Documents

Privacy Policy

Last updated October 6, 2026

This policy explains what data AdAce Ads at https://ads.adace.website processes, why, who receives it and how long it is kept. The data controller is FOP Verbovetskyi Mykhailo Ivanovych, doing business as Ad Ace Agency. The operator's representative is Mykhailo Verbovetskyi, founder.

The service helps advertising agencies and advertisers manage ads on Google Ads, Meta, LinkedIn, TikTok and Microsoft Advertising: it shows performance, checks website tracking, prepares change proposals and executes approved changes.

1. Account and sign-in

WhatWhy
Email address, namesign-up, sign-in, team invitations, service emails
Password hash; encrypted second-factor secret if enabledsign-in verification; the password itself is not stored
Technical session cookiekeeping you signed in; not an advertising cookie
Hashed IP address and email in an attempt counter (up to 10 minutes)protection against brute force and abuse
Activity log: who did what and whenaccountability for ad changes and security
Payment records: Stripe customer and subscription identifiers, plan, invoice and payment statuspaid plans; card details are entered on Stripe's page and never reach the service

The service has no visitor counters, advertising identifiers or third-party analytics.

2. Ad platform data (Google Ads, Meta, LinkedIn, TikTok, Microsoft Advertising)

An ad account is connected only through the platform's official consent screen; the service never asks for or receives ad account passwords.

WhatHow it is used
Platform access tokensstored encrypted; never written to logs or shown on screen
List of ad accounts, names, currency, time zoneso the user can choose accounts to work with
Campaigns, ad sets, ads, their texts and images, budgets, statuses, audience settingsdisplay, analysis and change proposals
Daily metrics, search terms, conversion actions, Meta pixel statusanalytics for the agency and its client, wasted-spend detection
Irreversible fingerprints of Meta and Google user identifiershandling Meta deauthorization and deletion requests; safe revocation of Google access; the identifiers themselves are not stored

Changes to ads. The service can change budgets and statuses of campaigns, ad sets and ads, add keywords and negative keywords, and create campaigns, ad sets and ads in a paused state. A change to existing ads starts as a proposal with a reason; it is executed by a human approver or — only if the workspace owner configured the client's policy that way — by the system within limits and for reversible actions only. New campaigns, ad sets and ads are created only paused, with no spend, and only by a workspace owner or admin (or the AI on their command); enabling them is again a proposal. Writes to live campaigns are enabled by the owner separately for each ad account. Every change is logged, and the state before and after the write is verified.

3. Google Analytics, Search Console, Tag Manager, Klaviyo and client websites

  • Google Analytics 4: list of properties; daily sessions, key events and revenue by source, medium and campaign. If the user granted edit access, the service creates a property, web stream, key event or Google Ads link on the user's command.
  • Search Console: list of sites; daily clicks, impressions and positions by query and page.
  • Klaviyo (read-only): account name, currency and time zone; email campaigns (name, status, send time) with aggregate metrics — recipients, delivered, opens, clicks, unsubscribes, orders and revenue. The service does not request or store individual recipient data (addresses, profiles, lists).
  • Tag Manager: reading the published container configuration; changes are prepared in a separate workspace and published only after the user confirms with their password.
  • Website audit: the service fetches public pages and tag scripts of websites whose addresses the user enters, to check tag installation.
  • Scripts for client websites: if a client puts the service's script on their website, a tap on "Telegram", "WhatsApp", a call or email link, or a form submission becomes a lead. Meta events (Conversions API) are only forwarded to Meta and are not stored. If the advertiser enabled feedback to Microsoft Advertising and the site has measurement consent, the script loads the Microsoft UET tag (bat.bing.com) and reports the lead to it; likewise the LinkedIn Insight Tag (snap.licdn.com) when feedback to LinkedIn is enabled. For a lead the service stores technical marks only: channel, page address without parameters and its language, UTM tags, Google (gclid, gbraid, wbraid), Meta (fbc, fbp), Microsoft (msclkid) and LinkedIn (li_fat_id) ad click marks, time and the status set by the advertiser. The service does not store names, phone numbers, email addresses, IP addresses or browser data; the IP address is used only for rate limiting, as a hash kept for 10 minutes.

4. Google API Services User Data Policy (Limited Use)

AdAce Ads's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data (Google Ads, Analytics, Search Console, Tag Manager) is used only to provide user-facing features the user sees and controls in the service: displaying and analyzing performance, checking tracking, proposing and executing approved changes. Google data is not sold, not used for advertising, not transferred to third parties except as necessary for these features (see section 6), not used to train artificial intelligence models, and not read by humans unless the user explicitly agreed, it is needed for security, or the law requires it.

5. AI analyst and AI clients

In-product AI analyst. If the AI analyst is enabled in a workspace, the user's question and the data needed to answer it (for example, campaign metrics) are sent to the model provider — Anthropic — only to generate the answer. The data is not used to train models.

Claude, ChatGPT, Cursor and other AI clients (MCP). A user may connect their own AI client to the service via OAuth or an API key, choosing the workspace and permissions. The data that client requests on the user's instruction is then sent to it under the user's account, and its further processing is governed by that client's terms. Access can be revoked at any time in the app under “Settings → AI clients”.

6. Who receives data

  • Advertising and analytics platforms (Google, Meta, LinkedIn, TikTok, Microsoft) — API requests on the user's behalf.
  • The server hosting provider; the email provider for service emails (sign-in, invitations, notifications).
  • Anthropic — only if the AI analyst is enabled (section 5).
  • Stripe — payment processing for paid plans (card, invoices, refunds).
  • AI clients the user connected (section 5); viewers of public dashboards if the user shared a link (links can be revoked).

Data is not sold and not used for advertising.

7. Retention and deletion

Data is kept while the account and the client relationship are active. Disconnecting an ad account erases the stored access tokens and asks the platform to revoke the permission; for Google this happens together with the last connection of the same Google account, so other connections keep working.

A Meta user can remove the app in Facebook settings or request data deletion: Meta notifies the service and the related data is erased automatically; a confirmation code is issued, and the request status is shown at https://ads.adace.website/privacy/meta/deletion. We delete your account, imported performance data and other related data on request to info@adace.website.

Ad account performance belongs to the advertiser: an individual's request does not erase a business's ad statistics — contact the advertiser for that.

Leads from client websites are deleted automatically after 90 days.

8. Security

HTTPS only. Access tokens are encrypted with a key stored separately from the database. Each workspace's and client's data is isolated at the database level; background processes run with separate, restricted permissions; actions are logged.

9. Your rights

You can ask what data about you is stored, request correction or deletion, restrict processing or withdraw the permissions you granted. Write to info@adace.website; we respond within 30 days.

10. Changes

If data processing changes, this text changes too and the date at the top is updated. The Ukrainian version prevails in case of discrepancies.