HitOS
Afluence LLC · HitOS

Privacy Policy

How Afluence LLC collects, uses, stores, and deletes information when agencies and creators use HitOS and connect provider accounts.

Effective: August 5, 2026

1. Who we are

Afluence LLC operates HitOS. In this policy, “Afluence,” “we,” and “us” refer to Afluence LLC. Agencies, creators, team members, and authorized operators who use HitOS are “users.”

2. Information we process

  • Account and organization data: name, email, role, tenant membership, creator assignments, authentication records, and support activity.
  • Creator workspace data: strategies, launches, content, files, forms, tasks, and other information entered by authorized users.
  • Connected-channel data: granted asset identifiers, Pages, professional Instagram accounts, Ad Accounts, Pixels or Datasets, WhatsApp Business Accounts and phone numbers, media, posts, comments, insights, campaigns, leads, conversations, messages, and delivery events made available through Meta APIs and webhooks.
  • Credentials: provider access tokens are encrypted and stored per authorization. Product tables store opaque references, not plaintext access tokens or App Secrets.
  • Technical and security data: IP address, device and browser information, request traces, audit events, error data, rate-limit state, and security signals.

3. Why we process information

We process information to provide the requested workspace and connected-channel features; authenticate and authorize users; publish, synchronize, measure, and moderate content and advertising; deliver and receive permitted messages; operate integrations and webhooks; prevent abuse; troubleshoot incidents; provide support; and comply with law.

4. Sources

Information comes from users and their authorized organizations, from provider APIs and signed webhooks after a user grants access, and from the operation of HitOS. We do not use a shared global creator token.

5. Sharing and service providers

We disclose information only as needed to provide HitOS: to authorized members of the applicable agency or creator workspace; to Meta and other providers when a user directs an operation; to infrastructure, security, email, and storage processors working for us; or when required to protect users, enforce agreements, or comply with law. We do not sell personal information.

6. Retention

Credentials are retained only while the authorization remains connected or as needed to complete revocation and deletion. Disconnecting destroys the stored credential and ends operational access. Consent and audit evidence may be retained to document who authorized or revoked access. Channel events, messages, leads, and operational records use documented retention schedules; current channel-event and lead records have a 24-month deletion horizon unless a shorter legal or customer requirement applies.

7. Security

We use tenant isolation, role-based access, signed webhook verification, encrypted credential storage, audited sensitive actions, transport encryption, idempotency controls, and provider-health checks. No system can guarantee absolute security; report suspected misuse to the contact below.

8. Your choices and rights

Authorized users can disconnect individual provider assets from the creator Connections screen. You may also request access, correction, export, restriction, or deletion by following the Data Deletion Instructions. We may need to verify identity and authority before acting.

9. International processing and children

HitOS may process information in countries where Afluence or its service providers operate, subject to appropriate safeguards. HitOS is a business service and is not directed to children.

10. Changes and contact

We may update this policy as the product, providers, or legal requirements change. The effective date above identifies the current version. Contact contact@byafluence.com with privacy questions.