Legal
Privacy Policy
Last updated: August 28, 2026
This policy explains what data pimads collects, why, who it is shared with, and the rights you have over it under the EU General Data Protection Regulation (GDPR). The short version: we collect only what the Service needs to work, we never sell personal data, and you can request deletion of everything at any time.
01Who we are
pimads (pimads.app) is an advertising management tool for Meta and Google Ads, operated from Romania. The operator of pimads is the data controller for the personal data described in this policy. For anything privacy-related, contact the pimads operator through the contact channel you received with your beta access.
02Data we collect
Account data. Your name, email address, and password when you sign up. Passwords are stored only as a cryptographic hash, never in plain text. We also store workspace names and member roles.
Platform connections. When you connect a Meta or Google account through OAuth, we store the access and refresh tokens the platform issues, encrypted at rest, along with basic ad account metadata such as the account id, name, and currency. Tokens are used only to call the platform APIs on your behalf.
Campaign data. Campaign, ad set, ad group, and ad names, their settings (budgets, schedules, bidding, targeting, keywords, assets), and performance metrics fetched from the Meta Marketing API and the Google Ads API for the accounts you connect. This data is processed transiently and cached briefly so the interface stays fast; the platforms remain the system of record.
Usage data. An activity log of the changes made through pimads in each workspace (who changed what, and when), visible to the members of that workspace, plus standard technical logs kept for security and debugging.
Notifications. Your in-app notification inbox and, if a workspace owner configures one, the Slack incoming-webhook URL used to mirror notifications to Slack.
03How we use your data
- to display and edit your campaigns on both platforms,
- to evaluate the automation rules you create and prepare proposed actions for your approval,
- to generate AI insights: the daily digest, suggestions, anomaly notes, and rules drafted from natural language,
- to power dashboards, budget pacing, analytics, and printable reports,
- to operate workspaces, roles, invites, and the activity log,
- to send you in-app and (if configured) Slack notifications,
- to secure the Service and comply with legal obligations.
We do not sell your data, and we do not use your campaign data to advertise to you or to anyone else.
04AI processing
The AI features in pimads run on a third-party AI infrastructure provider. To generate insights, suggestions, and alerts, we send snippets of your ad-performance data (campaign names, settings, and metrics) to that provider. We never send your password, your OAuth tokens, or more data than the feature needs. The provider processes this data as a service provider in order to return the result; we do not sell personal data to it or anyone else. See also International transfers.
05Legal bases
- Contract (Art. 6(1)(b) GDPR): most processing, because it is required to provide the service you signed up for, such as managing your campaigns, running your rules, and operating your workspaces.
- Legitimate interest (Art. 6(1)(f) GDPR): keeping the Service secure, preventing abuse, and debugging problems.
- Consent (Art. 6(1)(a) GDPR): where applicable, for optional features you actively enable; you can withdraw consent at any time.
07Data retention
- Account data is kept until you delete your account.
- Encrypted OAuth tokens are kept until you disconnect the platform or delete your account; disconnecting deletes them immediately.
- Cached campaign data is short-lived and continuously replaced by fresh data from the platforms.
- Activity logs are kept for as long as the workspace exists.
You can request deletion of your account and all associated data at any time by contacting the pimads operator through the contact channel you received with your beta access. We complete deletion requests within 30 days.
08Your GDPR rights
Under the GDPR you have the right to:
- access the personal data we hold about you,
- have inaccurate data rectified,
- have your data erased,
- receive your data in a portable format,
- restrict or object to certain processing,
- withdraw consent where processing is based on it.
To exercise any of these rights, contact the pimads operator through the contact channel you received with your beta access. You also have the right to lodge a complaint with a supervisory authority: in Romania this is the ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal), or you can contact the authority in your own EU country.
09Security
OAuth tokens are encrypted at rest with AES, all traffic is encrypted in transit with HTTPS, passwords are stored hashed, and workspace access is role-based (owner, editor, viewer) with secret invite links you control. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
11International transfers
Some processors are located outside the European Economic Area. In particular, our AI infrastructure provider is based in the United States. Where data leaves the EEA, the transfer is protected by appropriate safeguards under Chapter V of the GDPR, such as the European Commission’s standard contractual clauses.
12Changes to this policy
We may update this policy as the Service evolves. If a change is material we will notify you through the Service or by email before it takes effect. The date at the top of this page always reflects the latest revision.
13Contact
Data controller: pimads, operated from Romania. For any privacy question or request, contact the pimads operator through the contact channel you received with your beta access.