Privacy Policy
This Privacy Policy explains how Citrus for General Supplies and Contracting LLC ("PeakDigit", "we", "us", "our"), a limited liability company registered in Egypt (Commercial Register No. 25916, Cairo; Tax Registration 769-564-003; registered address: 1141 Zahraa Madinat Nasr, Apt 2, Nasr City, Cairo, Egypt), collects, uses, stores, shares and deletes personal data when you use the PeakDigit platform at app.peakdigit.com, our website at peakdigit.com, or any related services (together, the "Services").
If you have any question about this policy or your data, contact us at privacy@peakdigit.com.
1. Who we process data for
PeakDigit is a business-to-business (B2B) software platform. Our direct customers are businesses ("Clients") that use PeakDigit to manage their digital marketing, advertising analytics, customer conversations and sales pipeline. In most cases we process end-customer personal data on behalf of and under the instructions of our Clients, who act as the data controllers; PeakDigit acts as a data processor. For data about our Clients' own team members and website visitors, PeakDigit acts as the data controller.
2. Data we collect
2.1 Account and team data
- Name, email address, role and password hash of platform users (Client team members).
- Authentication logs, session tokens and security events.
2.2 Advertising platform data (Meta, TikTok)
When a Client connects its advertising accounts through the official APIs of Meta Platforms, Inc. ("Meta") or TikTok Pte. Ltd. ("TikTok"), we collect, with the Client's explicit authorization:
- Ad account metadata (account IDs, names, currency, time zone).
- Campaign, ad set, ad and creative structures and settings.
- Aggregated performance metrics (spend, impressions, clicks, reach, video views, conversation counts, cost metrics). These are statistical metrics, not personal profiles of end users.
- Click-to-WhatsApp referral identifiers provided by Meta (such as
ctwa_clidand source ad IDs) used solely to attribute a conversation to the ad that started it.
2.3 WhatsApp Business conversation data
When a Client connects its WhatsApp Business account, we process on the Client's behalf:
- Customer phone number and display name.
- Message timestamps, conversation identifiers and conversation metadata needed for routing, follow-up alerts and attribution.
- Business-initiated and customer-initiated message content, only to the extent required to display conversations to the Client's own team inside the platform.
2.4 CRM data
- Lead and deal records created by the Client or generated automatically from conversations (name, phone, stage, notes, activity history, tags, order values).
2.5 Website visitors
- Basic technical data (IP address, browser type, pages visited) collected through server logs for security and operations. Our marketing website does not use advertising trackers. See the Cookie Policy.
3. How we use data
- To provide, operate, secure and improve the Services for our Clients.
- To display advertising performance analytics and recommendations to the Client whose ad accounts generated them.
- To attribute conversations, leads and sales to advertising campaigns (revenue attribution).
- To send operational notifications to Client team members (e.g., balance alerts, follow-up reminders).
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal data. We do not use Platform Data obtained from Meta or TikTok to build or augment user profiles, for advertising unrelated to the Client that owns the data, or for any purpose other than providing the Services to that Client.
4. Platform Data — Meta and TikTok specific commitments
- We access Meta and TikTok APIs only with permissions granted by the Client through the platforms' official authorization flows (OAuth / Business Integrations / System Users managed by the Client).
- Data received from Meta ("Platform Data" as defined in the Meta Platform Terms) is used solely to provide the Services to the Client it belongs to, is never sold, and is never shared with third parties except as described in Section 6.
- We retain Platform Data only as long as needed to provide the Services (see Section 7) and delete it upon disconnection of the integration, Client request, or termination of the Client agreement.
- Clients and end users may request deletion at any time — see our Data Deletion Instructions.
- We maintain administrative, technical and physical safeguards appropriate to the sensitivity of Platform Data (Section 8).
