Privacy
Privacy Policy
Effective 2026-09-07. This page describes only what the product does today; when the code changes, this page changes in the same release.
Who operates this service
AttributionOps is operated by MİEKO BİLGİ TEKNOLOJİLERİ AŞ (Türkiye), the data controller for the personal data described here. The same legal entity owns the Meta app “Attribution Ops” through which you connect your ad account.
What the product does
AttributionOps reconciles advertising spend and reported results with the revenue recorded by your commerce platform, so that a marketing claim can be compared with the commerce truth. Connecting Meta lets the product read your advertising cost and results; it does not manage your ads.
Data we read from Meta
After you authorise the app, the product reads the following fields through the Meta Graph API. The lists are the exact field names the backend requests.
- Ad accounts you can see (account picker)
idnameaccount_statuscurrencytimezone_nametimezone_offset_hours_utc
- Token check (GET /me)
idname
- Daily insights per campaign / ad set / ad
campaign_idcampaign_nameadset_idadset_namead_idad_nameimpressionsclicksspendreachfrequencyctrcpccpmactionsaction_valuespurchase_roasdate_startaccount_currency
- Campaigns
idnamestatusobjectivebudget_remainingdaily_budgetlifetime_budgetstart_timestop_time
- Ad sets
idcampaign_idnamestatustargetingdaily_budgetlifetime_budgetstart_timeend_time
- Ads
idadset_idcampaign_idnamestatuscreative
- Pixel and dataset diagnostics (aggregate event counts and quality checks — no person-level data)
statsda_checksquality_diagnostics
We also store the identifiers of the ad account you select and the OAuth access token Meta issues, encrypted at rest (see Retention). We do not read your product catalog through this connection: that would need a permission we do not request.
Data we send to Meta
Reading the fields above means our requests carry your access token and account identifiers to Meta. Beyond that, the product does not send event data to Meta today.
The code base contains a Conversions API sender (POST /{pixel_id}/events (Conversions API)) that is not connected to any product path. If it is ever enabled, this is exactly what it would transmit, and this page will say so before it does:
Hashed (SHA-256) before sending
emphfnlndbgectstzpcountryexternal_id
Sent as received
client_ip_addressclient_user_agentfbpfbcsubscription_idfb_login_idlead_id
Permissions we ask Meta for
The consent screen lists exactly these permissions. A permission the code does not use is not requested.
ads_readRead your ad accounts, the campaign / ad set / ad structure and daily insights (spend, impressions, clicks, reach, actions) so that advertising cost can be reconciled against your commerce revenue. Read-only: the product makes no write call to your ad account, never posts ads and never changes a budget.
How long we keep it
- The Meta access token is the 60-day long-lived token Meta issues at authorisation. It is stored encrypted (Fernet) in our database. There is no automatic refresh job today, so it expires on Meta’s side about 60 days after you authorised unless you reconnect. Disconnecting pauses the connector; it does not delete the token.
- Aggregated advertising metrics (the insight and structure fields listed above) are kept for as long as your workspace exists. There is no automatic deletion schedule.
- Account data (your e-mail, name, company name, base currency, reporting time zone) is kept for as long as your workspace exists.
- User e-mail addresses in the Google Ads change history are stored and shown only to your workspace owner and administrators.
Disconnecting a connector in the app (DELETE /connectors/{id}) sets it to paused and stops scheduled syncs. It does not delete data: the connector record, including the encrypted access token, the sync history of that connector, the daily insight rows already synced, the campaign structure snapshots already synced remain until you ask us to delete them. See Data deletion.
Third parties
- Hosting: Hetzner (Germany). Your data is stored and processed on servers in Germany.
- Meta Platforms: the exchange described above, under Meta's own terms and privacy policy.
- No other third party receives the data described on this page.
Your rights
Under the Turkish Personal Data Protection Law (KVKK) and, where it applies, the GDPR, you may ask what personal data we hold about you, ask for it to be corrected or deleted, object to its processing, and withdraw the Meta authorisation at any time. Withdrawing the authorisation on Meta's side (Settings → Business integrations) invalidates the token immediately; deleting what we already hold is described on the Data deletion page.
Contact
Write to yusuf.can@mieko.com.tr from the e-mail address of your workspace owner. We answer from the same address.
See also the Terms of Service.