Privacy Policy
Last Updated: September 18, 2026 • Version 2.4 (Enterprise & Meta Platform Compliant)
ZeroLeak Infra (zeroleakinfra.tech) operates strictly as an independent technical auditor. We are not an advertising agency, media buying firm, or data broker. We do not manage advertising spend, earn affiliate kickbacks, or sell user/client data to third parties.
1. Overview & Scope
This Privacy Policy describes how ZeroLeak Infra ("we", "our", or "us") collects, uses, protects, and discloses information when you visit our website (zeroleakinfra.tech), use our Client Audit Dashboard (/dashboard), or connect your Meta (Facebook) advertising accounts for technical data pipeline audits.
2. Information We Collect
A. Information You Voluntarily Provide
- Audit Requests: When submitting an infrastructure audit inquiry, we collect your brand domain name, corporate email address, estimated monthly ad spend bracket, and primary payment gateway provider.
- Direct Token Input: If you utilize our manual connection feature, you may provide a Meta Graph API Access Token or Ad Account ID to query your ad performance metrics directly.
B. Meta Platform Data (Facebook Marketing API)
When you authenticate your Meta Ad Account via Facebook Login or provide API credentials, we request strict, read-only permissions:
ads_read: To read campaign configuration parameters.read_insights: To fetch aggregate performance statistics (spend, impressions, clicks, CPC, reported conversions).business_management: To list the ad accounts accessible to your profile.
Important: We do not request write permissions. We cannot create, edit, modify, or delete your ad campaigns, ad sets, creatives, or billing settings.
C. Server Telemetry & Diagnostic Data
When accessing our edge infrastructure, our servers automatically log standard network transmission requests (IP address, browser user-agent, TLS version, and edge request latency) strictly for DDoS prevention, rate-limiting, and error diagnostics.
3. How We Use Collected Data
- To generate forensic audit reports detailing ad-blocker signal loss, mobile checkout speed friction, and silent payment gateway webhook drops.
- To calculate truth reconciliation discrepancies between Meta reported conversions and verified bank settlement records.
- To fulfill mutual obligations under executed Non-Disclosure Agreements (NDAs).
- To operate, maintain, and secure our high-performance edge infrastructure.
4. Data Sharing & Third-Party Disclosure
We do not sell, rent, trade, or monetize your data under any circumstances.
We only share information with third parties in the following limited circumstances:
- Infrastructure Hosting: With our secure cloud server hosting providers (Nginx / Linux VPS infrastructure) strictly for data transmission and processing.
- Legal Requirements: If required by enforceable court order, law enforcement inquiry, or statutory obligation under applicable Indian and international privacy laws.
5. Data Retention & Deletion Instructions
We retain customer inquiry details and audit reports only as long as necessary to provide technical consulting services or comply with legal obligations. Meta access tokens stored in your browser session can be removed instantly at any time by clicking the "Disconnect" button on your client dashboard.
If you wish to delete any audit telemetry, email records, or stored tokens associated with your domain or Meta account, please submit a formal deletion request to:
Or submit via our self-serve portal: Data Deletion Instructions & Request Portal →
Requests are processed and permanently wiped from our databases within 48 hours in compliance with Meta Platform Terms.
6. Data Security & Storage
All data transmitted between your browser and our servers is encrypted in transit using industry-standard Transport Layer Security (TLS 1.2 and TLS 1.3). Our production servers enforce strict firewalls, automated brute-force protection (Fail2Ban), and isolated system privilege execution.
7. Compliance with Indian DPDP Act & Global Standards
ZeroLeak Infra operates in compliance with the Digital Personal Data Protection (DPDP) Act of India, as well as recognizing principles established by the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) regarding user access, rectification, and erasure rights.
8. Contact Information & Grievance Officer
For questions, clarifications, or privacy grievance concerns regarding this policy, please contact our data protection team:
Legal & Data Compliance Desk
Website: https://zeroleakinfra.tech
Email: privacy@zeroleakinfra.tech