Legal
Privacy Policy
How we collect, use, and share information across the website and Service.
- Last Updated:
- September 21, 2026
This Privacy Policy explains how Ad Spend Technologies, Inc. (“Ad Spend,” “we,” “us,” or “our”) collects, uses, discloses, and protects information through our websites, software, applications, and related professional and managed services (the “Service”). Our Terms of Service, applicable Orders and Master Services Agreements, and Data Processing Agreement govern the contractual relationship without limiting mandatory privacy rights.
Who we are and our roles
Ad Spend Technologies, Inc. is a Delaware corporation with a mailing address at 1460 Broadway, New York, NY 10036, USA. Contact support@theadspend.com for privacy matters, legal notices, or security concerns.
We act as controller of information used for our own business administration, including website, account-contact, and billing information. We act as processor, service provider, or subprocessor for information we process on a customer's documented lawful instructions, including information from connected accounts (“Customer Data”). Personal data within Customer Data is “Customer Personal Data.”
When an agency or another customer provides your information, that organization or its underlying client generally determines how the information is used. Direct requests to the organization responsible for the account, or contact us for help routing your request. We will assist as required by law and the Data Processing Agreement.
Information we collect
We collect information directly from users, automatically through use of the Service, from systems customers authorize, and from service providers and business contacts.
- Account and business information: Names, business email addresses, company details, roles, credentials, preferences, and account-administration information.
- Billing information: Billing contacts, addresses, plan and invoice details, transaction status, and limited payment-method metadata. Our payment processor handles full payment credentials.
- Communications and submitted content: Support requests, correspondence, feedback, prompts, uploads, and content you provide in connection with the Service.
- Usage and device information: IP address, browser and device characteristics, approximate location derived from IP address, timestamps, session and diagnostic information, and security logs.
- Connected System information: Data described below that you or an Authorized User authorizes us to access.
We do not request sensitive or special-category personal data for ordinary use. Customers must not intentionally submit government identifiers, health information, precise geolocation, or similarly sensitive information unless expressly agreed. Information incidentally contained in authorized files, messages, or other content remains subject to applicable restrictions and is not authorized for unrelated uses.
Connected Systems and authorized actions
“Connected Systems” are supported third-party accounts and systems that customers choose to connect. Connection screens identify the provider, requested permissions, and user-facing purpose. Connecting one account does not authorize access to unrelated accounts or services.
Depending on the enabled feature and permissions, we access account and user identifiers; campaign, audience, spend, performance, and measurement data; tags and configurations; and content and associated metadata you submit or authorize for that feature. We disclose additional data categories and purposes before requesting new access.
We use this information to retrieve and display requested content, provide analysis and assistance, and perform customer-authorized workflows. Authorized write actions may include creating, editing, sending, publishing, pausing, or deleting records or settings. The actions depend on the enabled feature and authorization; technical access does not by itself authorize every possible action.
Customers and Authorized Users must obtain required permissions and provide required notices, including to underlying clients, before connecting accounts. We may rely on their authority representations unless we know or reasonably suspect access is unauthorized, and may suspend questionable connections. Nothing in this Policy authorizes access without permission or removes our own legal obligations.
You can revoke access through the Service or the provider's account-permission controls. Revocation stops future authorized access but does not automatically delete information already retained. Contact support@theadspend.com to request deletion.
How we use information
We use information to provide, maintain, secure, and support the Service; authenticate users; execute authorized instructions; perform purchased professional services; resolve errors and abuse; communicate with users; administer billing; comply with law; and establish or defend legal claims.
We use business-contact information for service communications and, where permitted, marketing communications. You can opt out of promotional emails using the unsubscribe mechanism or by contacting us; necessary service and billing messages may continue.
We may use de-identified operational telemetry to improve reliability and performance. This does not permit repurposing customer account contents, campaign data, files, messages, or confidential business information for another customer. We do not attempt to re-identify data we maintain as de-identified, except as permitted by law to test de-identification safeguards.
Where an enabled feature uses automated or AI processing, relevant content may be processed by contracted providers solely to deliver that feature under applicable confidentiality, processing, and platform restrictions. We do not authorize those providers to use Customer Data for independent purposes.
Uses we prohibit
We do not sell personal information or Customer Data. We do not share personal information for cross-context behavioral advertising, use one customer's Connected System Data to serve another customer, or use Customer Data to train generalized AI models or authorize our providers to do so.
These restrictions apply notwithstanding general references to improvement, analytics, or de-identification elsewhere in our agreements. Applicable platform restrictions continue to apply to aggregated, anonymized, or derived data.
Legal bases
For information we process as controller, applicable legal bases may include performance of a contract with the individual; legitimate interests in operating and securing a B2B service and managing business relationships, balanced against individual rights; compliance with legal obligations; and consent where required. For Customer Personal Data processed on instructions, the responsible controller determines the lawful basis.
A technical OAuth authorization does not necessarily constitute every consent or lawful basis required by privacy law. Where consent is required, withdrawal does not affect the lawfulness of processing before withdrawal.
Disclosures
We disclose information only as described here and subject to applicable restrictions.
- Contracted providers: Providers of hosting, storage, connectivity, communications, support, security, analytics, and enabled processing features, subject to appropriate confidentiality and processing obligations.
