Legal

Privacy policy

This explains what we collect, what we do with the access you grant us inside Meta, and how to take that access back without asking us first. It is written to be read, not to be survived.

Last updated 8 October 2026

The short versionPlain English
  • 01This website runs no analytics, no advertising pixel and no third party tracker. That is why there is no cookie banner.
  • 02Your ads run inside your Meta account, on your Page, with your pixel, paid with your card. We never hold the account.
  • 03To work in there we need a Meta access token. It is a key, not your password. We never see your password.
  • 04The token is encrypted, used only to run your advertising, and every change it makes is written into Meta's own audit log where you can read it.
  • 05You can cut our access off from inside Meta in under 1 minute, on your own, without telling us.
  • 06We do not sell your data, and we never have.
01Who this covers

Plauqe is a Meta ads media buying desk operated by RASH PRINT LLC, 5830 East 2nd Street, Casper, WY 82609, United States. In this policy "we", "us" and "Plauqe" mean RASH PRINT LLC, which is the data controller for everything described here.

"You" means one of 3 people: someone reading plauqe.com, a brand that sends us an application, or a client whose advertising we are running. Where a section only applies to one of those, it says so.

02The Meta access token

This is the part that matters, so it goes first and it is the longest section on the page.

Plauqe does not run your ads out of a Plauqe ad account. Everything runs inside your own Meta Business Manager, on your own ad account, under your own Page and pixel, paid with your own card. We are a partner on your account, not the owner of it. To work in there, we need a Meta access token.

What an access token actually is

When you add Plauqe as a partner on your Business Manager, or connect your account through our application, Meta issues a credential called an access token. It is not your password. We never see, ask for or store your Facebook password, and you should never send it to us or to anyone else.

A token is a key Meta signs. It says that one named application may perform one named list of actions on one named set of accounts, and nothing else. Meta can revoke it, you can revoke it, and it expires on its own. If a token were somehow taken from us, it would still only be able to do the things on that list, to the accounts on that list.

The permissions we ask for, and why

The exact set depends on what you want run. We ask for the narrowest set that does the job. If you only want reporting, we take ads_read and nothing else.

ads_management

Create, edit, pause and delete campaigns, ad sets and ads, and upload creative. This is the permission that actually launches the ads.

ads_read

Read performance back: spend, impressions, clicks, results and cost per result, by ad and by day. Reporting and the daily budget calls run on this.

business_management

See the assets inside your Business Manager, so the right ad account, Page and pixel get attached to a campaign.

pages_show_list, pages_read_engagement, pages_manage_ads

Run the ads from your own Page, and read and answer the comments underneath them.

instagram_basic

Place the same ads on your Instagram account.

catalog_management

Build and run catalog and dynamic product ads off your product feed. Only if you sell from a catalog.

leads_retrieval

Pull the leads out of a lead form ad and hand them to you. Only if we run lead ads for you.

What we do with it

We call the Meta Marketing API with that token. In plain terms, our systems and our buyers use it to:

  • 01Upload creative, meaning images, video and copy, into your ad account.
  • 02Create campaigns, ad sets and ads inside it.
  • 03Set, raise, lower and pause budgets.
  • 04Turn individual ads on and off.
  • 05Read performance back, by ad and by day.
  • 06Build audiences from your own pixel, and from a customer list if you choose to give us one.
  • 07Read and answer the comments sitting under the ads we run.

That is the whole list. Every one of those actions is written into your own Meta account against the user or system user the token belongs to, so you can read back every change we have ever made from Meta's own audit log, without asking us and without taking our word for anything.

What we do not do with it

  • 01Move money. Billing stays on your payment method, inside your account. We do not touch billing settings.
  • 02Use your ad account, your audiences, your pixel data or your creative on any other brand.
  • 03Keep or resell your customer lists. A list you provide for a Custom Audience is hashed before upload, used only to build that audience on your account, and the source file is deleted from our systems once it is built.
  • 04Sell, rent or share your data with data brokers. There is nobody to sell it to who would help us.
  • 05Reach anything outside the assets you attached to the token.

How the token is stored

Encrypted at rest. Reachable only by the people working your account and the systems that run your campaigns. Tokens are never written into logs, support tickets, spreadsheets, chat messages or email, and they are never shared between clients.

How to take it back

You do not need our permission and you do not have to tell us first. It takes under 1 minute:

Access stops at that moment. You can also pull the app under Settings, then Business Integrations, on your personal Facebook account. If you would rather we did it, write to us and we will remove ourselves and confirm it in writing the same day. Within 30 days of access ending we delete the token and the credentials tied to it.

Removing our access does not delete your campaigns, your creative, your audiences or your history. All of it is in your account and stays there, because it never left.

