Boostly helps businesses in Mongolia run their Facebook and Instagram advertising from one dashboard. To do that we need access to parts of your Meta account. This policy explains exactly which parts, why each one is needed, how the data is protected, and how to take it all back.
1Who We Are
Boostly is operated by JKING HOLDINGS, #2116, Building 1/7, Dunjingarav Street, Zaisan /17020/, 11th Khoroo, Khan-Uul District, Ulaanbaatar, Mongolia. In this policy, "we" and "us" mean that company, and "you" means the person or business using Boostly.
We decide what data Boostly collects and why, which makes us the controller of that data. If you have a question about anything here, write to ceo@jkingholdings.llc — a person reads that address.
2Information We Collect
We collect four kinds of information, and nothing beyond what the features you use require.
- Account information
- Your name, email address and password. The password is stored only as a cryptographic hash, so nobody at Boostly can read it.
- Meta platform data
- When you connect your Facebook account, we read your Pages, the Instagram account linked to them, your ad accounts, your published posts, your audiences and your advertising results — through Meta’s official APIs and only with the permissions you approve.
- Technical information
- Device type, browser and basic interactions with the dashboard, used to keep the service working and to find faults. Our hosting provider also keeps short-lived request logs that include your IP address.
- Payment information
- The record of your subscription invoices: our invoice number, the plan, the amount in tugriks, the status, QPay’s invoice and transaction identifiers, and the dates. If you ask for a company e-receipt, the 7-digit tax register number you enter is stored on that invoice too. We never see or store card numbers, bank account numbers or banking credentials — the payment itself happens inside your own bank’s app. See “Paying for Boostly” below.
3Permissions We Request From Meta
When you connect your Facebook account, Meta asks you to approve a specific set of permissions. Each one exists for a feature you use. We request the following, and nothing else:
- The Facebook Pages you manage
- So you can choose which Page an ad runs under.
- Pages you manage strictly through a Business portfolio
- So those Pages appear in the list as well.
- Posts, photos and reels published by your Page
- So you can choose an existing post to promote.
- Your ad accounts, campaigns and audiences
- So Boostly can create and publish the ads you build, create and select audiences, and pause, resume or adjust an ad after it launches.
- Results for the ads you run
- So Boostly can show the performance of the specific ads you ran.
- The IG account linked to your FB Page
- So you can receive Instagram DMs for your click-to-message ads.
We request no other permissions. We do not ask for access to your personal Facebook profile, your friends, or your private messages. Facebook lists the exact permissions being requested on its approval screen before you connect, so you can see them for yourself.
You can review or withdraw these permissions at any time in Facebook under Settings → Business Integrations — the list of apps and websites connected to your account, which Facebook occasionally renames. Withdrawal takes effect immediately and stops Boostly from acting on your account.
4How We Use Your Information
We use your data to provide the features you came for: building and publishing ad campaigns, promoting posts you have already published, creating and choosing audiences, pausing, resuming or adjusting ads after they launch, and showing you what your advertising did.
We also use technical information to keep the service running, diagnose faults and protect accounts from misuse. We do not use Meta platform data for any purpose beyond the features you use.
The legal basis for this processing is your consent, given when you create an account and again when you connect your Meta account, together with the performance of our agreement with you. You may withdraw consent at any time by disconnecting Meta or deleting your account.
5What We Never Do
Some limits are worth stating plainly rather than leaving you to infer them.
- We never sell your data or your customers’ data.
- We never use Meta platform data to train models.
- We only run ads you created and launched in Boostly. Nothing is published on your behalf automatically — including scheduled campaigns, which start at the date and time you chose, on the budget you set.
- We never read your private messages or direct messages.
- We never process your advertising budget — Meta charges your ad account directly.
- We never see or store your card number, bank account number, PIN or banking password. Nothing of the kind is ever typed into Boostly, so there is nothing for us to lose.
- We never keep a card on file, and we hold no standing authority to charge you. Every payment is one you start yourself, in your own bank’s app.
