← Back to home

Privacy Policy

Last updated: 2026-07-25

This Privacy Policy describes how Adswave (“we”, “us”, or “our”) collects, uses, stores, and protects your information when you use our web application at adswave.io and related services (the “Service”).

Data controller

The data controller is Adswave Software Kft., registered at 1028 Budapest, Széchenyi utca 21/A, Hungary. Adószám (Tax ID): 33089326-2-41. Cégjegyzékszám: 01 09 458535. You can reach us at hello@adswave.io.

Information we collect

Account information

When you sign up we collect your email address and display name. If you sign in with Google we receive your name, email, and profile picture from Google.

Organization and workspace settings

To run the product we store the settings you create in Adswave: organizations, workspaces, clients, monthly budgets, report configurations, alert rules, team invites and roles, branding (such as logos and agency names), and similar configuration you enter. This is your account structure, not a copy of your full ad account history from Google or Meta.

Connected advertising platform data

When you connect Google Ads or Meta Ads with secure sign-in, we receive access and refresh tokens. We use those tokens to fetch advertising metrics on your behalf (for example campaign results, product and search-term reports, creative asset information, and account structure).

We do not keep a lasting warehouse or archive of your Google or Meta campaign metrics. Numbers are fetched from Google and Meta when you use the Service. For speed, we may keep short-lived caches in memory (typically minutes, and up to about 30 minutes) so the same view does not re-fetch every time. Those caches are temporary and are cleared when they expire, when the service restarts, or when you disconnect.

We do not modify, create, or delete campaigns or other objects in your advertising accounts. Adswave is read-only analysis. You make changes in Google Ads or Meta yourself.

Usage and diagnostic data

We collect anonymised error reports (via Sentry) and basic usage telemetry to maintain reliability and improve the Service. We do not intentionally collect personally identifiable information in those reports.

Payment information

Payments are processed by Stripe. We do not store credit card numbers or bank account details. Stripe may collect information as described in Stripe’s Privacy Policy.

How we use your data

  • To provide, operate, and maintain the Service (budget tracking, campaign analysis, product and keyword checks, creative insights, change history, alerts, and client reports).
  • To authenticate your identity and manage sessions.
  • To process payments and manage your subscription via Stripe.
  • To send transactional emails (for example invitation links and alert notifications you configure).
  • To monitor and improve performance, security, and reliability.
  • To comply with legal obligations.

Sub-processors

We use a small number of third parties to operate the Service. Each is bound by a data processing agreement and may process personal data only on our documented instructions. The current list, what each one receives and where it is hosted, is published at adswave.io/subprocessors. The application and its database run in the European Union (Google Cloud, europe-west1, Belgium).

Google API Services User Data Policy

Adswave’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only request access to the data necessary to provide the features you use.
  • We do not sell, rent, or share Google user data with third parties for advertising, data brokering, or any purpose unrelated to the Service.
  • We do not use Google user data to build user profiles for advertising or to serve ads.
  • We do not use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models, including foundation models. Google user data is never sent to any third-party AI model provider.
  • We only retain Google user data as long as necessary to provide the Service to you. You may revoke access at any time.
  • Access to Google user data is limited to the features described in this policy and is not transferred to other applications.
  • Human access to Google user data is limited to what you have explicitly authorised, what is needed for security purposes (for example to investigate abuse), to comply with applicable law, or where the data is aggregated and anonymised.

Meta Platform data

Data obtained through Meta’s advertising tools is used solely to provide analytics and insights inside Adswave. We comply with Meta’s Platform Terms. We do not sell Meta data, use it to build advertising profiles, or share it with third parties for purposes beyond operating the Service. You can disconnect Meta at any time in Adswave or in Meta Business Integrations. See our Data Deletion page for how to remove connected data.

Legal basis for processing

We process your personal data on the following legal grounds under the GDPR:

  • Contract: processing necessary to provide the Service you signed up for (Art. 6(1)(b)).
  • Consent: when you explicitly grant access to your Google Ads or Meta Ads account via secure sign-in (Art. 6(1)(a)). You may withdraw consent at any time by disconnecting the integration.
  • Legitimate interest: error monitoring, security, and service improvement, where our interests do not override your rights (Art. 6(1)(f)).
  • Legal obligation: where we are required to retain or disclose data by applicable law (Art. 6(1)(c)).

Data sharing

We do not sell your personal data. We share data only with the following categories of service providers, and only to the extent necessary to operate the Service:

  • Google Cloud Platform: hosting, database, and secret management.
  • Firebase (Google): authentication and identity.
  • Stripe: payment processing.
  • Sentry: error monitoring (anonymised).

We may also disclose information if required by law, regulation, or legal process.

Data retention

We retain your account and organization settings for as long as your account is active. Advertising metrics from Google and Meta are not kept as a lasting archive. They are fetched when you use the Service and may sit briefly in short-lived caches for speed, then expire.

When you disconnect an integration, we destroy the stored tokens for that connection in Google Cloud Secret Manager. For Google, we additionally call Google’s token revocation endpoint so the grant itself is withdrawn on Google’s side, not only forgotten on ours. If that call cannot be completed — for example because you already revoked access yourself — we still destroy our copy of the tokens, and you can confirm removal in your Google Account permissions. Meta does not offer an equivalent server-side revocation for this integration: we destroy the stored token, and you can withdraw the grant in Meta Business Integrations.

Deleting your account or organization runs the same revocation and token destruction for every connected account first. Associated personal data (account info, tokens, organization settings, workspaces, clients, budgets, reports, and alert rules) is permanently removed within 30 days, except where retention is required by law. For step-by-step instructions, see Data Deletion.

International data transfers

Our infrastructure is hosted on Google Cloud Platform, which may process data in regions outside the European Economic Area (EEA). Where data is transferred outside the EEA, we rely on Google’s Standard Contractual Clauses (SCCs) and other appropriate safeguards to ensure an adequate level of protection as required by the GDPR.

Security

We take commercially reasonable measures to protect your data. Access tokens are encrypted at rest using Google Cloud Secret Manager. All traffic between your browser and our servers is encrypted via TLS. Access to production systems is restricted and audited.

Cookies and local storage

Inside the Adswave application (after you sign in) we use first-party localStorage and cookies that are strictly necessary to run the Service — storing your authentication token and user preferences. Firebase may set a small number of first-party cookies for authentication. Product usage inside the app is measured with our own first-party, server-side telemetry; we do not load third-party advertising or analytics trackers on signed-in application pages.

On our public marketing pages (such as our homepage and sign-up pages) we use Google Tag Manager, Google Analytics 4, and related Google advertising tags to understand how visitors find and use the site. These may set third-party cookies. They load only after you give consent through our cookie banner, and Google Consent Mode keeps them disabled until then. You can review the categories and change or withdraw your choice at any time via our Cookie Policy.

Your rights (GDPR & applicable law)

If you are located in the European Economic Area or in a jurisdiction with similar data-protection laws, you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: ask us to delete your data (“right to be forgotten”).
  • Restriction: ask us to restrict processing while we verify your request.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at the email below. We will respond within 30 days.

Third-party links

The Service may contain links to third-party websites or services (for example Google Ads, Meta Business Suite, Stripe). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal data.

Children’s privacy

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by placing a prominent notice in the Service. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

Contact

If you have questions about this Privacy Policy or wish to exercise your data-protection rights, please contact us at hello@adswave.io.