AdFence legal

How AdFence processes personal data

A plain-language record of processing activities. The full policy is the Privacy Policy.

What we process, and why

  • Account & profile data (name, email, previous email addresses after a change, hashed password, timezone, avatar)

    Operating your account: sign-in, identity, preferences.

    Contract: required to provide the service.

  • Workspace monitoring data (connected ad accounts, scan results, alerts, domains, evidence packs)

    The product itself: detecting and reporting threats to your ad accounts.

    Contract: required to provide the service.

  • Ad platform access tokens (Meta, Google, TikTok)

    Reading your ad account state on your behalf. Stored encrypted (AES-256-GCM); decrypted only server-side at scan time.

    Contract: you connect these deliberately in the app.

  • Billing data (plan, subscription state, card brand and last four digits)

    Charging for the service. Full card numbers never touch AdFence; payment collection is handled by Stripe.

    Contract and legal obligation (accounting records).

  • Session & device data (IP address, browser, device, approximate location)

    Security: the Active devices list in your profile, sign-out-everywhere, and abuse prevention.

    Legitimate interest: protecting your account.

  • Activity & audit logs (who did what, when, from which IP)

    The workspace activity trail and incident forensics.

    Legitimate interest: security and accountability.

  • Consent records (what you agreed to, which version, when)

    Demonstrating consent decisions, including withdrawals.

    Legal obligation (GDPR Art. 7).

  • Product analytics (PostHog)

    Understanding feature usage to improve the product. Runs ONLY after you accept it.

    Consent: opt-in via the cookie banner or Settings → Profile.

  • Support chat (Crisp)

    Live support inside the app, including from error screens.

    Legitimate interest: providing support to signed-in customers.

Processors we rely on

  • StripePayment processing and invoicing
  • ShopifyBilling for merchants who install AdFence from the Shopify App Store
  • SendGridTransactional and alert email delivery
  • PostHogProduct analytics(only with your consent)
  • CrispSupport live chat
  • SentryError monitoring
  • MongoDB AtlasDatabase hosting
  • VercelApplication hosting
  • DigitalOceanBackground worker hosting
  • Amazon S3Evidence pack file storage
  • ipinfoIP geolocation for the session security features
  • Telegram / SlackOptional notification channels, only if you connect them
  • Cloudflare TurnstileBot protection on signup

AdFence also reads data FROM Meta, Google and TikTok on your instruction when you connect ad accounts. Those platforms are data sources you authorize, and you can revoke that access on the platform or in AdFence at any time.

Retention & deletion

  • Deleting your account is a permanent hard delete of your account, every workspace you own, and the data in them. Your access ends immediately (all sessions are revoked) and the deletion itself completes in the background within minutes. There is no soft-delete and no grace period.
  • Exceptions that survive deletion, for one-trial-per-customer fraud prevention only: the card fingerprint that redeemed a free trial (never a card number) and the email address it was redeemed with. That record is what stops a deleted account signing up again for a second free trial, so it is kept rather than erased with the account.
  • Denormalized email addresses also remain inside administrative audit records.
  • Admin action logs are retained for 730 days for compliance.
  • Alert action tokens are purged one week past expiry; stale browser sessions are swept automatically.

Your controls, in the app

  • Export your data: Settings → Profile → Export your data (machine-readable JSON, GDPR Art. 20).
  • Withdraw analytics consent: Settings → Profile → Analytics cookies, or decline in the cookie banner (Art. 7(3)).
  • Delete your account and data: Settings → Profile → Delete account & data (Art. 17).

For anything these controls do not cover, contact [email protected].