Privacy Policy
Last Updated: October 2026
1. Introduction
AdPeak Ltd (“AdPeak,” “we,” “our,” or “us”) is a company registered at Companies House under company number 17261264, with its registered office at M-SPARC, Menai Science Park, Gaerwen, Gwynedd, LL60 6AG, United Kingdom. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our website, products, services, or applications (collectively, the “Services”).
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
This Privacy Policy should be read together with our Terms of Service, our Data Processing Addendum, and our Sub-Processor list.
2. Our Role: Controller and Processor
AdPeak acts in two different capacities depending on the data concerned:
- As a controller. For the personal data we collect to operate our business and provide the Services to you — including account and contact details, authentication credentials, billing information, website usage data, and support communications — AdPeak determines the purposes and means of processing and is the data controller.
- As a processor. When you connect an account to the Services (such as Google Ads, Google Merchant Center, Meta Ads, or Shopify — see Sections 3.2 to 3.12), or otherwise make data available to the Services (for example, by uploading a file, by what you write in a conversation, or through memory files — see Section 3.13), we process that data on your behalf and on your documented instructions in order to provide the Services. For that data, you (or your organisation) are the controller and AdPeak is the processor. This processing is governed by our Data Processing Addendum, which forms part of your agreement with us.
The Services are designed not to need personal data about your customers. They work on advertising, catalogue, and sales performance data, which in the ordinary course does not identify your customers or other end-consumers. Where a connected platform could return customer details, we limit what we request: for example, our Shopify integration is technically prevented from reading your shoppers’ names, email addresses, phone numbers, or postal addresses (see Section 3.11). Connected-account data can nonetheless contain some personal data — such as the names or email addresses of your own staff in account change histories, or whatever you choose to include in a conversation or file. You are responsible for having a lawful basis to make that data available to us, and we process it only as a processor under the Data Processing Addendum.
3. Information We Collect
3.1 Personal Information (AdPeak as controller)
We collect personal information that you voluntarily provide to us when you:
- Register for an account
- Subscribe to our Services
- Request customer support
- Participate in surveys or promotions
- Communicate with us
This information may include:
- Name
- Email address
- Phone number (for example, if you link WhatsApp to your account)
- Company name
- Billing information, including billing country and, where you provide one, a VAT number (payments are processed by our payment provider — see Section 7)
- Account credentials and authentication identifiers (including Google account identifiers used for sign-in)
- The name and email address of the account you use when you connect a third-party platform (for example, the Google account or Facebook user that authorised a connection)
3.2 Google Ads Account Data (AdPeak as processor)
When you connect your Google Ads account to our Services, we read information from your Google Ads account in order to analyse performance and generate reports, insights, and product-labelling outputs, including but not limited to:
- Campaign and ad-group data
- Ad performance metrics (such as clicks, impressions, cost, and conversions)
- Product-level performance data
- Historical campaign information
- Account change history, which may include the email addresses of people in your organisation who made changes
We use Google Ads data to report and analyse. AdPeak does not create, edit, pause, or otherwise change your Google Ads entities, except where the plan-and-apply feature has been made available to you, you have enabled it, and a specific plan has been explicitly approved (see Section 14 and our Terms of Service).
3.3 Google Merchant Center Account Data (AdPeak as processor)
When you connect your Google Merchant Center account to our Services, we read information from your Merchant Center account, including but not limited to:
- Product catalogue data (titles, descriptions, prices, and other attributes)
- Data-source information (feed schedules, statuses, and file information)
- Account settings, and market insights that Google provides for your account (such as price competitiveness and best-selling products)
Based on this data, we generate a product-labelling output feed that we make available to you at a stable URL. Output feeds contain product identifiers and labels only. You choose whether to connect that feed to your Merchant Center account as a supplemental feed. When you do, your Merchant Center fetches the labels from the feed. AdPeak does not change your Merchant Center product data or data sources through Google’s API. (To use Google’s Merchant API, we register AdPeak’s own Google Cloud project with your Merchant Center account when you connect it; this does not change your product data.)
3.4 Google API Services — Limited Use
AdPeak’s use and transfer of information received from Google APIs (including the Google Ads API, the Google Merchant Center / Content and Merchant APIs, and, where you connect them, the Google Analytics, Search Console, and Tag Manager APIs) adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We access Google user data only to provide and improve the user-facing features of the Services described in this Privacy Policy.
- We do not transfer or sell Google user data for advertising, or for any purpose other than providing or improving those features, except as necessary to comply with applicable law or as part of a merger or acquisition.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless: we have your consent for specific data; it is necessary for security purposes (such as investigating abuse); it is required to comply with applicable law; or the data has been aggregated and anonymised.
- We do not use Google user data to train, fine-tune, or otherwise develop generalised or foundation AI/ML models, and, under the applicable providers’ data-processing terms and the account settings we configure, our AI model providers do not do so either (see Section 6.2).
3.5 Usage and Analytics Data (AdPeak as controller)
When you access our Services, we automatically collect certain information about your device and usage patterns, including:
- IP address
- Browser type and version
- Device type and model
- Operating system
- Access times and dates
- Pages viewed and time spent on pages
- Features used and actions taken
- Referring websites
- Error logs and performance data
3.6 Conversation and Assistant Data
When you interact with our AI assistant, agents, or MCP-connected tools — in the AdPeak app, in Slack, or through WhatsApp where available — we collect:
- Messages sent to and received from the AI assistant, and who sent them
- The tools the assistant used and their results, including data retrieved from your connected accounts
- Files you attach to a conversation (currently CSV files), and reports or exports the assistant generates
- Plan-and-apply approval records (your decisions to approve, reject, or modify proposed actions)
- Conversation metadata such as timestamps, the organisation and businesses a conversation relates to, and the agent used
Conversations, including the tool results within them, are stored in your account so that you can return to them, and are used to provide our AI-powered features and to maintain records of actions taken on your behalf. Conversation content may include connected-account data, which we process as a processor under the Data Processing Addendum. The assistant does not need personal data about individuals to work, so please do not include it in your messages or files unless it is necessary.
Who can see a conversation. Conversations are private to the person who started them unless that person chooses to share one. The owner can share a conversation read-only with their organisation, in which case any current member of the organisation who has the link can read the whole conversation, including tool results.
Slack. If your organisation connects Slack, anyone who can post in a Slack channel or conversation where AdPeak is present can send requests to the assistant and continue threads that AdPeak started, and those requests are answered using your organisation’s connected data. Only add AdPeak to channels whose members should have that access.
Memory. The assistant and agents can save and read memory files, as described in Section 3.13. They do not learn automatically from your conversation history.
Access by AdPeak staff. Authorised AdPeak staff may review conversations, including the assistant’s tool calls and results, to provide support and to maintain and improve the Services (for example, to investigate errors and to improve the quality of the assistant’s answers). Staff access is limited to people who need it for those purposes and is subject to confidentiality obligations. Where a conversation contains data received from Google APIs, staff read that data only as permitted by Section 3.4, and we handle data from other connected platforms in line with those platforms’ terms.
3.7 Account Security and Network Information
To secure the Services and protect against account sharing, credential compromise, and account takeover, we collect and process information about how your account is accessed, including:
- IP addresses and browser user agents associated with requests to the Services
- Device, browser, and operating-system characteristics associated with sign-in
- Authentication events, session identifiers, and access timestamps, including approximate location derived at a coarse level from IP address
- Indicators of concurrent or anomalous access used to detect sharing or unauthorised use
We use this information to verify legitimate access, detect and investigate suspicious activity, enforce our Terms (including the account-sharing restrictions in Section 7 of the Terms), and protect our customers and our Services. The legal basis for this processing is our legitimate interests in maintaining the security and integrity of the Services and, where applicable, compliance with legal obligations (see Section 5).
3.8 Free Report and Lead Data
When you request a free report or use a similar promotional tool by signing in with your Google account, we collect:
- Your name and business email address, and other basic profile information you approve at the Google consent screen
- Identifiers for your connected Google Ads and/or Merchant Center accounts
- Summary advertising data used to produce the report, such as spend, clicks, impressions, conversions, and related performance metrics, accessed on a read-only basis
We use this information to generate and deliver your report, to respond to your enquiry, to maintain records of leads in our CRM and sales systems, and — where permitted by applicable law — to send you marketing communications about AdPeak (see Section 4.1). The legal bases for this processing are the steps taken at your request, our legitimate interests in business-to-business marketing, and, where required, your consent (see Section 5).
3.9 Model Improvement Data
To maintain and improve the quality of our optimisation methods, we may analyse anonymised and aggregated data derived from usage of the Services (for example, aggregate performance patterns across accounts). This data does not identify you or any individual, account and user identifiers are removed before aggregation, and we create and use it only where, and to the extent, permitted by the terms of the platforms from which the underlying data originates. We do not use your identifiable data, conversation content, or connected-account data to train third-party or general-purpose AI models, and, under the applicable providers’ data-processing terms and the account settings we configure, our AI model providers do not train their models on your data (see Section 6.2).
3.10 Meta Ads Account Data (AdPeak as processor)
When you connect your Meta (Facebook and Instagram) advertising accounts to our Services, we ask Meta for read access to your ad accounts (the ads_read and business_management permissions) and read information in order to analyse performance and generate reports and insights, including:
- Business, ad-account, campaign, ad-set, and ad structure and settings (including targeting settings)
- Ad performance metrics (such as reach, impressions, clicks, spend, and conversions), which Meta provides in aggregated form
- Ad creative content (such as ad copy, images, and preview links)
- Account change history, which may include the names or identifiers of people in your organisation who made changes
- Quality and diagnostic information about your Meta Pixel and Conversions API datasets
We use Meta data to report and analyse. AdPeak does not create, edit, pause, or otherwise change your Meta campaigns, ad sets, or ads. We do not access Meta audience lists or user-level data about the people who see or interact with your ads, and we use Meta data only to provide the Services to you, in accordance with Meta’s Platform Terms. When you disconnect Meta in the Services, or when your organisation is deleted, we ask Meta to revoke our access. You can also remove AdPeak’s access at any time in your Meta Business settings. To request deletion of data we hold from Meta, see Sections 9 and 10.4.
3.11 Shopify Store Data (AdPeak as processor)
When you connect your Shopify store to our Services, we ask Shopify for read-only access to orders and products (the read_orders and read_products scopes; Shopify limits this to recent orders) and read information in order to analyse product and sales performance, including:
- Product and inventory data (such as titles, variants, SKUs, prices, costs, and stock levels)
- Order-level data (such as order numbers and dates, statuses, line items, quantities, order values, discounts and discount codes, refunds, shipping and tax amounts, order tags, and the marketing source and campaign parameters Shopify records for an order)
Our Shopify integration is technically prevented from reading customer-identifying fields — such as customers’ names, email addresses, phone numbers, postal addresses, IP addresses, and order notes — and from looking up customer records. Order-level data can still relate to an individual purchase, so we treat it as personal data processed on your behalf under the Data Processing Addendum. AdPeak does not create, edit, or delete orders, products, or other records in your Shopify store.
When you disconnect Shopify in the Services, we revoke our access, which uninstalls the AdPeak app from your store; you can also uninstall it from your Shopify admin. We act on the data-protection requests Shopify sends us on your behalf: when Shopify asks us to erase a customer’s data, we remove that customer’s identifiers from content stored in your account, and when you uninstall the app and Shopify asks us to erase your store’s data, we delete your store connection.
3.12 Other Connected Platforms and Data You Provide (AdPeak as processor)
You can also connect the following platforms and data sources. When you do, we process the data described below on your behalf, solely to provide the Services:
- Google Analytics, Google Search Console, and Google Tag Manager. We ask Google for read-only access (the
analytics.readonly,webmasters.readonly, andtagmanager.readonlyscopes) and read aggregated website analytics, search performance (such as search queries and page addresses, with their clicks and impressions), and your Tag Manager container configuration, so that the Services can report on your site and check whether your conversion tracking is set up correctly. We do not request individual-user or individual-visitor data from Google Analytics. - Website analytics platforms (Plausible, Matomo, and Fathom). Using an API key you provide, we read aggregated visitor statistics only. We do not request individual visit logs, and we remove query strings from page addresses.
- E-commerce platforms (WooCommerce, BigCommerce, and Squarespace). Using an API key you provide, we read product, stock, cost, and sales information. We only send read requests and never change your store. We do not request customer, billing, or shipping fields; where a platform’s API includes them in a response anyway, we discard them before use.
- Stripe (revenue). Using a restricted, read-only key you create (we refuse full-access keys), we read only your balance, account, and balance-transaction totals — never your Stripe customers, charges, invoices, or payment methods.
- Google Sheets and product feeds. You can provide data by sharing a Google Sheet with AdPeak’s Google service account, or by giving us the address of a product feed. When you add a sheet, you confirm that you have the right to share it with us and that it does not contain personal data. Sheet contents are copied into a data workspace for your organisation (see below), and the copy is deleted when you remove the sheet in the Services. You can also remove AdPeak’s access in the sheet’s Google sharing settings.
- Custom product-labelling strategies. An agent can write queries (SQL) that run in a data workspace in Google BigQuery, located in the European Union, to build product-labelling output feeds from your connected data. Every query is checked before it runs so that it can only read your organisation’s workspace and cannot export data, call external services, or reach other customers’ data. A custom strategy only goes live after a person in your organisation approves it.
You can disconnect any of these in the Services at any time. For platforms connected with an API key, you can also revoke the key in that platform’s settings, and you can remove AdPeak’s Google access in your Google account settings.
3.13 Memory Files (AdPeak as processor)
The AI assistant and agents can keep memory files: short notes, kept between conversations, about your businesses, your ways of working, and decisions or facts that are useful to remember. Memory files are stored in three kinds of folder:
- Business folders belong to a business in your organisation. Every member of the organisation can read them, and members with the Editor role or above can change them.
- Agent folders belong to an agent. Anyone who can see the agent can read them. The assistant can change an agent’s folder only in a conversation or task that runs as that agent, and people need the Editor role or above.
- Your personal folder is private to you. Only you, and the assistant when it is working for you, can use it — other members of your organisation, including owners and administrators, cannot open it in the Services. The assistant uses your personal folder in conversations that are yours: web chat, your scheduled tasks, WhatsApp from your verified number, and MCP clients you connect. It does not use it in Slack.
