Bifro Connect Bifro Connect
Dashboard Billing Settings
Free
Upgrade
Bifro Connect Bifro Connect
Dashboard Billing Settings Contact Us Terms & Conditions Privacy Policy Delete Account Data Deletion Security
Current Plan: Free
Upgrade Plan

Trust

Security & Data Handling

A plain-language description of how Bifro Connect protects account and Meta connection data, where responsibility is shared, and how to report a concern.

Encrypted Meta tokens No Facebook passwords stored Security contact: info@bifro.ca

On this page

Security model Authentication Encryption Application controls Operations Your role Report an issue

1. Security model

Bifro Connect is designed to reduce password sharing. Agencies and clients authenticate through Meta, review the requested access in Meta's interface, and keep their Facebook password and two-factor authentication codes with Meta.

Bifro stores the limited account, connection, asset, billing, and audit data needed to operate the service. Security controls are reviewed as the application changes, but no internet service can promise that incidents will never occur.

No certification claim: Bifro Tech Inc. does not currently claim SOC 2, ISO 27001, PCI DSS certification, or a Meta Business Partner designation. Payment-card processing is provided by Stripe.

2. Authentication and permissions

  • Agency and client Meta authentication occurs through Meta OAuth rather than a Bifro password form.
  • Bifro requests access needed for the selected ads or social-media workflow and does not request Instagram inbox or direct-message access for the current flow.
  • Sessions use HTTP-only cookies, SameSite protections, and secure cookies in HTTPS production environments.
  • State-changing application requests are protected with request checks designed to reduce cross-site request forgery.
  • Access can be revoked from Bifro or directly through Meta Business Settings.

Meta remains responsible for its authentication interface, account controls, permission review, and platform availability.

3. Encryption and sensitive data

Production traffic is sent over HTTPS. Meta access tokens stored by Bifro are encrypted at the application layer using authenticated AES-256-GCM encryption before being written to the database.

Encryption keys and service credentials are supplied through protected production environment configuration rather than embedded in public pages. Bifro does not store Facebook passwords, two-factor authentication codes, or complete payment-card numbers.

Stripe handles card entry and payment processing. Supabase provides the managed database infrastructure. More information about providers and cross-border processing is available in the Privacy Policy.

4. Application controls

Current application safeguards include:

  • input validation and controlled database queries;
  • security-focused HTTP headers and a content security policy;
  • rate limiting on sensitive and high-volume endpoints;
  • session expiration and server-side session storage;
  • structured audit records for important account, connection, billing, and administrative events;
  • restricted administrative access; and
  • dependency and automated test checks before release.

Specific controls may change as threats, providers, and the application evolve. Public detail is intentionally limited where disclosure could weaken a control.

5. Monitoring, response, and deletion

Bifro records operational and security events needed to investigate failures, suspicious activity, billing problems, and access changes. Alerts are used for important service failures, and administrative tooling provides visibility into account and connection status.

When a deletion request reaches final processing, Bifro removes stored tokens, sessions, account data, and connection metadata that are not legally required. Failed external revocations are retried or escalated rather than silently treated as complete. Retention periods are listed in the Privacy Policy.

If Bifro determines that a breach of security safeguards creates a real risk of significant harm, Bifro will investigate, notify affected individuals and regulators as required, and preserve the legally required breach record.

6. Shared responsibility

Agencies and clients also play an important role. We recommend that you:

  • enable multi-factor authentication on Meta and email accounts;
  • send approval links only through trusted channels and only to authorized business administrators;
  • request the minimum access needed and review active connections regularly;
  • remove former team members from Meta and Bifro promptly;
  • keep devices, browsers, and agency tools up to date; and
  • report an unexpected approval, login, or connection immediately.

7. Infrastructure providers

Bifro depends on reputable service providers including Meta, Supabase, Stripe, Render, and an email delivery provider. Each provider secures the systems it operates under its own terms and security program. Bifro configures and uses those services but cannot guarantee their availability or security.

8. Report a security concern

Email info@bifro.ca with the subject Security Report. Include a clear description, the affected URL or account, steps to reproduce, and your contact details. Do not include passwords, access tokens, private client data, or complete card information.

Please act in good faith, avoid accessing data that is not yours, and give us reasonable time to investigate before public disclosure.

Bifro Tech Inc.
Business Number 773892377 · Registry ID 18000166
34 Orwell Dr, Vaughan, ON L4H 4P7, Canada
Bifro Connect Bifro Connect

Your clients, connected in one click.

Operated by Bifro Tech Inc., an active Ontario business corporation.

Product

Dashboard Pricing Settings

Legal

Terms & Conditions Privacy Policy Delete Account Data Deletion Policy Security Contact Us

© 2026 Bifro Tech Inc. All rights reserved.

BN 773892377 · Registry ID 18000166 · 34 Orwell Dr, Vaughan, ON L4H 4P7, Canada · info@bifro.ca