Boostly does not currently upload or process customer contact lists. The audiences it creates are rule-based — Page engagement, website visitors, lookalikes — and are built inside Meta from data Meta already holds. If we add customer-list audiences in the future, we will update this policy and tell you before the feature is available to you.
6Cookies
Boostly sets cookies that keep you signed in and keep your session secure. These are necessary for the product to work — without them every page load would log you out — and we do not use advertising or tracking cookies, or third-party analytics.
Clearing them in your browser signs you out and has no other effect.
7Paying for Boostly
The Boostly subscription is paid through QPay, Mongolia’s shared payment network. You never enter card or bank details into Boostly. We create an invoice, QPay returns a QR code and a list of bank links, and you complete the payment inside your own banking app.
That detail matters more than it looks. The app you pay from is one your bank opened for you after the identity checks it is legally required to perform, so the person paying has already been verified by the bank — at no cost to you, and without Boostly collecting a single identity document. Authentication happens in that app, under your bank’s controls. None of it passes through us.
The consequence is that there is a whole category of sensitive data we simply do not hold. Card numbers, bank account numbers, CVV codes, PINs and banking passwords never reach Boostly’s servers, and we could not produce them if we were asked to. QPay and your bank handle those, each under its own regulatory obligations.
What stays with us is a record of the purchase, not of the payment method: our invoice number, the plan, the amount, the status, QPay’s identifiers and the dates. It shows what you bought. It says nothing about how you paid for it.
QPay publishes its own security standards, and they are worth knowing, because QPay is the party that actually touches your money. It has been certified against PCI DSS every year since 2020, audited by SISA Information Security, and holds ISO/IEC 27001:2022 certification issued through Moncertf LLC, accredited by the France-based Afnor group. It runs internal and external vulnerability assessments quarterly and must remediate what those find before it can be recertified. QPay’s full statement is published at qr.qpay.mn/privacy-and-security.
An e-receipt (и-баримт) is issued for every payment, as Mongolian law requires. Before the QR code appears we ask who the receipt is for. Choose a personal receipt and nothing identifying is sent — it is issued anonymously and still enters the lottery. Choose a company receipt and we ask for the 7-digit tax register number (ТТД), which is stored on that invoice and passed to QPay so the receipt can be issued in the company’s name. We ask at checkout because a receipt is issued against one specific payment and cannot afterwards be reissued to somebody else.
Your advertising budget is a separate matter and does not go through QPay at all. Meta charges your ad account directly, in US dollars, and Boostly never receives, holds or forwards that money. QPay is used only for the Boostly subscription itself.
8Storage & Security
Your data is held on managed cloud infrastructure, encrypted in transit with TLS and encrypted at rest. Access requires an authenticated session, and each account can reach only its own data.
The access tokens Meta issues when you connect your account receive extra protection: they are encrypted before being written to the database with a key held outside it, they are never sent to your browser, and they are used only to carry out actions you request. Revoking Boostly in Facebook under Settings → Business Integrations invalidates them immediately, whatever we hold.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority without undue delay.
9How Long We Keep It
Account and Meta platform data is kept while your account is active. If an account stays unused for 12 months, we delete it and everything attached to it.
Technical request logs are short-lived and kept only as long as our hosting provider retains them for operations and security.
Payment records are attached to your account and are erased with it. Two things outlive that, because they are not ours to erase: an e-receipt already issued to the tax authority, and QPay’s own record of the transaction. Each is kept for as long as their rules require.
One record survives deletion: when you delete your data we keep a row containing the confirmation code, the time and the outcome. Meta requires a status page for deletion requests, and that record is what it reads. It contains no Meta platform data and no advertising content.
10Deleting Your Data
There are three ways to remove your data. None of them require emailing anyone, and none of them wait on us.
- In Boostly
- In Boostly, Settings → Connections lets you disconnect Meta and erase the Meta data we hold for you. You receive a confirmation code straight away.
