Security at Digital Growth Studio

Protecting your advertising data, account information, and business information is a core part of Digital Growth Studio.

Digital Growth Studio is an AI-powered advertising optimization platform that connects with advertising platforms such as Meta to help businesses analyse campaign performance and make better advertising decisions. Because our platform can process sensitive business and advertising information, we use technical and organizational safeguards designed to protect your data.

1. Security by Design

Security is considered throughout the Digital Growth Studio platform, including:

  • Authentication and Session management
  • API access authorization protocols
  • Database encryption and isolated storage structures
  • Infrastructure firewall and routing controls
  • Real-time application security monitoring
  • Compliant data deletion mechanism

We follow the principle of providing users and internal services with only the access required to perform their intended functions.

2. Account Security

Digital Growth Studio uses secure authentication mechanisms to protect user accounts. Depending on the authentication method available, this may include secure session management, password protection through our authentication provider (Firebase Authentication), OAuth authorization tokens, and protection against unauthorized access.

We do not intentionally store your Meta account password.

3. Meta Account Security

When you connect a Meta advertising account, Digital Growth Studio uses Meta's official authorization system to obtain the permissions required for the functionality you choose to use.

Your Meta credentials are not provided directly to Digital Growth Studio.

YouMeta AuthorizationDigital Growth Studio

This allows Meta to control which permissions are granted to our application. The permissions requested depend on the specific features you choose to use.

4. Access Tokens

Digital Growth Studio may receive authorization tokens from Meta that allow our application to perform permitted API operations. These tokens are treated as sensitive credentials.

We take reasonable measures to:

  • Restrict access to authorization credentials
  • Prevent unauthorized exposure
  • Store credentials securely using database-level encryption
  • Avoid exposing credentials through the user interface
  • Use credentials only for authorized application functionality

Authorization credentials are not intentionally shared with other users.

5. Data Encryption

We use encryption and secure communication technologies designed to protect information during transmission. Communication between your browser and Digital Growth Studio is protected using HTTPS/TLS.

Sensitive information stored within our infrastructure is protected using appropriate security controls. The exact encryption mechanisms may vary depending on the infrastructure and service provider used.

6. Database Security

Digital Growth Studio uses controlled database infrastructure to store application and advertising-related information. Security controls may include authentication, access restrictions, network controls, granular database permissions, secure credentials, backup controls, and active system monitoring.

Database access is restricted to authorized services and personnel where necessary.

7. Infrastructure Security

Digital Growth Studio operates using controlled cloud/server infrastructure. Our infrastructure may include application servers, database instances, secure private networking, reverse proxies with SSL termination, firewall controls, monitoring, logging, and automated backup systems.

Infrastructure access is restricted and protected using authentication and authorization controls.

8. API Security

Digital Growth Studio communicates with third-party advertising platforms through authorized APIs. API requests are authenticated, authorized, limited according to granted permissions, associated with the appropriate user/account, and logged where appropriate for operational and security purposes.

We do not intentionally bypass platform security mechanisms or access advertising accounts without authorization.

9. Role-Based Access

Digital Growth Studio may use role-based access controls to limit what users and administrators can access. For example, access may be restricted according to user organization, ad account configurations, billing subscriptions, and specific application permissions.

A user should only be able to access advertising accounts that have been authorized and made available to their account.

10. AI Security

Digital Growth Studio uses AI to analyse advertising performance and generate recommendations. AI processing is designed around the advertising data necessary to provide the requested functionality.

AI recommendations may analyse campaign metrics, ad performance, historical trends, spend, conversion information, and account configurations. AI does not receive your Meta account password.

AI-generated recommendations do not automatically mean that a campaign will be modified. Where user approval is required, the user remains responsible for approving the recommended action.

11. Write Access Protection

Certain Digital Growth Studio functionality may allow approved recommendations to make changes to advertising accounts.

Performance analysis
AI recommendation & User review
User approved API execution

This architecture is designed to reduce unintended campaign modifications.

12. Monitoring and Logging

We may maintain technical logs to help us detect security issues, investigate errors, troubleshoot API failures, monitor system health, detect suspicious activity, and improve reliability. Logs are subject to appropriate access controls. We aim to avoid unnecessarily storing sensitive information in application logs.

13. Employee and Administrative Access

Access to production systems and sensitive information is limited to authorized personnel who require access for legitimate business or technical purposes. Where appropriate, administrative access may be protected through secure authentication, role-based permissions, restricted infrastructure access, and audit logging.

14. Third-Party Service Providers

Digital Growth Studio may use trusted third-party providers for services such as authentication, cloud hosting, payment processing, email delivery, error monitoring, and AI interface APIs.

Third-party providers may have their own security practices and policies. We aim to select service providers that provide appropriate security controls for the services they provide.

15. Data Deletion

Users may request deletion of their Digital Growth Studio data. Depending on the request, this may include account profiles, connected Meta integrations, cached advertising statistics, and dashboards.

For details, see our Data Deletion Instructions page.

16. Security Incident Response

If we become aware of a security incident affecting user information, we will investigate the incident and take reasonable steps to identify the issue, contain the event, assess potential impact, remediate the underlying issue, prevent recurrence, and notify affected users or authorities where required by law.

17. Responsible Disclosure

If you discover a potential security vulnerability in Digital Growth Studio, please contact our team immediately:

Vulnerability Reports: digitalgrowthstudioteam@gmail.com

Please provide a description of the vulnerability, steps to reproduce, potential impact, and screenshots where appropriate. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.

18. Important Disclaimer

No online service can guarantee absolute security. While Digital Growth Studio takes reasonable measures to protect information, no system, network, database, or internet transmission can be guaranteed to be completely secure.

Users should also maintain appropriate security practices, including protecting their login credentials and avoiding unauthorized sharing of account access.

19. Contact

For security-related questions or vulnerability reports:

Security: digitalgrowthstudioteam@gmail.com
Privacy: digitalgrowthstudioteam@gmail.com
Support: digitalgrowthstudioteam@gmail.com