Meta Platform Terms (Section 4.f) Compliance

MetaAppDeauthorizationProtocol

Official deauthorization and permission revocation procedure for the LeadOne (OneConstruction) Facebook & Instagram integrations in compliance with Meta Platform Terms, Google Play Store Policies, and India DPDP Act 2023.

1. What Happens When You Remove LeadOne

When you remove the LeadOne app from your Facebook account, Meta notifies our server. We then turn off every Facebook page connection linked to your Facebook account and delete the access tokens we stored for it.

Tokens Deleted

The Page access tokens and Facebook user tokens we stored for your connections are deleted from our database.

Lead Sync Stopped

Your page connections are marked inactive. Without a stored token LeadOne cannot fetch new lead form answers from your Pages.

Reconnect Only by Choice

Nothing more is read from your Facebook account unless you connect a page again from LeadOne. Leads already delivered stay in your organisation’s workspace.

2. Step-by-Step Instructions to Deauthorize via Facebook

You can disconnect LeadOne at any time directly through your Facebook account settings. Follow either of the instructions below:

Option A: Via Facebook Desktop / Web Browser

  1. Log in to your Facebook account at facebook.com.
  2. Click your profile picture in the top-right corner and select Settings & privacy > Settings.
  3. In the left sidebar menu, click Apps and websites.
  4. Find LeadOne under your active apps.
  5. Click the Remove button next to the app.
  6. Confirm by clicking Remove. Facebook will automatically dispatch a real-time deauthorization notification to our server.

Option B: Via Facebook Mobile App (iOS / Android)

  1. Open the Facebook mobile app on your device.
  2. Tap the Menu tab (three lines or your profile avatar).
  3. Tap the Settings gear icon in the top right.
  4. Scroll down to the Permissions section and tap Apps and websites.
  5. Locate and tap LeadOne.
  6. Tap Remove and confirm your selection.

3. Automated Server-to-Server Callback (Technical Specification)

LeadOne provides the deauthorize callback described in Meta’s developer documentation:

Callback URL:https://www.oneconstruction.in/api/deauthorize

When you remove the app, Meta sends an HTTP POST with a signed payload (signed_request). Our server checks its HMAC-SHA256 signature with the app secret and rejects anything that does not match. For a valid request it reads the app-scoped user_id, marks that user’s page connections inactive and deletes their stored tokens. If the update fails, the server answers with an error so Meta retries.

4. Deauthorization vs. Permanent Data Deletion

Need Complete Data Purge?

Deauthorization stops new lead syncing and deletes the stored Facebook tokens. Leads already delivered belong to the builder’s organisation and stay in its workspace, where the builder can delete them. A data deletion request made through Facebook removes the page connection and tokens in the same way. For anything else, use our Data Deletion page:

Go to User Data Deletion Request Page

5. Contact Data Governance & Support

If you encounter any issues disconnecting your account or require confirmation of complete access revocation, our technical and compliance team is available:

Kiviro Labs & PropPulse Compliance Desk

Email: vedant@kivirolabs.com

Phone / WhatsApp: +91 97026 57702

SLA: Under 24 Business Hours