Last updated: 27 July 2026
Privacy Policy
Blockwise (“Blockwise”, “we”, “us”) is a B2B real estate advertising workflow tool operated from Australia. Blockwise is operated by SHELLEY, STEVEN JOHN. This policy explains what personal data we collect, why we collect it, how we store and use it, and how you can request a copy or have it deleted. It applies to the Blockwise website and application at blockwise.sale.
1. Who this policy is for
Blockwise has two distinct user groups, and the data we hold for each differs:
- Real estate agents and agency staff who sign in to Blockwise to plan, approve, and review advertising campaigns.
- Members of the public who submit a Meta Lead Ad form created by a Blockwise customer (an agent). Blockwise processes that lead data on behalf of the agent so they can contact the prospective seller.
2. Data we collect from Blockwise customers (agents)
- Account profile: verified email address, preferred name when provided, optional phone number, timezone, workspace name, and role.
- Authentication metadata managed by Supabase, including magic-link or one-time-code verification.
- Workspace and advertising configuration: website, confirmed country, Brand Pack, target locations, ad copy and images you provide or approve, lead form questions, and lead destination preferences.
- Billing records: Stripe customer, Checkout, subscription, invoice, payment status, accepted offer, and cancellation references. Stripe processes your payment method; Blockwise does not store the full card number.
- Onboarding records: hosted booking identifier, booking status, scheduled time, and attendance status.
- Product analytics: server-confirmed activation and billing milestones, workspace, country, acquisition source, and small non-sensitive event facts. Funnel event rows do not store your email address, payment card data, or provider access tokens.
- Audit history of approvals, publishes, and configuration changes.
3. Data we access through the Meta Marketing API
When you connect a Meta Business ad account to Blockwise, we receive an OAuth access token from Meta with your consent. The token is encrypted at rest with AES-256-GCM using a key managed in our application secrets, and is only decrypted in memory at the moment a Meta API request is being made on your behalf. Using that token, Blockwise reads or writes the following Meta data:
- Ad account metadata (ID, currency, timezone) so we can show the agent which account they connected.
- Facebook Pages you administer (name, ID), so the agent can pick which Page will host the lead ads.
- Campaign, ad set, and ad objects we create on your account. These are created or changed only after the in-application approval required for that action. We do not publish or modify a campaign without that approval.
- Lead form submissions you have authorized us to retrieve from forms Blockwise created on your behalf — see Section 4 below.
- Insights data (impressions, reach, clicks, spend, leads) for campaigns Blockwise manages on your account, so we can show you live performance inside Blockwise Monitor.
We do not use Meta data for purposes other than running and reporting on the campaigns you have explicitly created in Blockwise. We do not sell or share Meta data with any third party other than the infrastructure providers listed in Section 6.
4. Data we collect from members of the public who submit a lead form
If you have submitted a Meta Lead Ad form created by a real estate agent who uses Blockwise, the agent has used Blockwise to fetch your submission from Meta and store it inside their Blockwise workspace. The fields stored depend on the form the agent built but typically include: name, phone number, email address, suburb, and any free-text answers you provided. Blockwise acts as a processor of this data on behalf of the agent (the controller).
If you wish to access, correct, or delete this data, you should contact the agent directly. You may also contact us at privacy@blockwise.sale and we will forward the request to the agent and, on confirmation, delete the data from our systems.
5. Retention
- Account and configuration data: retained while your Blockwise workspace is active.
- Cancelling a subscription does not delete the workspace. A separate workspace deletion request follows the deletion periods in Section 7.
- Billing acceptance, invoice, cancellation, security, and dispute records may be retained after workspace deletion where needed for accounting, legal, fraud-prevention, or dispute obligations.
- Meta access and refresh tokens: stored encrypted and rotated on Meta’s schedule; deleted within 30 days of you disconnecting the integration.
- Lead submissions: retained for 24 months by default and then anonymised, unless the agent deletes them sooner or you exercise your deletion right.
- Audit logs: retained for 24 months for security and dispute resolution.
6. Sub-processors
We use the following infrastructure providers, who are contractually bound to confidentiality:
- Vercel (application hosting)
- Supabase (authentication, application database, encrypted storage)
- Stripe (Checkout, payment methods, tax calculation, subscriptions, and receipts)
- Cal.com (hosted onboarding scheduling)
- Meta (connected business assets, campaign delivery, lead forms, and reporting)
- Model providers and gateways (large language model inference for ad copy generation)
- Cloudflare (egress filtering and model gateway)
7. Requesting Data Deletion
You have the right to request that we delete all data we hold from or about you. There are three ways to do this:
- If you are a Blockwise customer:open your workspace settings and click “Delete workspace”. This permanently removes your workspace, all configuration, all stored Meta tokens, and all stored lead submissions within 30 days.
- If you submitted a Meta Lead Ad form created by a Blockwise customer: email privacy@blockwise.salewith the subject “Delete my data” and tell us the agency or agent who ran the ad. We will route the request to the agent and delete the data from our systems within 30 days of confirmation.
- If you are a Facebook user who connected Blockwise:you can revoke Blockwise’s access from your Facebook account’s “Business Integrations” settings. Meta will notify Blockwise through our Data Deletion Callback (
/api/integrations/meta/data-deletion), and we will delete the associated data within 30 days and return a confirmation code that you can use to track the deletion at privacy@blockwise.sale.
Deletion requests are normally completed within 30 days. Some backup systems may retain a copy for up to 90 days before being permanently overwritten.
8. Security
All traffic to Blockwise uses HTTPS. Access tokens for third-party providers, including Meta, are encrypted at rest with AES-256-GCM. Production access is restricted to named personnel with two-factor authentication.
9. Contact
Privacy questions: privacy@blockwise.sale
General contact: hello@blockwise.sale
10. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be notified to active customers by email.