Data Deletion
Last updated: 24 September 2026
This page explains how to remove Hipereach's access to an advertising account, and how to ask us for a copy, a correction or the deletion of personal data we hold about you. In most cases one email is enough: write to hello@hipereach.com with the subject "Data deletion request", and the request is completed within 30 days.
1. Who this page is for
Four groups of people are likely to need this page:
- brand partners, and their staff, who gave us access to a TikTok or Meta ad account;
- visitors to hipereach.com;
- anyone who has emailed us, whether with a brief, a question or a partnership proposal;
- customers of our own brands, whose email address or phone number may have been added, in hashed form, to a custom audience on TikTok or Meta.
What we collect from each group, and why, is set out in the Privacy Policy. This page covers the other end: stopping that processing and removing the data.
2. Removing our access to an ad account
If your campaigns run in your own ad account, you can remove our access whenever you like, without asking us first and without giving a reason. Use the route that matches how access was given:
- in TikTok Business Center, remove Hipereach from your partners, or stop sharing the ad account with us;
- in Meta Business Manager, remove Hipereach as a partner on the ad account;
- if you approved our internal tools on the platform's own authorization page, remove that authorization in your TikTok for Business or Meta account settings, where connected apps and businesses are listed;
- or email hello@hipereach.com with the subject "Data deletion request" and the account name or ID, and we remove ourselves.
Within 24 hours of learning that access was removed, we delete the stored credentials that linked our tools to the account. From then on, no new data comes in from it. Campaign structure and reporting data already received is kept under the retention rules in the Privacy Policy, for up to 24 months after disconnection, to cover reconciliation, invoice queries and accounting. Then it is deleted. You can ask for earlier deletion. We agree unless a record is still needed for an open invoice or a legal obligation.
3. Requesting access, correction or deletion
To have personal data deleted, email hello@hipereach.com with the subject "Data deletion request". For a copy or a correction, "Privacy request" is the better subject, but both go to the same people, so neither gets missed. Whichever subject you use, please include:
- your name and the email address or phone number you used with us;
- how you know us: brand partner, website visitor, correspondent, or customer of one of our brands (and which brand, if you remember);
- what you are asking for: a copy, a correction, deletion, or removal from custom audiences;
- for an ad account, the platform and the account name or ID.
We ask for as little proof of identity as we can. A request from an address we already have on file is usually enough. Extra details are needed only when the request cannot be matched to our records, or when sending the data to the wrong person could cause harm. Please do not send a copy of an identity document unless we ask for one.
You will get an acknowledgment within two business days, and the request is completed within 30 days of receipt. There is no charge.
4. What we delete and what we keep
Deletion covers what we hold in our own systems: email correspondence, contact details, briefs and materials you sent, the credentials for any ad account you connected and, for a brand partner who asks, the campaign and reporting data from that account.
Some records have to stay. Invoices, signed agreements and the accounting records behind them are kept for as long as accounting and tax law require. For a former brand partner, that usually means the agreement, the monthly reconciliations and the invoices stay, while email threads, briefs and campaign materials are deleted. We may also keep what is needed to establish or defend a legal claim that is open or reasonably expected. After a deletion, a short note of the request itself remains (who asked, when, and what was done), so that we can show it was handled.
Data held by TikTok or Meta in their own systems, including the history of a brand partner's own ad account, is controlled by those companies and by the account owner. We cannot delete it for you, but we can tell you where to send that request.
5. Hashed entries in custom audiences
For our own brands, lists of customers who agreed to it may be uploaded to TikTok or Meta to build custom audiences. Email addresses and phone numbers are hashed with SHA-256 before upload, so the platform receives a coded string rather than the address itself, and the raw file is deleted within 7 days of upload. The platforms match the hashed values against their own users and report back only an approximate audience size. We never learn which people matched.
On request, your hashed entry is removed from every custom audience we control and from the lists used to refresh them. We treat the request as a withdrawal of your consent to this use, and keep your hashed identifier on a suppression list for one purpose only: making sure you are not uploaded again.
Customers of a brand partner should contact that brand first. The brand decides how its customer data is used, and we act only on its written instructions.
6. Website access logs
This website sets no cookies and runs no analytics. The only personal data it produces is the access log kept by our hosting provider: IP address, browser user agent, the page requested and the time. These logs exist for security and are deleted automatically after 30 days.
A log line cannot usually be tied to a named person, so we can only look for yours if you give us the IP address and the approximate time of your visit.
7. How we confirm completion
When a request is complete, we reply by email to the address it came from. The reply lists what was deleted, corrected or removed, anything we kept, the reason for keeping it and the date it will be deleted. A copy of your data, if you asked for one, comes as a PDF or CSV attachment.
For access removal, the confirmation also gives the date and time the account credentials were deleted.
8. If you are not satisfied
If you think a request was handled wrongly, reply to our confirmation and say what is missing. We will look at it again.
You also have the right to complain to a data protection supervisory authority (Article 77 GDPR), in particular in the EU country where you live, where you work or where you think the problem occurred, or in France, where Hipereach is registered. The French authority is the Commission nationale de l'informatique et des libertés (CNIL), at cnil.fr.
Your rights are described in full in the Privacy Policy. For anything else, the contact page lists how to reach us.