Privacy Policy

Effective date: 20 July 2026

This Privacy Policy describes how First Page Australia (“First Page”, “we”, “us”) collects, uses, stores, and discloses personal information in connection with FP Meta Hub (the “Platform”) — our internal operations platform used by our team to plan, produce, launch, and report on paid social advertising campaigns for our clients. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Information we collect

  • Team member information. Name, work email address, profile photo, professional bio, and role, collected when First Page team members sign in with their Google Workspace account and complete their specialist profile.
  • Client business information. Business details our clients provide during onboarding: company information, brand assets, marketing objectives, target-audience descriptions, contact names and email addresses of client representatives, and campaign approval records.
  • Advertising account data.Campaign structures, budgets, creative assets, and aggregated performance metrics accessed from Meta (Facebook/Instagram) advertising accounts that clients have authorised us to manage, via Meta’s Marketing API. We do not collect personal information about individuals who see or interact with advertisements.
  • Usage and audit records. Actions performed in the Platform (who did what, and when) are logged for security, quality assurance, and accountability.

Google user data

The Platform uses Google Sign-In to authenticate First Page team members. We access only basic profile information (name, email address, profile picture) to create and secure the team member’s account. The Platform’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow humans to read it except with consent, for security purposes, or as required by law.

Meta platform data

Where clients grant our Business Manager access to their Meta advertising assets, we access campaign, creative, and performance data solely to provide the advertising services those clients have engaged us for. Access tokens are encrypted at rest. Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies. We do not use this data for any purpose other than serving the relevant client, and we do not combine it across clients.

How we use information

  • To operate the Platform and deliver paid social advertising services to clients.
  • To prepare media plans, creative briefs, advertising creatives, and reports.
  • To identify our team members to clients on client-facing documents.
  • To secure the Platform, maintain audit trails, and meet legal obligations.

We use third-party AI services to assist in drafting documents and analysing campaign performance. Inputs to these services are limited to the business information needed for the task, are screened to remove credentials and secrets, and are not used by us to train AI models.

Disclosure

We do not sell personal information. We disclose information only to: (a) the client to whom the information relates (for example, reports and approval records); (b) service providers who host and process data on our behalf (cloud hosting, database, file storage, background-job, email, and AI processing providers), under obligations of confidentiality; and (c) where required by law. Some service providers may store data outside Australia; where they do, we take reasonable steps to ensure comparable protections apply.

Security

Access to the Platform is restricted to authorised First Page team members via Google single sign-on with domain allow-listing and role-based permissions. Advertising API tokens are encrypted at rest. Client-facing links use unguessable tokens and can be revoked. All material actions are audit-logged.

Retention

We retain information for as long as needed to provide services to the relevant client and to meet our legal and contractual obligations, after which it is deleted or de-identified.

Access, correction, and complaints

You may request access to or correction of personal information we hold about you, or make a privacy complaint, by contacting us at [email protected]. We will respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

Changes to this policy

We may update this policy from time to time. The current version will always be available at this page, with its effective date shown above.