Privacy Policy
Last updated: September 10, 2026
1. Introduction and Data Controller
Admazing is an advertising management platform operated by influio s.r.o., ID No. 22238697, with its registered office at Varšavská 715/36, Vinohrady, 120 00 Praha, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file no. C 412818 ("we", "us", "our"). We are committed to protecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our advertising management platform at app.getadmazing.com (the "Service").
We act as the data controller for the personal data described in this Policy. Where the Service is used to manage advertising campaigns and ad accounts belonging to your organization, you act as the controller of the personal data contained in those campaigns and accounts, and we act as your processor, processing that data on your documented instructions.
We process personal data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Czech Personal Data Processing Act (Act No. 110/2019 Coll.), applicable EU/EEA data protection laws, and Meta Platform Terms.
2. Data We Collect
2.1 Account Data
When you register, we collect your email address and organization name, and we store a securely hashed version of your password. We also record whether your email address has been verified, and we maintain session tokens that keep you signed in. This data is necessary for account creation and service delivery (GDPR Art. 6(1)(b) — contractual necessity).
2.2 Meta (Facebook) Platform Data
If you choose to connect your Meta account to the Service via Facebook Login, we access and store:
- Ad account information — account ID, account name, currency settings
- Campaign data — campaign names, budgets, targeting countries, deployment status
- Performance insights — aggregate metrics such as impressions, clicks, spend, conversions, and return on ad spend (ROAS)
- Page and pixel identifiers — used for campaign deployment and conversion tracking
- Meta user ID — used to identify your connection for data deletion and deauthorization callbacks
We do not access your personal Facebook profile data, friends list, photos, private messages, or any data unrelated to advertising management.
2.3 Google Analytics Data
If you choose to connect your Google Analytics account to the Service via Google sign-in, we access your GA4 property through the official Google Analytics API using the read-only analytics.readonly scope, with your explicit consent granted through Google's OAuth consent screen. We access and store:
- Analytics reporting data — aggregated e-commerce performance metrics for the property you select, such as purchases, revenue, and item-level sales figures
- Account and property information — the list of Analytics accounts and properties available to you, used only to let you choose which property to connect
- OAuth tokens — encrypted at rest (AES-256) and in transit (TLS)
See Section 11 for how we use, protect, and delete Google user data.
2.4 Payment Data
Subscription payments are processed by Stripe, Inc. We store your Stripe customer ID and subscription status but do not store credit card numbers, bank account details, or other payment credentials. All payment processing is handled directly by Stripe under their Privacy Policy (https://stripe.com/privacy).
2.5 Usage Data
Our infrastructure providers may capture IP addresses, request timestamps, and HTTP metadata in server logs for security monitoring and debugging. Application-level logs contain request context but do not systematically record IP addresses. Infrastructure logs are retained for up to 30 days.
2.6 AI Assistant Conversations
The Service includes an in-app AI assistant. When you use it, we store the messages you send and the assistant's replies so that your conversation history remains available to you. Because you compose these messages freely, they may contain personal data; we ask that you do not enter personal data that you do not wish to be processed in this way. Your messages and recent conversation context are transmitted to our AI provider in order to generate a reply (see Section 6). You can delete any conversation at any time from within the Service.
3. How We Use Your Data
- Campaign management — creating, deploying, pausing, and monitoring advertising campaigns on Meta platforms
- Performance analytics — displaying campaign insights and generating reports to help you optimize your advertising
- Product catalog management — creating and managing product catalogs for shopping campaigns
- AI-powered content generation — when you use AI features, we send your brand information and campaign context to our AI provider to generate suggested ad copy. We do not include your Meta access tokens or payment credentials in these requests.
- AI assistant — when you use the in-app assistant, we send the messages you write and your recent conversation context to our AI provider in order to generate a reply
- Service improvement — anonymized, aggregate analytics to improve our platform (no personally identifiable information is used)
- Security — detecting and preventing unauthorized access, fraud, and abuse
4. Legal Basis for Processing (GDPR)
- Contractual necessity (Art. 6(1)(b)) — processing required to provide the Service you signed up for
- Legitimate interest (Art. 6(1)(f)) — anonymized analytics to improve our platform, security monitoring, fraud prevention, protecting our rights in case of a dispute
- Consent (Art. 6(1)(a)) — connecting your Meta account via Facebook Login is a voluntary action that constitutes explicit consent for accessing your ad account data
5. Data Retention
We retain your data for as long as your account is active and the Meta connection is established. When you disconnect your Meta account or request data deletion:
- All personally identifiable Meta data (access tokens, user IDs, account names, campaign names, external IDs) is anonymized immediately — nulled or replaced with non-identifying placeholders
- Aggregate performance metrics (impressions, clicks, spend) are retained in anonymized form as they cannot be linked back to any individual
- Database backups containing pre-anonymization data are retained for 7 days and then automatically deleted
- AI assistant conversations are retained until you delete them, or until your account is deleted
- Account data (email, organization) is retained until you delete your account or request erasure
6. Third-Party Sharing and Sub-Processors
We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We share data only with the categories of recipients described below.
