Introduction
Effective date: October 8, 2026.
This policy covers the "Nolimit Connect" Chrome extension and the Nolimit Connect app at https://ex.nolimitadsmanager.com (together, "Nolimit Connect"). Nolimit Connect is operated by Nolimit Core Technology, Vietnam ("Nolimit", "we"). Contact: privacy@nolimit.dev.
Nolimit Connect lets you manage your own Facebook advertising assets (ad accounts, Business Managers, Pages, Pixels, campaigns, billing and payment methods) using the Facebook account already signed in to your Chrome. It runs the checks and scheduled jobs you turn on and syncs the results to your Nolimit WorkSpace. You need a Nolimit account and API key to use it.
This policy is separate from the policy of our earlier extension at /privacy-extension.
Your consent comes first
When you install the extension it opens a consent page that lists the data below. Before you agree, the extension does not read your Facebook data, does not run background jobs and does not send anything to Nolimit.
You can withdraw consent at any time from the extension popup or the consent page. If the data we collect changes, the consent page opens again and asks you to agree again.
Data we collect
Sign-in and authentication data:
- Facebook session cookies and access tokens of the account signed in to this Chrome. Used to make the Facebook requests you start. After you consent, they are sent over HTTPS to your Nolimit WorkSpace so your scheduled jobs can run.
- Instagram session cookies. Used only on your device to check whether a linked Instagram account is active or suspended. Never sent to Nolimit.
- Your Nolimit API key. Stored on your device and sent to our server to identify your WorkSpace.
- 2FA codes. When Facebook asks for verification, Nolimit Connect shows the code from the 2FA key you saved in your WorkSpace. The code is sent only to Facebook.
- Your saved Facebook password, only if you saved one in your WorkSpace. Used only to confirm a Business Manager invitation with Facebook when the normal path fails. Sent only to Facebook.
Account and identity data:
- Facebook account name, ID, email, country and profile picture; Instagram username and ID; names of Business Manager admins.
Advertising data:
- Ad accounts, Business Managers, Pages and Page posts, Pixels, campaigns and their performance, and the ad account activity log, read from Facebook.
Financial and payment data:
- Ad account balance, spend, spending threshold, amount due and invoices.
- Payment methods on your ad accounts and Business Managers: card brand, last 4 digits, expiry date and cardholder name. Full card numbers are never synced.
- Card number and CVV you type when you use Add card. Sent directly to Facebook to add the card to your ad account. Nolimit does not store them.
Location data:
- Country, time zone and currency of your ad accounts and accounts. We do not collect GPS location.
Email content:
- If you use the Business Manager invitation tool, our server searches the mailboxes connected to your WorkSpace for Facebook's invitation email. Only the invitation link is returned to the extension.
We do not collect your browsing history. The extension reads the address of a tab only for the Facebook and Instagram windows it works with, at that moment, and does not store or send it.
How we use data
Only to show and manage your advertising assets in Nolimit Connect, carry out the actions you request, and run the checks and scheduled jobs you turn on.
We do not use your data for advertising, profiling, credit or lending decisions, or any purpose unrelated to this.
Who can read your data
Members of your WorkSpace see the data synced to that WorkSpace, according to the roles you give them.
Nolimit staff do not read your cookies, access tokens, 2FA keys or passwords, except when you explicitly ask us to (for example in a support request), when needed to investigate a security incident, or when the law requires it.
Storage, retention & deletion
- On your device: your consent choice, API key, connected account details and tokens, cached asset lists, job schedules and settings, in Chrome's extension storage. Removing the extension deletes them.
- On our servers (Malaysia, Indonesia and Vietnam): data is kept while your WorkSpace is active. Each sync replaces the previous Facebook session.
- Removing the extension does not delete data already on our servers. To delete it, email privacy@nolimit.dev from the email address of your Nolimit account. We delete it within 30 days and reply within 30 days.
Security
All data is sent over HTTPS. Saved passwords and 2FA keys are encrypted on our servers. Access to production systems is limited to the staff who operate them.
No system is completely secure. If a breach affects your data, we will notify you as the law requires.
Your rights
You can withdraw consent, and ask to access, correct or delete your data, by writing to privacy@nolimit.dev. After you withdraw consent, the extension stops sharing your Facebook session and your scheduled jobs stop.
You may also complain to the data protection authority in your country.
Nolimit Connect is for advertisers aged 18 or over. We do not knowingly collect data from children.
Chrome Web Store compliance (Limited Use)
Nolimit Connect's use and transfer of information it receives complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Nolimit is not affiliated with or endorsed by Meta Platforms. Facebook and Instagram are trademarks of Meta Platforms. Your use of Facebook remains subject to Facebook's terms.
Changes to this policy
If we change what data we collect or how we use it, we update this page and its effective date, and the extension asks for your consent again before the change applies.
Contact
Nolimit Core Technology, Vietnam. Email: privacy@nolimit.dev.
Questions about your data?
Email the Nolimit team about how Nolimit Connect handles your data, or to request deletion.