Privacy Policy
Last updated: September 6, 2026
1. Introduction
This Privacy Policy explains how AdProtektor Inc. (“AdProtektor,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information in connection with our website at adprotektor.app, our application at app.adprotektor.app, and the services we provide (collectively, the “Service”).
AdProtektor provides AI-powered click fraud detection and prevention for digital advertising. Our Service involves two distinct roles in data processing, which are described throughout this policy.
If you have questions about this policy, contact us at support@adprotektor.app.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
- Name and email address
- Password (stored in hashed form)
- Company name (optional)
- Domain names you register for protection
2.2 Payment Information
Payments are processed by a third-party payment provider. We do not store your credit card numbers, bank account details, or other sensitive financial information on our servers. The payment provider’s privacy policy governs the processing of your payment data.
2.3 Tracking Data from Customer Websites (Processed on Behalf of Customers)
When our customers install the AdProtektor tracking script on their websites, we collect the following data from their website visitors to detect and prevent click fraud. In this context, our customer is the data controller, and AdProtektor acts as a data processor. This data includes:
- Network information: IP addresses
- Device and browser information: general technical characteristics of the visitor’s device and browser
- Visitor identification: a browser-based identifier used to recognize returning visitors across sessions
- Behavioral signals: on-page interaction and engagement signals describing how a visitor navigates and engages with the page (no message, form-field, or keystroke content is captured)
- Session recordings: recordings of page interactions, with input field values masked by default
- Advertising parameters: advertising click identifiers and campaign parameters used to attribute a visit to a paid ad click
- Page information: landing page URL and referrer URL
- Geographic data: approximate location (country, city) derived from IP address
2.4 Google Ads & Meta (Facebook / Instagram) Ads Integration Data
If you connect your Google Ads account, we access your Google Ads account ID and campaign information to manage IP exclusion lists on your behalf. If you connect a Meta (Facebook / Instagram) ad account by partner-sharing it with AdProtektor’s Business Manager, we access your Meta ad-account metadata, campaign list, and audience identifiers to manage exclusion audiences on your behalf. We do not use Facebook Login and we do not store any login tokens for your account. For enabled reporting and optimization features, we also read supported account and campaign performance data, such as spend, clicks and conversions, and Google Ads search-term and ad-text information. The data accessed depends on the connected platform and the features you use.
2.5 ConversionOS Data (Standalone or Add-on)
When you use ConversionOS, either through the standalone True Tracking plan or an eligible protection-plan add-on, our customer’s website passes conversion event data to AdProtektor — for example, order ID, order value, currency, and customer-supplied identifiers such as email address, phone number, and name. Before this data leaves our servers we hash these identifiers using SHA-256 in line with the matching requirements of Meta and Google. We then dispatch the hashed conversion event to the destinations you have configured for that domain (Meta Pixel + Conversions API, Google Analytics 4, and/or Google Enhanced Conversions for Web), using a shared event ID for de-duplication. We do not sell or retain this data for our own marketing.
2.6 Website Chat (Pre-Sales Assistant)
When contact verification is enabled for our website chat, we ask for your name, email address, and company or website, and optionally your phone number, monthly advertising budget, and the advertising platforms you use. We send a verification code to your email address that you enter before chatting. We also record the messages exchanged in the chat, the page you started it from, your referrer, and any campaign parameters (such as UTM tags) present in the URL, along with your IP address and browser user agent. To generate replies, we send conversation messages and, when available, your name, company, website, advertising budget and platform preferences to OpenAI. In this context we act as the data controller. We use these details to answer your enquiry and to follow up on it; we send marketing communications only if you tick the optional consent box, and you can withdraw that consent at any time.
