Creative Augmentation
  • Home
  • Services
    Amazon Ads Management Flipkart Ads Management Performance Marketing eCommerce Management Chatbots & Automation SEO & Web Development
  • Tools
    Chat StudioAds ConsoleCreativ Outreach
  • About Us
  • Contact
Get a Free Audit →
Home Services
Amazon Ads Flipkart Ads Performance Marketing eCommerce Mgmt Chatbots SEO & Web Dev
Tools About Us Contact My Account Get a Free Audit
Legal

Privacy Policy

Last updated: September 4, 2026

Creative Augmentation ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website creativeaugmentation.in, including any other media form, media channel, mobile website, or mobile application related or connected thereto, and when you interact with us through Instagram or Facebook messaging. Please read this privacy policy carefully.

1. Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the website includes:

  • Personal Data: Personally identifiable information, such as your name, email address, phone number, and contact details that you voluntarily provide to us when you register on the website, make a purchase, fill out a form, or otherwise contact us
  • Derivative Data: Information our servers automatically collect when you access the website, such as your IP address, browser type, operating system, access times, and the pages you have viewed directly before and after accessing the website
  • Financial Data: Financial information, such as data related to your payment method (e.g., valid credit card number, card brand, expiration date) that we may collect when you purchase, order, return, exchange, or request information about our services

2. Amazon Integration

We are an Amazon advertising agency. On behalf of our clients, and only with their explicit authorisation, we access data through the Amazon Advertising API and the Amazon Selling Partner API ("Amazon SP-API"). This section specifically addresses how we handle data obtained through Amazon's APIs.

  • No Buyer Personal Data: We do not request, receive, or store Personally Identifiable Information (PII) about Amazon buyers. We have not applied for any of Amazon's Restricted roles, and we do not use Restricted Data Tokens. We hold no customer names, shipping addresses, email addresses, or phone numbers from Amazon
  • What We Access: Advertising performance data (campaigns, ad groups, keywords, search terms, spend, sales, ACOS), product catalogue and pricing data, inventory levels, and aggregated sales, traffic and search-query metrics. This is business data about our client's own account — it does not identify any individual shopper
  • Authorisation: We only ever access an Amazon account that has explicitly authorised us through Amazon's official OAuth consent flow. We never ask for, and never accept, a client's Amazon login credentials. Authorisation can be revoked by the client at any time — from their Creative Augmentation account portal (account.creativeaugmentation.com → Revoke Amazon access), from Seller Central, or from the Amazon Ads console
  • Strict Client Separation: Each client's Amazon data is stored in a separate, isolated data store and is used only to manage that client's own campaigns. We do not pool, aggregate, benchmark, or share one client's Amazon data with any other client, or with any third party
  • Data Protection: All Amazon data is encrypted in transit and at rest. Access is restricted to authorised personnel on a need-to-know basis, reviewed regularly
  • Compliance: We comply with the Amazon Advertising API License Agreement, the Amazon Ads Data Protection Policy and Acceptable Use Policy, and the Amazon Selling Partner API Data Protection Policy and Acceptable Use Policy at all times

3. Meta Ads Integration (Facebook & Instagram Advertising)

We also manage Facebook and Instagram advertising for our clients through the Creativ Ads Console (ads.creativeaugmentation.com), using Meta's Marketing API. This section explains what data we access through Meta on our clients' behalf, how we use and protect it, and how it can be deleted.

How access is granted. A client grants us access to their Meta ad account by sharing it with our Meta Business portfolio (Creative Augmentation, Business ID 1396739397786188) in Meta Business Settings, or by having us create and manage an ad account on their behalf. Our access runs through a Meta System User whose permissions the client controls. The client can revoke that access at any time in Meta Business Settings, without contacting us.

What we access. For each ad account shared with us — using the ads_read, ads_management and business_management permissions:

  • Ad account details: account name and ID, currency, time zone, status, spend limits and amount spent
  • Campaign structure: campaigns, ad sets and ads — names, IDs, status, objectives, budgets, bid settings and creative IDs
  • Performance insights: impressions, reach, clicks, spend, cost metrics and conversion actions, at campaign, ad-set and ad level, by day
  • Custom-audience metadata: audience names, types, sizes and status. We never upload, download or view customer lists, nor any personal data of the people in an audience
  • Business details: the ad accounts associated with our Business portfolio, to discover which accounts are shared with us

We do not access Facebook or Instagram user profiles, messages, posts, comments, Pages content, or pixel/browser-level data of end users through the console. We hold no names, email addresses, phone numbers or other personal data of the people who see or interact with a client's ads.

How we use it.

