Privacy Policy
Balloon (“Balloon,” “we,” “us,” or “our”) provides software that helps brands analyze their websites, generate marketing content, and publish and manage posts and ads on platforms such as Facebook and Instagram. This Privacy Policy explains how we collect, use, share, and protect information when you use balloon.marketing, our admin app, our APIs, our website tracking script, and related services (together, the “Services”).
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
1. Who this policy covers
This policy applies to:
- Customers and account users — people who create or use a Balloon account to manage projects and publish content.
- Website visitors — people who visit balloon.marketing or related marketing pages.
- End users of customer sites — people whose activity may be collected when a customer installs our tracking script on their website.
When customers use Balloon to process data about their own end users or social audiences, Balloon acts as a service provider / processor for that customer. Customers are responsible for providing appropriate notices and obtaining any consents required for their use of Balloon.
2. Information we collect
2.1 Account and contact information
When you create or use an account, we may collect your name, email address, password (stored in hashed form), account membership details, and communications you send us.
2.2 Project and website content
To provide the Services, we collect project settings (such as website URLs and budgets), content we fetch from customer websites for analysis, generated creatives and copy, deployment and performance records, and related configuration.
2.3 Connected platform data (Meta / Facebook / Instagram)
If you connect Facebook or Instagram through Balloon, we receive authorization tokens and related account metadata needed to act on your behalf. Depending on the permissions you grant, this may include:
- Facebook Page ID, name, and Page access tokens
- Linked Instagram Business or Creator account IDs and usernames
- Ad account identifiers (when you use paid ads)
- Content, comments, engagement metrics, and other data returned by Meta APIs for Pages, posts, ads, and Instagram accounts you authorize
We only request permissions that are needed to operate the features you use (for example, publishing organic posts, managing ads, reading engagement, and moderating comments). You can disconnect Meta at any time in project settings; you may also remove Balloon's access from your Meta account settings.
2.4 Tracking and product analytics
If a customer installs the Balloon tracking script on their site, we may collect event data such as page views, clicks, conversions, referrers, device or browser characteristics, and identifiers needed to attribute activity to a project. This data is used to measure campaign performance and improve recommendations for that customer.
2.5 Usage and technical data
We automatically collect logs and technical information when you use the Services, such as IP address, browser type, approximate location derived from IP, timestamps, request paths, error reports, and cookie or session identifiers used for authentication and security.
2.6 Information from service providers
We may receive information from infrastructure and AI providers that help us run the Services (for example, hosting, email, analytics, or model providers), subject to their terms and our agreements with them.
3. How we use information
We use information to:
- Provide, operate, secure, and improve the Services
- Authenticate users and maintain sessions across the admin app and APIs
- Analyze customer websites, generate marketing content, and publish or manage posts and ads on connected platforms
- Retrieve and process engagement data (including comments) so customers can moderate and respond
- Measure performance and run learning / optimization workflows
- Communicate about the Services, support requests, and important updates
- Detect, prevent, and investigate abuse, fraud, or security incidents
- Comply with law and enforce our terms
We do not sell your personal information. We do not use Meta Platform data to build unrelated advertising profiles, and we do not share Meta Platform data with third parties for their independent marketing purposes.
4. How we share information
We may share information with:
- Platform partners you connect — for example Meta (Facebook / Instagram), when you authorize Balloon to publish content, manage ads, or read engagement data on your behalf.
- Service providers — vendors that host infrastructure, store data, process payments (if applicable), provide AI model inference, email, or monitoring, under contracts that limit use of the data to providing services to us.
- Account members — other users you invite to your Balloon account or project.
- Legal and safety — when required by law, legal process, or to protect the rights, safety, or property of Balloon, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
5. Cookies and similar technologies
We use cookies and similar technologies that are necessary to sign you in, keep sessions secure, and operate the Services. We may also use limited analytics cookies on our marketing site to understand aggregate traffic. You can control cookies through your browser settings; disabling necessary cookies may prevent parts of the Services from working.
6. Data retention
We retain information for as long as needed to provide the Services, fulfill the purposes described in this policy, resolve disputes, and meet legal or security requirements. Connected platform tokens are stored while a project remains connected and are removed or invalidated when you disconnect (or when tokens expire and can no longer be refreshed). You may request deletion of your account and associated project data as described below.
7. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), access controls, hashed passwords, and restricted handling of platform tokens and secrets. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. Your choices and rights
Depending on where you live, you may have rights to:
- Access, correct, or delete personal information we hold about you
- Export a copy of certain data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of non-essential marketing communications
You can disconnect Meta from a project in Balloon settings, refresh or revoke tokens, and delete projects (which removes associated ads, deployments, events, metrics, and related data). To exercise privacy rights or request account deletion, contact us at privacy@balloon.marketing. We may need to verify your request before acting on it.
9. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
10. International transfers
We may process and store information in the United States and other countries where we or our providers operate. Those countries may have different data protection laws than your home country. Where required, we use appropriate safeguards for cross-border transfers.
11. Third-party services
The Services interoperate with third-party platforms (including Meta) and providers whose own privacy policies govern their handling of data. Balloon is not responsible for third-party practices outside our control. Review the privacy policies of any platforms you connect.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated through the Services or by email. Continued use of the Services after an update means you accept the revised policy.
13. Contact us
Questions about this Privacy Policy or our data practices can be sent to:
Balloon
Email:
privacy@balloon.marketing
Website:
https://balloon.marketing