3. How We Use Information
We use the information we collect to:
- Provide and operate the Service, including fraud detection, visitor classification, and automated blocking
- Identify returning and repeat sources of invalid activity
- Distinguish legitimate visitors from invalid or automated traffic
- Generate threat scores and make automated blocking decisions
- Record and replay visitor sessions, where session recording is enabled for the customer’s domain, for verification purposes
- Manage Google Ads IP exclusion lists and Meta Custom Audience exclusions based on detected threats
- Provide analytics, reporting, and AI-assisted analysis
- Send notifications about detected threats and account activity
- Process payments and manage subscriptions
- Improve and develop our fraud detection capabilities
- Respond to support requests
- Answer and follow up on enquiries you start in our website chat, and — where you have consented — send you product news
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, we process personal data under the following legal bases:
- Contractual necessity: Processing necessary to provide the Service you have subscribed to
- Legitimate interest: Processing for fraud prevention and security purposes, which constitutes a legitimate interest under GDPR Recital 47
- Consent: Where required by law, such as for certain types of cookies or marketing communications
- Legal obligation: Where processing is required to comply with applicable laws
5. Data Sharing and Third Parties
We share personal data with the following categories of service providers, solely as necessary to operate the Service:
- Payment processor — secure payment and billing processing
- Google Ads API — IP exclusion list management and enabled account reporting and optimization features (only when you connect your Google Ads account)
- Meta Marketing API (Facebook) — Custom Audience exclusion management and enabled account reporting (only when you connect your Meta ad account)
- Meta Conversions API, Google Analytics 4 Measurement Protocol, Google Enhanced Conversions for Web — conversion event delivery, only when ConversionOS is enabled through standalone True Tracking or a protection-plan add-on and you have configured the corresponding destination for a domain
- Google Gemini — AI-powered traffic analysis
- OpenAI — replies from our website chat assistant, using conversation messages and available enquiry context
- GeoIP services — IP address geolocation
- Hosting infrastructure — secure data storage and application delivery
We do not sell, rent, or trade your personal data to third parties for marketing or advertising purposes.
We may disclose information if required by law, regulation, or legal process, or to protect the rights, property, or safety of AdProtektor, our customers, or others.
6. Data Retention
We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this policy:
- Account data: retained while your account is active and for a reasonable period afterward
- Tracking events, visitor identifiers and conversion history: retained as needed for traffic analysis, fraud investigation, attribution and revenue reporting. Base event records may remain longer than the ConversionOS detail-cleanup period below; there is no automatic 90-day deletion limit for all tracking data.
- ConversionOS detail records: order line items and conversion-delivery records have a default cleanup period of 730 days (approximately two years). Authorized administrators can configure a different period. This cleanup does not delete the base event records used for revenue history.
- Blocked IP and visitor records: retained for the duration of the blocking period configured in your settings
- Session recordings: retention windows depend on the subscription and recording type. Across Standard, Pro and Enterprise, windows range from 7 days for ordinary replays to 90 days for fraud evidence; custom plans may specify different periods.
- Payment records: retained as required by applicable tax and financial regulations
Automatic cleanup depends on the configured retention period and whether cleanup is enabled. If cleanup is suspended, records may remain beyond the default or plan-based window until cleanup resumes or a deletion request is processed. Contact support@adprotektor.app to confirm the applicable settings or request deletion.
These operational settings do not override applicable deletion obligations. For personal data processed on a customer’s behalf, termination and deletion follow the Data Processing Agreement, including its 30-day deletion commitment unless retention is required by law. Other account and payment records remain subject to the purposes and legal requirements described above.
7. International Data Transfers
AdProtektor processes data on servers located in the United States. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States.
For transfers of personal data from the EEA, UK, or Switzerland, we rely on appropriate transfer mechanisms, including Standard Contractual Clauses (SCCs) where applicable.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Objection: Object to processing based on legitimate interest
- Restriction: Request that we restrict the processing of your data
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at support@adprotektor.app. We will respond to your request within 30 days. If you connected a Meta ad account, you can revoke AdProtektor’s access at any time by removing us as a partner in your Meta Business Settings; doing so stops all further access to that ad account.
California Residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a request, contact us at support@adprotektor.app.
9. AdProtektor as a Data Processor
When AdProtektor collects data from the websites of our customers (via the tracking script), we act as a data processor on behalf of our customers, who are the data controllers.
Our customers are responsible for ensuring they have a lawful basis for the data collection performed by the tracking script, including providing appropriate privacy notices and obtaining consent from their website visitors where required.
The relationship between AdProtektor and our customers as data controllers is governed by our Data Processing Agreement.
10. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS), access controls, input masking in session recordings, and regular security reviews.
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
11. Children’s Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at support@adprotektor.app and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on our website. Your continued use of the Service after such changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
AdProtektor Inc.
Email: support@adprotektor.app