A current, itemized list of our sub-processors — naming each provider, the purpose for which it processes data, and the region in which it does so — is available at app.getadmazing.com/subprocessors. We will give advance notice of any change to our sub-processors by email or in-app notification.
- Advertising platforms — if you choose to connect your Meta account to the Service, we will send campaign configuration data to Meta Platforms via their Graph API to manage your advertising campaigns. Meta's processing of this data is governed by Meta's Privacy Policy (https://www.facebook.com/privacy/policy/).
- Cloud infrastructure providers — we use cloud infrastructure for hosting, database, object storage, and message queuing. All Service data is stored and processed within the European Union.
- AI service providers — when you use AI-powered features or the in-app assistant, we send brand context, campaign parameters, and the messages you write to our AI provider to generate suggested content or replies. We do not include your Meta access tokens or payment credentials in these requests. Your data is not used to train the provider's models.
- Email delivery providers — we send transactional email (such as account verification, invitations, and password resets) through an email delivery provider, which processes your email address for that purpose.
- Stripe, Inc. (payment processing) — we share your Stripe customer ID and subscription data with Stripe for payment processing. Stripe's handling of payment data is governed by Stripe's Privacy Policy (https://stripe.com/privacy).
- Google LLC (font delivery) — the Service loads font files from Google Fonts so that ad templates and the template editor display the correct typefaces. As a technical necessity of any request your browser makes to a third-party server, your IP address, browser user-agent, and the address of the page you are viewing are transmitted to Google. Google Fonts does not set cookies and we do not send Google any account, campaign, or identifying data of our own. Google's handling of this data is governed by Google's Privacy Policy (https://policies.google.com/privacy).
We may also disclose data if required by law, regulation, or valid legal process.
7. International Data Transfers
Your data is stored and processed within the European Union. When data is transmitted to Meta Platforms, Inc., Stripe, Inc., or Google LLC (each headquartered in the United States), such transfers are governed by the EU-U.S. Data Privacy Framework and the respective service provider's Data Processing Terms. Where required, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as a supplementary transfer mechanism. Apart from the instances mentioned above and those identified in our sub-processor list, we do not independently transfer your data outside the EU/EEA.
8. Data Security
We implement industry-standard security measures to protect your data:
- All Meta access tokens are encrypted at rest using AES-256-GCM
- All API communication uses HTTPS/TLS encryption
- App secrets are stored server-side only and never exposed to the frontend
- Meta webhook callbacks are verified using HMAC-SHA256 signatures with timing-safe comparison
- Access to production systems is restricted to authorized personnel only
9. Your Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of the personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate data
- Right to erasure (Art. 17) — request deletion or anonymization of your data. You can do this directly from the Connections page in your account settings, or by removing our app from your Facebook Settings.
- Right to restriction of processing (Art. 18) — request that we limit how we process your data in certain circumstances
- Right to data portability (Art. 20) — request your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)) — disconnect your Meta account at any time from the Connections page
We do not make automated decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). Our AI-powered features generate content suggestions that are always subject to your review and approval before use.
To exercise any of these rights, contact us at admin@getadmazing.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů (ÚOOÚ) — https://uoou.gov.cz/
10. Data Deletion via Meta
When you remove Admazing from your Facebook Settings (Apps & Websites), Meta sends us a data deletion callback. We automatically anonymize all data associated with your Meta user ID and provide a confirmation code you can use to verify the deletion status. The anonymization is performed immediately upon receiving the callback.
11. Google User Data
The Google Analytics data we collect when you connect your account is described in Section 2.3. This data is used solely to provide features to you inside Admazing — showing sales performance for your own products and letting you manage your product feeds based on it. We do not use Google user data for advertising or ad targeting, and we do not transfer it to any advertising platform. We do not use, transfer, or sell this data to create, train, fine-tune, or improve any AI or machine-learning models. We do not sell Google user data or share it with third parties, except sub-processors strictly necessary to operate the Service (see Section 6), who are bound by data-processing agreements. Aggregated metrics derived from your Analytics data are stored on our infrastructure in the European Union.
When you disconnect the Google Analytics integration, we revoke our access token with Google and stop accessing your data; stored Google-derived data is deleted within 30 days of disconnection or account termination. You can also revoke Admazing's access at any time in your Google Security Settings.
Admazing's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Cookies and Local Storage
The Service uses the following essential cookies and browser storage:
- Authentication cookies — two HttpOnly, Secure cookies ("access_token" and "refresh_token") used solely for session authentication. These cannot be accessed by JavaScript and are transmitted only over HTTPS.
- Browser local storage — we store your selected brand preference and application settings (theme, layout) in your browser's local storage. This data never leaves your browser and contains no personal information.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not use Google Analytics, Meta Pixel, or any other third-party analytics service on our platform. Since we use only strictly necessary cookies for authentication and functionality, no cookie consent is required under the ePrivacy Directive (2002/58/EC) as transposed into Czech law (Act No. 127/2005 Coll. on Electronic Communications).
13. Children's Privacy
The Service is intended for business use and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at admin@getadmazing.com and we will promptly delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top indicates when the policy was last revised. Continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact
For any privacy-related questions or to exercise your rights, contact us at: