Privacy Policy
Last updated 27 August 2026
What this covers
This policy covers DigiElevate Ads CRM: the marketing site, and the CRM application behind the login. Throughout, "we" means the operator of this installation and "you" means the business using it.
What we collect
From visitors to this website. If you submit the demo form we store your name, phone number, and optionally your email, industry and message, along with the IP address the request came from. That is used to contact you about your enquiry and nothing else.
From customers using the CRM. Your account details (name, email, hashed password, role) and everything your workspace puts into the system: leads, their contact details and form answers, notes, call logs, tasks, and the attribution data attached to each lead.
Automatically. A session cookie to keep you signed in, and an audit log of significant actions taken in your workspace, with the acting user and IP address.
Lead data belongs to you
Leads in your workspace are your data. We process them on your instructions to provide the service. We do not sell them, share them between workspaces, or use them to train anything. You are the data controller for your leads; we are the processor.
Because those leads are other people's personal information, you are responsible for having a lawful basis to collect and contact them, and for honouring any request they make to you directly.
What we send to Meta
This is the part worth reading carefully. When a lead reaches a pipeline stage you have mapped to a Meta event, we send a Conversions API event to Meta containing:
- Identifiers hashed with SHA-256 before transmission — email, phone, first and last name, city. Meta cannot read the original values from these.
- Sent unhashed, because Meta requires it: the Facebook click identifiers
(
fbc,fbp), the lead's IP address, browser user agent, and Meta's own lead ID. - The event name, a timestamp, a deduplication ID, and optionally the deal value and campaign names.
Notes, call recordings, tasks and custom form answers are never sent to Meta. You control which stages send anything at all, and you can map none of them. Once Meta receives an event it is governed by Meta's own data policies, not ours.
Other processors
Your hosting provider stores the database. Email notifications pass through the mail service configured on that host. That is the entire list — there is no analytics script, no advertising pixel and no third-party tracker on this site.
How long we keep things
Leads and account data stay until you delete them or close your account. Raw webhook payloads are kept 60 days for troubleshooting, email records 90 days, and the audit log one year. Deleting a lead removes its notes, calls and tasks with it.
Security
Passwords are stored as bcrypt hashes and are never recoverable in plain text. Sessions use HTTP-only cookies. Every workspace's data is isolated at the query level, and reps can only reach leads assigned to them. Serve the application over HTTPS — several of these protections are weakened without it.
No system is perfectly secure. If you find a vulnerability, please report it to hello@thedigielevate.com before disclosing it publicly.
Your rights
You can export everything in your workspace to CSV at any time from the app. To correct or delete your account data, or to ask what we hold about you, email hello@thedigielevate.com. If you are one of the leads in a customer's workspace rather than a customer yourself, contact that business — they control that record, not us.
Questions about any of this? Email hello@thedigielevate.com. DigiElevate Ads CRM is an independent product and is not affiliated with or endorsed by Meta Platforms, Inc.