How memories are created. People can write, upload, edit, and delete memory files in the Services. The assistant can also save notes while it works for you in a conversation or task, including notes it judges useful without being asked (such as your preferences, decisions, or facts about your accounts). Nothing runs in the background to extract memories from your conversation history.
How memories are used. Memory content is not added to the assistant’s instructions automatically. The assistant reads a memory file when it is relevant, and the content it reads becomes part of the conversation: it is sent to our AI model providers (see Section 6.2), or to your MCP client’s AI provider if you use one (see Section 14.2), and is kept in the conversation history. If you share a conversation with your organisation, other readers do not see what the assistant read from or saved to your personal folder or an agent’s folder, but they do see the assistant’s replies, which may reflect it.
Personal data in memory. We instruct the assistant to record information about your business, accounts, and ways of working, and not to store credentials or sensitive personal data (such as contact details, identification or payment numbers, health information, or other people’s details), and not to repeat your personal notes where others can see them unless you ask. These are instructions to the AI rather than technical guarantees, so please review your memory files and avoid putting personal data in them, especially in business folders that your whole organisation can read.
Your controls. You can view, edit, download, mark as read-only (so that the assistant cannot change it), and permanently delete memory files at any time, in Settings for your personal folder, on the business page for business folders, and from the agent’s menu for agent folders. Memory files are retained as described in Section 9.
4. How We Use Your Information
Where AdPeak is the controller, we use the information we collect to:
- Provide, maintain, and improve our Services
- Process transactions and send related information
- Analyse and report on your ad campaigns, product catalogue, and sales performance using AI technology
- Power the AI assistant, agents, scheduled tasks, and MCP-connected tools
- Respond to your comments, questions, and requests
- Send you technical notices, updates, security alerts, and support messages
- Monitor and analyse trends, usage, and activities in connection with our Services
- Detect, prevent, and address technical issues, fraud, and security risks
- Verify account access and detect, investigate, and prevent account sharing, credential compromise, and account takeover
- Generate and deliver free reports and other resources you request
- Send marketing communications about our products and services, where permitted by law, and manage your communication preferences
- Develop new products, services, features, and functionality
- Improve our optimisation methods using anonymised and aggregated data only
- Measure the effectiveness of our own advertising on Meta’s platforms, and understand which businesses visit our website, only with your consent (see Section 12)
- Comply with legal obligations
Where AdPeak is a processor, we process connected-account data, data you provide, conversation content, and memory files only to provide the Services and only on your documented instructions, as set out in the Data Processing Addendum. Connecting an account, providing data, or asking the assistant or an agent to carry out a task is one of those instructions.
4.1 Marketing Communications and Your Choices
Where permitted by applicable law, we may use the contact details you provide — including business email addresses captured when you request a free report or other resource — to send you marketing communications about AdPeak’s products and services. For business-to-business marketing we generally rely on our legitimate interests or on the “soft opt-in” available under applicable electronic-marketing rules; in other cases we rely on your consent.
We do not bundle marketing consent into your acceptance of our Terms, and you are never required to agree to marketing in order to use the Services or to receive a free report. You can opt out of marketing at any time by using the unsubscribe link in any message or by contacting privacy@adpeak.ai, and we will honour your request. Opting out of marketing does not stop service, security, or transactional messages that are necessary to provide the Services.
5. Legal Basis for Processing (EU/UK Users)
Where AdPeak is the controller and you are located in the European Union or United Kingdom, we process your personal information based on one or more of the following legal grounds:
- Performance of a contract: Processing necessary to provide the Services under our contract with you (for example, account, authentication, and billing data)
- Legitimate interests: Processing necessary for our legitimate interests, provided those interests are not overridden by your rights. We rely on legitimate interests for purposes including: securing, maintaining, and improving the Services; detecting and preventing fraud, account sharing, and account takeover (including by processing IP addresses and related access data described in Section 3.7); analysing anonymised usage; maintaining audit records of actions taken on your behalf; and direct marketing of our business-to-business services to relevant contacts. Where we rely on legitimate interests, we carry out a balancing assessment, and you may object at any time (see Section 10)
- Consent: Processing based on your specific consent (for example, analytics and marketing cookies and business identification on our website, certain notifications, and advertising measurement with Meta as described in Section 12.3)
- Legal obligation: Processing necessary to comply with legal obligations (for example, tax and VAT records)
You can withdraw consent at any time by contacting us (or, for advertising measurement cookies, by using the Cookie preferences link described in Section 12.2), though this will not affect the lawfulness of processing carried out before withdrawal.
Where AdPeak is a processor of connected-account data, data you provide, or conversation content, the controller (you or your organisation) is responsible for establishing the legal basis for that processing.
