Legal

Privacy Policy

Last updated: April 21, 2026

Rock Creek Performance Partners ("we," "us," or "our") operates the website at rockcreekperformancepartners.com. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. We keep this policy straightforward and only collect what is necessary to operate our business.


1. Information We Collect

Information You Provide Directly

When you submit the contact form on our website, we collect:

  • First and last name
  • Company name
  • Email address
  • Phone number (optional)
  • Company website URL (optional)
  • Inquiry type and message content

This information is used solely to respond to your inquiry and communicate with you about our services.

Information Collected Automatically

When you visit our website, our hosting provider (Vercel) automatically collects standard server log data, which may include your IP address, browser type, referring page, and the date and time of your visit. This data is used for security, performance monitoring, and bot protection purposes. We do not use this data to build advertising profiles or track you across other websites.


2. How We Use Your Information

We use the information we collect to:

  • Respond to your contact form submissions and inquiries
  • Schedule and conduct strategy sessions or consultations
  • Send follow-up communications related to your inquiry
  • Protect our website from spam and automated abuse
  • Comply with applicable legal obligations

We do not sell, rent, or share your personal information with third parties for marketing purposes.


3. Third-Party Services

We use the following third-party services to operate our website. Each has its own privacy practices:

Vercel (Hosting & Infrastructure)

Our website is hosted on Vercel. Vercel processes server logs and request metadata as part of normal hosting operations. Vercel also operates bot protection features that analyze browser signals to distinguish human visitors from automated bots. No personal data is collected by Vercel for advertising purposes. Vercel Privacy Policy →

Resend (Email Delivery)

When you submit our contact form, your submission data is transmitted to Resend, a transactional email service, to deliver your message to our inbox. Resend processes your data solely to deliver the email and does not use it for any other purpose. Resend Privacy Policy →

Google Fonts

Our website loads fonts from Google Fonts, which requires your browser to make a request to Google's servers. This may result in Google logging your IP address. We use Google Fonts solely for typographic presentation. Google Privacy Policy →

Calendly (Appointment Scheduling)

If you book a strategy session using the Calendly link on our site, you will be directed to Calendly's platform. Any information you provide during booking is governed by Calendly's own privacy policy. Calendly Privacy Policy →


4. Apps Platform & Social Media Integrations

In addition to our website, Rock Creek Performance Partners operates a subscription-based apps platform that provides AI-powered automation tools to business clients. Our apps — including Social Media Agent — enable clients to connect their own third-party accounts (such as Facebook Pages, Instagram business accounts, LinkedIn profiles, and X accounts) and use our platform to create, schedule, and publish content on those accounts on their behalf.

This section describes how we handle information accessed through those integrations. It applies to clients of our apps and to the end users of the social media platforms those clients connect.

4.1 Information Accessed Through Social Media Integrations

When a client connects a third-party account to our platform, we access only the information necessary to provide the requested service. Depending on the platform connected, this may include:

  • Account identifiers (e.g., Facebook Page ID, Instagram Business Account ID, LinkedIn Person URN, X account handle)
  • Account metadata (page or profile name, basic account information used to label connections in our user interface)
  • Posts and media we create (posts our platform publishes on behalf of the client and media assets the client uploads to support those posts)
  • Engagement metrics where the platform exposes them (likes, comments, shares, clicks), used solely to report performance back to the client
  • OAuth access tokens and refresh tokens issued by the third-party platform during the client's consent flow

We do not access private messages, friend lists, ad accounts, or any data beyond what is required to draft and publish content to the client's authorized accounts.

4.2 How We Use This Information

Information accessed through social media integrations is used solely to:

  • Draft platform-specific posts using the client's own brand guidelines and approved topics
  • Publish approved posts to the client's own authorized accounts
  • Report engagement and performance metrics back to the client in their dashboard
  • Maintain the connection — for example, refreshing access tokens before they expire

We do not use information from social media integrations for advertising, cross-client analytics, model training, or any purpose beyond operating the service for the specific client who authorized the connection.