4.1 Meta permissions we request and how each is used
The PeakDigit app requests the following Meta permissions. For each permission, this table describes exactly what data is accessed and why:
| Permission | Data accessed | Why we need it (user-facing feature) |
|---|---|---|
ads_read | Ad account structure and aggregated performance insights (spend, impressions, clicks, reach, video metrics, cost metrics) | Displays the Client's own advertising performance dashboards, creative-level analytics and budget alerts inside the platform. |
ads_management | Campaign, ad set and ad settings (status, budget) | Lets authorized Client team members pause/resume ads and adjust budgets directly from the platform's campaign console, acting on the Client's own ad accounts. |
business_management | Business portfolio assets metadata (ad accounts, pages owned by the Client's Business) | Lists the Client's own business assets so the Client can choose which ad accounts to connect. |
whatsapp_business_management | WhatsApp Business Account configuration (phone numbers, message templates) | Shows connection status and template setup for the Client's own WhatsApp Business Account. |
whatsapp_business_messaging | Messages between the Client's WhatsApp Business number and its customers, including Click-to-WhatsApp referral metadata (ctwa_clid, source ad ID) | Powers the conversation desk (so the Client's team can view and respond to its own customer conversations) and attributes each conversation to the ad that generated it. |
pages_show_list, pages_read_engagement (if requested) | Pages owned by the Client and aggregated page/post engagement | Connects ad creatives to the Client's own page posts for creative-performance reporting. |
We request only the permissions needed for the features above. We never use these permissions to collect data about users unrelated to the Client, to build advertising profiles, or to serve ads outside the Client's own accounts.
4.2 TikTok scopes we request and how each is used
| Scope | Data accessed | Why we need it |
|---|---|---|
| Ad Account Management (read) | Advertiser account metadata | Lists the Client's own TikTok advertiser accounts for connection. |
| Reporting | Aggregated campaign/ad performance metrics | Displays the Client's TikTok ad performance dashboards. |
| Ads Management (if requested) | Campaign and ad status/budget settings | Lets authorized Client team members manage the status and budget of the Client's own TikTok campaigns. |
5. Legal bases
Where applicable law (such as the Egyptian Personal Data Protection Law No. 151 of 2020 or, where relevant, the GDPR) requires a legal basis, we rely on: performance of a contract with our Clients; our Clients' instructions as data controllers; legitimate interests in operating and securing the Services; and compliance with legal obligations.
6. Sharing and disclosure
We share personal data only with:
- The Client that owns the data — all conversation, lead and ad data is visible only to the authorized team of the Client it belongs to (strict per-tenant isolation).
- Infrastructure providers — hosting, database and backup providers under data processing agreements, solely to run the Services.
- Platform providers — Meta and TikTok, when the Client performs actions through PeakDigit (e.g., pausing an ad), via their official APIs.
- Authorities — where required by applicable law or valid legal process.
We never share one Client's data with another Client, and we never disclose Platform Data to data brokers or advertising networks.
7. Data retention
- Account data: retained while the Client agreement is active and deleted within 90 days of termination.
- Advertising metrics and attribution data: retained while the related integration remains connected, to provide historical reporting to the Client.
- WhatsApp conversation data: retained under the Client's instructions and deleted on the Client's request or integration disconnection.
- Backups: encrypted backups are retained for up to 35 days, after which deleted data ages out automatically.
8. Security
- All traffic is encrypted in transit (TLS). Access tokens and credentials are stored encrypted and never exposed in client-side code.
- Strict multi-tenant isolation is enforced at the database query layer: every data access is scoped to the owning Client.
- Role-based access control restricts what each team member can see and do.
- Audit logging records administrative and sensitive actions.
- Daily encrypted backups with restore testing.
9. Your rights
Depending on applicable law, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. End customers of our Clients should direct requests to the business they interacted with (the data controller); we support our Clients in fulfilling such requests. You can also contact us directly at privacy@peakdigit.com and we will respond within 30 days.
10. International transfers
Our infrastructure is hosted in secure data centers. Where data is transferred across borders, we use appropriate safeguards consistent with applicable data protection law.
11. Children
The Services are intended for business use and are not directed to children under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a new "Last updated" date, and notify Clients of material changes.
13. Contact
Citrus for General Supplies and Contracting LLC (PeakDigit)
1141 Zahraa Madinat Nasr, Apt 2, Nasr City, Cairo, Egypt
Email: privacy@peakdigit.com · legal@peakdigit.com