SocialRIZ
Effective September 4, 2026

Privacy Policy

This policy explains how SocialRIZ handles information across our website, mobile app, business workspace, marketing, advertising, and operational tools.

Information we collect

Depending on how you use SocialRIZ, we may collect:

  • Contact information you provide when creating an account, asking for support, submitting a website form, or using a current or past product-interest or waitlist form.
  • Account information such as your name, email, and organization.
  • Business information you provide, including services, locations, websites, contact details, and public profile links.
  • Publicly available marketing information and evidence used in an audit.
  • Information returned by services you choose to connect, such as advertising account names, identifiers, status, and campaign records.
  • Workspace content such as conversations, team schedules, time-off information, orders, customer details, leads, estimates, files, images, videos, approvals, and activity history.
  • Website-form and attribution information such as landing page, referring site, campaign parameters, advertising click identifiers, and the information a visitor submits in a contact, lead, or estimate form.
  • Device and notification information, such as device type, push permission status, push subscription identifiers, and the account identifier used to route notifications.
  • Billing and subscription identifiers and status when paid services are purchased. SocialRIZ does not store full payment-card numbers.
  • Security and usage information needed to operate, protect, and improve the service.

Connected advertising accounts

Google Ads, Microsoft Advertising, and Meta Ads connections use their authorization flows. SocialRIZ stores the resulting access credentials in encrypted form and uses them only to perform actions an authorized user requests. Credentials are not exposed to the browser or included in campaign records.

You can disconnect an advertising provider from the Connections view. Disconnecting removes the stored authorization credentials from SocialRIZ. For Meta Ads, SocialRIZ also requests authorization revocation from Meta. Local credentials are removed even if Meta is temporarily unavailable.

How we use information

  • Create accounts and send requested account, product, support, and service communications.
  • Provide marketing audits, recommendations, and planning tools.
  • Generate and publish content that an authorized user approves.
  • Create approved advertising campaigns in a paused state.
  • Maintain account security, access controls, and audit records.
  • Provide conversations, schedules, orders, customer-management tools, and optional push notifications.
  • Diagnose problems and improve service reliability.
  • Meet legal, security, and platform-policy obligations.

Third-party services

We use the providers below to operate SocialRIZ and limit the information they receive to what is reasonably needed for the requested workflow. Information a provider collects directly is also governed by that provider's terms and privacy policy.

OpenAI

We use the OpenAI API for marketing audits, recommendations, and draft content. We may send business profile information, public marketing evidence, and summarized connected-account metrics. We do not include passwords, stored authorization credentials, or full payment-card numbers in AI prompts. Learn more in the OpenAI Privacy Policy and OpenAI business data privacy commitments.

Google Ads

If you connect Google Ads, Google and SocialRIZ process authorized advertising account identifiers, account details, campaign records, and authorization credentials so we can show account information and perform actions you approve. SocialRIZ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. See also the Google Privacy Policy.

SocialRIZ also uses the Google tag on its own website to understand visits and actions, measure advertising performance, and attribute conversions. Google may process information such as the page visited, browser and device details, IP address, referring or advertising-click information, and identifiers stored in cookies or similar technologies. This website measurement is separate from any Google Ads account you connect to a SocialRIZ workspace.

Microsoft Advertising

If you connect Microsoft Advertising, Microsoft and SocialRIZ process authorized account identifiers, account details, campaign records, reporting metrics, and authorization credentials to provide the workflows you request. SocialRIZ also uses Microsoft Universal Event Tracking (UET) on its own website to measure visits, website-form submissions, advertising performance, and conversion attribution. Microsoft may process page, browser, device, network, advertising-click, cookie, and similar identifier information. See the Microsoft Privacy Statement.

Meta Ads, Facebook, and Instagram

If you connect a Meta service, Meta and SocialRIZ process authorized profile and advertising account identifiers, campaign records, insights, and authorization credentials so we can provide the requested connection and advertising workflows. You can disconnect Meta and request deletion as described below. Learn more in the Meta Privacy Policy.

TikTok

If you connect TikTok, TikTok and SocialRIZ process authorized profile identifiers, publishing credentials, selected media, captions, privacy choices, and post-performance metrics needed to provide the requested publishing and analytics workflows. Learn more in the TikTok Privacy Policy.

Stripe

When billing is enabled and you purchase a paid service, Stripe processes contact, billing, and payment information. SocialRIZ stores billing and subscription identifiers and status, but not full payment-card numbers. Learn more in the Stripe Privacy Policy.

Resend

Resend delivers transactional and support email and may process the recipient address, sender information, subject, and message content. Learn more in the Resend Privacy Policy.

OneSignal

If you enable push notifications, OneSignal processes device and push subscription information and a SocialRIZ account identifier so we can route requested conversation and schedule notifications to your web browser or mobile device. Notification permission can be changed in your browser or device settings. Learn more in the OneSignal Privacy Policy.

Hosting and infrastructure

Cloudflare hosts and delivers the frontend and stores the images and videos you upload to your media library, while Render hosts the API, background services, and database. These providers may process network information such as IP addresses and request metadata, operational logs, and stored account or business information as needed to provide and secure the service. Review the Cloudflare Privacy Policy and the Render Privacy Policy.

Sharing and selling

SocialRIZ does not sell personal information or connected advertising account data. We may disclose information to service providers acting on our instructions, when you direct us to share it, to protect the service and its users, or when legally required.

Retention and deletion

We retain information while it is needed to provide the service, maintain security and approval records, resolve disputes, and meet legal obligations. A signed-in user may initiate permanent personal account deletion from Organization settings under Security. A last owner may need to finish listed active work or provider connections first; an active subscription for a workspace that closes is canceled as part of account deletion. Organization owners may separately delete an eligible workspace from Workspace identity. You may request help with an inaccessible account by emailing support@socialriz.com. Some records may be retained where required for security, legal, or compliance reasons.

Meta may send SocialRIZ a signed deauthorization or data-deletion request. After verifying Meta's signature, SocialRIZ removes the associated Meta authorization credential, selected ad-account identifier, and provider identity. A deletion request receives a random confirmation code and a public status page that does not expose the Meta user identifier. See our Meta data-deletion instructions.

Security

We use access controls, encrypted connections, credential encryption, and organization-level data separation. No system can guarantee absolute security, but we design the product to minimize unnecessary access and prevent advertising execution without approval.

The optional mobile app lock asks the device operating system to verify Face ID, Touch ID, or the device passcode. SocialRIZ does not receive or store a biometric template from that verification.

Your choices and rights

You may request access, correction, deletion, or a copy of personal information associated with your account. You may also disconnect linked providers and revoke access from the provider's own account settings. Depending on where you live, additional rights may apply, including the right to know about covered disclosures, to opt out of covered sale or sharing, and not to receive discriminatory treatment for exercising a privacy right. We may verify your identity before completing a request.

Browser privacy signals

Browsers do not currently provide a uniform “Do Not Track” standard, so SocialRIZ does not respond to legacy Do Not Track signals. When a browser sends a Global Privacy Control signal, SocialRIZ does not load its Google or Microsoft advertising-measurement tags for that visit. You may also use browser privacy controls or contact support@socialriz.com with questions about marketing measurement or privacy choices.

Children

SocialRIZ is a business service and is not directed to children under 13. We do not knowingly collect personal information from children.

Changes and contact

We may update this policy as the service changes. The effective date above will identify the current version. Questions and privacy requests can be sent to support@socialriz.com.