  • Reporting: dashboards and summaries of a client's own advertising performance
  • Optimisation: recommendations and, where a client asks us to act, changes such as pausing or resuming a campaign or ad set and adjusting a budget or bid, within limits the client sets. Every change is logged with who requested it and what changed
  • Audience management: listing a client's custom audiences and, on request, creating rule-based audiences (website- or engagement-based) in the client's own ad account
  • AI assistance: we may use large language models to summarise or answer questions about a client's own advertising data. The models see only that client's data, never another client's, and neither we nor our AI providers train models on it

We never sell advertising data, never combine one client's data with another's, and never use a client's data to advertise to anyone.

Where it is stored and for how long. Data is stored on Google Cloud in the Mumbai (asia-south1) region, isolated per client. We keep campaign- and ad-set-level daily performance for up to 730 days, ad-level daily performance and audience snapshots for up to 180 days, and a technical log of our API calls (endpoint, timing, outcome — no advertising data) for operational monitoring. Data is deleted on request at any time (see our Data Deletion page) and when a client relationship ends.

Who we share it with. Only the sub-processors needed to run the service — Google Cloud (hosting, storage, AI models) and the client's own Meta platform. We do not transfer Meta platform data to data brokers, advertising networks or any other third party.

How we protect it. Encryption in transit and at rest; a dedicated, least-privilege service identity for the Meta integration; API credentials held in a managed secret store, never in code or logs; the console reachable only through our web application firewall; per-user sign-in with named, revocable accounts and role-based access to each client; and an audit trail of every read and change. We comply with Meta's Platform Terms and Developer Policies.

Your rights. A client may ask us at any time to show, correct or delete the advertising data we hold for their ad account — see our Data Deletion page. Revoking our access is done by the client directly in Meta Business Settings; we then stop collecting new data immediately and delete what we hold on request.

4. How We Use AI

We use large language models to help deliver our service. Specifically:

  • Reporting Chat: answering your questions about your own advertising data
  • Search-Term Classification: labelling your search terms as branded, competitor, or generic
  • Optimisation Recommendations: suggesting bid and budget changes

What the models see. Only your own Amazon advertising data — never another client's. We do not use your data to train AI models, and our AI providers do not train on it.

Accuracy. AI-generated classifications, insights and recommendations are estimates, not guarantees. They can be wrong. Any classification can be reviewed and overridden by a human, and we apply automated validation checks and guardrails before any change reaches your Amazon account.

Automated changes. Where you have enabled automation, we may adjust bids and budgets on your behalf. Every automated change is bounded by limits you configure (minimum and maximum bid, maximum budget), is subject to cooldown periods, and is logged.

Data freshness. Reporting data is refreshed at least daily. Amazon itself restates advertising figures for up to 14 days after the fact, so recent numbers may change.

5. Instagram, Messenger & WhatsApp Messaging (Meta Platforms)

We provide an AI messaging assistant and a shared team Inbox that answer customer messages across Meta's messaging platforms — Instagram Direct, Facebook Messenger, and WhatsApp. We operate this both on our own business accounts and, as a service (our "Chat Studio" product), on the accounts of business clients who authorise us to act on their behalf. This section explains how we handle data obtained through Meta's platforms when you message a business we serve.

  • Our Role: When you message one of our client businesses, that business is the controller of your messages and we act as its processor, handling the messages only on its instructions to provide the messaging service. When you message our own accounts, we are the controller.
  • Data Collection: When you send a message to a connected Instagram account, Facebook Page, or WhatsApp Business number, we receive and process the content of your message, your platform-scoped user ID or WhatsApp number, your public profile name or display name, and message timestamps, so that the business can respond to your enquiry.
  • Purpose: This data is used solely to answer your messages on behalf of the specific business you contacted — for example pricing, delivery, product information and support — through automated replies and, where needed, human responses from that business's team. We do not use it for advertising, profiling, any unrelated purpose, or to train AI models.
  • Authorisation & Permissions: Each business connects its own accounts through Meta's official authorisation flows (Instagram Business Login, Facebook Login for Business, and WhatsApp Embedded Signup) — we never ask for or store account passwords. The business remains the owner of the connected account or Page and can disconnect at any time. We access messages only after you message the business first, using these Meta-approved permissions:
    • Instagram API with Instagram Login: instagram_business_basic, instagram_business_manage_messages
    • Messenger Platform / Facebook Login for Business: public_profile, pages_show_list, pages_messaging, pages_manage_metadata, pages_read_engagement, business_management
    • WhatsApp Business Cloud API (planned — this channel is not yet live): whatsapp_business_messaging, whatsapp_business_management
  • Where the Data Is Held: Messaging data is processed and stored on Google Cloud Platform in India (region asia-south1), and the access token for each connected account is held in Google Secret Manager.
  • Strict Client Separation: Each client's messaging data is stored in an isolated data store and used only to serve that client's own customers. We never pool, aggregate, benchmark, or share one client's messaging data with any other client or third party.
  • Retention: Messaging data is retained only as long as necessary to provide the service and is deleted or anonymised within 90 days, unless a longer period is required by law.
  • Sharing: We do not sell your messaging data. It may be processed by trusted subprocessors (for example, cloud hosting and AI processing) solely to operate the service on the business's behalf.
  • Your Control: You may request deletion of your messaging data at any time via our Data Deletion page. You can also stop messages by blocking the business, or the business can revoke our access from Instagram → Settings → Apps and Websites, Facebook → Settings → Business Integrations, or the WhatsApp Business Manager. Disconnecting removes our access immediately. We also honour Meta's deauthorisation and data-deletion callbacks: when a business removes the app, or Meta sends us a deletion request on your behalf, the associated data is deleted.
  • Compliance: We comply with the Meta Platform Terms, Meta Developer Policies, the Instagram Platform Policy, the Messenger Platform Policy, and the WhatsApp Business Messaging Policy at all times.

