This Privacy Policy explains how Rino ("we", "our", or "us") handles information processed through the Rino internal portal (the "Portal"). The Portal is an internal tool for Rino team members and contractors. It is not offered to the general public, and accounts are provisioned by the administrators only.
1. Who this policy applies to
This policy applies to Rino team members, contractors, and other authorized persons who sign in to the Portal, as well as to data about company-managed Facebook ad accounts that the Portal mirrors from Meta.
2. Information we process
- Account information. When you sign in with Google we receive your name, email address, and profile picture URL. We do not receive your Google password.
- Facebook integration data. When a company Facebook ad account is connected to the Portal we store an access token and mirror the ad accounts, campaigns, ad sets, ads, creatives, and Facebook Pages that account is permitted to manage, so they can be shown and managed in the Portal.
- Content you upload. Files (images, videos, ad copy) that you stage in the Portal for launching campaigns.
- Usage data. Server logs that contain your IP address, browser user-agent, and the URLs you request, kept for security and debugging.
-
Cookies. A single first-party session cookie
(
FBADSSESSID) that keeps you signed in. The Portal does not use third-party advertising or tracking cookies.
3. How we use information
- To authenticate you and keep your session active.
- To call the Facebook Marketing API on the company's behalf so the Portal can read and manage company campaign data.
- To operate, maintain, and troubleshoot the Portal.
- To detect, prevent, and investigate unauthorized access, abuse, and security incidents.
4. Monitoring
The Portal is a company system. Activity in it — sign-ins, API calls, changes to campaigns, and uploads — may be logged and reviewed by the administrators for security, compliance, and operational purposes.
5. Sharing of information
We do not sell personal information. Information is shared only with:
- Meta Platforms, Inc. — when the Portal calls the Facebook Graph / Marketing API using the stored access tokens.
- Google LLC — when we authenticate you via Google OAuth.
- Infrastructure providers we rely on for hosting, under confidentiality terms.
- Authorities — when required by applicable law, subpoena, or court order.
6. Data retention
Your Portal account and its data are kept while you work with Rino; access is removed at offboarding. Mirrored advertising data is retained as a business record of the company's ad accounts. To request deletion of your personal data, contact the administrators at care@rino-app.com; we will action requests within 30 days except where retention is required for legal or accounting purposes.
7. Security
All traffic uses HTTPS and data is stored on access-controlled servers.
Facebook access tokens are scoped to the permissions granted during the
OAuth flow (ads_read, ads_management,
business_management) and can be revoked at any time from the
company's Facebook settings. No method of transmission or storage is
100% secure, so we cannot guarantee absolute security.
8. Your rights
Depending on your jurisdiction (GDPR, CCPA, and similar laws), you may have the right to access, correct, export, or delete personal information we hold about you. To exercise any of these rights, contact care@rino-app.com.
9. Third-party platforms
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of information received from the Meta Platform adheres to Meta's Platform Terms and Developer Policies.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced to the team.
11. Contact
Questions about this Privacy Policy? Contact the administrators at care@rino-app.com.