← Back to AdSpend Hero

Privacy Policy

Last updated: 25 September 2026

AdSpend Hero Pro is a service of GOODVIBES ENTERPRISE - FZCO, a company registered in Dubai, United Arab Emirates (trade licence 50179), at IFZA Properties, Dubai Silicon Oasis, Dubai, UAE. In this policy "we" means that company and "you" means the person or business using the service.

This policy explains exactly what we collect, why, where it lives and how you get it back or removed. If anything here is unclear, write to privacy@adspend-hero.com and we will answer in plain language.

1. What we collect

Your account

  • Your email address and, if you enter one, your name.
  • A cryptographic hash of your password — never the password itself.
  • If you switch on two-step login: a secret for your authenticator app and the fingerprints of your recovery codes.
  • When you last signed in, and which language you picked.

Your advertising data

When you connect a TikTok or Meta advertising account, we read — for the accounts you select and no others:

  • Campaign, ad group and ad names, their status and their budgets.
  • Performance figures: spend, impressions, clicks, add-to-carts, purchases and revenue.
  • The remaining balance or spending limit of the advertising account.
  • An access token that lets us read those figures and pause or resume ad groups on your behalf.

We do not read your creatives, your audiences, your customer lists, your pixel data or anything about the people who see your ads. We never see the personal data of your own customers.

Usage

We keep a log of what the service did for you — which ad group was paused, when, and on which rule — so you can check our work. Our web server keeps ordinary technical logs (IP address, time, page requested) for security and troubleshooting.

We use no tracking cookies, no advertising pixels and no analytics that follow you. The only cookie we set is the one that keeps you signed in.

2. Why we use it, and on what basis

WhatWhyLegal basis (GDPR)
Account detailsTo let you sign in and to keep your data separate from other customersPerformance of our contract with you
Advertising dataTo show your numbers and to run the rules you set upPerformance of our contract with you
Action logSo you can verify what was paused and why, and so we can prove itOur legitimate interest in an auditable service
Technical logsSecurity, abuse prevention, troubleshootingOur legitimate interest in a safe service
Billing detailsTo take payment and issue invoicesLegal obligation and performance of contract

3. Who else sees it

We do not sell your data and we do not share it for anyone else's marketing. It is passed only to the parties we need to run the service:

WhoWhat forWhere
Google CloudThe server your data lives onUnited States
TikTok for BusinessReading your figures and pausing your ad groups, at your instructionPer TikTok's own policy
MetaThe same, if you connect a Meta accountPer Meta's own policy
StripePayments, once paid plans are live. We never see or store your card details.Ireland / United States
Where your data is stored. Our server currently runs in a Google Cloud region in the United States. If you are in the European Union, that is a transfer outside the EU, made on the basis of the European Commission's Standard Contractual Clauses with Google. We are working towards hosting inside the EU; when that happens this page will say so.

4. How long we keep it

  • Account and connections: for as long as your account exists.
  • Action log: two days in detail; the savings totals per day are kept so your dashboard keeps its history.
  • Technical logs: a few weeks, then overwritten.
  • Backups: fourteen days.
  • Invoices: as long as tax law requires us to keep them.

Close your account and we delete your data, including your access tokens, within 30 days — apart from what we are legally required to keep.

5. How it is protected

  • Everything travels over an encrypted connection (HTTPS); plain connections are refused.
  • Access tokens and platform keys are stored encrypted, not as readable text.
  • Passwords are hashed with scrypt and cannot be read back.
  • Every query is bound to your account number, so one customer cannot reach another's data. We test this automatically and repeat the test after every change.
  • Two-step login is available to every account and we recommend switching it on.
  • The service runs under a restricted system account, with automatic security updates and nightly backups.

6. Your rights

If you are in the European Union you have the right to see your data, correct it, have it deleted, take it with you, and to object to how we use it. Everywhere else we apply the same rights, because it is the decent thing to do.

Write to privacy@adspend-hero.com and we answer within 30 days. You may also complain to your national data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

7. Children

The service is for businesses. It is not meant for anyone under 18 and we do not knowingly collect their data.

8. Changes

If we change this policy we update the date at the top, and we email you before anything that materially affects you takes effect.

9. Contact

GOODVIBES ENTERPRISE - FZCO · Trade licence 50179
IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates
privacy@adspend-hero.com

← Back to AdSpend Hero