Privacy Policy

Cartalyst Growth · Last updated: 12 September 2026

Cartalyst Growth is an advertising analytics tool for small and medium businesses. A business connects its own Meta (Facebook/Instagram) ad account and sees how its advertising performs. This policy explains exactly what we store, why, and how to get it deleted.

1. Who we are

Cartalyst Growth is operated by Robert Afanasiev, a registered sole proprietor under the law of Ukraine (фізична особа-підприємець Афанасьєв Роберт Олегович), entered in the Unified State Register of Ukraine on 12 September 2026 under record number 2011600000000118060, registered at 10 Olhiivska St., apt. 10, Odesa, 65029, Ukraine. That sole proprietor is the controller of the data described here — it is run by one person, and that person is who you are dealing with and who answers for the data. Contact for any privacy question or request: robertafanasyevv@gmail.com.

2. What we collect

2.1 Account data of our users

People who use Cartalyst Growth on behalf of a business. We store: e-mail address, display name, role inside the company, a salted password hash (never the password itself), and — only if the person links it themselves — a Telegram chat identifier used to deliver notifications.

2.2 Advertising data from your Meta ad account

Retrieved from the Meta Marketing API using an access token that you (or your Business Manager administrator) grant to us. We store:

2.3 Access tokens

The Meta access token you grant is stored encrypted (AES-256-GCM) and is used for one purpose only — to call the Meta API on your behalf. It is never shown in our interface, never written to logs, and never sent to anyone else.

2.4 Lead form submissions

If your advertising uses Meta Lead Ads, we retrieve the submissions so you can see and work with them. These contain personal data of the people who filled in your form — typically full name, phone number and e-mail, depending on how your form is configured.

For this data we act as a processor on your behalf: you decide what the form asks and what happens with the answers. We only store them and show them to you.

2.5 Technical records

A log of API calls we make to Meta (endpoint, status, error text — never the token), and error reports used to fix failures. Error reports are stripped of request bodies before they leave our servers.

2.6 Figures you enter yourself

If you tell us how many sales you actually made — for example when your sales happen in direct messages and no pixel can see them — we store that number together with the period it refers to. This data is never sent to Meta in any form: not as an offline conversion, not as a pixel event, not through the advertising API. It is used only to show you an honest payback verdict.

3. What we do not do

4. Why we process it, and on what basis

DataPurposeLegal basis
Account dataSign-in, access control, notifications Performance of a contract with you
Advertising dataThe analytics you asked for Performance of a contract with you
Lead submissionsShowing you your own leads Processing on your instruction; you are the controller
Technical recordsDiagnosing failures, keeping the service working Legitimate interest in a reliable service

4.1 Industry benchmarks

We compute typical figures — cost per result, click-through rate and similar — across customers in the same industry and country, and show them as a reference point when your own history is too thin to judge by. This is the difference between us telling you "a lead costs about $8" as our estimate and telling you "in your industry it is $8, measured".

Three limits keep this an aggregate rather than a window into another business:

If the group is too small, we say that instead of showing a number. You can ask us to exclude your company from these aggregates at any time, in writing, without giving a reason.

5. Who else sees it

Nobody else. We do not have advertising partners, data brokers or analytics resellers.

6. How long we keep it

Advertising data and account data are kept while your company has an active account with us. When you close the account or ask for deletion, everything belonging to your company is removed — see Data Deletion. Access tokens are destroyed immediately when you disconnect an ad account or revoke our access in Business Manager.

7. Keeping it separate and safe

Each customer's data is isolated at two independent levels: every query in the application carries an explicit company scope, and the database itself enforces row-level security under a role that cannot bypass it. Access tokens are encrypted at rest. Passwords are stored as PBKDF2-SHA256 hashes with a per-user salt.

8. Your rights

You can ask us to show you what we hold about you, correct it, or delete it. Write to robertafanasyevv@gmail.com and we will answer within 30 days. If you believe we handled your data wrongly, you may also complain to your local data protection authority.

9. Children

Cartalyst Growth is a tool for businesses. It is not directed at, and must not be used by, anyone under 18.

10. Changes

If we change this policy we update the date at the top. Material changes are announced inside the product before they take effect.