outreach.creativeaugmentation.com) is our outbound messaging tool. Our own team uses it, and clients who ask us to run outreach for them authorise it on their own accounts. It sends multi-step email and WhatsApp sequences from mailboxes and WhatsApp Business numbers that the customer owns, and it stops a recipient's sequence when they reply, bounce, unsubscribe or send STOP.
When a customer connects a Google mailbox, Creativ Outreach requests two Gmail permissions through Google's OAuth consent screen, and uses each only as described:
gmail.send) — to send the messages the customer composed, to the contacts the customer imported, on the schedule the customer set. Every email carries the customer's own sender address and a one-click unsubscribe link.gmail.metadata) — to read message headers only (sender, recipient, subject, date, message identifiers such as Message-ID, In-Reply-To and References, and automatic-reply and delivery-failure markers). We use these to recognise that a recipient replied or that a message bounced, and to stop that recipient's sequence. We never read message bodies, attachments, drafts, contacts or labels beyond what the headers carry, and we never change mailbox settings.We also read the connected mailbox's email address to label the connection in the portal.
Creativ Outreach's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
WhatsApp messages are sent only as Meta-approved message templates, from a WhatsApp Business number on the customer's own WhatsApp Business Account, through Meta's WhatsApp Business Platform. Replies and STOP messages are received so that a recipient's sequence can be stopped and their number suppressed; Creativ Outreach does not answer messages. Delivery and read receipts are stored per message for reporting.
If you received an email or WhatsApp message sent through Creativ Outreach, the customer who sent it holds your name, email address and/or phone number, company details they imported, and a record of what was sent to you, whether it was opened or clicked, and whether you replied. Emails include a small tracking image and tracked links so the sender can see opens and clicks. You can stop further messages at any time: use the unsubscribe link in any email, reply STOP to any WhatsApp message, or write to mail@creativeaugmentation.in. An opt-out is applied within minutes and honoured permanently: we keep a hashed record of an opted-out address or number precisely so it is never contacted again. Message and event records are kept for 12 months; see our Data Deletion page to have your data removed.
Having accurate information about you permits us to provide you with a smooth, efficient, and customised experience. We may use information collected about you via the website to:
We use commercially reasonable physical, administrative, and technological safeguards to preserve the integrity and security of all information collected through our website.
However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach, we will notify affected users in accordance with applicable law.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Creative Augmentation aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal data. You have the following rights:
We will respond to all legitimate requests within one month. If you wish to exercise any of these rights, please contact us at mail@creativeaugmentation.in. For a fast, self-serve way to delete your data — including any data collected through Instagram or Facebook messaging — see our Data Deletion page.
We do not sell, trade, rent, or otherwise share your personal information with unauthorised third parties. We may share your information only in the following situations:
We will never sell or misuse your personal information for purposes unrelated to the services we provide.
Subprocessors. We use the following providers to process data on our behalf. Each is bound by contractual confidentiality and security obligations, and none of them use your data to train their models:
We keep this list current and will update it before adding a new subprocessor that processes client data.
Our website and services are not directed to children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from anyone under the age of 13 without verification of parental consent, we will take steps to remove that information from our servers.
We may use your information to send you newsletters, promotional materials, and other communications related to our services. This includes:
You can opt out of receiving marketing communications from us at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at mail@creativeaugmentation.in. Please note that even if you opt out of marketing communications, we may still send you transactional or administrative messages related to your account or our services.
Outreach emails sent through Creativ Outreach carry a one-click unsubscribe (List-Unsubscribe) header in addition to the unsubscribe link.
We may update this Privacy Policy from time to time in order to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this page.
Your continued use of the website after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
If you have questions or concerns about this Privacy Policy, please contact us at mail@creativeaugmentation.in.