6. Sharing Your Information
We may share your information in the following circumstances:
6.1 Service Providers
We share your information with third-party vendors, service providers, and contractors who perform services for us or on our behalf, including:
- Cloud hosting and infrastructure providers
- Payment processors
- Email delivery providers (for account, security, and notification emails)
- Notification and messaging platforms
- Marketing and communication platforms
- Customer relationship management (CRM) and sales tools, in which we store lead and free-report data and manage communications with you
These service providers are bound by written agreements to process personal data only on our instructions and in accordance with this Privacy Policy and the Data Processing Addendum. Our current sub-processors are listed at /sub-processors.
Destinations you choose. When you ask us to, we also send data to services you select, such as Slack workspaces, webhook destinations (for example, Microsoft Teams, Google Chat, Discord, or your own HTTPS endpoint), email recipients and, where available, WhatsApp numbers for scheduled task results, and MCP clients you connect (see Section 14.2). Those services receive the content you have chosen to send them and process it under their own terms.
6.2 AI Model Providers
To power the AI assistant, agents, and analysis capabilities within our Services, certain categories of your data are processed by third-party AI model providers. The data shared with these providers may include:
- Product catalogue data, performance metrics, and other connected-account data included in a request
- Conversation content (messages you send to the AI assistant, files you attach, and responses generated)
- Memory file content the assistant reads or saves while working on your request (see Section 3.13)
- Tool invocation parameters and results necessary to fulfil your requests
We route AI inference to a primary provider, Google Cloud Vertex AI, and — where the primary provider is unavailable or at capacity, and for some specific tasks — to OpenRouter, which passes the request to an upstream model provider. Our controls require that:
- No training on your data. Under the applicable providers’ data-processing terms, and the account and routing settings we configure, your data is not used to train their foundation or general-purpose models.
- Request-time processing. AI providers process your data to return a response to the request. AdPeak itself stores conversations only as described in Section 9; any temporary handling of requests by AI providers is governed by their terms.
- Location. AI inference may take place outside the United Kingdom and European Union, including in the United States (see Section 11).
The providers we use are listed on our Sub-Processor list, which we maintain as a living document. We commit to providing at least 30 days’ notice before adding any new AI model sub-processor.
6.3 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal information.
6.4 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (for example, a court or government agency). We may also disclose your information to:
- Enforce our Terms of Service
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing in connection with the Services
- Protect the personal safety of users of the Services or the public
6.5 With Your Consent
We may share your information with third parties when we have your explicit consent to do so. In particular, if you accept advertising measurement cookies, we share the data described in Section 12.3 with Meta Platforms Ireland Limited (for UK and EEA users) or Meta Platforms, Inc. (elsewhere, as applicable) to measure the effectiveness of our ads. See the Meta Privacy Policy.
7. Sub-Processors
We maintain a list of sub-processors (third-party service providers that process personal data on our behalf) at /sub-processors. This list includes AI model providers, cloud infrastructure providers, and other services integral to delivering our platform.
We will update the sub-processor list when we engage new sub-processors and will provide at least 30 days’ advance notice before any new sub-processor begins processing your data, as set out in the Data Processing Addendum. If you have concerns about a new sub-processor, you may contact us at privacy@adpeak.ai.
8. Data Security
We have implemented appropriate technical and organisational measures designed to protect the security of personal data we process. These measures include:
- Encryption of personal data in transit and at rest, with connection credentials (such as OAuth tokens and API keys) additionally encrypted using keys managed in Google Cloud Key Management Service
- Access controls, least-privilege authorisation, role-based permissions within each organisation, and authentication requirements (including two-factor authentication)
- Separation of each organisation’s data, with every conversation, connection, memory file, and resource tied to a single organisation, and personal memory folders accessible only to their owner
- Read-only access to connected platforms except where you have approved a plan under the plan-and-apply feature, and technical controls that limit the data we can request (see Sections 3.10 to 3.12)
- Checks on every agent-written query so that it can only read your organisation’s data workspace
- Logging and audit trails for actions taken within the Services
- Regular security assessments of our systems
- Staff awareness of data-protection responsibilities
- Incident response procedures, including breach notification as described in the Data Processing Addendum
A summary of our technical and organisational measures is set out in the Data Processing Addendum. No security measures are perfect or impenetrable, and we cannot guarantee the absolute security of your data. We recommend that you also take steps to protect your data, such as using strong passwords, enabling two-factor authentication, and keeping your devices and credentials secure.
9. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this Privacy Policy, and to comply with our legal obligations, resolve disputes, and enforce our agreements.
Specifically:
- Account and connected-account data is retained for as long as your account remains active. Data fetched from connected accounts is stored where a feature needs it — for example, Google Ads and Merchant Center data used for product labelling is stored in our data warehouse, and tool results are stored in the conversations in which they were used.
- Conversations are retained in your account until you delete them or your account is deleted. When you delete a conversation, it is removed from your account immediately and the reports and files it produced are deleted; its stored content is then permanently deleted when your account or organisation is purged (see below).
- Memory files are kept until they are deleted. A memory file you delete is permanently deleted straight away and cannot be recovered, although conversations that already used it keep the copy shown in their history. Deleting an agent or a business permanently deletes its memory files straight away; when businesses are merged, their memory files are combined. When your account is deleted, or you are removed from an organisation, your personal folder and the folders of your private agents are permanently deleted at the end of the 30-day grace period; notes you added to business or shared agent folders stay with the organisation, without your name attached. When an organisation is deleted, all of its memory files are permanently deleted at the end of the grace period.
- Disconnecting an account stops our access to it. Data already fetched from it (for example, in conversations or in a product-labelling dataset that still uses it) is retained until you delete that resource or your account or organisation is purged. You can ask us to delete it sooner (see Section 10.4).
- Individual resources (such as product-labelling profiles, agents, tasks, and reports) can be deleted by you at any time, and follow the same soft-delete then hard-delete lifecycle.
- Account and organisation deletion — grace period. When you delete your account, or an owner deletes your organisation, we immediately mark the account (or the organisation and its data) as deleted and remove it from use. When an organisation is deleted, we also ask Meta to revoke our access to any connected Meta accounts. The account or organisation remains recoverable on request for a 30-day grace period. After that, a scheduled job permanently deletes the associated data from our application database and data warehouse, including conversations, memory files, agents, tasks, connections and their stored credentials, data sources, and product-labelling and data-workspace datasets. Our database backups are kept for about seven days, so deleted data is fully removed from them shortly after the purge. You can also remove AdPeak’s access to a connected platform at any time from that platform’s own account settings.
- Audit logs recording actions taken within the Services (which can include IP addresses and browser user agents) are retained under legitimate interest for security, billing reconciliation, and compliance purposes: for up to 90 days in our operational database, and in our analytics store for as long as necessary for those purposes.
- Usage counters for MCP tools (daily counts of tool calls per organisation, user, and tool) are retained while your account is active.
- Application and security logs are retained by our hosting provider for a limited period for security, account-protection, and abuse-detection purposes, and longer where required to investigate a specific incident or to comply with a legal obligation.
- Free report, lead, and CRM records (including business contact details and the marketing preferences associated with them) are retained for up to 24 months from your most recent engagement with us, or until you ask us to delete them or to stop marketing, whichever is sooner, except that we may retain a minimal suppression record in order to honour your opt-out.
- Advertising attribution records (collected only with your consent; see Section 12.3) are kept while your account is active and are deleted with it, following the account-deletion lifecycle above. Your consent choice itself is stored only in your browser.
- Billing and tax records are retained for as long as required by tax and accounting law.
- Aggregated and anonymised data that no longer identifies you or any individual is not personal data and may be retained for the purposes described in Section 3.9.
Some data may be retained for longer where required to comply with a legal obligation or to establish, exercise, or defend legal claims.
10. Your Data Protection Rights
Depending on your location, you may have certain rights regarding your personal information. Where AdPeak is a processor of connected-account data, we will refer requests to the relevant controller or assist that controller in responding, as required by law.
10.1 For EU/UK Residents (UK GDPR and EU GDPR)
You have the right to:
- Access: Request copies of your personal data
- Rectification: Request correction of inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data in certain circumstances
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Data Portability: Receive your personal data in a machine-readable format to transfer to another controller
- Automated Decision-Making: Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see Section 14.3)
10.2 For California Residents (CCPA/CPRA)
You have the right to:
- Know/Access: Know what personal information is collected, used, shared, or sold
- Deletion: Request deletion of your personal information
- Opt-out: Opt out of the “sale” or “sharing” of your personal information (we do not sell your personal information)
- Non-Discrimination: Not face discrimination for exercising your rights
- Correction: Request correction of inaccurate personal information
- Limit Use: Limit the use and disclosure of sensitive personal information
10.3 For Other Jurisdictions
Many other jurisdictions provide similar rights. We will honour requests from all users to exercise their data-protection rights in accordance with applicable laws.
10.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@adpeak.ai. We may need to verify your identity before responding. We will respond to all legitimate requests within the timeframes required by applicable law (generally within one month for UK/EU GDPR requests and 45 days for CCPA requests). You can also view, edit, and delete your memory files, and delete conversations, resources, connections, and your account, directly in the Services (see Sections 3.13 and 9).
11. International Data Transfers
AdPeak is based in the United Kingdom and hosts platform data on Google Cloud Platform. Our application database and servers are located in the United Kingdom (London), and our data warehouse (Google BigQuery) and file storage are located in the European Union. Your information may also be transferred to, stored in, or processed in other countries, including the United States, where data-protection laws may differ from those in your jurisdiction — for example, by our authentication provider, our email and messaging providers, and our AI model providers.
