App Review consists of six components - verification, app settings, allowed usage, data handling, data protection, and reviewer instructions. An app will need to pass all these components to get access to the requested permissions and features. It is also possible for some permissions to be approved and not others. The details of your submission results are detailed on the request overview page. Below, you can find a breakdown of the different components of App Review.
In the verification section, Meta verifies that the organization associated with your app is a registered business. This part of App Review will ask you to select an organization to connect to your app. If your organization is not verified, you will need to submit Business Verification from the Business Suite.
The app settings section will require you to upload your app icon, your privacy policy URL, app category, and business email. You will also need to provide the platforms that your app will be available on (website, iOS store, etc.)
During the allowed usage section, you will be asked to certify that your app is using or will be using all advanced access permissions, features, and APIs within their allowed usage. You will be asked to describe how your app will use the data tied to the permissions requested and how it may enhance the user experience.
If your app is already verified in the business verification process, you may be prompted to complete data handling questions before providing your app testing instructions. Learn more about data handling questions here.
The data protection questions are designed to determine whether you comply with our Platform Terms relevant to your use of, sharing, and protecting Platform Data. These questions cover app purpose, data sharing, data deletion and data security requirements.
In this section, you will be asked to provide information to ensure that Meta can access the app and review its functionality. Examples of information may include: specifics on which locations your app is accessible, provision of test credentials and/or payment codes to enable app access.