- Customers and their permitted users: Information available within the customer's account and authorized workflows. Customers control whom they invite or authorize.
- Connected System providers and directed recipients: Information transmitted when performing an authorized action or at the customer's direction.
- Professional advisers: Lawyers, accountants, insurers, and similar advisers under appropriate confidentiality duties.
- Legal and security recipients: Authorities or other recipients where disclosure is legally required or reasonably necessary to protect rights, investigate misuse, or address security, subject to applicable law and platform restrictions.
- Business transfers: Limited information may be disclosed for due diligence under confidentiality safeguards or transferred with our business in a merger, acquisition, reorganization, or asset sale. A successor must assume applicable privacy and contractual obligations. These disclosures remain subject to law, the DPA, platform restrictions, and any required prior notices or consent.
We do not disclose Customer Data to other customers. Affiliates and professional-services contractors may access it only to perform authorized services under applicable restrictions, not for independent commercial use.
Details of subprocessors and processing locations are available through the Subprocessor Information page. Payment processors may act as independent controllers for their own payment, fraud-prevention, and compliance functions.
Google API data
If you connect a supported Google service, we access only the data you authorize for the disclosed feature. Our use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable. The storage, security, retention, and deletion provisions of this Policy also apply.
Data subject to Limited Use, including derived or aggregated data, is used only for permitted prominent user-facing features for the requesting user. It is not sold, used to serve ads, or used for credit or lending decisions. Human access and transfers are limited to the policy's permitted circumstances; applicable business transfers require explicit prior user consent.
A general services agreement does not replace any required specific consent. These restrictions also apply to our personnel, providers, and successors.
Payments
We process payments through Stripe or another designated payment processor. We receive billing and transaction information needed to administer accounts and collect agreed fees, not unrestricted payment-card credentials. Payment processors' own notices apply to their independent processing.
Billing and collection rely on necessary account, payment, and transaction records. They do not authorize independent use of connected message bodies, file contents, or advertising-account data for debt collection.
Cookies and similar technologies
We use cookies, local storage, and similar technologies for authentication, security, preferences, analytics, and performance. You may control them through your browser and any consent tools offered in the Service, although blocking necessary technologies can affect functionality.
We obtain consent for nonessential technologies where required and honor legally applicable opt-out signals, including Global Privacy Control. We do not sell or share personal information for cross-context behavioral advertising.
Retention and deletion
We retain information only as long as needed for the disclosed purpose, taking into account the account relationship, the nature of the information, legal requirements, dispute needs, and security. The DPA and mandatory law control retention of Customer Personal Data.
| Information | Retention criteria |
|---|---|
| Account and business-contact information | While needed for the relationship and related administration, then only for permitted legal or business purposes |
| Connected System Data | While needed for the authorized Service; after processing ends, return or deletion under the DPA |
| Billing records | Applicable accounting, tax, and legal-record requirements |
| Security logs and support records | The period reasonably needed to investigate, support, and secure the Service, subject to data minimization |
When the relevant Service ends, you may request return of available Customer Personal Data within 30 days; otherwise we delete it under the DPA. Routine backups expire in the ordinary course and are not used for new purposes. Lawfully required records or records reasonably needed for legal claims may be retained to the extent permitted, not as a blanket exception for all account content.
Permitted de-identified operational telemetry may be retained while useful for the disclosed purposes. De-identification does not override platform-specific deletion or use restrictions.
Security
We maintain administrative, technical, and organizational measures designed to protect information, including the measures stated in the DPA where it applies. No transmission or storage method is completely secure, and we do not guarantee that every incident can be prevented.
Customers remain responsible for their credentials, authorized users, and systems they control. We notify affected customers or individuals as required by law and applicable agreements. Contractual liability is addressed in the applicable Terms or MSA, without limiting non-waivable rights or regulatory obligations.
International processing
We are based in the United States and may process information where we and authorized providers operate. Where required, we use applicable Standard Contractual Clauses, the UK Addendum, and other lawful transfer mechanisms described in the International Data Transfer Annex.
Privacy rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; appeal a denied request; or complain to a competent regulator. Send requests and appeals to support@theadspend.com. We verify identity and authority proportionately and respond within legally required periods.
Authorized agents may act where permitted by law. We do not discriminate for exercising privacy rights. When acting as a processor, we route requests to the responsible customer and assist it as required.
For California and other applicable US state laws, the information categories, purposes, and recipient categories are described above. We do not sell or share personal information for cross-context behavioral advertising, including information about individuals under 16, and do not use sensitive personal information for purposes requiring a right to limit beyond legally permitted service purposes.
Certain information may be retained or requests limited where permitted by law, including for legal claims, security, and required records. We will explain a denial and available appeal options as required. EEA and UK individuals may complain to their local supervisory authority.
Children
The Service is intended for business users aged 18 or older. We do not knowingly solicit personal information directly from children; if we learn we collected it contrary to this Policy, we take appropriate deletion steps, subject to legal requirements.
Changes and contact
We may update this Policy and will provide notice of material changes through the website, email, or the Service as appropriate. A change does not retroactively authorize a materially different use of previously collected data; we obtain additional consent where required, including for new Google data uses.
Contact Ad Spend Technologies, Inc., 1460 Broadway, New York, NY 10036, USA, or support@theadspend.com.