Legal Document

Privacy Policy

Last updated: June 21, 2026

Effective date: January 1, 2026

This Privacy Policy describes how Easyad ("we", "us", or "our") collects, uses, stores, and protects your personal information when you use our digital marketing automation platform at https://easyad.in. By accessing or using Easyad, you agree to the practices described in this Privacy Policy.

1

Information We Collect

We collect the following categories of information to provide and improve our services:

1.1 Account Information

  • Full name and email address (collected at signup)
  • Business name and business type (collected during onboarding)
  • Password (stored as bcrypt hash — we never store plain text passwords)
  • Profile information you voluntarily provide

1.2 Connected Platform Data

  • Meta (Facebook & Instagram): OAuth access tokens, ad account IDs, Page IDs, Pixel IDs, and campaign/ad set/ad data you authorize
  • Google Ads: OAuth refresh tokens, Google Customer ID, campaign data you authorize
  • WhatsApp Business: Phone number IDs and message logs for campaigns you run

1.3 Usage & Technical Data

  • IP address, browser type, operating system, device type
  • Pages visited, features used, time spent on platform
  • Error logs and crash reports (for debugging purposes)
  • Referring URL and exit pages

1.4 Campaign & Creative Data

  • Ad copy, headlines, descriptions you create or AI generates on your behalf
  • Uploaded images and generated creatives stored in your account
  • Campaign budgets, targeting settings, and scheduling data
  • Performance data (impressions, clicks, ROAS, conversions) pulled from connected platforms

1.5 Lead & CRM Data

  • Lead information collected via Meta Lead Ads (name, email, phone — as authorized by you)
  • Lead notes, tags, and pipeline stages you add manually
  • WhatsApp conversation logs for leads you import
2

How We Use Your Information

We use the information we collect strictly for the following purposes:

  • Platform Operations: To create, manage, and publish your ad campaigns on Meta and Google Ads on your behalf
  • AI Content Generation: To generate ad copy, images, and creatives using your business details and campaign goals
  • Analytics & Reporting: To display campaign performance metrics, ROAS, lead counts, and spend data in your dashboard
  • Lead Management: To store and display leads captured via your Meta Lead Ads forms
  • WhatsApp Messaging: To send WhatsApp campaigns and manage conversations with your leads
  • Billing: To process subscription payments via Stripe and manage your plan
  • Communication: To send transactional emails (account alerts, campaign status, billing receipts)
  • Platform Improvement: To analyze usage patterns and improve platform features
  • Security: To detect fraud, abuse, and unauthorized access
  • Legal Compliance: To comply with applicable laws and Meta/Google platform policies
We do NOT use your data for advertising our own products to third parties. We do NOT sell, rent, or trade your personal data or your connected platform data to any third party.
3

Meta (Facebook & Instagram) Data

💡This section is specifically required for Meta App Review and explains exactly how we use Meta Platform Data in compliance with Meta's Platform Terms and Developer Policies.

3.1 Meta Permissions We Request

When you connect your Meta account, we request the following permissions. Each permission is used only for the stated purpose:

PermissionWhy We Need It
ads_managementCreate, update, and manage ad campaigns, ad sets, and ads in your Meta ad accounts
ads_readRead campaign performance insights (impressions, clicks, spend, ROAS) for your dashboard
business_managementAccess your Meta Business Manager to list ad accounts and pages
pages_read_engagementList Facebook Pages associated with your account for ad targeting
pages_show_listDisplay the list of Pages you manage to select for campaign publishing
leads_retrievalDownload leads captured via Meta Lead Ads forms that you created
instagram_basicAccess Instagram account information for Instagram ad campaigns

3.2 How We Store Meta Access Tokens

  • Access tokens are encrypted at rest using AES-256 encryption in our PostgreSQL database
  • Tokens are never logged, printed in error messages, or exposed in client-side code
  • Long-lived tokens are refreshed automatically using the Meta Token Refresh API (daily cron job)
  • Tokens are scoped to your specific ad accounts — we cannot access accounts you have not explicitly authorized

3.3 Meta Data We Do NOT Collect

  • We do not collect or store personal data of your Facebook/Instagram page followers or fans
  • We do not collect data about people who see your ads (audience data belongs to Meta)
  • We do not collect your Facebook personal profile data (friends, posts, personal timeline)
  • We do not access any Facebook data beyond what is necessary to manage your ad accounts

3.4 Meta Data Sharing

Meta Platform Data (including your access tokens, ad account data, and lead data retrieved from Meta) is:

  • Used ONLY to provide Easyad services to you — the user who authorized the connection
  • Never sold, licensed, or shared with any third party for advertising or marketing purposes
  • Never used to train AI models or create audience profiles for other advertisers
  • Never transferred to data brokers or analytics aggregators

3.5 Disconnecting Meta

You can disconnect your Meta account at any time from Dashboard → Settings → Connected Accounts → Meta → Disconnect. Upon disconnection:

  • Your Meta access token is immediately deleted from our servers
  • We stop all API calls to Meta on your behalf
  • Historical campaign data already pulled remains in your account (for your records) but can be deleted on request
  • You can also revoke access directly from your Facebook account settings at facebook.com/settings?tab=business_tools
⚠️Easyad is an independent platform and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. Use of Meta services is subject to Meta's own Terms of Service and Privacy Policy.
5

WhatsApp Business Data

  • We use the WhatsApp Business API (via Meta) to send campaign messages and manage lead conversations on your behalf
  • We store message logs (sender, recipient phone number, message content, timestamp) for campaigns you run
  • Phone numbers of your leads are used only to send messages you explicitly schedule or send
  • We do not use your WhatsApp data to contact leads for our own marketing purposes
  • Message logs are retained for 90 days for audit and support purposes, then automatically deleted
6

AI & Content Generation Data

Easyad uses AI models (including OpenAI GPT-4 for copy generation and image generation models for creatives) to power our campaign builder, poster generator, and ad copy tools.

  • Business information you provide (name, description, target audience) is sent to AI providers to generate content
  • We do not use your data to train AI models — your data is used only for inference (generating content for you)
  • Generated content (copy, images) is stored in your account for your use
  • AI providers (OpenAI, Pollinations.ai) process data subject to their own privacy policies
  • You can delete any generated content from your account at any time
💡OpenAI's API does not use data submitted via API calls to train their models (as per their API data usage policy). Generated images and ad copy belong to you.
7

Payment & Billing Data

Easyad uses Stripe as our payment processor. We do not collect or store your credit card numbers, CVV, or full banking information on our servers.

  • Payment card data is handled entirely by Stripe (PCI DSS Level 1 compliant)
  • We store: your Stripe Customer ID, subscription plan, billing cycle, and invoice history
  • Ad spend goes directly through your own Meta/Google accounts — Easyad does not handle your ad spend
  • Subscription charges are billed by Easyad for platform usage only
  • You can manage your billing, download invoices, and cancel from Dashboard → Billing
8

Cookies & Tracking Technologies

8.1 Cookies We Use

Cookie TypePurposeDuration
AuthenticationKeep you logged in to your Easyad account (JWT token)Session / 30 days
PreferencesRemember your dashboard settings and display preferences1 year
AnalyticsVercel Analytics — anonymous usage data (no personal identifiers)Session
EssentialCSRF protection and security tokensSession

We do NOT use third-party advertising cookies, tracking pixels for other advertisers, or behavioral profiling cookies.

9

Data Sharing & Third Parties

We share your data only with the following categories of third parties, and only as necessary to provide our services:

Service ProviderPurposeData Shared
Meta Platforms, Inc.Ad campaign publishing & Lead retrievalYour access token, campaign data you create
Google LLCGoogle Ads campaign managementYour OAuth token, campaign data you create
OpenAI, Inc.AI content generation (copy & images)Business description, campaign brief
Stripe, Inc.Payment processingEmail, subscription plan (no card data)
Vercel, Inc.Platform hosting & analyticsAnonymous usage data, no personal data
Neon / PostgreSQLDatabase hostingAll account data (encrypted at rest)
We NEVER sell your personal data. We NEVER share your Meta Platform Data or Google Ads data with any party other than the platforms themselves. We do not use your data for cross-context behavioral advertising.

We may also disclose your information if required by law, court order, or governmental authority, or to protect the rights and safety of Easyad, our users, or the public.

