Business Privacy Policy

Effective Date: March 14, 2026

This policy describes how Local Treasure handles business account data, campaign data, and linked social platform credentials.

1. Definitions

  • Platform Data: Data from linked social platforms, including account IDs and OAuth token metadata.
  • Campaign Data: Campaign setup, submissions, analytics, moderation, and reward-related records.

2. Business Data We Collect

  • Business profile information and contact details
  • Campaign configuration, content, and performance metrics
  • Plan, billing, and account lifecycle metadata

3. Social Media Data and Tokens

When a business links social accounts, we may store:

  • Platform username and platform account/user ID
  • OAuth access tokens and refresh tokens (if provided)
  • Token expiration and linked-account metadata

How this data is used:

  • Enable linked-account features and relinking workflows
  • Fetch approved analytics and insights metrics
  • Support campaign verification and moderation operations

Token handling and security:

  • Encrypted at rest using application encryption controls
  • Transmitted over HTTPS
  • Limited internal access with role-based controls
  • Deleted from active records when accounts are unlinked

4. Retention Windows

  • Linked social token credentials are retained while account linking is active.
  • On unlink, token credentials are deleted from active account records.
  • Campaign and analytics records are retained while needed for service operation, reporting, support, security, and legal compliance.

5. Processors and Integrations

We use service providers and APIs, including:

  • Cloud hosting and storage infrastructure (including AWS services)
  • Identity/authentication providers (including Amazon Cognito)
  • Social platform APIs (including Instagram/Meta)
  • Payments infrastructure used for business subscriptions
  • Email and communications infrastructure

6. How We Share Data

We do not sell business personal data. We may share data with processors that support hosting, storage, communications, analytics, or legal compliance.

7. Requests from Public Authorities

  • We review each request for legal validity and scope
  • We challenge or narrow overbroad requests where legally permitted
  • We disclose only data required by law (data minimization)
  • We document requests, responses, and legal reasoning

8. Contact

Privacy questions can be sent to info@local-treasure.com.