DR Flow

DR Flow Legal

Privacy Policy

Effective date: May 11, 2026

DR Flow is operated by Roy Group. DR Flow helps direct-response teams manage creative operations, deployment tracking, and advertising performance reporting. This Privacy Policy explains how DR Flow collects, uses, shares, and protects information when people use the service, including when they connect Meta business assets.

Information We Collect

We may collect the following categories of information:

  • Account information, such as name, email address, organization membership, role, and authentication state.
  • Workspace information entered by users, including offers, copies, creatives, ad packs, tasks, assets, operational notes, approvals, and audit history.
  • Integration information from connected platforms, including Meta data authorized by the user.
  • Technical and security information, such as login events, request metadata, browser/device metadata, audit logs, error logs, and service health signals.

Meta Platform Data

If a user connects Meta to DR Flow, DR Flow may access only the Meta data that the user authorizes and that the user is permitted to access. Depending on the approved permissions, this may include:

  • Meta business portfolios and related business metadata.
  • Ad accounts accessible to the authorized user.
  • Facebook Pages accessible to the authorized user.
  • Instagram business account identifiers returned through connected Page data.
  • Existing campaign, ad set, and ad identifiers, names, statuses, and account relationships.
  • Advertising performance insights, including spend, impressions, reach, clicks, CTR, CPC, CPM, leads, purchases, purchase value, revenue, ROAS, dates, and currency.

DR Flow currently uses Meta data for read-only reporting, resource inventory, deployment traceability, and operational dashboards. DR Flow does not create, edit, pause, publish, or delete Meta ads in the current Meta integration.

How We Use Information

We use information to:

  • Provide, operate, and secure DR Flow.
  • Authenticate users and enforce organization-level access.
  • Display operational workflows, dashboards, reporting, and audit trails.
  • Sync connected-platform reporting data after user authorization.
  • Troubleshoot errors, support users, prevent abuse, and improve reliability.

How We Share Information

We do not sell user data. We may share information only in limited circumstances:

  • With service providers that help operate hosting, storage, email, analytics, security, infrastructure, or support.
  • With authorized users inside the same DR Flow organization, according to their roles and permissions.
  • When required by law, legal process, or to protect rights, safety, security, and service integrity.

Data Retention

We retain account, workspace, integration, audit, and reporting data while the organization uses DR Flow and as needed for security, compliance, support, and legitimate business purposes. Users may request deletion as described in our Data Deletion Instructions.

Security

DR Flow uses access controls, organization scoping, audit logs, and encryption for provider credentials to help protect user and integration data. No transmission or storage system is perfectly secure, but we use reasonable technical and organizational safeguards to protect information.

Your Choices

Users may request access, correction, or deletion of applicable data by following the Data Deletion Instructions or contacting the support contact associated with their DR Flow workspace. Users may also revoke Meta access from their Meta account settings.

Contact

For privacy questions or data requests, use the support contact associated with your DR Flow workspace or the App Contact Email listed for DR Flow in the Meta App Dashboard.