4.3 How Data Is Stored and Secured

  • OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM encryption before being written to our database.
  • Access to stored data is limited to the server-side processes required to publish content on the client's behalf. Our staff do not routinely access client tokens or content.
  • All data is transmitted over HTTPS with TLS 1.2 or higher.
  • Tenant isolation is enforced at the database layer — each client organization can access only its own data.

4.4 Meta Platform Data (Facebook & Instagram)

When a client connects a Facebook Page or Instagram Business account, our use of data accessed from Meta's platforms complies with Meta's Platform Terms and Developer Policies. Specifically:

  • We access Meta data only with the client's explicit OAuth consent.
  • We use Meta data only for the purposes disclosed to the client — drafting and publishing content on their behalf.
  • We do not sell, license, or transfer Meta data to third parties.
  • We do not use Meta data to build cross-service profiles or advertising audiences.
  • We maintain appropriate technical and organizational measures to protect Meta data consistent with Meta's requirements.

4.5 Data Retention and Deletion

  • While a connection is active, we retain access tokens and minimal account metadata for as long as needed to provide the service.
  • When a client disconnects an account through our platform, we delete the stored access tokens and stop accessing that account.
  • When a client cancels their subscription or requests account deletion, we delete all stored client data within 30 days, subject to any legal retention obligations.
  • Posts and media we generate are stored for up to 90 days after publishing or rejection, then deleted from our storage. Posts already published remain on the client's own platform accounts until the client (or the platform) removes them.

4.6 Requesting Data Deletion

Clients — and end users whose data has been processed by our platform through a connected account — may request deletion of their data at any time by:

  • Disconnecting integrations from the client dashboard, or
  • Emailing us at privacy@rockcreekpartners.com, or
  • Submitting a request via our data deletion page at rockcreekpartners.com/data-deletion

If a Meta user removes our app from their connected apps in Facebook or Instagram settings, Meta will notify us via a deletion callback and we will delete all associated data within 30 days.

4.7 Sub-Processors

To operate the apps platform, we share limited data with the following sub-processors, each governed by their own privacy commitments:

  • Supabase — database and file storage (data encrypted at rest and in transit)
  • OpenAI — text and image generation; API calls are excluded from model training per OpenAI's API policy
  • Anthropic — text generation for content drafting; zero data retention configured
  • Vercel — application hosting and compute
  • Upstash — queued job processing and rate limiting
  • Clerk — authentication and identity
  • Resend — transactional email delivery
  • Stripe — subscription billing and payment processing

A current list of sub-processors is available on request at privacy@rockcreekpartners.com.


5. Cookies & Tracking

We do not use cookies for advertising, analytics, or cross-site tracking. Our website does not run Google Analytics, Meta Pixel, or any other behavioral tracking scripts.

Vercel's bot protection features may use browser-level signals (such as JavaScript execution and device characteristics) to classify visitors as human or automated. This analysis is performed for security purposes only and does not result in persistent tracking identifiers being stored on your device.


6. Data Retention

Contact form submissions are retained in our email inbox for as long as necessary to manage our business relationship with you. Server logs maintained by Vercel are subject to Vercel's own retention policies. If you wish to have your information removed, please contact us using the information below. Apps platform data retention is governed by Section 4.5 above.


7. Data Security

We implement reasonable technical and organizational measures to protect your information, including HTTPS encryption for all data in transit, server-side form validation, bot protection at the infrastructure level, and access controls on our systems. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.


8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request that we correct inaccurate or incomplete information
  • Deletion: Request that we delete your personal information
  • Objection: Object to our processing of your information
  • Portability: Request your data in a portable format

To exercise any of these rights, please contact us at the address below. We will respond within 30 days.


9. Children's Privacy

Our website is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will delete it.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after changes constitutes acceptance of the updated policy.


11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us: