Privacy Policy.

Last Updated: April 13, 2026

Effective Date: April 13, 2026

Adbloop (“we,” “our,” or “us”), operated by Nishith Pandya (sole proprietor, based in Ahmedabad, Gujarat, India), is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and protect information when you use:

  • Adbloop — Meta Ads Dashboard (the “Add-on”), a Google Sheets™ add-on distributed via Google Workspace Marketplace
  • Adbloop SaaS (the “Dashboard”), our web-based application at app.adbloop.com
  • Our website at adbloop.com (the “Website”)

Collectively referred to as the “Service.” By using the Service, you agree to the practices described in this policy.

1. Information We Collect

1.1 Information You Provide Directly

Account information (Dashboard and Add-on):

  • Your email address (via Google Sign-In, or direct signup for the Dashboard)
  • Your name (if provided during signup)
  • Authentication credentials (handled securely by Supabase Auth for the Dashboard; by Google for the Add-on)

Subscription and billing information:

  • Plan selection (Free, Pro, Agency, Enterprise)
  • Payment details — processed entirely by Razorpay (India) or Stripe (international, when active). We never see or store full payment card details.
  • Billing history (invoices, dates, amounts)

Support communications:

  • Name, email, subject, and message content when you contact support@adbloop.com or use the contact form at adbloop.com/contact

1.2 Meta (Facebook / Instagram) Integration Data

When you connect your Meta account to use the Service, we access:

  • Meta Business Manager and Ad Account metadata (account IDs, names, currencies, time zones, spending limits)
  • Pages and Instagram accounts linked to your ad account (IDs, names) — used to select destinations for your ads
  • Campaigns, ad sets, and ads (names, objectives, targeting, creatives, budgets, schedules, delivery status)
  • Performance metrics (impressions, clicks, conversions, spend, CPM, CPC, CTR, ROAS, etc.)
  • Meta Pixels and Custom Conversions linked to your ad accounts — used for conversion tracking setup
  • Creative assets (image and video hashes, ad copy) that you upload or reference

1.3 Google Workspace Data (Add-on Only)

When you use the Adbloop Google Sheets Add-on, we access:

  • The spreadsheet in which the Add-on is installed — Adbloop reads campaign data you enter and writes results back to the sheet
  • Google Drive files you explicitly select — when you upload creative assets (images, videos) to campaigns via the Add-on
  • Your Google account email address — used for licensing (to match your paid subscription to your Google identity)

We do not access: your other Google Sheets, your entire Drive, Gmail, Calendar, Contacts, Docs, or any other Google data beyond what’s listed above.

1.4 Information Collected Automatically

  • Usage data: feature usage patterns, campaigns created, errors encountered — used to improve the product and diagnose issues
  • Technical data: browser type, device information, IP address, pages visited, timestamps (Dashboard only; the Add-on runs entirely within Google’s environment and we do not collect browser telemetry there)
  • Error logs: stack traces and error context when the Service encounters issues — used for debugging; scrubbed of personal identifiers where possible

2. How We Store Your Meta Access Token

This section describes our handling of Meta (Facebook) access tokens in detail, because it is material to our data practices and your trust.

2.1 In the Google Sheets Add-on

Your Meta access token is stored in Google’s encrypted PropertiesService — specifically, in User Properties scoped to your Google account within the Apps Script runtime. The token never leaves Google’s infrastructure. Adbloop’s servers never receive or store Add-on user tokens.

2.2 In the Dashboard (SaaS)

Your Meta access token is stored encrypted at rest in our Supabase database (hosted on AWS infrastructure in the ap-south-1 region). Encryption uses industry-standard AES-256. The token is used by our backend (Supabase Edge Functions) to make authenticated requests to Meta’s Marketing API on your behalf when you perform actions in the Dashboard or when scheduled operations run (e.g., automated rules, scheduled reports).

2.3 Token Deletion

When you disconnect your Meta account from the Dashboard, your Meta access token is deleted immediately and permanently from our database. No copies, no backups, no soft-delete. You can disconnect at any time from the Dashboard’s Settings page or by revoking app permissions in your Meta Business Settings at business.facebook.com/settings/business-users.

When you delete your Dashboard account, any stored Meta access token is deleted as part of the account deletion process within 30 days.

