Privacy Policy

Last updated: April 26, 2026

1. Introduction

Adship ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our advertising management platform and related services (the "Service"). Adship supports Meta (Facebook/Instagram) and TikTok platforms.

By accessing or using our Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: When you create an account, we collect your name, email address, and authentication credentials.
  • Meta (Facebook/Instagram) Data: When you connect your Meta account, we access your advertising account information, campaigns, ad sets, ads, Facebook Pages, and Instagram accounts through Meta's Marketing API, only what's needed to create, manage, and monitor your ads.
  • TikTok Ads Data: When you connect your TikTok Ads account, we access your advertiser accounts, campaigns, ad groups, ads, and identity information through TikTok's Marketing API to create and manage your TikTok advertising campaigns.
  • Legacy Google Ads Data: Google Ads is no longer available for active connections or campaign management. If you connected it previously, encrypted tokens, account metadata, and historical records may be retained securely for data integrity, support, and deletion requests; Adship does not use them for active Google Ads operations.
  • Google Drive Data: If you import creatives from Google Drive, we temporarily access selected files to upload them to your ad platforms. We do not store your Google Drive files on our servers.
  • Payment Information: If you subscribe to a paid plan, our payment processor (Stripe) collects your billing information. We do not store your full payment details.
  • Communications: When you contact us, we collect the information you provide in your messages.

About Performance Data:

We access ad performance metrics (spend, impressions, clicks, CTR, ROAS, etc.) solely to display analytics within our dashboard and help you manage your campaigns. We do NOT store this performance data long-term, share it with third parties, or use it for any purpose other than displaying it to you.

2.2 Information Collected Automatically

  • Usage Data: We collect information about how you interact with our Service, including pages visited, features used, and actions taken.
  • Device Information: We collect device type, operating system, browser type, and IP address.
  • Cookies: We use cookies and similar technologies to enhance your experience and collect analytics data.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process your transactions and manage your subscriptions
  • Create, manage, and monitor your advertising campaigns across Meta and TikTok on your behalf
  • Upload your creative assets (images/videos) to your connected ad platforms
  • Manage ad comments and moderation across your connected accounts
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze app usage trends (not your ad performance) to improve user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

4. Data Sharing and Disclosure

We may share your information in the following circumstances:

  • With Meta Platforms: To create, manage, and monitor your advertising campaigns and ad comments through Meta's APIs.
  • With TikTok: To create and manage your advertising campaigns through TikTok's Marketing API.
  • With Google: To provide optional Google Drive and Sheets import features. Google Ads is dormant; retained legacy Google Ads credentials are not used for active campaign operations. Adship's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • With AI providers: Product information and prompts you submit for AI features (ad copy, image, video generation) are processed by third-party AI APIs solely to fulfill your generation request.
  • Service Providers (Subprocessors): With the third-party vendors listed in Section 13 (Subprocessors) below, who process data on our behalf under written agreements.
  • Legal Requirements: When required by law or to protect our rights, privacy, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.

We do not sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, secure servers, and access controls.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. We will also retain and use your information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request access to your personal information.
  • Correction: Request correction of inaccurate personal information.
  • Deletion: Request deletion of your personal information.
  • Portability: Request a copy of your data in a portable format.
  • Opt-out: Opt out of marketing communications at any time.

7.1 Self-Serve Data Export and Deletion

You can request a copy of your personal data or delete your account and associated data at any time:

  • Data export: Email support@adship.ai from your account email and we will deliver a portable copy of your data within 30 days.
  • Account deletion: Open Settings → Account and choose "Delete account", or email us. Deletion removes profile data, ad campaign metadata, AI generations, and OAuth tokens we hold for you. We honor deletion requests within 30 days.
  • Subscription cancellation: Open Settings → Billing. Cancellation takes effect at the end of your current billing period; you keep access until then.

For any other privacy request, contact us at support@adship.ai. We respond within 30 days as required by GDPR Article 12.

