Privacy policy
ClyBear is operated by CC Company, Morocco ("we", "us"). This policy explains what data we process when you use ClyBear (order, inventory and customer management) and Dashmore by ClyBear (advertising analytics and campaign management).
1. Data we collect
- Account data: name, email, password (stored as a salted hash) and workspace settings.
- Store and order data that you import or sync from your stores (for example YouCan, Shopify, WooCommerce): orders, products, prices, costs, delivery statuses and the customer contact details needed to process your orders.
- Advertising data from ad accounts you choose to connect through official APIs (TikTok API for Business, Meta Marketing API, Google Ads API): ad account names and IDs, currency, campaigns, ad groups, ads and their performance metrics (spend, impressions, clicks, conversions).
- Technical data: IP address and browser information for security, sessions and logs.
2. How we use data
- To provide the service you requested: dashboards, reports, profit calculations, alerts and campaign actions you confirm.
- To secure the service and prevent abuse (rate limits, audit log).
- We do not sell personal or advertising data and we do not use it for advertising profiles.
3. Advertising platform data (TikTok, Meta, Google)
Access to an ad account is granted by the advertiser through the platform's official authorization screen and can be revoked at any time from the platform settings or from Dashmore (Integrations → Disconnect). Data received from these platforms is used only to show reports and perform actions for that same advertiser inside their workspace. It is not shared with other users or third parties, except the infrastructure providers listed below acting on our behalf. Access tokens are encrypted (AES-256) on our servers and are never exposed in the browser.
4. AI assistant
When you use the AI assistant, the question and the minimum data needed to answer it (for example aggregated campaign metrics) are sent to the AI provider configured for your workspace (Google Gemini or Anthropic Claude) to generate the answer. Actions proposed by the assistant are only executed after your explicit confirmation.
5. Service providers
- Hosting: DigitalOcean (servers).
- AI processing: Google (Gemini API) and/or Anthropic (Claude API), only when the assistant is used.
- The advertising and store platforms you connect, under their own terms.
6. Retention and deletion
We keep data while your workspace is active. When you disconnect an integration, its stored credentials are deleted immediately. You can request deletion of your workspace data at any time — see Data deletion. Deletion requests are completed within 30 days.
7. Security
HTTPS everywhere, hashed passwords, encrypted platform tokens, role-based access, rate limiting and an activity log of every change.
8. Your rights
You can access, correct, export or delete your data, and withdraw any platform authorization. Moroccan Law 09-08 on the protection of personal data applies.
9. Contact
Email: contactus@clybear.com
ClyBear