Privacy Policy
Effective date: 21 August 2026 · Mandala (runmandala.com)
Who we are
Mandala is a marketing analytics application operated at runmandala.com ("Mandala", "we"). It lets businesses view the performance of their own Meta advertising by connecting their Facebook account. Contact: anirudh.dev@runmandala.com.
Data we access
When you log in with Facebook and grant the requested permissions, Mandala accesses, through Meta's APIs:
- Your name and Facebook user ID (basic profile).
- The list of businesses you manage and their verification status
(
business_managementpermission). - The list of ad accounts you can access, and their advertising
performance metrics — spend, impressions, clicks, reach, CTR, CPM and
conversion metrics (
ads_readpermission).
How we use it
Solely to display your own advertising analytics back to you inside Mandala. We do not sell data, share it with third parties, use it for advertising, or use it for any purpose other than showing you your own dashboard.
Storage and retention
Mandala keeps no server-side database of your data. Ad performance data is fetched live from Meta's APIs each time you open the dashboard and is not retained after the response is rendered. Your access token is stored encrypted inside a signed session cookie in your own browser and expires with the session. Logging out, or using Disconnect, removes it immediately.
Data deletion
Because no data is stored server-side, deletion is immediate:
- In Mandala: click Disconnect in the dashboard — this revokes every permission you granted and clears your session.
- From Facebook: remove Mandala at
Settings & Privacy → Settings → Apps and Websites and send a
data deletion request. Our deletion callback confirms the request and
issues a confirmation code you can check at
runmandala.com/deletion-status. - By email: write to anirudh.dev@runmandala.com.
Requests from public authorities
If a public authority requests personal data about Mandala users, our policy is to: (1) review the legality of the request before responding, and seek legal counsel where appropriate; (2) challenge requests we consider unlawful; (3) disclose only the minimum information necessary to comply with a valid request; and (4) document each request, our response, the legal basis, and the parties involved. Note that Mandala stores no user data at rest — ad performance data is fetched live from Meta's APIs and not retained — which inherently limits what could be produced in response to any request.
Cookies
Mandala uses a single first-party session cookie, required for login. No analytics or tracking cookies are set.
Changes
If this policy changes, the effective date above is updated and the current version is always available at this URL.