8. Third-Party Integrations

8.1 Meta (Facebook/Instagram)

Our Service integrates with Meta's Marketing API for ad creation, management, and comment moderation. When you connect your Meta account, we access:

  • Your ad account list (to let you choose which account to use)
  • Campaigns, ad sets, and ads (to manage your advertising)
  • Facebook Pages and Instagram accounts (required for ad creation)
  • Custom audiences and pixels (optional, for targeting)
  • Ad creatives and existing ads (for duplication and management features)
  • Ad comments (for comment moderation via our Comments AI feature)
  • Ad performance metrics (spend, impressions, clicks, CTR, ROAS, etc.) to display in our analytics dashboard

Important: Performance data is fetched on-demand when you view analytics and is displayed only to you. We do not store this data long-term or share it with any third parties.

You can revoke our access to your Meta account at any time through your Meta account settings or by disconnecting your account within our Service.

8.2 TikTok Ads

Our Service integrates with TikTok's Marketing API for ad creation and campaign management. When you connect your TikTok Ads account, we access:

  • Your advertiser accounts (to let you choose which account to use)
  • Campaigns, ad groups, and ads (to manage your TikTok advertising)
  • Ad creatives and identity information (required for ad creation)
  • Ad performance metrics to display in our dashboard

You can revoke our access to your TikTok Ads account at any time through your TikTok Business Center settings or by disconnecting your account within our Service.

8.3 Google Ads

Google Ads is a dormant legacy integration. New connections and active API campaign management are disabled. For accounts connected before dormancy, we may retain:

  • Your Google Ads account information (account ID, name, currency)
  • Previously synchronized campaign, ad group, ad, and performance records

Data storage: Legacy Google Ads OAuth tokens remain encrypted on our servers, are never exposed to your browser, and are not used for active provider calls. You may request deletion through support.

Limited Use Disclosure: Adship's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, AI/ML model training, or any purpose other than providing and improving our Service to you.

You can revoke our access to your Google Ads account at any time through your Google account settings at myaccount.google.com/permissions or by disconnecting your account within our Service.

8.4 AI-Powered Features

Our Service uses AI to help you create ad copy, ad images, and ad videos, and to extract product information from URLs you provide. These features are powered by third-party AI APIs.

  • AI generation: Product information and prompts you submit are sent to AI provider APIs solely to generate the content you requested. Providers do not receive your account credentials, ad spend data, or contact lists.
  • Product extraction: When you provide a website URL, we fetch publicly available information from that page to help pre-fill product details.

Data handling: We cache extracted product information for up to 24 hours to improve performance. AI-generated content is stored in your account so you can reuse it.

Enterprise customers can request the full list of AI subprocessors and their privacy policies under NDA via DPA. Email support@adship.ai.

8.5 Google Drive

If you choose to import creatives from Google Drive, we request access to:

  • Files you explicitly select through the Google Drive Picker

We do NOT access: Your entire Google Drive, other files, folders, or any data beyond what you specifically select. Files are downloaded temporarily to your browser and uploaded directly to your ad platform, they are not stored on our servers.

You can revoke our access to Google Drive at any time through your Google account settings at myaccount.google.com/permissions.

8.6 Subprocessors

We use the following third-party subprocessors to operate the Service. We update this list when we add or replace material providers; check back periodically.

SubprocessorPurposeRegion
SupabaseDatabase, authentication, storage, edge functionsEU / US
VercelFrontend hosting, edge runtime, serverless functionsGlobal
StripeSubscription billing and payment processingUS / EU
ResendTransactional and onboarding email deliveryUS
UpstashRate limiting and ephemeral cache (Redis)Global
SentryError monitoring and performance tracingEU / US
Microsoft ClarityAnonymized session analytics on marketing pagesUS
AI providersLLM inference, image generation, video generation. Receive only the prompts and product information you submit. Do not receive personal account data. Full vendor list available under NDA via DPA.Global
Meta PlatformsFacebook / Instagram Marketing API integrationGlobal
TikTok / ByteDanceTikTok Marketing API integrationGlobal
GoogleOptional Drive and Sheets import; secure retention of dormant legacy Google Ads recordsGlobal

Enterprise customers can request a Data Processing Addendum (DPA) by emailing support@adship.ai.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.

10. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at: