Privacy Policy for Adscriptly
Last Updated: July 14, 2026
Welcome to Adscriptly!
This Privacy Policy explains how Adscriptly ("we," "us," or "our") collects, uses, shares, and protects information when you use our AI-driven advertising optimization platform located at adscriptly.com ("Service" or "Platform").
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our practices, please do not use our Service.
1. INFORMATION WE COLLECT
1.1 Account Information
- Name and contact information
- Email address
- Company name and details
- Billing and payment information (processed securely through third-party payment processors)
- Account credentials and authentication data
1.2 Advertising Platform Data
When you connect your advertising accounts, we collect:
- Google Ads and Meta Ads account information
- Campaign performance metrics
- Ad spend and budget data
- Conversion tracking data
- Custom audience information
- Ad creative and targeting parameters
1.2.1 Meta (Facebook) Platform Data
When you use our Service, we collect and process the following data in connection with Meta's advertising platform:
- Meta Pixel data: We deploy Meta Pixel (Facebook Pixel) on adscriptly.com to track page views, site navigation, and conversion events (such as sign-ups and purchases) on our own website
- Meta Conversions API (CAPI) data: We upload offline conversion events from your connected CRM systems, call tracking platforms, and other business tools to Meta's Conversions API on your behalf, including hashed customer identifiers, conversion event types, conversion values, and event timestamps
- Custom Audiences: We create and manage Custom Audiences in your Meta Ads account using CRM segment data, customer lists, and conversion data you authorize
- Lookalike Audiences: We seed Lookalike Audiences using your highest-value customer segments to help Meta find similar potential customers
- Advanced Matching data: When enabled, we use hashed email addresses, phone numbers, and other contact identifiers to improve conversion attribution accuracy through Meta's Advanced Matching feature
1.3 Business System Integration Data
Through your authorized integrations, we collect:
CRM Data:
- Lead and contact information (with PII automatically redacted)
- Deal stages and pipeline status
- Customer interaction history
- Revenue and conversion data
Call Tracking Data:
- Call duration and metadata
- Call recordings and transcripts (with PII redaction)
- Caller ID information (hashed)
- Call quality metrics
Form Submission Data:
- Form responses and field data
- Submission timestamps
- Lead qualification information
- User intent signals
Communication Data:
- Meeting recordings and transcripts from Zoom, Google Meet, Microsoft Teams
- Calendar event data
- Email metadata for lead qualification
- Slack/Teams feedback data
- Contract and e-signature status
Analytics Data:
- Website behavior and engagement metrics
- User journey and conversion paths
- Attribution data
1.4 Automatically Collected Information
- IP addresses (for security and analytics)
- Browser type and version
- Device information
- Usage patterns and interaction data
- Cookies and similar tracking technologies
- Performance and error logs
2. HOW WE USE YOUR INFORMATION
2.1 Service Delivery
- Process and route quality signals between offline systems and ad platforms
- Power AI agents for campaign optimization
- Generate lead scores and customer lifetime value predictions
- Provide analytics and reporting dashboards
- Execute automated campaign adjustments
2.2 AI-Powered Features
- Natural Language Processing for call and meeting analysis
- Sentiment analysis and intent detection
- Pattern recognition for lead qualification
- Predictive modeling for CLTV estimation
- Automated PII detection and redaction
2.3 Account Management
- Authenticate users and manage access controls
- Process payments and billing
- Send service-related communications
- Provide customer support
2.4 Service Improvement
- Analyze usage patterns to improve features
- Conduct A/B testing and performance optimization
- Develop new AI models and capabilities
- Ensure platform security and reliability
2.5 Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contractual necessity: Processing required to deliver the Service you have subscribed to, including routing conversion data to ad platforms, AI-powered optimization, and analytics
- Consent: Processing of Meta Pixel tracking data, Advanced Matching data, and marketing communications, which you may withdraw at any time
- Legitimate interest: Processing for platform security, fraud prevention, service improvement, and internal analytics, balanced against your privacy rights
- Legal obligation: Processing required to comply with applicable laws, tax requirements, and regulatory obligations
3. DATA SECURITY AND PROTECTION
3.1 Encryption
- All data transmission uses TLS 1.3 encryption
- Data at rest is protected with AES-256 encryption
- Field-level encryption for highly sensitive data
- Secure key management using cloud-native KMS
3.2 PII Protection
- Automated PII detection and redaction engine
- Irreversible hashing of sensitive identifiers
- No storage of raw personal information from leads
- Data masking in non-production environments
3.3 Infrastructure Security
- Application hosted within secure Virtual Private Cloud (VPC)
- Regular vulnerability scanning and penetration testing
- DDoS protection and rate limiting
- Comprehensive audit logging of all security events
3.4 Access Controls
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA) support
- OAuth 2.0 for API integrations
- Regular access reviews and principle of least privilege
4. DATA SHARING AND THIRD PARTIES
4.1 Service Providers
We share data with carefully vetted service providers:
- Cloud infrastructure providers (AWS/GCP)
- Payment processors (Stripe)
- AI/ML services (OpenAI)
- Analytics providers
- Customer support tools
4.2 Integration Partners
Data is shared with platforms you explicitly connect:
- Google Ads (for offline conversion uploads and campaign optimization)
- Meta/Facebook Ads: We transmit the following data to Meta on your behalf:
(a) Offline conversion events via Meta's Conversions API (CAPI), including hashed customer identifiers, event type, event time, and conversion value
(b) Customer list data for Custom Audience creation and management
(c) High-value customer segments for Lookalike Audience seeding
(d) Meta Pixel data from adscriptly.com for our own advertising attribution
- Your connected CRM systems (Salesforce, HubSpot, Pipedrive, Zoho, Close, GoHighLevel)
- Call tracking providers (CallRail)
- Calendar and scheduling tools (Google Calendar, Calendly)
All data shared with Meta is processed in accordance with Meta's Developer Data Use Policy and Meta's Terms of Service. We do not use data obtained from Meta's APIs for any purpose other than providing and improving our Service as described in this Privacy Policy.
4.3 Legal Requirements
We may disclose information if required by:
- Court orders or legal process
- Government requests
- To protect our rights or safety
- To investigate fraud or security issues
4.4 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. DATA RETENTION AND DELETION
5.1 Configurable Retention
- You control data retention periods through platform settings
- Automated deletion based on your configured policies
- Different retention periods for different data types
5.2 Default Retention Periods
- Account data: Duration of service + 90 days
- Campaign performance data: 24 months
- Call recordings/transcripts: User-configured (default 6 months)
- Audit logs: 12 months
- Deleted account data: 30 days before permanent deletion
5.3 Data Deletion Rights
You can request deletion of your data through any of the following methods:
- Self-service: Navigate to Dashboard > Settings > Billing & Subscription and select "Cancel Account" to initiate deletion of all your data. Data is permanently deleted 30 days after cancellation takes effect, allowing you to reactivate if you change your mind.
- Immediate deletion: For same-day data deletion, cancel your account and email support@adscriptly.com with the subject line "Immediate Data Deletion Request."
- Email request: Send a deletion request to support@adscriptly.com and we will process it within 30 days.
Upon receiving a deletion request, we will:
(a) Delete your account data and personal information from our systems
(b) Request deletion of your data from connected third-party platforms, including Meta and Google Ads, where technically feasible
(c) Confirm completion of the deletion via email
(d) Retain only data required for legal or compliance purposes, which will be deleted when the retention obligation expires
For full details on data deletion, visit adscriptly.com/data-deletion.
6. YOUR PRIVACY RIGHTS
Depending on your location, you may have the following rights:
6.1 Access and Portability
- Request access to your personal information
- Receive your data in a structured, machine-readable format
6.2 Correction and Deletion
- Correct inaccurate personal information
- Request deletion of your personal information
6.3 Control and Consent
- Opt-out of certain data processing activities
- Withdraw consent for data processing
- Object to automated decision-making
6.4 Do Not Sell
- We do not sell personal information
- You can opt-out of any data sharing for advertising purposes
To exercise these rights, contact support@adscriptly.com
7. COOKIES AND TRACKING
7.1 Essential Cookies
- Authentication and security
- Load balancing and performance
- User preferences and settings
7.2 Analytics Cookies
- Usage patterns and feature adoption
- Error tracking and debugging
- Performance monitoring
7.3 Marketing Cookies
- Attribution tracking for our own marketing
- Conversion tracking for service improvement
You can manage cookie preferences through your browser settings or our cookie consent tool.
8. INTERNATIONAL DATA TRANSFERS
If you access our Service from outside the United States:
- Your data may be transferred to and processed in the United States
- We implement appropriate safeguards for international transfers
- Standard Contractual Clauses are in place where required
- You consent to such transfers by using our Service
9. COMPLIANCE AND CERTIFICATIONS
9.1 Regulatory Compliance
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- SOC 2 Type II certification (in progress)
- HIPAA assessment (if healthcare clients become a focus)
9.2 Industry Standards
- Privacy by Design principles
- Regular third-party security assessments
- Data Processing Agreements with all sub-processors
- Comprehensive vendor security reviews
9.3 Platform-Specific Compliance
- Meta Developer Data Use Policy: We comply with Meta's Developer Data Use Policy, Platform Terms, and Business Tools Terms. Data obtained through Meta's APIs and tools is used solely for providing our Service and is not sold, licensed, or shared with third parties except as required to deliver the Service. We promptly delete Meta-obtained data upon request or when it is no longer needed for the authorized purpose.
- Google API Services User Data Policy: We comply with Google API Services User Data Policy, including the Limited Use requirements.
