Privacy Policy
Last updated September 10, 2026
Glitchy Hub (“the Hub”) is an internal operations platform built and operated by Glitchy (“we”, “us”). It is used exclusively by Glitchy employees and contractors to run our affiliate marketing and media buying operations. It is not offered to the public, and accounts are created only by a Glitchy administrator. This policy explains what data the Hub processes, why, and how we protect it.
1. Who uses the Hub
Account managers, the offer team, leadership, administrators and the internal media buying team. Every user is a Glitchy staff member with a personal login. There are no consumer users.
2. Data we process
- Staff account data: name, work email, role, and a salted password hash. Used for sign-in and access control.
- Affiliate and advertiser business data: partner names, tracking-platform IDs, contact notes, outreach logs and performance figures imported from our tracking platform (TUNE).
- Campaign performance data: clicks, conversions, payouts and revenue per offer and per day, synced from our tracking platform and from our own finance spreadsheets.
- Advertising account data (TikTok Marketing API): when an authorised staff member connects a TikTok for Business ad account that Glitchy operates, the Hub stores the OAuth access and refresh tokens, the advertiser IDs returned by TikTok, and reporting data for those accounts (spend, impressions, clicks, conversions and cost metrics at account, campaign and ad level). We request read-only reporting permissions. The Hub does not create, edit, pause or delete ads, campaigns or audiences, and does not access any TikTok end-user or creator personal data.
- Creative assets: ad videos and images produced by our team, their descriptions and performance notes.
- Activity logs: who changed what and when, for accountability inside the team.
3. Why we process it
To operate our own marketing campaigns: track partner performance, manage offer caps, reconcile ad spend against revenue, review creatives and keep the team aligned. Advertising account data is used solely to display spend and performance of accounts we already manage alongside the revenue those campaigns generate. We do not use it for any other purpose.
4. Sharing
We do not sell, rent or share Hub data with third parties for their own purposes. Data is shared only with the infrastructure providers that host the Hub, acting as processors on our instructions:
- Railway (application hosting and PostgreSQL database)
- Cloudflare R2 (storage for creative files)
- Google Workspace (finance spreadsheets synced into the Hub)
- Anthropic (answers questions about our internal SOP documents; no advertising or partner data is sent)
TikTok data is never shared with anyone outside Glitchy and is never transferred to other advertising platforms.
5. Security
All traffic is encrypted with TLS. Passwords are stored as bcrypt hashes. Sessions are signed, validated against the database on every request and revoked immediately when an account is deactivated or a password changes. Access is role-based and enforced on the server: users only see the data their role requires. API tokens and secrets are stored only in the hosting provider's encrypted environment configuration, never in source code. The application is regularly security-reviewed.
6. Retention and deletion
- Staff accounts are deactivated when someone leaves Glitchy; their sessions are revoked immediately.
- TikTok access and refresh tokens are deleted when the connection is removed in the Hub or when access is revoked in TikTok Business Center. Reporting data is kept for as long as we need it for financial reconciliation, and deleted on request.
- Other business data is kept for the life of the business relationship and our accounting obligations.
7. Disconnecting a TikTok account
An authorised staff member can disconnect an ad account from the Hub at any time from the Media Buyers section, which deletes the stored tokens. Access can also be revoked from TikTok Business Center, after which the Hub can no longer read the account.
8. Cookies
The Hub uses two first-party cookies: a session cookie required for sign-in, and a theme preference cookie. No advertising or analytics cookies are used.
9. Contact
Questions about this policy or requests relating to data in the Hub: levi@glitchy.com.
10. Changes
We will update this page when the way the Hub handles data changes. The date above shows the latest revision.