Privacy Policy
Last updated: July 24, 2026
1. Introduction
AdFlint ("we," "our," or "us") operates the AdFlint platform at adflint.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our advertising management service.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and authentication credentials. We use secure third-party authentication providers (such as Google OAuth) to manage sign-in.
Campaign Data
When you create advertising campaigns, we collect the information you provide including business name, ad copy, target audience parameters, budget allocations, and creative assets.
Payment Information
Payment processing is handled by Stripe. We do not store your credit card numbers or banking details on our servers. Stripe collects and processes your payment information in accordance with their own privacy policy.
Identity Verification
To prevent fraud and abuse, we may require identity verification for certain accounts, performed by Stripe Identity. Any government-issued ID, selfie, or Social Security information you provide is collected and held by Stripe, not by AdFlint. We receive only a verification result and minimal confirmation data — we never receive or store your SSN, ID number, or images. Stripe processes this information under its own privacy policy.
Usage Data
We automatically collect certain information when you use our platform, including IP address, browser type, device information, pages visited, and timestamps. This data helps us improve our service and troubleshoot issues.
Advertising & Conversion Tracking
To measure ad performance, our first-party pixel captures advertising click identifiers (such as Google's gclid, Meta's fbclid, Microsoft's msclkid, TikTok's ttclid, X's twclid, and Pinterest click IDs), an approximate location derived from your IP address, and a randomly generated visitor ID stored in your browser. We use this to attribute conversions and improve campaign optimization, and we may share conversion data (including click identifiers) with connected advertising platforms to measure and optimize ad delivery. You can decline this non-essential tracking via the cookie banner, and we honor a Global Privacy Control (GPC) or “Do Not Track” signal automatically.
3. How We Use Your Information
- To create, manage, and optimize advertising campaigns on your behalf across currently available platforms (Google Ads and Meta), with additional integrations as they become available
- To process your subscription payments and manage billing
- To provide campaign performance analytics and reporting
- To use AI-powered features to generate ad copy, optimize targeting, and improve campaign performance
- To communicate with you about your account, campaigns, and platform updates
- To detect and prevent fraud or abuse of our services
- To comply with legal obligations and enforce our terms of service
4. Advertising Platform Data
AdFlint acts as an intermediary between you and advertising platforms. When we run campaigns on your behalf, the advertising platforms (currently Google and Meta) may collect data in accordance with their own privacy policies. We share the minimum information necessary to create and manage your campaigns, such as ad copy, targeting parameters, and budget details.
5. Google User Data
When you connect a Google Ads account, AdFlint requests your permission through Google OAuth and accesses data in that account on your behalf. This section describes exactly what we access, why, and how it is handled.
Scopes we request and why
https://www.googleapis.com/auth/adwords— required to read the campaigns, ad groups, keywords, ads, budgets, conversion actions, performance metrics, and Google-generated recommendations in the Google Ads account you authorize, and to create, update, pause, and resume campaigns, budgets, and ads in that same account. AdFlint is an ad-management product, so read-only access is not sufficient — launching and optimizing campaigns requires write access.https://www.googleapis.com/auth/datamanager— required to upload offline conversion events you send us (for example, a sale that closed after an ad click) back to your Google Ads account through the Google Data Manager API, so that Google can attribute and optimize for conversions that happen off your website.
How we store and protect it
OAuth access and refresh tokens are encrypted at rest on our servers and are used only to make API calls to Google on your behalf. Google Ads data we retrieve (campaign structure and performance metrics) is stored to render your dashboard and reporting. No AdFlint employee accesses your Google user data except where you have given explicit consent (for example, to troubleshoot a support request), where it is necessary for security purposes, or where required by law.
Retention and deletion
You can disconnect a Google Ads account at any time from Settings, which immediately revokes AdFlint's access and deletes the stored tokens. Google Ads data previously retrieved for that account is deleted within 30 days of disconnection, except where we are required to retain records for legal, accounting, or fraud-prevention purposes. You may also request deletion of your account and all associated data at privacy@adflint.com.
Limited Use
AdFlint's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising purposes other than operating the advertising campaigns you have asked us to run in your own account, we do not use it to train generalized artificial intelligence or machine learning models, and we do not transfer it to third parties except as necessary to provide or improve the features you use, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
6. AI Processing
AdFlint uses artificial intelligence to generate ad copy, suggest targeting parameters, and optimize campaign performance. Your campaign data may be processed by AI models to provide these features. We do not use your data — including any data obtained from Google APIs — to train generalized artificial intelligence or machine learning models. AI processing is used solely to provide and improve the features you are actively using.
If you opt into Google ad-strength auto-optimization, we may send the campaign's Google ad text, platform ad-strength feedback, and related campaign context to our AI service provider to generate revised headlines and descriptions. This opt-in feature is capped at two attempts per campaign. This transfer is limited to providing that feature to you: the provider is contractually prohibited from using the data to train its own models or for any other purpose, and the data is not sold, used for advertising outside your own account, or read by humans.
7. Data Sharing
We may share your information with:
- Advertising Platforms: Google Ads and Meta to run campaigns on your behalf. Additional platforms may be added as integrations become available.
- Payment & Identity Processors: Stripe for payment processing and identity verification
- AI Service Providers: To power campaign optimization and ad copy generation
- Analytics Providers: To help us understand and improve our service
- Legal Requirements: When required by law, court order, or governmental authority
We do not sell your personal information for money. We do share advertising and conversion data with Google and Meta to measure and optimize ad delivery, which some privacy laws (such as California's CPRA) classify as “sharing” for cross-context behavioral advertising. You can opt out of this at any time via the cookie banner or by enabling a Global Privacy Control (GPC) signal in your browser.
8. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), encrypted data at rest, and secure authentication mechanisms. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. Data Retention
We retain your account data for as long as your account is active. Campaign data and analytics are retained for up to 24 months after a campaign ends. You may request deletion of your account and associated data at any time by contacting us.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request data portability
- Withdraw consent at any time
To exercise any of these rights, please contact us at the email address below.
11. Cookies
We use essential cookies required for authentication and platform functionality. We also use non-essential cookies and browser storage for analytics and advertising/conversion measurement (including the click identifiers and visitor ID described above). You can decline the non-essential ones via our cookie banner — and we honor a Global Privacy Control (GPC) or “Do Not Track” browser signal automatically — or manage cookies through your browser settings.
12. Children's Privacy
AdFlint is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our platform with a revised "Last updated" date. Your continued use of AdFlint after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@adflint.com