Privacy Policy
How Adreporter collects, processes, stores, and protects personal data of users.
1. Data Controller
This Privacy Policy (hereinafter "Policy") explains how Ad Reporter (hereinafter "Company", "We", or "Adreporter") processes and protects the personal information of platform users.
Company: Ad Reporter Address: Tashkent, Uzbekistan Email: [email protected] Privacy Inquiries: [email protected]
2. Categories of Processed Data
In the course of providing our services, we may collect and process the following categories of data:
- Profile & Account Data: first name, last name, phone number (optional), email address, hashed password, role in company, interface language, and theme preferences, as well as workspace industry, website or social media profile, and monthly ad budget range;
- Advertising Analytics Data: Meta ad account IDs, campaigns, ad sets, ads, impressions, spend, clicks, and associated performance metrics;
- CRM Data: amoCRM deals, pipelines, stages, and customer contact data explicitly selected by the User for export (name, phone, email);
- Technical & Network Data: IP address, browser type and version, device parameters, access timestamps, and server log files.
3. Purposes and Legal Basis for Processing
We process personal data solely when there is a lawful basis and for specific purposes:
1. Performance of Contract: delivering Adreporter services, generating analytics reports, monitoring campaign KPIs, and routing conversions;
2. Legitimate Interests: safeguarding platform security, fraud prevention, troubleshooting technical issues, and enhancing service performance;
3. User Consent: connecting external accounts (Meta, Google, amoCRM) and receiving optional service updates.
4. Third-Party Service Providers and Sub-processors
To provide the services, we work with trusted third-party service providers who process data strictly under our instructions:
- Meta Platforms Ireland Ltd. — retrieving advertising metrics and synchronizing conversion events via Meta Marketing API and Conversions API (CAPI);
- amoCRM (Qsoft / amoCRM Inc.) — importing deals and sales funnel analytics;
- Google LLC — Google OAuth authorization and Google Sheets API synchronization for automated report exports;
- Hosting and Infrastructure Provider: Cloudflare Inc. and EU cloud hosting servers, server location: Germany and European Union (EU);
- Transactional Email Provider: SMTP & Transactional Email Services.
5. Special Provisions for Google User Data
Adreporter strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Under the Google Sheets integration, we request only the following scopes: https://www.googleapis.com/auth/drive.file, openid, email, and profile. Access is strictly limited to files created by or explicitly opened with AdReporter to automate marketing data exports. We do not request or use broad spreadsheets or full Google Drive access scopes.
Adreporter's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
These permissions are used solely to execute user-configured export jobs: writing and appending analytics rows to spreadsheets created or managed by AdReporter.
Our explicit guarantees: 1. We NEVER sell Google user data to any third party; 2. We do NOT use Google user data for advertising, targeting, or user profiling; 3. We do NOT use or transfer Google user data to train, develop, or improve artificial intelligence (AI) or machine learning (ML) models; 4. Google OAuth tokens are securely stored in our database encrypted using industry-standard AES-256-GCM encryption.
6. Data Retention Periods
User personal data and integration tokens are retained for the duration of an active account and subscription.
Upon account deletion, all personal identifiers, third-party credentials, and cached marketing data are purged from active databases within 30 days.
Tax and accounting records are retained in compliance with applicable statutory retention requirements for 5 years.
7. Data Security Measures
We employ state-of-the-art technical and organizational measures to safeguard data against unauthorized access, loss, alteration, or disclosure:
All incoming and outgoing connections are encrypted via TLS 1.3 / HTTPS. Sensitive secrets, API keys, and OAuth tokens are stored encrypted at rest using AES-256-GCM.
Platform access is enforced through multi-tier Role-Based Access Control (RBAC), and workspaces are logically isolated from one another.
8. User Rights
Users hold the following rights regarding their personal data:
1. Right to access and obtain a copy of their personal data; 2. Right to rectify inaccurate or incomplete personal information; 3. Right to request erasure of personal data ("Right to be Forgotten"); 4. Right to withdraw consent and disconnect integrations at any time.
You can exercise these rights via account profile settings or by contacting [email protected].
10. Privacy Contact Information
For any inquiries regarding this Privacy Policy or personal data processing, please contact our Data Protection Officer at:
Email: [email protected] Company: Ad Reporter Address: Tashkent, Uzbekistan