6. The Creativ Chat Mobile App

Creativ Chat (Android/iOS) is the companion app to Creativ Chat Studio, for businesses and their team members. When you use the app we process: your name and email address (from your Google or Microsoft sign-in — we never receive your password), the Instagram Direct Message conversations of your business's connected account (to show the inbox and let authorised team members reply), saved replies and chat-assignment records you create, a push-notification token for your device (only if you allow notifications, used to tell you a conversation was assigned to you), and basic service logs.

This data is stored on Google Cloud Platform (Mumbai, India); conversation threads and service logs are automatically deleted after at most 90 days. It is shared only with the processors that make the service work — Meta Platforms (Instagram messaging), Google Cloud (hosting), Google/Microsoft (sign-in), and Expo (notification delivery) — and is never sold or used for advertising. The app contains no ads and no third-party tracking. All data is encrypted in transit.

You may sign out at any time (removing the token from your device), disable notifications in system settings, and request access, correction, or deletion of your data by emailing mail@creativeaugmentation.in. The app is intended for business users aged 18 and over.

7. Shopify App (Creativ Chat Studio)

When a merchant installs our Shopify app, we access their store's product catalog to power automated chat replies. Where the merchant enables order tracking, we also access order details (order number, fulfillment status, and the phone number on the order) solely to answer that customer's own order-status questions after identity verification in chat. We store the merchant's store connection credentials securely, never process or store customer payment information, and delete all store data automatically when the app is uninstalled or upon request at hello@creativeaugmentation.in.

8. Creativ Outreach (Email & WhatsApp Campaigns) — Google User Data

Creativ Outreach (outreach.creativeaugmentation.com) is our outbound messaging tool. Our own team uses it, and clients who ask us to run outreach for them authorise it on their own accounts. It sends multi-step email and WhatsApp sequences from mailboxes and WhatsApp Business numbers that the customer owns, and it stops a recipient's sequence when they reply, bounce, unsubscribe or send STOP.

Google user data we access

When a customer connects a Google mailbox, Creativ Outreach requests two Gmail permissions through Google's OAuth consent screen, and uses each only as described:

  • Send email on your behalf (gmail.send) — to send the messages the customer composed, to the contacts the customer imported, on the schedule the customer set. Every email carries the customer's own sender address and a one-click unsubscribe link.
  • View email message metadata (gmail.metadata) — to read message headers only (sender, recipient, subject, date, message identifiers such as Message-ID, In-Reply-To and References, and automatic-reply and delivery-failure markers). We use these to recognise that a recipient replied or that a message bounced, and to stop that recipient's sequence. We never read message bodies, attachments, drafts, contacts or labels beyond what the headers carry, and we never change mailbox settings.

We also read the connected mailbox's email address to label the connection in the portal.

How we store and protect it

  • The Google credential (a refresh token) is encrypted with AES-256-GCM and stored on Google Cloud Platform in Mumbai, India (region asia-south1). It is deleted immediately when the mailbox is disconnected in the portal or when access is revoked at myaccount.google.com/permissions.
  • From message headers we keep only what is needed to link a reply or bounce to a campaign: message identifiers and the recipient address, for up to 12 months. Subject lines are not retained in analytics.
  • Google user data is never used for advertising, never sold, and never shared with third parties except the sub-processors listed in "Third-Party Sharing" below (Google Cloud Platform). Our staff do not read Google user data except to investigate a problem the customer asked us to investigate.

Creativ Outreach's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

WhatsApp campaigns

WhatsApp messages are sent only as Meta-approved message templates, from a WhatsApp Business number on the customer's own WhatsApp Business Account, through Meta's WhatsApp Business Platform. Replies and STOP messages are received so that a recipient's sequence can be stopped and their number suppressed; Creativ Outreach does not answer messages. Delivery and read receipts are stored per message for reporting.