In particular, AI inference by our primary provider (Google Cloud Vertex AI) and our fallback provider (OpenRouter and its upstream model providers) may take place outside the UK and EU, including in the United States (see Section 6.2). Transfers of personal data from the UK to the EEA rely on the UK’s adequacy regulations for the EEA.
For transfers of personal data from the UK, EEA, or Switzerland to countries not covered by an adequacy decision, we implement appropriate safeguards, which may include:
- The European Commission’s Standard Contractual Clauses (SCCs)
- The UK International Data Transfer Agreement or the UK Addendum to the SCCs
- Reliance on an adequacy decision (such as the UK–US Data Bridge / EU–US Data Privacy Framework where the recipient is certified)
- Derogations such as your explicit consent or contractual necessity, where applicable
Further detail on transfer mechanisms is set out in our Data Processing Addendum.
12. Cookies and Tracking Technologies
12.1 Types of Cookies We Use
We use cookies and similar tracking technologies to operate our website and understand how it is used. We use the following types of cookies:
- Essential cookies: Necessary for the functioning of our website and app, such as keeping you signed in
- Preference cookies: Remember your preferences and settings
- Analytics cookies: Help us understand how visitors interact with our website. Our website (adpeak.ai) uses Google Analytics, which sets cookies and sends Google information about your visit, such as the pages you view, your browser and device, and your IP address. See how Google uses information from sites that use its services.
- Business identification: Our website (adpeak.ai) uses Lead Forensics, which uses the IP address of your visit to identify the business or organisation you are visiting from, and records the pages viewed, so that we can understand which businesses are interested in AdPeak. Lead Forensics identifies organisations, not individuals; we may follow up with the business using contact details that are publicly available or that we already hold, as described in Section 4.1. See the Lead Forensics privacy policy.
- Marketing cookies: Used to measure our advertising, as described below
On adpeak.ai, Google Analytics, Lead Forensics, and the Meta Pixel are loaded only after you accept in our cookie banner, and none of them is loaded if you decline. On app.adpeak.ai, the cookie banner covers the Meta Pixel only. For advertising measurement we use Meta’s _fbp and _fbc marketing cookies, set by the Meta Pixel on the adpeak.ai domain (so they apply to both adpeak.ai and app.adpeak.ai) and used to measure our Meta advertising as described in Section 12.3. Your choice is remembered in your browser’s local storage.
12.2 Your Cookie Choices
You can change or withdraw your choice at any time using the Cookie preferences link in the footer of adpeak.ai (and on the app.adpeak.ai sign-in page), which shows the cookie banner again and stops Google Analytics and the Meta Pixel from sending further data from that page. Withdrawing is as easy as giving consent. Because your choice is stored per site, you may be asked separately on adpeak.ai and app.adpeak.ai.
You can also instruct your browser to refuse all cookies or to indicate when a cookie is being sent, and you can opt out of Google Analytics using Google’s opt-out browser add-on. However, if you do not accept cookies, you may not be able to use some portions of our Services. For EU/UK users, we obtain consent for non-essential cookies and similar technologies in accordance with the Privacy and Electronic Communications Regulations and the ePrivacy Directive.
12.3 Advertising Measurement with Meta — only with your consent
We advertise AdPeak on Meta’s platforms (such as Facebook and Instagram). AdPeak is the controller for this processing. To measure how well those ads work, and only if you accept in the cookie banner on adpeak.ai or app.adpeak.ai, we use the Meta Pixel and Meta’s Conversions API to share the following with Meta:
- From your browser (Meta Pixel): Meta’s first-party cookies
_fbp(a browser identifier) and_fbc(a click identifier, set when you arrive from a Meta ad), together with the pages you view on adpeak.ai and app.adpeak.ai. These cookies are set on the adpeak.ai domain so that they are shared between our website and our app. Meta also receives the information your browser sends with any web request, such as your IP address and browser user agent. - From our servers (Conversions API): when you sign up, start a trial, or make your first subscription payment, we send Meta that event together with a SHA-256 hash of your email address, a SHA-256 hash of your AdPeak user identifier, your IP address, your browser user agent, the
_fbpand_fbcvalues above, and the address of the page (without any query string) where the event happened. For trials and payments we also send the plan value and currency (and, for trials, an estimated subscription value). We do not send your name, your unhashed email address, your payment details, or any data from the accounts you connect to the Services.
To connect a trial or payment (which our payment provider tells us about later) to the browser that saw the ad, we keep a record of the attribution details captured at checkout (your user identifier, the _fbp/_fbc values, IP address and user agent) and whether your first payment has already been reported. This record is deleted with your account (see Section 9).