10. CHILDREN'S PRIVACY
Our Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at support@adscriptly.com.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
Material changes will be notified via:
- Email notification to account holders
- In-platform notifications
- 30-day notice period before changes take effect
12. DATA PROTECTION OFFICER
For privacy-related inquiries, contact our Data Protection Officer:
Email: support@adscriptly.com
Address: 1100 South Lamar Blvd, Austin TX, 78704 USA
13. CONTACT US
For questions about this Privacy Policy or our privacy practices:
Email: support@adscriptly.com
Support: support@adscriptly.com
Address: 1100 South Lamar Blvd, Austin TX, 78704 USA
California residents may also contact us regarding their privacy rights under CCPA.
By using Adscriptly, you acknowledge that you have read and understood this Privacy Policy and agree to our data practices as described herein.Adscriptly Tracking Chrome extension
The extension has one purpose: collect privacy-bounded browser evidence for a conversion tracking audit that an authenticated Adscriptly user requested. It does not scan in the background. A check begins only for the active tab, after the user opens a bound audit and selects “Agree & check this page” in the side panel.
Data collected and transmitted
For the requested check, the extension processes the page origin; the Adscriptly workspace, audit, task, and selected integration context; tag and request-family presence, counts, and timing; event duplicate counts; consent, conversion-linker, same-origin navigation, and form state; and the presence of known click-ID key names, never their values, in the URL query, cookies, browser storage, and form field names. The scrubbed browser result is capped at 64 KiB.
The extension does not collect page or form text, field values, full URLs, query values, cookie or browser-storage values, request or response bodies, screenshots, general browsing history, passwords, payment information, or advertising-platform OAuth tokens. Browser presence evidence alone is not treated as proof of provider receipt or attribution.
Use, disclosure, and service providers
The extension sends its opaque session, bound audit identifiers, origin, operational failure codes, and scrubbed evidence only to the Adscriptly API over HTTPS. We use this information to authenticate the user, perform and display the requested audit, diagnose findings, support an Assistant handoff, and verify an authorized repair. The extension does not transmit browser evidence directly to Google Ads, Meta, or Google Tag Manager.
Adscriptly and its contracted cloud infrastructure and AI processing providers, including OpenAI, may process this bounded information solely to provide, secure, and support the requested audit. Connected Google Ads, Meta, and Google Tag Manager data is accessed separately by Adscriptly servers only through integrations the user authorized; Nango provides server-side OAuth token management. Providers are bound by confidentiality, security, and purpose limitations.
Retention, deletion, and user control
The opaque extension session expires after 15 minutes and is kept in Chrome session storage until expiration, sign-out, or the browser session ends. Bound browser evidence becomes part of the user's Adscriptly audit record. It follows the account-data default retention period above: the duration of the service plus 90 days, unless the user configures a shorter period or law requires a different period. Users can sign out to clear the extension session, disconnect integrations in Adscriptly, and request access or deletion through the methods in Section 5.3. Deletion requests include extension audit data unless retention is legally required.
Chrome Web Store Limited Use
Adscriptly Tracking's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only for the disclosed audit purpose and related security and support. It is not sold and is not used for personalized advertising, creditworthiness, or training generalized AI models. We do not permit human access except with the user's specific consent for support, for security or legal obligations, or for aggregated and anonymized internal operations as allowed by the policy.
Connected platform data
When you choose to connect Google Analytics 4, Google Tag Manager, Google Search Console, Meta Ads, or Slack, Adscriptly receives the account identifiers, profile or workspace details, configuration, and reporting data needed to provide the feature you requested. Depending on the product, this can include analytics properties and aggregate metrics, tag containers and configuration, Search Console properties and performance reports, ad accounts and campaign performance, or Slack workspace and installation details.
We use this data only to provide, secure, support, and improve the connected feature for your account. We do not sell connected-platform data, use it for generalized AI model training, or use it to target advertising unrelated to the service you requested.
Adscriptly uses Nango as an OAuth connection and token-management service provider. Platform access tokens are handled server-side and are not exposed in the Adscriptly browser interface. We may also use infrastructure and support providers under contractual confidentiality and security obligations.
Adscriptly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We retain connected-platform data only for as long as needed to provide the requested feature, meet legal obligations, resolve disputes, and maintain security. You can disconnect a provider in Adscriptly settings, revoke access with the provider, and request deletion using the process in our Data Deletion Instructions.
Slack integration
For Slack, we process workspace and installing-user identifiers, authorization metadata, text a user explicitly submits with /adscriptly, command responses, and notification content an authorized user chooses to send through Adscriptly. We do not request or retain broad Slack message history for either use case.
After a confirmed Slack uninstall or verified deletion request, we delete retained Slack customer data within 14 business days unless a longer period is required by law. Questions can be sent to support@adscriptly.com.