1.What data we hold
Depending on how you use Outsource, we may hold:
- Account information — your name, email, role, company, and authentication details.
- Content you provide — briefs, comments, files, brand assets, and other materials you submit for marketing work.
- Integration tokens — encrypted OAuth tokens for connected platforms (e.g. LinkedIn, Meta), used solely to perform actions you initiate.
- Brand assets — logos, colours, guidelines, and reference materials you upload.
- Usage analytics — pages visited, actions taken, and device and browser information.
For the full picture, see our Privacy Policy.
2.How to request deletion
You have three ways to have your data deleted.
a) From within the app
If you have an account, write to us from the address on your account and we will delete it. A self-service Delete my account control is not available yet to trigger deletion of your personal data. Workspace owners can also close a workspace from Subscription → Deactivate, which schedules deletion of that workspace’s data.
b) By email
Email contact@thegoodpicture.com with the subject “Data deletion request”. Include the email address on your account and, if you connected a social platform (Facebook, Instagram, LinkedIn), mention which one so we can also revoke the stored tokens. We may ask you to confirm from the email address on file before acting, to prevent someone else deleting your data.
c) Disconnect an integration only
To remove only our access to a specific platform (without closing your account), go to Profile → Settings → Integrations and click Disconnect. This immediately deletes the stored access tokens for that platform.
3.Timeline
- In-app deletion — takes effect immediately. Personal data is removed from active systems the moment you confirm.
- Email requests — acknowledged within 5 business days and completed within 30 days of confirmation, in line with GDPR Article 12(3).
- Confirmation — once deletion is complete, we email a confirmation to the address on file.
- Backups — data may persist in encrypted, access-controlled backups for up to 90 days before being overwritten by our normal rotation.
4.What is retained after deletion
Even after your personal data is deleted, we are required by law or legitimate operational need to keep:
- Billing and invoicing records — retained for 7 years to comply with Kenyan tax law.
- Anonymised usage analytics — aggregated data that cannot be linked to you may be kept for platform improvement.
- Support tickets and correspondence — retained up to 12 months for reference and dispute resolution, then deleted.
- Audit and security logs — retained up to 2 years for security investigation and compliance.
None of the retained data can be used to re-identify you or to contact you for marketing purposes.
5.For Meta / Facebook users specifically
If you connected Outsource to Facebook or Instagram, you can revoke our access directly from Facebook:
- Go to Facebook → Settings → Business Integrations (facebook.com/settings/?tab=applications).
- Find “Outsource by TGP” in the list of connected apps.
- Click “Remove” — this immediately revokes the access token Facebook holds for us.
Once you revoke access on Facebook’s side, the tokens we stored become invalid. To also delete the associated data from our systems, send a deletion request by email as in section 2(b), mentioning that you removed the integration. As required by Meta’s Platform Terms, we process any resulting request within 30 days and confirm by email.
6.Contact
For any question about data deletion, or to check the status of a request, contact contact@thegoodpicture.com. The Good Picture — Nairobi, Kenya.