legal · last updated 27 May 2026
privacy.
Product: Noem (noem.llc)
Operator: Sitekik Marketers (sole proprietorship), Udyam/MSME-registered, A48c, A Block, Sector 27, Noida 201301, Uttar Pradesh, India
Contact: shik@sitekik.co.in | +91 99119 19480
Effective date: 27 May 2026
1. Introduction
This Privacy Policy describes how Sitekik Marketers ("Sitekik", "we", "us", "our"), the operator of Noem (the "Service", accessible at noem.llc), collects, uses, stores, shares, discloses, and protects personal data and business data when you ("you", "user", "data principal") access or use the Service.
Noem is an AI-assisted ad-diagnostics and ad-strategy platform that connects to your Meta (Facebook/Instagram) advertising account, analyses your campaign data, and delivers diagnostic verdicts, recoverable-spend identification, and daily WhatsApp briefs.
This policy is issued in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 ("DPDPA"), and, where applicable to non-Indian users, the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and Meta's Platform Terms and Developer Policies.
By accessing or using Noem, you confirm that you have read, understood, and consented to this Privacy Policy. If you do not agree, do not use the Service.
2. Who we are
Sitekik Marketers is a sole proprietorship registered under Udyam (MSME) in the Republic of India, owned and operated by Shikhar Bhardwaj. Noem is a product of Sitekik Marketers. For the purposes of the DPDPA, Sitekik Marketers is the Data Fiduciary. For the purposes of the GDPR, Sitekik Marketers is the Data Controller for data collected directly from users, and a Data Processor for advertising data retrieved on your authorisation from Meta.
The Grievance Officer / Data Protection Officer for the purposes of this policy is:
Shikhar Bhardwaj
Sitekik Marketers, A48c, A Block, Sector 27, Noida 201301, Uttar Pradesh, India
Email: shik@sitekik.co.in · Phone: +91 99119 19480
3. Scope
This Privacy Policy applies to:
- The Noem website (noem.llc and any subdomains, including www.noem.llc),
- The Noem web application and dashboard,
- The Noem WhatsApp delivery service,
- Any communications, support interactions, payments, and other touchpoints between you and Noem,
- Any personal or business data we receive about you from Meta on your authorisation,
- Any personal or business data we receive about you from our payment processor on your authorisation.
This policy does not apply to third-party services that integrate with Noem (Meta, WhatsApp, Cashfree, OpenAI, etc.). Their handling of your data is governed by their own privacy policies.
4. Definitions
- Personal Data — any data about an individual who is identifiable by or in relation to such data.
- Business Data — non-personal data relating to your business operations, including advertising performance metrics, campaign structures, and ad creative.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure, or erasure.
- Sensitive Personal Data — financial information, passwords, and any data designated sensitive under applicable law.
- Data Principal — the individual to whom personal data relates (you).
- Data Fiduciary — the entity that determines the purpose and means of processing (us).
- Meta Data — data obtained from the Meta Marketing API and Meta Login on your authorisation, including ad account structure, campaign performance, audience parameters, creative assets, and spend.
5. Categories of data we collect
5.1 Account and identity data
- Your mobile phone number (used as your primary account identifier).
- Your name, profile picture URL, first name, last name, and Meta user ID, as returned by Meta Login when you connect your Meta account.
- One-time passwords (OTPs) generated for verification (transient, not persisted in plaintext).
- Email address, if you provide one for support or invoicing.
5.2 Authorisation and token data
- Meta OAuth access tokens issued to Noem on your authorisation.
- Token scopes granted (e.g.,
ads_read,business_management,public_profile). - Token expiry timestamps and refresh metadata.
- The Meta ad account IDs you selected during onboarding.
5.3 Advertising data (received from Meta on your authorisation)
- Ad account structure: ad accounts, business managers, campaigns, ad sets, ads, creatives.
- Performance metrics: impressions, reach, frequency, clicks, CTR, CPM, CPC, conversions, ROAS, spend, CAC, video metrics, hook rate, thumbstop rate, and other Meta Marketing API fields we request.
- Audience parameters and saturation indicators.
- Creative metadata and asset URLs.
- Pixel and conversion API metadata where exposed by Meta.
- Time series of the above, retained for trend, fatigue, and delta analysis.
5.4 Service-generated data
- AI-generated diagnostic outputs: forensic verdicts, account health grades (A–F), grade rationales, morning brief narratives, today's-action recommendations, ranked diagnoses ("charges"), strategic priorities, unit-economics callouts, and positive-pattern flags.
- Recoverable-spend computations in INR.
- Chat transcripts with Shasha (the in-product assistant), up to the session message limit.
- Brief delivery logs (timestamps, channel, delivery status).
5.5 Payment data
- Plan selected (Trial ₹49 / Basic ₹499 / Pilot ₹2,499 / Studio ₹7,499).
- Cashfree order ID, payment ID, payment status, and timestamps.
- The phone number and (optionally) email used for the transaction.
- Invoice metadata.
We do not receive, store, or process your full card number, CVV, UPI PIN, or bank login credentials. These are handled exclusively by our payment processor, Cashfree Payments India Pvt. Ltd.
5.6 Communication data
- Your WhatsApp number (same as your account phone number) and a record of which briefs were dispatched, the channel provider's message ID, and delivery/read status.
- Inbound replies to Noem on WhatsApp, email, or support channels.
- Support ticket content.
5.7 Technical and device data
- IP address, approximate geolocation derived from IP, ISP, device type, OS, browser type and version, screen resolution, referrer URL, language preference, and timezone.
- Server logs, including request URLs, HTTP status codes, latency, and error traces.
- Cookies, local storage entries, and session identifiers (see Section 14).
5.8 Marketing and analytics data
- Pages visited, time on page, scroll depth, button clicks, form submissions, funnel position.
- UTM parameters and referral source.
- A/B test bucket assignments where applicable.
5.9 Data we do not collect
We do not knowingly collect: biometric data; government-issued ID numbers (Aadhaar, PAN, passport, etc.); caste, religion, political opinion, or trade-union membership; health, genetic, or sexual-orientation data; or data on individuals under 18. If we receive any such data inadvertently, we will delete it on becoming aware.
6. Sources of data
We collect data from: you directly (signup, OTP, payment, messages); Meta (when you authorise Noem via Meta Login, only the data covered by the scopes you approve); Cashfree (payment status, transaction metadata, checkout contact details); WhatsApp delivery providers (MSG91 / Gupshup or equivalent — message delivery callbacks); and automatic collection (cookies, logs, analytics tools, as described in Sections 5.7 and 14).
7. Purposes of processing
- Service delivery — to authenticate you, render your dashboard, generate diagnostic verdicts, compute recoverable spend, dispatch WhatsApp briefs at 07:00, 14:00, and 20:00 IST, and operate the Shasha assistant.
- AI processing — to send your advertising data (in part or in whole), de-identified where feasible, to large language model providers (OpenAI and/or Anthropic) for the generation of diagnostic outputs.
- Billing and fraud prevention — to process payments via Cashfree, generate invoices, verify transactions, and detect fraudulent or abusive activity.
- Communications — to send transactional messages (account creation, payment confirmation, brief delivery, support replies, security alerts) and, where you have explicitly opted in, product updates.
- Customer support — to respond to your queries, troubleshoot issues, and improve the Service.
- Security and integrity — to detect, prevent, and address technical issues, abuse, or violation of our Terms.
- Analytics and improvement — to understand how the Service is used and improve its features, copy, and reliability.
- Legal compliance — to comply with applicable Indian and foreign laws, court orders, lawful requests by public authorities, tax obligations, and Meta Platform Terms.
- Internal record-keeping — to maintain financial, tax, and dispute-resolution records as required by law.
We do not use your Meta-derived advertising data to train any generally-applicable AI model, sell it to third parties, or share it with any other Noem user or advertiser.
8. Legal basis for processing
Under DPDPA, GDPR, and equivalent regimes, we rely on: consent (for connecting your Meta account, dispatching WhatsApp briefs, processing through third-party LLMs); performance of a contract (to deliver the Service you have paid for); legal obligation (tax, anti-money-laundering, statutory requirements); legitimate interest (security, fraud prevention, analytics, internal record-keeping). You may withdraw your consent at any time (see Section 13). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
9. Sharing and disclosure
9.1 Service providers (Data Processors)
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Meta Platforms, Inc. | OAuth, advertising data source | OAuth callback parameters, requested scopes | USA / EU |
| Cashfree Payments India Pvt. Ltd. | Payment processing | Order amount, phone, email, payment metadata | India |
| OpenAI, L.L.C. and/or Anthropic PBC | LLM-based diagnostic generation | Aggregated and per-account advertising data needed for analysis | USA |
| MSG91 / Gupshup | WhatsApp brief delivery, OTP | Phone number, message content | India |
| Replit, Inc. | Application hosting and Postgres database | Application data at rest and in transit | USA |
| Email and support tooling providers | Customer communication | Email content, support metadata | India / USA |
Where any provider is located outside India, we rely on contractual safeguards (including Standard Contractual Clauses where required) and on the lawful-transfer provisions of the DPDPA.
9.2 Cashfree-specific disclosure
We use Cashfree Payments India Pvt. Ltd. as our exclusive payment processor. Payment instrument data (card numbers, UPI handles, net-banking credentials, CVV) is collected and processed by Cashfree on Cashfree's own infrastructure, under Cashfree's own privacy policy and PCI-DSS certification. Sitekik Marketers does not see, store, or have access to your full payment instrument data at any time.
9.3 Meta-specific disclosure
Data received from Meta is used only for the limited purposes for which you authorised access. We do not sell, license, or otherwise transfer Meta-derived data to any data broker or third party; use Meta-derived data for purposes incompatible with what you authorised; or retain Meta-derived data after you disconnect Meta or delete your account, except as required by Section 12.
9.4 Legal disclosure
We may disclose your data to comply with binding court / regulatory orders, respond to lawful law-enforcement requests, protect rights/property/safety, or enforce our Terms.
9.5 Business transfer
If Sitekik Marketers is involved in a merger, acquisition, asset sale, or similar transaction, your data may be transferred to the acquiring entity under the same terms of this Privacy Policy.
9.6 What we never do
We do not sell, trade, or rent your personal data; share your advertising data with other Noem users, agencies, or advertisers; or use your advertising data as training data for any general-purpose AI model.
10. International data transfers
Some of our service providers are based outside India (notably OpenAI, Anthropic, Meta, and Replit, which are based in the United States). By using Noem, you understand that your data may be transferred to, stored in, and processed in jurisdictions whose data-protection laws may differ from those of your country. We rely on contractual commitments, DPDPA cross-border transfer provisions, and GDPR transfer mechanisms where applicable.
11. Data security
We implement reasonable security practices and procedures: TLS encryption for all data in transit; encryption of access tokens and sensitive fields at rest; role-based access control; audit logging; regular review of access permissions; vetted third-party processors with industry certifications; network-level isolation of database and application layers; idempotent payment webhooks with signature verification.
No system is invulnerable. You are responsible for safeguarding your own device, your Meta credentials, and any OTPs sent to you. In the event of a personal-data breach likely to result in significant harm, we will notify the Data Protection Board of India and affected data principals in accordance with the DPDPA.
12. Data retention
| Data category | Retention period |
|---|---|
| Account identifiers (phone, name, Meta user ID) | Until account deletion, then deleted within 30 days |
| Meta OAuth tokens | Until you disconnect Meta or your token expires; revoked tokens deleted within 7 days |
| Meta advertising data (raw) | Up to 90 days from collection, then rolled into aggregated metrics |
| Aggregated diagnostic outputs | Up to 12 months, then deleted |
| Chat transcripts with Shasha | 60 days |
| WhatsApp delivery logs | 12 months |
| Payment records (transaction metadata) | 8 years from the financial year of the transaction (Indian tax law) |
| Invoice records | 8 years (Indian tax law) |
| Support tickets and email | 24 months from resolution |
| Server logs and security logs | 90 days, unless required for incident investigation |
| Marketing analytics | 24 months |
13. Your rights
Under the DPDPA, GDPR, and equivalent laws, you have rights to: information, access, correction, erasure (see our Data Deletion Policy), withdraw consent (you may disconnect your Meta account from inside Noem at any time), data portability, grievance redressal, nominate another individual, and against automated decision-making (Noem's outputs are advisory only).
To exercise any of these rights, email shik@sitekik.co.in. We will respond within 30 days.
14. Cookies and similar technologies
We use cookies, local storage, and similar technologies to keep you signed in, remember preferences, maintain session state, track analytics, and detect security anomalies. Categories: strictly necessary (authentication, CSRF, load balancing — cannot be disabled), functional (preferences), analytics (aggregated usage). You can configure your browser to refuse cookies, but parts of the Service may not function correctly without them.
15. Children
Noem is not intended for individuals under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact shik@sitekik.co.in.
16. Third-party links
Noem may contain links to third-party websites (e.g., Meta, Cashfree, sitekik.co.in). We are not responsible for the privacy practices of those sites.
17. AI processing and automated outputs
Noem uses large language models (currently OpenAI's GPT family and/or Anthropic's Claude family) to generate diagnostic verdicts, daily briefs, and chat responses. We have data-processing agreements prohibiting these providers from training their general-purpose models on your data. Noem's outputs are advisory and do not constitute financial, legal, accounting, or tax advice.
18. Marketing communications
Transactional messages cannot be opted out of while you have an active account. Product updates can be opted out by replying STOP. Marketing communications are sent only with your explicit opt-in.
19. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email, WhatsApp, or in-product notice at least 7 days before the change takes effect.
20. Grievance redressal
Shikhar Bhardwaj, Grievance Officer, Sitekik Marketers, A48c, A Block, Sector 27, Noida 201301, Uttar Pradesh, India. Email: shik@sitekik.co.in · Phone: +91 99119 19480. We acknowledge within 48 hours and resolve within 30 days. If unsatisfied, you may approach the Data Protection Board of India under the DPDPA.
21. Governing law and jurisdiction
This Privacy Policy is governed by the laws of the Republic of India. The courts at Gautam Buddh Nagar (Noida), Uttar Pradesh shall have exclusive jurisdiction, subject to Section 23 of our Terms and Conditions (arbitration).
22. Contact
Email: shik@sitekik.co.in · Phone: +91 99119 19480
Address: Sitekik Marketers, A48c, A Block, Sector 27, Noida 201301, Uttar Pradesh, India
Proudly built in Noida, India.