Recipients — what we hold about you and your choices

If you received an email or WhatsApp message sent through Creativ Outreach, the customer who sent it holds your name, email address and/or phone number, company details they imported, and a record of what was sent to you, whether it was opened or clicked, and whether you replied. Emails include a small tracking image and tracked links so the sender can see opens and clicks. You can stop further messages at any time: use the unsubscribe link in any email, reply STOP to any WhatsApp message, or write to mail@creativeaugmentation.in. An opt-out is applied within minutes and honoured permanently: we keep a hashed record of an opted-out address or number precisely so it is never contacted again. Message and event records are kept for 12 months; see our Data Deletion page to have your data removed.

9. How We Use Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customised experience. We may use information collected about you via the website to:

  • Provide, operate, and maintain our website and services
  • Improve, personalise, and expand our website and service offerings
  • Understand and analyse how you use our website
  • Develop new products, services, features, and functionality
  • Communicate with you, either directly or through one of our partners, for customer service, updates, and other website-related information
  • Send you newsletters, marketing, and promotional communications (with your consent)
  • Process your transactions and manage your orders
  • Find and prevent fraud

10. Data Storage & Security

We use commercially reasonable physical, administrative, and technological safeguards to preserve the integrity and security of all information collected through our website.

  • All data is stored on secure servers with encryption at rest and in transit
  • Access to personal data is restricted to authorised personnel who need it to perform their job functions
  • We regularly review and update our security practices to ensure ongoing protection
  • We use SSL/TLS encryption for all data transmissions between your browser and our servers

However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach, we will notify affected users in accordance with applicable law.

11. Your Rights (GDPR)

If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Creative Augmentation aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal data. You have the following rights:

  • Right of Access: You have the right to request copies of your personal data
  • Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete
  • Right to Erasure: You have the right to request that we erase your personal data, under certain conditions
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions
  • Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions
  • Right to Object: You have the right to object to our processing of your personal data, under certain conditions

We will respond to all legitimate requests within one month. If you wish to exercise any of these rights, please contact us at mail@creativeaugmentation.in. For a fast, self-serve way to delete your data — including any data collected through Instagram or Facebook messaging — see our Data Deletion page.

12. Third-Party Sharing

We do not sell, trade, rent, or otherwise share your personal information with unauthorised third parties. We may share your information only in the following situations:

  • Service Providers: We may share your information with third-party service providers that perform services for us or on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance
  • Legal Requirements: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business

We will never sell or misuse your personal information for purposes unrelated to the services we provide.

Subprocessors. We use the following providers to process data on our behalf. Each is bound by contractual confidentiality and security obligations, and none of them use your data to train their models:

  • Google Cloud Platform — hosting, data warehousing (BigQuery) and AI models (via Vertex AI); primary region India (asia-south1)
  • Amazon Web Services — receipt and buffering of Amazon Marketing Stream advertising data (Kinesis Data Firehose and S3, encrypted, retained for a maximum of 90 days) before transfer into our data warehouse; processed in the EU (Ireland) and the United States
  • Razorpay — payment processing; processed in India
  • Google LLC — Gmail API (email sending and message-header reads for Creativ Outreach), Google Cloud Platform (India, asia-south1)
  • Meta Platforms — WhatsApp Business Platform (message delivery for Chat Studio and Creativ Outreach)

We keep this list current and will update it before adding a new subprocessor that processes client data.

13. Children's Privacy

Our website and services are not directed to children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from anyone under the age of 13 without verification of parental consent, we will take steps to remove that information from our servers.

14. Direct Marketing

We may use your information to send you newsletters, promotional materials, and other communications related to our services. This includes:

  • Email newsletters about industry updates, tips, and best practices
  • Promotional offers and discounts on our services
  • Updates about new features or service offerings
  • Invitations to webinars, events, or consultations

You can opt out of receiving marketing communications from us at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at mail@creativeaugmentation.in. Please note that even if you opt out of marketing communications, we may still send you transactional or administrative messages related to your account or our services.

Outreach emails sent through Creativ Outreach carry a one-click unsubscribe (List-Unsubscribe) header in addition to the unsubscribe link.

15. Policy Updates

We may update this Privacy Policy from time to time in order to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this page.

Your continued use of the website after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

If you have questions or concerns about this Privacy Policy, please contact us at mail@creativeaugmentation.in.

Services
  • Amazon Ads Management
  • Flipkart Ads
  • Performance Marketing
  • eCommerce Mgmt
  • SEO & Web Dev
  • Chatbots & Automation
Tools
  • Chat Studio
  • Ads Console
  • Creativ Outreach
Company
  • About Us
  • Careers
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Cancellation Policy
  • Data Deletion
© 2026 Creative Augmentation. All rights reserved.
India·UAE·USA