03What you send us

The application form. Brand name, website, email address, phone number if you give one, the band your current monthly ad spend falls into, and a few lines on what you sell and what is stuck. We use it to work out whether we can win with your brand and to write back. Nothing on that form is used for advertising, and it is never passed on.

Anything else you send. Emails, calls, documents, access details and files you hand over while we work together.

04What we see in your accounts

Advertising data. Campaign structure, creative, spend, impressions, clicks, results and cost per result, by ad and by day.

Store and revenue data. If you give us access to Shopify or another platform, or connect a reporting tool, we see orders, revenue and attribution. We use it to judge whether the advertising is actually working, because the platform alone counts the same purchase more than once. We use it for nothing else.

Almost all of this is aggregate. We do not need, do not ask for and do not want the names, addresses or card details of your customers.

05What this website collects

Less than you expect. There is no Google Analytics on plauqe.com, no Meta pixel, no session recorder and no third party tracker of any kind.

Our host, Vercel, keeps ordinary server logs: IP address, browser user agent, the page requested and a timestamp. That is needed to serve the site and to stop abuse, and it is kept for 30 days. When you submit the application form, what you typed is recorded on our side and sent to our inbox.

06How we use it
  • 01To decide whether to take your brand on.
  • 02To write back to you.
  • 03To build, launch and run your advertising.
  • 04To report what happened and what we changed.
  • 05To work out what we are owed, once you decide to keep us.
  • 06To keep the website and our systems standing.
  • 07To meet legal, accounting and tax duties.

We do not use one client's data to advertise for another. We do not publish your numbers, your creative or your name as a case study anywhere without your written permission, which is also why there are no logos on this website.

07Legal bases

If you are in the UK or the EU, the GDPR asks us to name a lawful basis for each use. Ours are: contract, to run the advertising you hired us for; legitimate interests, to assess applications, keep our systems safe and understand what is working; consent, where you have given it, which you can withdraw at any time; and legal obligation, for tax and accounting records.

08Who else touches it

A short list, and each one is bound by contract to use the data only to provide its service to us.

Meta Platforms, Inc.

The advertising itself. What happens inside your ad account is also governed by Meta's own terms and privacy policy, not only by this one.

Vercel Inc.

Hosting for this website and the application form.

Email and messaging

Carrying applications and correspondence between you and us.

Accounting and payments

Invoicing, once you have decided to keep us and there is something to invoice.

We may also disclose data where the law requires it, or to establish or defend a legal claim. We will tell you if that happens, unless we are forbidden from doing so.

09Where it goes

We operate from the United States and our providers are mostly United States companies. If you are in the UK or the EU, your data is transferred there under Standard Contractual Clauses or an equivalent approved safeguard.

10How long we keep it
Application from a brand we declineUp to 12 months
Access tokens and credentialsDeleted within 30 days of access ending
Advertising performance records24 months
Creative we made for youYours, handed over at the end
Invoices and tax records7 years, because the law says so
Server logs30 days
11Deleting your data

Write to privacy@plauqe.com and ask. You do not have to give a reason. We confirm what was deleted within 30 days.

If you are a client, revoking our Meta access as described in section 02 is the faster route and it is entirely in your hands. The only thing we cannot delete on request is invoice and tax records, which the law obliges us to keep. If that applies we will tell you exactly what stayed and why.

12Security

Encryption in transit and at rest. Access limited to the people actually working your account. 2 factor authentication on every Meta, platform and email login we use. Credentials never stored in plain text, never in a spreadsheet and never in a chat message.

No system is perfect and we are not going to pretend otherwise. If a breach affects your data we will tell you what happened, what it touched and what to do about it, and we will do it quickly rather than quietly.

13Your rights

UK and EU, under the GDPR. You can ask for a copy of your data, have it corrected, have it deleted, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw consent where you gave it. You can also complain to your data protection authority, and in the UK that is the ICO.

California, under the CCPA and CPRA. You can ask what we collect and why, ask for it to be deleted or corrected, and opt out of the sale or sharing of personal information. We do neither, so there is nothing to opt out of. We will never treat you worse for exercising any of this.

Use privacy@plauqe.com for all of it. It is free, and we answer within 30 days.

14Cookies

plauqe.com sets no cookies of its own, no advertising cookies and no analytics cookies. There is no consent banner on this site because there is nothing to consent to. If that ever changes, the banner arrives before the cookie does.

15Children

This is a service sold to businesses. It is not directed at anyone under 18 and we do not knowingly collect data from children. If you believe a child has sent us something, write to us and we will delete it.

16Changes and contact

When this policy changes we update the date at the top. If a change materially affects how we handle access to client accounts, every active client gets an email about it before it takes effect, not after.

ContactData controller

RASH PRINT LLC

5830 East 2nd Street

Casper, WY 82609

United States

privacy@plauqe.com

+1 860 855 1751