Privacy

Privacy Policy

How Site Factory handles information for its public website and its current client-authorised Facebook Page organic analytics service.

Effective date
14 August 2026
Last updated
14 August 2026

1. Who we are

Site Factory is operated by Graeme Wilson, a New Zealand sole trader trading as Site Factory.

18 Matangi Street, Hei Hei, Christchurch 8042, New Zealand

Privacy officer: Graeme Wilson

Email: privacy@graemewilson.nz

2. Scope of this policy

This policy covers the Site Factory public compliance website and Site Factory's current Meta integration for Facebook Page organic analytics provided to authorised client businesses in New Zealand.

It does not describe future Meta products or permissions that Site Factory has not implemented. If the service expands materially, this policy must be reviewed before that expanded processing goes live.

3. Information the public website collects

The public compliance website does not provide accounts or forms and does not intentionally use analytics, advertising pixels, social embeds or other marketing trackers. Normal hosting/CDN infrastructure may process ordinary request information needed to deliver and secure web pages, such as IP address, request time, requested URL and browser/network metadata.

4. Meta Platform Data and client-authorised analytics

When a client business authorises Site Factory's Meta integration, the current service accesses Facebook Page data needed to collect and report organic Page performance.

The approved v1 data inventory includes:

  • Facebook Page and post identifiers;
  • post message text, creation time, permalink and full-picture URL;
  • aggregate share and comment counts;
  • post media views and unique media viewers/reach;
  • post clicks; and
  • aggregate reaction counts by type used by the current reporting process.

The current collector does not retrieve or retain individual commenter identities, commenter profile details, individual comment text, or lists of the people who reacted to a post.

The connection flow performs an identity pre-flight request to Meta (`/me?fields=id,name`) to verify that the Meta Page access token resolves to the configured Facebook Page. The returned identifier and name are used solely for that validation check and are not retained as an analytics dataset or report output.

While the service does not target individual user profiles or commenter identities, public Facebook Page post content may incidentally contain personal information where an identifiable individual appears in or is referred to in authorised public Page content. Such information is processed strictly for the client's analytics and reporting purposes.

5. Why we process the data

Site Factory processes the authorised Meta data to:

  • verify and operate the authorised client connection;
  • collect Facebook Page organic post and insight data required for the client service;
  • prepare client-specific analytics and reports;
  • maintain data lineage and auditability for the analytics process; and
  • support correction, deletion and service troubleshooting.

Site Factory does not claim a right to sell the client's Meta data or use it for unrelated advertising or profiling.

6. How the data is handled

The current analytics process uses raw Meta response data, staged post-level records and curated/reporting outputs. These are associated with the relevant client and used to produce the agreed service output.

Site Factory primarily processes and stores client analytics data on infrastructure located in New Zealand. Applicable backup data is stored using CrashPlan in Australia. Cloudflare is used to deliver and protect the public Site Factory website and may process associated website connection and security data as part of providing that service.

7. Who receives information

Meta is the originating platform and source of the authorised Facebook Page data, not a Site Factory subprocessor. Site Factory processes the data for the relevant client business, and the client receives the resulting analytics and reporting output. Material service providers involved in delivering and supporting the service include Cloudflare (website delivery and security) and CrashPlan (backup storage in Australia).

8. Retention

During an active client service, Site Factory retains the client data needed to provide and support that service.

After service termination, clients have 5 working days to request an export of their data. After that period, deletion may proceed. Once initiated, deletion is targeted for completion within 48 hours.

A verified deletion request made through the process described in the Data Deletion Instructions is targeted for completion within 48 hours.

Deletion requests cover applicable live analytics data and applicable backup/archive data. Backup/archive treatment forms part of the verified deletion process. No separate lawful or operational retention exception currently applies.

9. Security safeguards

Site Factory separates live credentials from public website content, client configuration and source control, restricts access to credentials and operational analytics data, prevents secrets from being intentionally included in logs and reports, and applies controlled retention and deletion procedures to operational and backup data.

10. Access, correction and privacy requests

If Site Factory holds personal information about you that is covered by New Zealand privacy law, you may contact the privacy officer to ask for access or correction, or to raise another privacy concern. Site Factory may need enough information to identify the relevant client/connection and verify that the request relates to the correct person or authorised client representative.

Email privacy@graemewilson.nz.

11. Deletion and Meta disconnection

A client can revoke or disconnect Site Factory's Meta access through the applicable Meta business/app controls. Revocation stops future authorised collection through that connection; it does not by itself guarantee deletion of data already stored by Site Factory.

For stored-data deletion, follow the Data Deletion Instructions.

12. Overseas processing and disclosure

Site Factory's initial client scope is New Zealand-first. Site Factory primarily processes and stores client analytics data on infrastructure located in New Zealand. Applicable backup data is stored using CrashPlan in Australia. Cloudflare is used to deliver and protect the public Site Factory website and may process associated website connection and security data as part of providing that service.

13. Changes to this policy

Site Factory will update this policy when the Meta product/data scope, material processing practices, retention, business identity or applicable privacy obligations change. The current version will remain available at this stable URL with its effective and last-updated dates.