Legal

Privacy Policy

What we collect, why we collect it, and the control you keep over your data.

Last updated: July 13, 2026

This Privacy Policy describes how Ad Spend Technologies, Inc., a Delaware corporation ("The Ad Spend," "we," "us," or "our"), handles personal information in connection with The Ad Spend — our website at https://theadspend.com and the connected product application, including our Slack and Microsoft Teams apps (together, the "Service").

Ad Spend Technologies, Inc. operates the Service. For questions about this Policy or your data, or to make a privacy request, contact privacy@theadspend.com, or write to us at Ad Spend Technologies, Inc., 1460 Broadway, New York, NY 10036, USA.

For information about our own website visitors, prospects, and the individuals who create and administer accounts, we act as a controller (or "business" under U.S. state privacy laws). For Connected Platform Data and other content our customers route through the Service, we act as a processor / service provider: we process it on the customer's behalf and documented instructions to provide the Service, and not for our own independent purposes. Where a separate written agreement with a customer addresses data processing, that agreement governs the customer-to-provider processing relationship for that data; this Policy continues to describe our practices and the rights individuals have under applicable law. Customers are responsible for having a lawful basis and any required notices and consents for the data they connect.

"Connected Platforms" means the advertising platforms a customer connects to the Service — currently Google Ads, Meta (Facebook/Instagram) Ads, LinkedIn Ads, TikTok Ads, Reddit Ads, and, as support launches, OpenAI Ads (advertising in ChatGPT). "Connected Platform Data" means data obtained from a Connected Platform through its official API with the customer's authorization.

Information you provide directly:

  • Account information — name, work email, company, role, and authentication credentials.
  • Context you supply — business overviews, objectives, notes, taxonomy, and similar context entered to tune analysis.
  • Communications — messages you send to support or sales, form submissions, and survey responses.
  • Meetings — where you meet with our team, meeting notes and, only with the affirmative consent of participants obtained before recording begins, recordings and transcripts.

Information collected when you use the Service:

  • Connected Platform Data — campaign settings, change history, performance metrics, conversion events, creative content and descriptions, and related metadata, accessed through each platform's official API with your authorization. Depending on how you configure your accounts and conversions, this may include limited person-level or device-level identifiers.
  • Authorization data — OAuth access and refresh tokens and related authorization identifiers for Connected Platforms, stored encrypted and used solely to operate the connection.
  • Workspace and messaging data — if you install our Slack or Microsoft Teams app: workspace name and identifiers, user identifiers and roles, the channels the app is added to, and messages and commands sent to the app. We do not read messages outside the app's channels and commands.
  • Usage and device data — log data, IP address, browser and device type and identifiers, pages viewed, referring URLs, and interactions with the product, collected via server logs and the technologies described in Section 7.

We use personal information to:

  • Provide and secure the Service — ingesting changes, generating analysis and recommendations, authenticating users, managing workspaces and seats, and preventing fraud and abuse (performance of a contract; legitimate interests).
  • Bill and manage accounts — subscriptions, invoicing, taxes, and payment status (performance of a contract; legal obligation).
  • Communicate with you — account, security, support, and, where permitted, marketing communications you can opt out of at any time (legitimate interests; consent where required).
  • Operate our website — analytics, performance, and marketing attribution as described in Section 7 (legitimate interests; consent where required).
  • Improve the Service — using the operational data described in Section 9 (legitimate interests).
  • Comply with law and enforce our terms, and evaluate or complete corporate transactions (legal obligation; legitimate interests).

When you connect a Connected Platform, we access only the data needed to operate the Service on your behalf, using each platform's official APIs and the permissions you grant. We use Connected Platform Data solely to provide the Service to the customer that connected it — not to build products for anyone else, and not for advertising. You can disconnect a platform at any time in Settings, which stops further ingestion, results in revocation and deletion of the associated tokens, and triggers deletion of that platform's raw data as described in Section 10 (and within any timeframe the platform's terms require).

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We handle each platform's data in accordance with that platform's API terms and developer policies.

