Privacy Policy
Last updated: January 5, 2026 | Effective: January 5, 2026
1. Introduction
Hiboo ("we," "our," or "us") operates the Hiboo e-commerce management platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and handling your data in an open and transparent manner. By using our Service, you agree to the collection and use of information in accordance with this policy.
Contact Information:
Email: privacy@hiboo.app
Website: https://hibooapp.co
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, and password when you create an account
- Business Information: Store details, business address, and contact information
- Payment Information: Billing details processed through our payment provider (Stripe)
- Communications: Information you provide when contacting our support team
2.2 Information from Connected Platforms
When you connect third-party platforms to Hiboo, we collect data necessary to provide our services:
Shopify Integration
- Order data (order ID, products, amounts, customer information, shipping details)
- Product catalog (titles, SKUs, prices, inventory)
- Store configuration and settings
Meta (Facebook/Instagram) Integration
- Ad account information (account ID, name, status, currency)
- Campaign, ad set, and ad performance data
- Spend, impressions, clicks, and conversion metrics
- Page information for connected Facebook Pages
- Page engagement metrics
Google Ads Integration
- Ad account information and campaign data
- Performance metrics (spend, conversions, ROAS)
- Keyword and ad group data
2.3 Automatically Collected Information
- Device information (browser type, operating system)
- IP address and approximate location
- Usage data (pages visited, features used, timestamps)
- Cookies and similar tracking technologies
3. Meta Platform Data Usage
Hiboo integrates with Meta's Marketing API to provide advertising analytics and management features. This section specifically describes how we handle data received from Meta platforms.
3.1 Permissions We Request
We request the following Meta permissions:
- ads_read: To read your advertising campaign data and performance metrics
- ads_management: To manage and optimize your advertising campaigns
- business_management: To access your Business Manager and connected ad accounts
- pages_show_list: To display your connected Facebook Pages
- pages_read_engagement: To read engagement data from your Pages
3.2 How We Use Meta Data
- Display advertising performance dashboards and analytics
- Calculate key performance indicators (KPIs) like ROAS, CPA, and CPM
- Generate historical trend reports and insights
- Enable campaign management and optimization features
- Aggregate metrics for business intelligence
3.3 Meta Data Storage
- Campaign and ad performance metrics are stored in our secure database
- Daily snapshots are retained for historical reporting
- Access tokens are encrypted at rest using AES-256 encryption
- Data is retained for as long as your account is active
3.4 Meta Data Sharing
We do not sell, rent, or share your Meta advertising data with third parties for their marketing purposes. Meta data is only used to provide you with our Service.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Display unified analytics dashboards across your connected platforms
- Calculate business metrics and generate insights
- Process transactions and send related information
- Send administrative notifications and updates
- Respond to your comments, questions, and support requests
- Monitor and analyze usage trends to improve user experience
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
5.1 Service Providers
We share data with third-party service providers who perform services on our behalf:
- Firebase/Google Cloud: Database hosting and authentication
- Stripe: Payment processing
- Resend: Transactional email delivery
5.2 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, privacy, safety, or property.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. We will also retain and use your information as necessary to:
- Comply with our legal obligations
- Resolve disputes
- Enforce our agreements
Historical advertising metrics and order data are retained for reporting purposes. When you delete your account, we will delete or anonymize your data within 30 days, except where retention is required by law.
7. Your Rights & Data Deletion
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Withdrawal: Withdraw consent for data processing
- Restriction: Request restriction of processing
How to Request Data Deletion
To request deletion of your data:
- Email us at privacy@hiboo.app with the subject line "Data Deletion Request"
- Include your account email address and specify what data you want deleted
- We will process your request within 30 days and confirm completion
You can also disconnect integrated platforms (Meta, Google, Shopify) at any time through your Hiboo dashboard settings. Disconnecting will stop new data syncing, and you can request deletion of previously synced data.
8. Data Security
We implement appropriate technical and organizational security measures to protect your data:
- Data encryption in transit (TLS 1.3) and at rest (AES-256)
- OAuth 2.0 authentication for third-party integrations
- Access tokens encrypted using industry-standard encryption
- Regular security audits and monitoring
- Role-based access control for team members
- Secure cloud infrastructure (Google Cloud Platform)
While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies: Required for authentication and security
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Understand how you use our Service
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of our Service.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses approved by relevant authorities. By using our Service, you consent to such transfers.
11. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice via email or through our Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@hiboo.app
- General Inquiries: hello@hiboo.app
- Website: https://hibooapp.co
For data deletion requests or to exercise your privacy rights, please email privacy@hiboo.app with the subject line indicating your request type.