Last updated 25 May 2026v2.0 · effective 25 May 2026

Privacy Policy

JustClose is a customer-relationship and automation platform operated by Stay Active CommV. This policy describes what personal data we collect from you and from connected platforms (notably Meta), why we process it, who we share it with, and how you can exercise your data-protection rights.

§ 01

Overview & scope

This Privacy Policy applies to the JustClose web application available atjustclose.be and any sub-domains operated by Stay Active CommV (the "Service"). It governs how we process personal data of two groups:

  • Users — agency administrators and sub-account operators who log into JustClose to manage their CRM.
  • End-customers — individuals whose data is captured into JustClose by our Users (via web forms, Facebook Lead Ads, Messenger conversations, etc.).

For end-customers, Stay Active CommV acts as a data processor on behalf of the User (who is the controller). For account-related data of Users themselves, we act as the controller.

§ 02

Who we are

JustClose is operated by:

Stay Active CommV
Julius De Geyterstraat 268, 2610 Antwerpen (Wilrijk), België
VAT: BE0805615187 · Trading as RenoAd Agency / JustClose

You can reach us at [email protected] for any privacy-related question, data-subject request, or security report.

§ 03

Data we collect

We collect three categories of data:

From you directly

  • Account identity: full name, email address, telephone number, password (stored as a salted hash).
  • Business profile: company name, address, BTW/VAT number, logo, time-zone preference.
  • Contact records you import: names, emails, phone numbers, addresses, custom field values, tags.
  • Communications you send via the Service: SMS, email, WhatsApp, Messenger, and Instagram DM messages, plus any attached media.

Automatically

  • Technical metadata: IP address, browser user-agent, OS, screen size.
  • Session activity: login times, pages viewed, actions taken inside the dashboard.
  • Cookies strictly necessary for authentication and CSRF protection.

From connected third-party platforms

  • Meta (Facebook & Instagram) — see § 04 for the dedicated breakdown.
  • Stripe — payment events for our subscription billing (event IDs, masked card brand/last-four, not full card details).
  • Twilio & Postmark — message-delivery status callbacks for SMS, WhatsApp, and email.
§ 04

Data received via Meta APIs

When a User connects a Facebook Page (and any linked Instagram business account) to JustClose, we use Meta's Graph API + Webhooks to receive and process specific event types. The permissions we request are:

leads_retrieval
Fetch the contents of a Lead Ads form submission after Meta notifies us via webhook.
pages_manage_ads
List the Lead Ad forms attached to your Pages so you can choose which forms our app should sync.
pages_messaging
Receive and send Facebook Messenger messages to and from your connected Page.
instagram_manage_messages
Receive and send Instagram Direct Messages on your business account.
pages_show_list
List the Pages you administer when you connect a Page in our admin UI.
pages_manage_metadata
Subscribe your Page to receive the leadgen and messages webhook fields.
pages_read_engagement
Read Page metadata required to display the connection status.
instagram_basic
Read basic information about the Instagram business account linked to your Page.
business_management
Required for the System User token issued in your Business Manager to call Graph API on your behalf.

What we store

  • Page Access Tokens — encrypted at rest with AES-256-GCM via our INTEGRATION_ENCRYPTION_KEY. Used only for outbound Graph API calls (fetching leads, sending messages).
  • Lead form data — every field value submitted by the end-customer, persisted as a Contact in your sub-account.
  • Messages — text content, attachments, sender/recipient IDs, and Meta's message_id. Stored against the Conversation thread.
  • Webhook payloads — deduplicated by Meta's event ID. Raw payloads retained for 30 days for debugging.

What we do NOT do

  • We do not sell or rent any Meta-sourced data to third parties.
  • We do not use it for training machine-learning models.
  • We do not enrich it with data brokers or external profiling services.
  • We do not access Page data outside the explicit permissions listed above.
§ 05

How we use your data

We process the data above for the following purposes:

  • Service delivery — operating the CRM, routing leads and messages into the right sub-account, sending workflow-triggered communications.
  • Account administration — authentication, billing, support, fraud prevention.
  • Service improvement — aggregate usage analytics, error tracking via Sentry (no message bodies, no Meta data).
  • Legal compliance — responding to lawful requests, retaining records where statutorily required.