10

Data Security

We implement industry-standard security measures to protect your data:

  • All data transmitted between your browser and our servers uses TLS 1.2+ (HTTPS)
  • OAuth access tokens and refresh tokens are encrypted at rest using AES-256
  • Passwords are hashed using bcrypt with a salt factor of 12
  • Database access is restricted to application servers only (no public database exposure)
  • API endpoints are protected with JWT authentication and rate limiting
  • Meta Webhook signatures are verified using HMAC-SHA256 on every incoming request
  • Regular security audits and dependency vulnerability scanning
  • Production environment variables are stored securely and never committed to code repositories
⚠️No system is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security of data transmitted over the internet. Please use a strong, unique password for your Easyad account and enable two-factor authentication where available.
11

Data Retention & Deletion

Data TypeRetention Period
Account data (name, email, profile)Until account deletion + 30 days
Meta access tokensUntil you disconnect Meta or delete account (immediate deletion)
Google OAuth tokensUntil you disconnect Google or delete account (immediate deletion)
Campaign data & creativesUntil account deletion + 30 days
Lead data from Meta Lead AdsUntil you delete the lead or delete your account
WhatsApp message logs90 days, then auto-deleted
Payment/billing records7 years (required by Indian tax law)
Server logs & analytics90 days rolling window
12

Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Portability: Request your data in a machine-readable format (CSV/JSON)
  • Right to Object: Object to processing of your data for specific purposes
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Withdraw Consent: Disconnect connected platforms (Meta/Google) at any time from Settings
  • CCPA Rights (California): Right to know, delete, opt-out of sale (we do not sell data), and non-discrimination

To exercise any of these rights, email us at easyad.ai.marketing@gmail.com with the subject line "Data Rights Request". We will respond within 30 days.

13

Data Deletion Instructions

Meta requires all apps using their API to provide clear data deletion instructions. This section explains exactly how to delete your data from Easyad.

Method 1 — Delete From Dashboard (Recommended)

  1. Log in to your Easyad account
  2. Go to Dashboard → Settings → Account
  3. Scroll to the bottom and click "Delete My Account"
  4. Confirm deletion — all your data will be permanently deleted within 30 days

Method 2 — Disconnect Meta Only

  1. Go to Dashboard → Settings → Connected Accounts
  2. Click "Disconnect" next to Meta
  3. Your Meta access token is deleted immediately
  4. You can also revoke from Facebook at: facebook.com/settings?tab=business_tools

Method 3 — Email Request

Email easyad.ai.marketing@gmail.com with subject "Data Deletion Request". Include your registered email address. We will confirm deletion within 7 business days and complete it within 30 days.

What Gets Deleted

  • All account information (name, email, password hash)
  • All Meta and Google OAuth access tokens (immediately)
  • All campaigns, ad creatives, and generated content
  • All lead data imported from Meta Lead Ads
  • All WhatsApp message logs
  • All analytics and usage data

Billing records are retained for 7 years as required by Indian GST/tax law. These records contain only transaction amounts and plan details — no sensitive personal information beyond your email address.

14

Children's Privacy

Easyad is a business tool intended for use by adults and businesses only. Our platform is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children.

If you believe we have inadvertently collected data from a child, please contact us at easyad.ai.marketing@gmail.com and we will delete it promptly.

15

International Data Transfers

Easyad is operated from India. When you use our platform, your data may be processed by our third-party providers (such as Vercel, OpenAI, and Stripe) in the United States or other countries.

These providers maintain appropriate data transfer mechanisms including Standard Contractual Clauses (SCCs) and comply with applicable data protection laws. By using Easyad, you consent to your data being transferred to and processed in these countries.

16

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

  • We will notify you of significant changes by email (to your registered address) at least 7 days before they take effect
  • For minor updates, we will update the "Last Updated" date at the top of this page
  • Continued use of Easyad after the effective date constitutes acceptance of the updated policy
  • Past versions of this policy are available upon request
17

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Company

Easyad

Location

India

Response Time

Within 30 days for data requests

Support

Available Monday–Friday, 10 AM–6 PM IST

© 2026 Easyad. All rights reserved.

Terms of ServiceContact← Back to Home