Overview
This Policy describes how TLJ Tech Systems and Development, LLC handles information in connection with the TLJ Tracking application. The Application connects your Meta account (Facebook and Instagram) to your Bitrix24 account: when someone submits a Lead Ads form on one of your ads, the Application fetches that submission from Meta and creates the matching record in your CRM, along with campaign, ad set and ad attribution.
You — the owner of the Bitrix24 account and of the ad account — are the controller of the lead data. TLJ Apps acts as a processor: it handles that data on your behalf, following the configuration you set in the Application.
Data the Application Processes
| Data | Purpose | Retention |
|---|---|---|
| Lead form answers (name, e-mail, phone, company and any other question in your form) | Create the deal, contact and company in your Bitrix24 | In transit only. Not stored on our servers |
| Meta lead identifier (leadgen_id) | Prevent the same lead from creating two cards if Meta re-sends the event | No personal content — only the identifier and the created record number |
| Meta access tokens (user and pages) | Read your forms and fetch leads from your account | For as long as the connection exists; removed on disconnect |
| Bitrix24 access and refresh tokens | Write records into your CRM | For as long as the Application is installed |
| Campaign, ad set, ad, form and page identifiers | Attribute the lead source and build the UTMs in the CRM | Names are cached for up to 24 hours |
| Aggregated campaign metrics (spend, impressions, clicks, leads, currency) | Show cost per lead in the application and on the deal card | Cached for up to 3 days. Contains no personal data |
| Tracking code generated by the WhatsApp link (for example, TLJ-K7M2QX) | Connect the incoming conversation to the ad that produced the click | 30 days in the Application's storage, then discarded. Contains no personal data |
| Referral information Meta attaches to the first message, when the account uses the official WhatsApp Business connection | Attribute the campaign and the ad to the incoming conversation | 7 days, associated only with the number that started the conversation |
| Account domain, member_id and subscription status | Identify the installation and control access to the Application | For as long as the Application is installed |
Campaigns That Lead to WhatsApp
Ads that open a WhatsApp conversation carry no form, so the source has to be reconstructed another way. For those cases the Application offers a trackable link, which you use in the ad instead of the raw number. Every click gets a short code — something like TLJ-K7M2QX — and WhatsApp opens with that code already in the message the person is about to send. That code, and nothing beyond it, is what makes it possible to say which ad the conversation came from.
When that conversation becomes a record in your CRM, the Application looks up the Open Channel conversation linked to the record in Bitrix24 and reads its opening messages to find the code. Once the code is found, the campaign, ad set and ad are written onto the card exactly as they would be for a form. If your account uses the official WhatsApp Business connection, the Application also uses the referral information Meta attaches to the first message, which makes the code unnecessary.
This is the reason for the Open Channels (imopenlines) and Chat (im) permissions requested at installation. It is worth stating exactly what they do:
- Reading reaches only conversations linked to a CRM lead or deal, and only the opening messages of each — enough to locate the origin stamp.
- Message content is not stored by us. It is read, the code is extracted, and the text is discarded.
- The Application does not send messages, does not reply to customers and takes no part in the conversation.
- Conversations that did not come from an ad simply have no code: the Application finds nothing and writes nothing.
- The feature is optional. If you do not generate trackable links, this reading never happens.
Conversions Sent Back to Meta
If you enable this feature, when a deal reaches a stage you marked as won the Application reports that conversion to Meta through the Conversions API, so that the algorithm learns which ads generate real sales.
E-mail, phone and name never leave in plain text in that call: they are normalized and turned into a SHA-256 hash before leaving the Application, as required by Meta itself. A hash is one-way — the original value cannot be reconstructed from it.
Automatic Lead Analysis (Thermometer)
The Application offers an optional feature that rates each new lead as hot, warm or cold and records the reasoning as a comment on the card. The feature is OFF by default and only runs after a portal administrator turns it on in the configuration screen.
When enabled, the Application sends to Cloudflare's artificial intelligence model (Workers AI) only: the form answers that do not identify the person, the domain part of the email address, the campaign, ad set, ad and form names, the originating platform, and the ideal customer profile text you wrote.
- The lead's name, full email address and phone number are NOT sent to the model. From the email, only what comes after the @.
- According to Cloudflare's documentation, content sent to Workers AI is not used to train models or to improve Cloudflare or third-party services.
- The result — rating, score and reasoning — is written to your Bitrix24. We keep no copy of the analysis.
- The rating is a prioritisation suggestion produced by a statistical model that can be wrong. It decides nothing on its own and must not be used as the sole criterion to deny service to anyone.
- Turning the feature off stops the sending immediately. Analyses already written remain in your CRM, under your control.
What We Do Not Do
- We do not keep a lead database. Form answers pass through the Application and land in your Bitrix24.
- We do not sell, rent or transfer data to third parties.
- We do not use your data or your leads' data for our own advertising or for other customers.
- We do not access your CRM beyond what the integration requires: creating and updating records, reading pipelines, stages, fields and users to build the configuration screen and, when you use trackable links, reading the opening messages of the conversations linked to those records.
- We do not store WhatsApp conversation content, and we never send messages on your behalf or on your company's behalf.
- We do not use tracking cookies or third-party pixels in the Application screens.
Where Data Lives
The Application runs on Cloudflare's network (Cloudflare Workers) and uses Cloudflare's key-value storage to keep tokens and settings. Traffic is always encrypted in transit (HTTPS/TLS).
Third-Party Services
- Meta Platforms (Graph API and Marketing API): source of the leads and destination of the conversions.
- Bitrix24: destination of the records created by the Application.
- Cloudflare: hosting, storage and, when the lead thermometer is enabled, the artificial intelligence inference (Workers AI).
- Stripe: subscription payment processing. Card data is handled directly by Stripe — the Application never sees or stores it.
Your Rights
Because lead data lives in your Bitrix24, data subject requests for access, correction or deletion are fulfilled by you, directly in the CRM. For what is under our custody — tokens and settings — you may request deletion at any time at contato@tlj.net.br. The Brazilian LGPD (Law 13.709/2018) and, where applicable, the GDPR apply.
Data Deletion
Uninstalling the Application from your Bitrix24 account invalidates the tokens immediately. To also erase the settings and Meta tokens we hold, disconnect the Meta account in the Application screen or write to our contact — we respond within 30 days.
Security
All calls use HTTPS. Events received from Meta are verified by cryptographic signature before any processing, and Stripe events go through an equivalent check. Tokens are kept in restricted storage, reachable only by the Application itself. WhatsApp trackable links carry no personal data at all — only the link identifier and the click code — and the redirect is protected against abuse by a request rate limit.
Changes to This Policy
We may update this Policy to reflect changes in the Application or in applicable law. The update date at the top of this page indicates the current version.
Contact
Privacy questions: contato@tlj.net.br — TLJ Tech Systems and Development, LLC.
