Privacy Policy

Last updated: May 2026

1. Introduction

Welcome to ADsHisaab ("we," "our," or "us"). We are committed to protecting your personal data and your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services at adshisaab.com.

This policy is governed by and complies with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 (IT Act), and the rules thereunder. By using our services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We collect the following types of information:

2.1 Information You Provide

  • Account information: Your name, email address, agency name, and password when you create an account.
  • Brand information: Brand names, logos, and client details you add to your dashboard.
  • Recipient details: Email addresses of report recipients you configure for each brand.

2.2 Information from Third-Party Platforms

When you connect your advertising accounts, we access data from:

  • Google Ads: Campaign names, spend, impressions, clicks, and conversions.
  • Meta Ads (Facebook/Instagram): Campaign names, spend, impressions, clicks, and conversions.
  • Google Analytics 4 (GA4): Conversion events, session data, and traffic sources.

OAuth tokens from Google and Meta are encrypted using AES-256 before storage. We never store plain-text access tokens.

2.3 Automatically Collected Information

  • Usage data: Pages visited, features used, and actions taken within the platform.
  • Device information: Browser type, operating system, and device identifiers.
  • Log data: IP address, access timestamps, and error logs.

3. How We Use Your Information

We use your information for the following purposes:

  • Service delivery: To pull advertising data, calculate discrepancies, generate PDF reports, and send automated emails.
  • Account management: To create and maintain your account, authenticate your identity, and provide customer support.
  • Communication: To send you service-related emails (report delivery, account alerts, security notifications).
  • Improvement: To understand how our service is used and improve features, performance, and reliability.
  • Security: To detect, prevent, and address technical issues, fraud, and security vulnerabilities.
  • Legal compliance: To comply with applicable laws, regulations, and legal processes in India.

4. Third-Party Services

We integrate with the following third-party services. Each has its own privacy policy:

We only share the minimum data necessary with each service to deliver our functionality. We do not sell your data to any third party.

5. Data Storage & Security

We take the security of your data seriously and implement the following measures:

  • All OAuth tokens are encrypted using AES-256 encryption before storage.
  • Passwords are hashed using bcrypt with a salt factor of 12.
  • All data transmission uses HTTPS/TLS encryption.
  • Database access is protected by Row Level Security (RLS) policies.
  • Admin access is protected by separate bcrypt authentication.
  • We use industry-standard security practices and regularly review our security posture.

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide our services:

  • Account data: Retained until you delete your account.
  • Report data: Retained for the duration of your account to enable historical comparisons.
  • PDF reports: Stored in Supabase Storage and retained until you delete them or your account.
  • OAuth tokens: Retained while the connection is active. Deleted when you disconnect a platform.
  • Logs: System and cron logs are retained for 90 days for debugging and auditing purposes.

When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

7. Your Rights Under Indian Law

Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, you have the following rights:

  • Right to access: You can request a copy of the personal data we hold about you.
  • Right to correction: You can request that we correct inaccurate or incomplete personal data.
  • Right to erasure: You can request that we delete your personal data, subject to legal retention requirements.
  • Right to withdraw consent: You can withdraw your consent to data processing at any time by deleting your account.
  • Right to grievance redressal: You can lodge a complaint with our Grievance Officer if you believe your data protection rights have been violated.

To exercise any of these rights, please contact our Grievance Officer at nandakumarvnadar@adshisaab.com. We will respond to your request within 30 days.

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India as established under the DPDP Act, 2023.

8. Cookies & Tracking

We use minimal cookies necessary for the operation of our service:

  • Essential cookies: Session cookies for authentication (Supabase Auth). These are required for the service to function.
  • Preference cookies: Theme preference (dark/light mode) stored locally.

We do not use third-party tracking cookies, advertising pixels, or analytics trackers. We do not sell or share your browsing data with advertisers.

9. International Data Transfers

Your data may be stored and processed in the following locations:

  • Supabase: Data centers in Singapore (closest to India).
  • Vercel: Global edge network with primary servers in the United States.
  • Resend: Email delivery infrastructure in the United States.

These transfers are necessary to provide our service. We ensure that adequate data protection measures are in place through contractual safeguards and compliance with applicable data protection laws.

10. Children's Privacy

ADsHisaab is intended for use by businesses and professionals. Our service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at nandakumarvnadar@adshisaab.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically. Your continued use of ADsHisaab after any changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Grievance Officer: Nanda

ADsHisaab

Email: nandakumarvnadar@adshisaab.com

Bangalore, Karnataka, India

We will respond to all inquiries within 30 days, as required under the DPDP Act, 2023.