salut.ae
Privacy Policy
Last updated: 18 September 2026
This policy explains what data salut.ae (United Arab Emirates) (“salut”, “we”) collects, why, where it lives, and how to have it deleted. salut is a reporting tool for marketing agencies: it reads advertising performance data and presents it as dashboards and reports. It is read-only by design — it cannot change anything in an ad account.
Who this policy covers
- Agencies — the businesses that create a salut workspace and connect ad accounts.
- Report viewers — people who open a report share link an agency sends them. They do not need an account, and we collect no personal information from them.
What we collect
Account data
Your email address and agency name, used to sign you in (via a magic-link email — we never store passwords) and to label your workspace and reports.
Workspace data
The client names, logos and settings you add to organise your reporting.
Advertising data from Meta
When you connect a Meta ad account, you grant salut read-only permissions (ads_read, business_management). We access and store:
- Ad account metadata: account id, name, and billing currency.
- Daily aggregated performance metrics at account and campaign level: spend, impressions, clicks, and counts of lead actions (for example form submissions or messaging conversations started).
We deliberately do not access or store:
- Individual lead records — names, phone numbers or answers people submit in lead forms. We only store counts.
- Ad creatives, audiences, or custom audience lists.
- Any personal data about people who saw or clicked the ads.
Our use of Meta data complies with the Meta Platform Terms. salut is an independent product and is not affiliated with, endorsed by, or sponsored by Meta.
Access tokens
Connecting an ad account gives us an access token. Tokens are encrypted at rest (AES-256-GCM), are only ever handled on our servers, and are never exposed to browsers or included in reports.
Report link activity
When someone opens a report share link, we record the time it was last viewed so the agency can see whether their client opened it. We do not record who opened it, or from where.
Technical data
Our hosting providers keep standard server logs (IP address, request time, user agent) for security and reliability. We run no analytics or advertising trackers, and the only cookies we set are the session cookies required to keep you signed in.
How we use data
- To render your dashboards, share links and PDF reports.
- To refresh your data automatically (a nightly sync) and on demand.
- To tell you when a connection stops working.
- To provide support when you contact us.
We never sell data, never share it with advertisers, and never use one agency’s data for another agency. Workspace isolation is enforced in our database, not just in application code.
Where data lives
We use a small number of service providers to run salut:
- Supabase — database and authentication (hosted in the AWS Mumbai region, ap-south-1).
- Vercel — application hosting.
- Meta Platforms — the source of the advertising data you connect.
Retention
We keep your data while your workspace is active. Disconnecting an ad account deletes its access token. Deleting a client or closing your account removes the associated data from our production database.
Data deletion
You can have your data deleted at any time, in any of these ways:
- Disconnect in salut — removing a connection deletes its access token; deleting a client removes its metrics and share links.
- Revoke via Meta — remove salut in your Facebook settings under Settings & privacy → Business integrations. Our access stops immediately; you can then email us to delete already synced data.
- Email us — write to hello@salut.ae from your account email and we will delete your workspace and all associated data within 30 days, and confirm when it is done.
Security
- All traffic is encrypted in transit (TLS).
- Ad platform tokens are encrypted at rest.
- Every database table is protected by row-level security scoped to your workspace.
- Report share links use unguessable tokens, stored only as hashes, and can be revoked at any time.
Your rights
You may request access to, correction of, or deletion of your personal data by writing to hello@salut.ae. We handle personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Changes
If we change this policy, we will update the date at the top of this page. Material changes will be announced to account owners by email.
Contact
salut.ae (United Arab Emirates) — hello@salut.ae