The Service uses automated systems and third-party artificial-intelligence providers ("AI Service Providers") to help generate analysis, detection, and recommendations. Context you provide (such as business overviews and creative descriptions) may be processed by AI Service Providers to deliver these features. Connected Platform Data is sent to an AI Service Provider only where the applicable platform's terms permit it and only as necessary for a customer-facing feature of the Service — never for the provider's own purposes. We contract with AI Service Providers to process this information solely to deliver the Service and not to train their models on it. Recommendations are informational; where the Service can execute an approved action on your accounts, nothing is executed without your approval.

Our website and product use cookies and similar technologies for authentication, security, preferences, analytics, and measuring the performance of our own marketing. You can control cookies through your browser settings, and we honor Global Privacy Control (GPC) signals as an opt-out where required by applicable law.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. In the preceding 12 months, we have collected the categories of information described in Section 3 and disclosed them only as described in this Section; we have not sold or shared personal information within the meaning of the California Consumer Privacy Act. We disclose information only:

  • to service providers who process data on our behalf under contract (categories listed on our Data Handling page), limited to what each needs to provide its service to us;
  • to our payment processor (Stripe), which acts as an independent controller for certain payment-processing and fraud-prevention activities under its own privacy policy;
  • to your workspace — information you submit in a shared workspace is visible to other authorized users of that workspace as configured by your administrator;
  • when required by law, or to protect rights, safety, and the integrity of the Service; and
  • in connection with a merger, acquisition, financing, or sale of assets, in which case personal information remains subject to this Policy, and Connected Platform Data is transferred only as permitted by the applicable platform's terms, including obtaining any consent those terms require.

We may collect and use operational data — product usage counts, feature performance and latency, security telemetry, customer feedback, and fully de-identified operational statistics that do not contain or derive from Connected Platform Data — to operate, secure, and improve the Service. We commit to maintaining de-identified data in de-identified form and not attempting to re-identify it.

We do not use Connected Platform Data or customer content to train generalized AI models, create cross-customer benchmarks, develop unrelated datasets or offerings, advertise to third parties, or build products for anyone other than the customer that connected the data, unless that customer separately opts in in writing and the applicable platform's terms permit that use.

We retain personal information only as long as needed for the purposes described in this Policy:

CategoryRetention
Connected Platform Data (raw)Deleted from production promptly following platform disconnection or account closure, and within any timeframe the applicable platform's terms require
Backup copies of Connected Platform DataRemoved in the ordinary course of our standard backup cycles
OAuth tokens and authorization identifiersRevoked and deleted following disconnection
AI prompts and generated analysisDeleted with the workspace, unless separately saved by the customer
Account, workspace, and context dataDuration of the account, then deleted or de-identified within a reasonable period following closure
Support and sales communicationsUp to 3 years
Security and access logs12–24 months
Billing, tax, and transaction recordsUp to 7 years where required by law
Terms acceptance, action approvals, and audit records5–7 years, retained as narrow evidence of consent and approvals
Material subject to a legal holdDuration of the hold

Depending on your location, you may have rights to access, correct, export, delete, or restrict processing of your personal information, to object to certain processing, and to withdraw consent — including rights under U.S. state privacy laws (such as the CCPA) and, where applicable, the GDPR or UK GDPR.

To exercise these rights, email privacy@theadspend.com or use the privacy controls in your account settings. We will verify your request, respond within the time required by applicable law, and will not discriminate against you for exercising your rights. If we decline a request, U.S. state residents may appeal by replying to our decision. You may use an authorized agent to submit requests; we may verify the agent's authority. We honor Global Privacy Control signals as described in Section 7. EU/UK individuals also have the right to lodge a complaint with their supervisory authority.

If we process your information on behalf of one of our customers (for example, your employer or agency), we will refer or forward your request to that customer, as they control that data.

We use technical and organizational measures designed to protect information, including encryption in transit and at rest, access controls, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Suspected vulnerabilities can be reported to security@theadspend.com.

We process and store information in the United States and may process it in other countries. Where required, we use appropriate safeguards for cross-border transfers of personal information, such as the EU Standard Contractual Clauses and the UK Addendum.

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

We may update this Privacy Policy from time to time. When we make material changes, we will update the date above and provide notice — for example, by email or in-product notice — before the changes take effect, and we will obtain consent where applicable law or a Connected Platform's terms require it.

Questions about this Policy, or privacy requests, can be sent to privacy@theadspend.com, or by mail to Ad Spend Technologies, Inc., 1460 Broadway, New York, NY 10036, USA.