Privacy Policy
How Tamamoto collects, uses and protects personal data — on tamamoto.agency and in our integrations with Meta platforms and advertising systems.
This Privacy Policy describes how Oleksandr O. Lebedko, a private entrepreneur registered in Ukraine (ФОП Лебедько Олександр Олексійович), trading as Tamamoto ("Tamamoto", "we"), collects, uses, stores and protects personal data.
It applies to the tamamoto.agency website and to Tamamoto's applications and integrations, including our app for Meta platforms, which connects to our clients' Facebook Pages, Instagram accounts and other business accounts.
For data collected on our own website we act as the data controller. For data we receive from a client's business assets — Facebook Pages, Instagram accounts, ad accounts and CRM systems — we act as a processor on that client's instructions, and the client remains the controller.
We process personal data in accordance with the Law of Ukraine "On Personal Data Protection" and, for data subjects in the European Union and the United Kingdom, with regard to the requirements of the GDPR.
We collect information you provide voluntarily when you fill in a form on our website:
- Full name
- Phone number
- Email address
- The message you write in the form
We use this information to respond to your enquiry, deliver our services and stay in touch with you.
Technical data is also collected automatically when you visit the site:
- IP address, browser and device type
- Pages viewed, visit time and referring source
- Cookie identifiers, advertising click identifiers (fbp, fbc, gclid, wbraid, gbraid) and UTM tags
Cookies are small text files stored on your device. We use them to keep the site working correctly, for analytics and to remember your preferences. The site runs Google Tag Manager, through which web analytics and advertising services such as Google Analytics and the Meta Pixel may be loaded. You can restrict or block cookies in your browser settings.
Tamamoto builds and operates an app that connects to our clients' business accounts on Meta platforms — Facebook Pages and Instagram accounts, and other Meta messaging channels such as WhatsApp Business where a client connects them. A connection is only made after the client has granted us the corresponding access in Meta Business.
When someone messages such a business account, we receive a webhook from Meta and may process:
- The person's identifier within that Page or account (PSID for Messenger, IGSID for Instagram)
- The Facebook Page ID or Instagram account ID
- The message identifier, timestamp and status
- The message content — the text and attachments the person sent to the business account
- Delivery, read and conversation-handover events between apps
We process this data in order to:
- Display the conversation to the client's authorised staff and to our own authorised staff in a working interface
- Send replies to messages on behalf of the client's business
- Record that an enquiry took place, in order to measure advertising performance — see "Conversion measurement" below
Our app operates as a Secondary Receiver under Meta's conversation handover protocol: the primary receiver is normally the client's own CRM system. We have no access to private correspondence in your personal accounts, and we do not read conversations that are not addressed to our clients' business accounts.
We do not sell conversation content, do not share it with third parties and do not use it for advertising targeting. Only conversation identifiers are sent onward to the Meta Conversions API — never message text or attachments.
Tamamoto's core service is measuring advertising performance. To do this we send event data (an enquiry, an order, a message to a business) to advertising platforms through server-side interfaces: the Meta Conversions API, the Google Ads Data Manager API and the Google Analytics 4 Measurement Protocol.
What we send to the Meta Conversions API:
- For messaging events — the Facebook Page ID or Instagram account ID, the person's identifier within that account (PSID or IGSID), and the event name and time. Message text is not sent
- For website and order events — email address, phone number, first and last name as an irreversible SHA-256 hash, together with the IP address, user agent and browser advertising identifiers (fbp, fbc), which Meta accepts only in unhashed form
Google Ads and Google Analytics 4 receive events with hashed email address and phone number, and with advertising click identifiers (gclid, wbraid, gbraid).
This data is used solely to attribute and optimise the client's advertising. We do not sell personal data, and we do not share it with anyone beyond the advertising platforms listed above, the client's CRM system and the cloud infrastructure required to deliver the service.
Under applicable data protection law you have the right to:
- Access your personal data
- Have inaccurate or incomplete data corrected
- Request deletion of your data
- Restrict or object to processing
- Withdraw consent you previously gave
- Lodge a complaint with a supervisory authority
To access your data or request its deletion, send a request to info@tamamoto.agency. So that we can locate your data, please state the channel and business account you used to contact the business (the Facebook Page, Instagram account or WhatsApp number) and, if possible, the approximate date of the conversation.
We review the request and respond within 30 calendar days. Where the data is processed on a client's instructions, we will forward your request to that client as the data controller and let you know that we have done so.
Data is stored in Google Cloud Platform. The projects that run our integrations are located in a European region (europe-west2, London). Some data is stored in cloud projects that belong to and are controlled by the client.
We apply technical and organisational security measures: inbound Meta webhooks are verified with a cryptographic signature (HMAC-SHA256), access to service accounts and tokens is restricted, and personal data is accessible only to authorised staff who need it to do their job.
We keep personal data for as long as it is needed for the purposes described in this Policy and to meet legal requirements. Data is deleted on your request in accordance with the "Your rights and data deletion" section above.
For any question about how we process personal data, and for access or deletion requests, contact us at:
We may amend this Policy. The current version is always available at this address, and the date it was last updated is shown below. We recommend reviewing this page from time to time.
Last updated: September 1, 2026