Last updated: December 2025
1. Introduction
Welcome to ALTYAA LLC ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered reputation management platform and related services (collectively, the "Service"). We are committed to protecting your privacy and ensuring transparency about our data practices. By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect information in several ways to provide and improve our Service:
2.1 Account Information
When you create an account, we collect:
- Full name and display name
- Email address
- Password (encrypted and hashed)
- Business name, address, and contact information
- Payment and billing information (processed securely via Stripe)
2.2 Third-Party Platform Data
When you connect your business profiles, we access data from these platforms with your authorization:
- Google Business Profile: Business information, reviews, ratings, and responses
- Meta (Facebook/Instagram): Page information, reviews, recommendations, messages, comments, and page insights
- TikTok: Business account information, comments, and mentions
2.3 Usage and Technical Data
We automatically collect certain information when you use our Service, including IP address, browser type and version, device information, operating system, pages visited and features used, date and time of access, and referral URLs. This data helps us improve our Service and ensure security.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain our reputation management Service, including monitoring reviews, generating AI-powered responses, and providing analytics
- To process payments and manage your subscription
- To communicate with you about your account, service updates, and respond to your inquiries
- To analyze usage patterns and improve our Service
- To detect, prevent, and address technical issues, fraud, and security threats
- To comply with legal obligations and enforce our terms of service
3.1 AI-Assisted Content Generation (Human-in-the-Loop)
ALTYAA uses Artificial Intelligence (AI) to analyze customer sentiment and generate suggested drafts for review replies and social media posts. When you use our AI reply assistance feature, your review and comment text is processed by our AI service provider to generate draft response suggestions. This processing is temporary and occurs only when you explicitly request suggestions.
User Control: All AI-generated content is provided as a draft only. Users must manually review, edit (if desired), and approve all content before it is published to any Meta platform or other connected service. We do not use fully automated AI agents to post content without human intervention.
Data Usage: We do not use your private Meta Platform Data or your customers' personal information to train third-party AI models. Data sent to AI processors is used only for real-time generation and is handled according to our secure data processing agreements.
4. Third-Party Platform Integrations
Our Service integrates with third-party platforms to provide reputation management features. Each integration is subject to that platform's terms of service and privacy policy.
4.1 Google Business Profile
We use Google's APIs to access your business profile data. Our use of Google user data is limited to the practices explicitly disclosed in this privacy policy. We comply with Google API Services User Data Policy, including the Limited Use requirements.
Data accessed includes:
- Business profile information (name, address, categories)
- Customer reviews and ratings
- Your review responses
4.2 Meta Platform Data Integration (Facebook/Instagram)
Our Services allow you to connect your Meta (Facebook and Instagram) accounts via the Meta Graph API. By connecting these accounts, you authorize ALTYAA.com to access and process "Platform Data" (as defined by Meta), including but not limited to Page ratings, reviews, recommendations, comments, messages, and media content. We process this data solely to provide you with social media management, reputation analysis, and engagement tools. We comply with Meta's Platform Terms and Developer Policies.
Platform Data accessed includes:
- Facebook Pages and Instagram Business accounts you manage
- Reviews, recommendations, and ratings
- Messages and comments (only with your explicit consent)
- Page insights and analytics
When using Page Insights, ALTYAA LLC and Meta act as joint data controllers. You can review Meta's Page Controller Addendum for more information about this arrangement.
4.3 TikTok
We integrate with TikTok's Business API to monitor and manage your TikTok business presence. We access business account information, comments, and mentions in accordance with TikTok's API Terms of Service.
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: We share data with trusted third-party service providers who assist us in operating our Service (such as cloud hosting, payment processing, and AI processing partners). These providers are contractually bound to protect your data and use it only for the specific services we have authorized.
- Connected Platforms: When you use our Service to respond to reviews or post content, that data is shared with the respective platform (Google, Meta, TikTok).
- Legal Requirements: We may disclose your information if required by law, court order, or government request, or to protect the rights, property, or safety of ALTYAA LLC, our users, or others.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
Meta Platform Data Disclosure: ALTYAA does not sell, rent, or trade Meta Platform Data to third-party data brokers or advertisers. We only share Meta Platform Data with service providers (such as hosting and AI processing partners) who are contractually bound to protect your data and use it only for the specific services we have authorized.
6. Data Retention
We retain your information for as long as necessary to provide our Service and fulfill the purposes described in this policy. Specific retention periods include:
Meta Platform Data Retention: We retain Meta Platform Data only as long as it is necessary to provide our Services or until you disconnect your Meta account. Upon disconnection or account termination, we will purge all associated Meta Platform Data from our active servers within 30 days, unless retention is required by law.
| Data Type | Retention Period |
|---|---|
| Account Data | While active + 30 days |
| Meta Platform Data | Until disconnection + 30 days |
| Other Platform Data | Subscription duration + 30 days |
| Usage Logs | Up to 12 months |
| Billing Records | Up to 7 years (legal requirement) |
User-Initiated Disconnection: You may disconnect your Meta account at any time through your ALTYAA dashboard settings or by removing ALTYAA from your "Apps and Websites" settings on Facebook. Upon disconnection, all Meta Platform Data will be automatically purged within 30 days.
7. Data Security
We implement industry-standard security measures to protect your information:
Encryption
TLS 1.3 in transit, AES-256 at rest
Access Controls
RBAC and Row-Level Security
Monitoring
24/7 security monitoring
MFA
Multi-factor authentication available
8. Your Privacy Rights
8.1 Rights for European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request that we limit how we use your data
- Right to Data Portability: Request your data in a machine-readable format
- Right to Object: Object to processing of your data for certain purposes
- Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data
8.2 Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected, used, disclosed, and sold
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale or sharing of your personal information. Note: We do not sell your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
We do not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising.
9. Data Deletion
You may request deletion of your personal data at any time through the following methods:
- Through your ALTYAA dashboard: Navigate to Settings > Account > Delete Account
- By email: Contact us at privacy@altyaa.com with your deletion request
- Through our Data Deletion page: Visit /data-deletion for instructions and to submit a deletion request
Upon receiving a valid deletion request, we will delete or anonymize your personal data within 30 days, unless we are legally required to retain it.
For users who connected via Meta (Facebook/Instagram), we implement Meta's Data Deletion Request Callback. When you request deletion through Meta's app settings (Facebook Settings > Apps and Websites > Remove ALTYAA), we will automatically receive and process your deletion request. You will receive a confirmation code and can check the status of your deletion at /data-deletion/status.
Automatic Purge: Upon account termination or Meta disconnection, we will purge all associated Meta Platform Data from our active servers within 30 days, unless retention is required by law.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve your experience, analyze usage, and serve targeted advertisements. You can control cookie preferences through your browser settings or our cookie consent banner.
For detailed information about the cookies we use, please see our Cookie Policy.
11. Children's Privacy
Our Service is not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@altyaa.com, and we will take steps to delete such information.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission to ensure your data remains protected.
15. Legal Basis for Processing (GDPR)
Under the GDPR, we process your personal data based on the following legal bases:
- Contract Performance: Processing necessary to provide our Service to you as agreed in our Terms of Service
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing communications, connecting third-party platforms)
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our Service, fraud prevention, and security, provided these interests are not overridden by your rights
- Legal Obligation: Processing necessary to comply with applicable laws and regulations
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. For significant changes, we may also send you an email notification. We encourage you to review this policy periodically.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Email: privacy@altyaa.com