SmartAds

Privacy Policy

Version 1.0.0-draft · drafted 2026-08-16

Draft

This is a working draft. It has not been reviewed or approved by a lawyer, and it does not yet name a contracting entity or a governing law. 8 questions in it are still open for legal review, and each one is marked in the text below.

# Privacy Policy

> **DRAFT — NOT LEGALLY REVIEWED.**
> Prepared from the product's actual data model. Not reviewed or approved by a
> lawyer, and not a statement of compliance with any regime.

## 1. Who is responsible

**[LEGAL REVIEW REQUIRED — contracting entity and registered address]**

**[LEGAL REVIEW REQUIRED — controller / processor characterisation]** The
answer differs between account data (which the operator holds for its own
purposes) and advertising data synced on your behalf (which is yours). That
distinction drives most of this document and the DPA.

## 2. What is collected, and why

Each category below corresponds to real tables in the system. Nothing is listed
because it might be collected one day.

### Account and identity
Your name, email address and password hash; email verification and password
reset tokens; sessions. Used to sign you in and to keep your account secure.

### Workspace and membership
Workspaces, members and their roles, invitations (which contain the invited
email address), and workspace settings. Used to decide who may see what.

### Advertising platform connections
The authorisation you grant, and access tokens for the platforms you connect.
**Tokens are encrypted at rest and are never returned by any API, never written
to logs, and never included in a data export.**

### Advertising data
Advertising accounts, campaigns, ad sets, ads, creatives and daily performance
metrics read from platforms you connect. This is your business data, held on
your behalf.

### Commerce data
Stores, products, orders and order lines from a commerce store you connect.

> **Order customer identity is reduced to a one-way hash at the point of
> ingest.** No customer email address, name or postal address from your store is
> stored. The hash is salted with a secret that is not exported, so it cannot be
> reversed. It exists only to count repeat purchases.

### AI usage
Records of AI analyses run, the tokens consumed and the cost. Analysis input is
redacted before it is sent, and the AI provider does not receive account
credentials or store-customer identifiers.

### Uploaded files
Creative assets you upload, and metadata about them.

### Audit and security records
An append-only record of security-relevant actions: sign-in, permission changes,
integration connects and disconnects, and data deletions. **This record is kept
even when other data is deleted**, because it is the evidence that the deletion
happened.

### Operational records
Rate-limit counters, job records, and receipts used to recognise a repeated
webhook delivery. Webhook message bodies are not stored — only a hash.

### Billing
No payment is processed and no payment data is held. Billing is not enabled.

## 3. Who it is shared with

The current sub-processor list is maintained separately and is part of these
documents. Providers a customer's data can actually reach today are the AI
provider that produces analysis and the advertising and commerce platforms you
choose to connect.

**[LEGAL REVIEW REQUIRED — sub-processor characterisation]** Data from
advertising and commerce platforms flows *to* the service on your authorisation,
which is not the usual sub-processor direction.

## 4. International transfers

**[LEGAL REVIEW REQUIRED — international transfers and transfer mechanism]**
Unanswerable until a hosting provider and its regions are chosen. None has been.

## 5. How long it is kept

An engineering retention inventory exists and covers every table. The periods
themselves are unresolved.

**[LEGAL REVIEW REQUIRED — retention periods]** for audit records, accounting
records, webhook receipts, AI usage records, performance metrics, and backups.

What is settled today: expired sessions and expired verification tokens are
deleted automatically because they are already unusable; nothing else is deleted
on a timer.

## 6. Your rights

You can request an export of a workspace's data, and you can request deletion of
a workspace or of your own account. Deletion marks the subject immediately —
access stops at once — and a staged purge then erases the data.

**Three limits, stated plainly:**

- **Deletion does not reach database backups.** Data already deleted from the
  live system remains in backups taken before the deletion, until those backups
  age out. **[LEGAL REVIEW REQUIRED — how this is described, and backup
  retention.]**
- **Deletion does not reach the advertising platforms.** Your campaigns and
  their data remain in your own platform accounts, which are yours.
- **Deleting your own account does not delete a workspace's files.** Deleting
  your account removes your account, your sign-in credentials and your access,
  including your membership of every workspace. Files you uploaded — creative
  assets, product images and exports — are held as workspace records rather than
  personal ones: they stay with the workspace and remain available to its other
  members. We record who uploaded a file so the workspace knows where it came
  from, and that record alone does not make the file yours to remove. Deleting
  the **workspace** is what erases its files. **[LEGAL REVIEW REQUIRED — whether
  workspace files should be treated as the workspace's records rather than the
  uploader's personal data, and how that is described here.]**

Some records are deliberately retained: the audit trail, and accounting records
if any exist. **[LEGAL REVIEW REQUIRED — the legal basis and period for each.]**

**[LEGAL REVIEW REQUIRED — jurisdiction-specific rights]** including obligations
under Moroccan Law 09-08 / CNDP and, for EU customers, the GDPR.

## 7. Security

Tenant data is isolated at the database level as well as in the application.
Platform tokens are encrypted at rest. Passwords are hashed. Access to
credential tables is withheld from the application's own database role.

**This describes controls that exist. It is not a certification, and no
compliance claim is made.**

## 8. Contact

**[LEGAL REVIEW REQUIRED — privacy contact, and whether a data protection
officer or representative is required.]**