- In Facebook
- Removing BOOSTLY in Facebook under Settings → Business Integrations tells Meta to notify us, and our deletion endpoint erases your Meta data automatically. You do not need to contact us at all. (Leave the box “Send notification to BOOSTLY that you removed it” ticked — that notification is what reaches our servers. If you untick it, Meta tells us nothing and the data stays until you delete it in Boostly or email us.)
- Deleting the whole account
- Settings → Profile → Delete account removes your Boostly account itself, including your sign-in details, together with everything above. It happens immediately.
Every route gives you a confirmation code you can check at boostly.mn/data-delete. Deletion is permanent and cannot be undone; your ads, Pages and results stay in your own Meta account, which is unaffected.
If you would rather we did it for you, write to ceo@jkingholdings.llc and we will complete it within 30 days, usually much sooner.
11Companies That Process Data For Us
Running Boostly means a small number of providers necessarily handle some of your data. This is the current list; we update it as it changes, and each provider processes data under its own terms and privacy policy.
- Meta Platforms, Inc.
- The advertising platform itself — Facebook and Instagram. Your ads, Pages and results live here.
- Supabase
- Account sign-in and our database, where your Boostly account and your encrypted Meta access tokens are stored.
- Vercel
- Hosting. Serves the application and keeps short-lived request logs, which include IP addresses.
- QPay LLC
- Payment processing for Boostly subscriptions. QPay receives the amount, our invoice number and — only if you ask for a company e-receipt — the tax register number you enter. It receives none of your Meta data, none of your ads and none of your Boostly credentials. Your card and bank account details are handled by QPay and your own bank, and never pass through Boostly.
- CARTO
- Map images in the location picker, styled from OpenStreetMap data. Your browser requests the images from CARTO directly, so CARTO sees your IP address while that screen is open. It receives nothing from Meta — no account, Page or ad data — and it does not learn where you are: the map opens on Ulaanbaatar and moves only when you choose where your ad should run. OpenStreetMap itself receives nothing.
Most of these providers operate outside Mongolia, so using Boostly involves transferring your data abroad. QPay is the exception — it operates in Mongolia, and your payment data stays there. Beyond this list, we share your data with nobody, except where a Mongolian court or law requires it.
Being legally required is not the same as being asked. Before disclosing anything we check that the request is in writing, comes from a verifiable authority acting within its jurisdiction, cites a valid legal basis, and names specific data rather than asking us to go looking. We push back on requests that are unlawful, overbroad or improperly served. Where we do have to comply, we disclose only the minimum the request actually covers — never whole datasets, never unrelated users, and never your Meta access tokens as a convenience. Where the law permits it, we make reasonable efforts to tell you, so you can seek your own remedy.
12Your Rights
Under the Law of Mongolia on Personal Data Protection you may ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to delete it, and withdraw consent to our processing at any time.
Deletion and withdrawing consent you can do yourself, in Settings, and both take effect immediately — see “Deleting Your Data” above. Nothing about them waits on us.
For the other requests, write to ceo@jkingholdings.llc and we will answer within 30 days. If you believe we have handled your data improperly, you may also complain to the competent authority in Mongolia.
Exercising any of these rights costs nothing and will never affect your ability to use Boostly, except where deletion necessarily ends your account.
13Children
Boostly is a tool for businesses and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Ads created through Boostly may not target minors. Every ad carries a minimum age of 18, and Boostly applies that on its own side whatever age range is requested — so an ad aimed at a younger audience cannot be created here, whether by mistake or on purpose.
14Changes to This Policy
We may update this policy as Boostly changes. If a change materially affects how we handle your data — a new permission, a new provider, a new category of data — we will tell you in the app or by email before it takes effect, and update the date at the top of this page.
Continuing to use Boostly after a change takes effect means you accept the updated policy.
15Contact
Questions about this policy or your data: ceo@jkingholdings.llc.
To delete your data you do not need to write to us at all — Settings does it immediately.
If our contact address changes, we will update it here — this page is always the current one.
JKING HOLDINGS, #2116, Building 1/7, Dunjingarav Street, Zaisan /17020/, 11th Khoroo, Khan-Uul District, Ulaanbaatar, Mongolia.