If you decline, or do not make a choice, the Meta Pixel is not loaded and none of the above is shared with Meta. The legal basis for this processing is your consent (see Section 5). You can withdraw it at any time using the Cookie preferences link (see Section 12.2). Withdrawal stops the Meta Pixel in that browser and stops attribution details being captured from it. It does not recall events already sent to Meta, and a trial or first payment that follows a checkout you completed while you had consented may still be reported; to stop that, contact us at privacy@adpeak.ai and we will delete your attribution record.
Meta processes this data under its Business Tools Terms and, for its own purposes, as described in the Meta Privacy Policy. For users in the UK and EEA the recipient is Meta Platforms Ireland Limited; elsewhere it is Meta Platforms, Inc., as applicable. Data shared with Meta Platforms Ireland Limited may be transferred to Meta Platforms, Inc. in the United States; Meta states that it relies on the EU–US Data Privacy Framework (and its UK Extension) and Standard Contractual Clauses for these transfers (see Section 11).
13. Children’s Privacy
Our Services are intended for business use and are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will promptly take steps to delete it.
14. AI and Automated Processing
14.1 AI Processing
AdPeak uses artificial intelligence and machine learning technologies to provide our Services. This includes:
- Analysing your connected-account data (such as Google Ads, Merchant Center, Meta Ads, and Shopify data) to generate reports, insights, and optimisation recommendations
- Grouping products into performance tiers and generating product-labelling output feeds
- Powering the AI assistant for conversational support and analysis
- Powering agents and scheduled tasks that query your data, prepare reports, and prepare proposed changes for your review, and delivering their results to the destinations you choose
- Saving and reading memory files, so that the assistant and agents can keep useful context between conversations (see Section 3.13)
AdPeak is a decision-support tool. Our AI outputs are recommendations and analysis; they do not change your advertising campaigns unless you approve a plan under the plan-and-apply feature. You decide whether and how to act on them. Where you connect a product-labelling output feed to your Merchant Center, the labels in that feed update automatically each time the labelling runs, until you disconnect the feed or change the labelling.
14.2 MCP and Agent Data Processing
Our Services include agent and tool-use capabilities that may be accessed through MCP (Model Context Protocol) clients such as Claude, ChatGPT, or other compatible applications. When you use these features:
- You initiate the connection. You connect an MCP client by signing in to AdPeak and approving its access on our consent screen, which shows the account and organisation being connected. AdPeak exposes tools that your MCP client can invoke on your behalf, limited to what your plan and role allow.
- Conversation content is processed by your MCP client’s AI provider. When you connect a third-party MCP client to AdPeak, the conversation content (including any data returned by AdPeak tools) is sent to and processed by the AI model provider powering that client. That processing is governed by your agreement with that provider, not by AdPeak.
- AdPeak processes tool requests. When your MCP client invokes an AdPeak tool, we process the request parameters and return results. This may include querying your connected-account data, creating or changing resources in AdPeak (such as product labellings, output feeds, or tasks), or preparing a plan of proposed changes. Where plan-and-apply is available to you, a plan applied through an MCP client relies on the approval you give in that client.
- We record tool usage. We record daily counts of the tools each user calls through MCP, for usage metering and security. We do not store the parameters or results of MCP tool calls, except where a tool itself creates or changes a resource in your account.
You are responsible for reviewing and accepting the privacy practices of any MCP client and its underlying AI provider before connecting it to your AdPeak account.
14.3 Automated Decision-Making
AdPeak does not make decisions that produce legal or similarly significant effects on individuals based solely on automated processing. Our optimisation features are designed with a human in the loop:
- Recommendations, analysis, and reports are provided for your review.
- Product-labelling outputs, including those from agent-built strategies, are made available as a feed that you choose whether to connect to your Merchant Center.
- Where a plan-and-apply feature is available, proposed changes are presented as a reviewable plan that you must explicitly approve before anything is applied.
You remain in control of, and responsible for, the changes you choose to make to your accounts. You can contact us at privacy@adpeak.ai to request human review of any aspect of the Services.
15. Third-Party Links and Services
Our Services may contain links to third-party websites or services that are not operated by us. These third parties have their own privacy policies, and we have no responsibility or liability for their content, activities, or privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last Updated” date at the top of this Privacy Policy
- Sending an email to users where appropriate
Changes are effective when posted on this page. You are advised to review this Privacy Policy periodically.
17. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@adpeak.ai Data protection enquiries: privacy@adpeak.ai Post: AdPeak Ltd, M-SPARC, Menai Science Park, Gaerwen, Gwynedd, LL60 6AG, United Kingdom Company number: 17261264
For EU/UK Data Subjects
If you have concerns about our processing of your personal data, you have the right to lodge a complaint with a supervisory authority in the country where you reside or work. For UK residents, this is the Information Commissioner’s Office (ICO), ico.org.uk. For EU residents, you can find your national data-protection authority on the European Data Protection Board website.