Our legal basis under GDPR Art. 6 is (a) contractual necessity for Users and (b) legitimate interest of our User-controllers for end-customer data, balanced against the rights of the data subject.

§ 06

Sub-processors

We rely on a small number of carefully vetted sub-processors. Each is bound by a data-processing agreement that mirrors our obligations.

Meta Platforms Ireland
Source platform for FB Lead Ads, Messenger, Instagram DMs
EU/US
Hetzner Online GmbH
Application hosting, database, file storage
Germany (EU)
Twilio Inc.
SMS & WhatsApp message delivery
EU/US (SCC)
Postmark (ActiveCampaign LLC)
Transactional email delivery
EU/US (SCC)
Stripe Payments Europe Ltd
Subscription billing & payment processing
Ireland (EU)
Sentry GmbH
Application error monitoring
EU (Germany)
Cloudflare Inc.
DNS, custom-domain TLS, DDoS protection
Global (DPF)

SCC = Standard Contractual Clauses. DPF = EU-US Data Privacy Framework certified.

§ 07

Data retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:

  • Account data — for the duration of your active subscription, plus 90 days after termination for export/recovery.
  • Contact records & conversations — controlled by you. Deletable at any time from the dashboard. Hard-deleted from backups within 35 days.
  • Meta webhook payloads — 30 days, then purged.
  • Billing records — 7 years (Belgian tax law).
  • Server & security logs — 90 days rolling window.
§ 08

Your rights (GDPR)

Under the General Data Protection Regulation you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion ("right to be forgotten").
  • Restriction — limit processing in specific circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Lodge a complaint — with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be).

To exercise any of these, email [email protected] from the address registered to your account. We respond within 30 days.

§ 09

Requesting data deletion

You can request that JustClose delete your personal data through two channels:

Via Facebook Settings (for Meta-connected data)

  1. Open Facebook → Settings & privacySettingsApps and Websites.
  2. Find JustClose in the list, click Remove.
  3. Choose Request that the app delete data.

Facebook will forward your request to our /api/webhooks/meta-data-deletion endpoint. We acknowledge with a confirmation code and delete the corresponding data within 30 days. The confirmation URL we return lets you check status at any time.

Directly via email

Email [email protected] with the subject "GDPR deletion request" and include the email address you registered with. We confirm receipt within 5 working days and delete within 30 days.

§ 10

International transfers

Our primary infrastructure is in the EU (Hetzner, Germany). Some sub-processors (Twilio, Postmark, Stripe US-side) may process data outside the EU. Transfers rely on Standard Contractual Clauses (Module Two: Controller-to-Processor) and, where applicable, the EU-US Data Privacy Framework certifications.

§ 11

Security measures

We apply the following technical and organisational measures:

  • TLS 1.3 in transit for all customer-facing endpoints.
  • AES-256-GCM encryption at rest for secrets (access tokens, API keys, encrypted credentials).
  • HMAC-SHA256 signature verification on every inbound Meta webhook.
  • Per-project tenant isolation enforced at the database query layer via withScopedAuth.
  • Hashed and salted password storage (bcrypt).
  • JWT sessions with rotation, CSRF tokens, and rate-limited authentication endpoints.
  • Daily encrypted backups, retained 35 days.
  • Quarterly internal security audits, vulnerability disclosure at [email protected].
§ 12

Children's privacy

JustClose is not intended for use by individuals under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided data to us, please contact [email protected] and we will delete the record promptly.

§ 13

Changes to this policy

We may update this policy as the Service evolves or regulation changes. Material changes are announced via email to all active account holders at least 14 days before they take effect. The version number and effective date at the top of this page always reflect the current published policy.

§ 14

Contact

For any privacy matter — questions, requests, complaints, or vulnerability reports:

Data Protection contact
Stay Active CommV — Privacy Office
Julius De Geyterstraat 268, 2610 Antwerpen, België

Belgian Data Protection Authority: gegevensbeschermingsautoriteit.be

v2.0 · 25 May 2026↑ Back to top