Privacy policy
Variafy is a service through which an AI assistant manages ad accounts on behalf of their owner.
Who processes the data
[not filled in: legal entity name], [not filled in: registered address]. [not filled in: registration numbers]. Questions and requests: [not filled in: contact email address].
In what role we act
The role differs by category of data, and merging them into one label would be untrue.
- Customer and billing data
- Controller. Email address, company name, plan and subscription status are data about our counterparty under our own contract. We determine the purpose and the retention period.
- The customer's staff
- Processor on the customer's instructions. Who is invited to the console, what role they get and when they are removed is decided by the customer, not by us. We store an email address, a name and a role because the customer asked us to.
- Audit log and usage
- Controller. Records of sign-ins, approvals and service usage are processed for our own purposes: to establish who authorized spending on an ad account, to issue invoices, and to protect the service. This is declared in advance and is outside the customer's instructions.
- Ad account data
- Toward the customer — processor: we act only on their instructions and for their purposes, and data belonging to different customers is stored separately. Toward Meta — an independent controller, as Meta's platform terms require.
What we store
- About the customer: email address, company name, plan, billing status, Stripe identifiers. We never see or store card numbers — payment happens entirely on Stripe's side.
- About the customer's staff: email address, name, role, last sign-in time. There is no password: sign-in uses a single-use link and an email code.
- About activity: who signed in and when, which change they approved or rejected, on which ad account and for what amount. The IP address the request came from.
- About connected ad accounts: ad account ID and name, currency, time zone, granted permissions, ad account health. The access token is stored encrypted.
- About proposed changes: what was to be done, with which figures, who approved it and what the outcome was.
Legal bases
- Performance of a contract — everything the service cannot work without: connecting an ad account, executing changes, billing.
- Legitimate interest — the audit log and service usage records. The interest is specific: the service is used to authorize ad spend, and it must remain possible to establish who did so.
- Legal obligation — accounting and tax records.
How long we keep it
- 1 month
- revoked app connections (ChatGPT, Claude): kept while questions about recent access are resolved; the fact of connecting and revoking stays in the console audit log — live connections are kept until revoked or until they lapse after 60 idle days
- 3 years
- sign-ins and approvals: evidence of who authorized spending on an ad account, should the question come up later — the period follows the limitation period for claims between businesses
- 2 years
- payments and leads that a customer sends in to measure their advertising: kept while comparing this year with the last one still makes sense — no contacts of their customers are stored: a one-way hash at most, and anything that looks personal is dropped at the door
- 3 years
- service usage records: the basis for billing and for resolving disputes about it
- 1 month
- proposed changes: the preview and its arguments, while they can still be disputed — the fact of the approval outlives this cleanup: it is kept in the audit log as a self-contained entry, not as a pointer to this table
- 6 months
- Stripe payment events: protection against processing the same event twice
- 1 month
- sign-up requests: the email address, name and IP address are kept while they back the anti-abuse counter and while a disputed sign-up can be examined — an unaccepted request creates neither an account nor obligations: it expires in twenty minutes and is deleted outright
- 3 years
- data deletion requests: proof that the request was carried out — no personal identifier is kept here, only a hash
- 1 day
- Counts of calls to Meta, needed only to stay under Meta's 5-minute and hourly limits.
- 1 month
- The last known Meta limit state of an ad account.
- 6 months
- Which ad account a Meta object id belongs to, kept to avoid repeating the ownership check.
- 1 month
- Counts of calls to the Google Ads API, needed to stay under the Google Cloud project's daily quota and to measure Google's limits. — no queries and no results: only counts, status, error code and the Google request id
- 1 day
- Google Ads accounts found while a person chooses which of them to connect.
- 1 month
- Lists of image identifiers checked before an upload, kept while a proposal that uses them can still be approved — only identifiers of images inside the ad account library, no files and no personal data
- 1 month
- When the queue email was last sent to an account, kept only to space out those emails — one row per account: a timestamp, no addresses and no message contents
- 1 day
- Counts of competitor research calls, needed only to keep the shared Ad Library access under its hourly limit. — only the account and the time of the call: no domains, no results
- 3 months
- Problems the watchdog and monitors found in an ad account, kept after they stop so that a problem that comes back is recognised as returning — a problem that is still present is kept for as long as it lasts
- 6 months
- Monitors that were deleted, kept so that the question of why their emails stopped has an answer — monitors that are not deleted, including paused ones, are kept until they are deleted
- 6 months
- Scheduled briefs that were deleted, with their schedule and the address they went to, kept so that the question of why they stopped has an answer — briefs that are not deleted, including paused ones, are kept until they are deleted
- 3 months
- Records of failures in the background work of the service and of server errors, kept to find and fix problems that come back — they hold the error text and a short reference such as an ad account connection or a page address, not the content of requests
- 1 month
- unfinished campaigns: the answers a person gave while building one — the texts of the ad, the link, the audience and the budget — kept so that a build interrupted today can be continued tomorrow — a draft creates nothing in the ad account; it is deleted outright once a campaign is built from it and confirmed
- 3 months
- Records of alerts about such failures sent to the service operator, kept to space alerts out
These periods are not a verbal promise: automated cleanup runs against exactly this list, and they cannot be changed without changing it.
Who we share it with
- Meta Platforms
- Everything you ask us to do in an ad account. The service does not work without this. Meta's policy.
- Stripe
- Subscription billing: email address and an internal customer reference. Ad account data is not sent there.
- Railway
- Hosting for the server and the database — our infrastructure provider.
- Your assistant's vendor
- The text of your conversation with the assistant goes to whoever provides it (for example Anthropic or OpenAI), under your agreement with them, not ours. We receive only the resulting tool calls.
We do not sell data and do not share it for anyone else's advertising.
Transfers outside the European Economic Area
Such transfers do occur, and we do not conceal them:
- United States — Meta and Stripe. Both participate in a framework recognized by the European Commission as providing an adequate level of protection.
- Ukraine — if a customer grants console access to a member of staff located in Ukraine, that person views the data from there. There is no European Commission adequacy decision for Ukraine (verified against the Commission's list), so such a transfer is possible only with separate safeguards.
Your rights
You may ask what we hold about you, correct inaccuracies, request erasure, restrict processing, receive your data in a portable form, and object to processing based on legitimate interest. Write to [not filled in: contact email address] and we will respond.
If you are a member of a customer's staff rather than the customer: for most of this data we act on their instructions, so contacting them will be faster. We will still accept your request and pass it on to them.
You have the right to lodge a complaint with a data protection authority.
Deletion
How to delete data obtained through Facebook is described separately: https://www.variafy.com/data-deletion.
Changes
If this policy changes materially, we will tell customers before the change takes effect.