2.4 What We Never Do

  • We do not sell, share, rent, or license your Meta access token to any third party.
  • We do not use your Meta access token for any purpose other than providing the Service features you have explicitly enabled.
  • We do not train AI or machine learning models on your Meta data.
  • We do not share Meta ad performance data across users — your data is isolated to your account.

3. How We Use Your Information

We use the information we collect to:

  1. Provide the Service — create, edit, and analyze your Meta ad campaigns; deliver dashboards, reports, and creative library features
  2. Authenticate and authorize access — verify your identity, enforce your subscription tier, prevent unauthorized use
  3. Process payments — bill your subscription via Razorpay or Stripe, send invoices and receipts
  4. Communicate with you — send verification emails, billing notifications, important service updates, and responses to support requests
  5. Improve the Service — analyze aggregated usage patterns, fix bugs, develop new features
  6. Ensure security — detect and prevent fraud, abuse, and unauthorized access; maintain audit logs
  7. Comply with legal obligations — respond to lawful requests from government authorities, preserve records as required by law

We do not:

  • Sell your personal information to any third party.
  • Use your data for advertising targeting outside the Service.
  • Use your Meta ad performance data to build benchmarks visible to other users.

4. Legal Basis for Processing (GDPR — EU/EEA Users)

If you are located in the European Economic Area (EEA), European Union (EU), or United Kingdom, our legal bases for processing your personal data are:

  • Contract performance (Art. 6(1)(b) GDPR): to provide the Service you’ve subscribed to or requested.
  • Legitimate interests (Art. 6(1)(f) GDPR): to improve the Service, ensure security, prevent fraud, and communicate with you about the Service.
  • Consent (Art. 6(1)(a) GDPR): where you have given explicit consent — for example, for non-essential marketing communications. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c) GDPR): where processing is necessary to comply with applicable law.

5. Your Rights

Regardless of where you live, you can:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your campaign data and analytics from the Service
  • Disconnect your Meta account at any time
  • Opt out of non-essential communications

To exercise any right, email support@adbloop.com. We will respond within 30 days.

5.1 Additional Rights for EEA / EU / UK Users (GDPR)

  • Right to restriction of processing in certain circumstances
  • Right to object to processing based on legitimate interests
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to lodge a complaint with your local Data Protection Authority

5.2 Additional Rights for Indian Users (DPDP Act, 2023)

  • Right to information about the personal data being processed
  • Right to correction and erasure of personal data
  • Right to grievance redressal — contact our Grievance Officer (see Section 15)
  • Right to nominate another individual to exercise your rights in case of death or incapacity

5.3 Additional Rights for California Residents (CCPA / CPRA)

  • Right to know what personal information we collect, use, and disclose
  • Right to delete personal information we hold about you
  • Right to correct inaccurate personal information
  • Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, so this right is honored by default
  • Right to limit use of sensitive personal information — we do not use sensitive personal information for inferring characteristics
  • Right to non-discrimination — we will not discriminate against you for exercising these rights

We do not use financial incentives tied to the collection, sale, or deletion of personal information.

6. Data Sharing and Disclosure

We share your information only with the following categories of recipients, and only to the extent necessary:

RecipientPurposeData Shared
Meta PlatformsDeliver ad campaign operations you requestMeta access token, campaign data you submit
Google LLCAuthentication (OAuth) for the Add-on and Dashboard; host the Add-on runtimeEmail, OAuth scopes you grant
Supabase, Inc.Database hosting, authentication, and serverless functions for the DashboardAccount data, encrypted Meta tokens, campaign metadata
Amazon Web ServicesUnderlying infrastructure for Supabase (ap-south-1 region)Data stored in Supabase
RazorpayPayment processing (Indian users)Name, email, payment details
Stripe, Inc.Payment processing (international users, when active)Name, email, payment details
Brevo (Sendinblue)Transactional and marketing email deliveryEmail address, name
Law enforcement / governmentComply with lawful requests (subpoena, court order, etc.)As required by law

We do not share your data with advertisers, data brokers, or analytics companies for their own purposes.

7. Data Retention

Data TypeRetention Period
Account information (name, email)For the duration of your account, plus 90 days after deletion
Encrypted Meta access tokensUntil you disconnect (deleted immediately) or close your account (deleted within 30 days)
Campaign metadata in DashboardFor the duration of your account, plus 90 days after deletion
Billing records and invoices7 years (to comply with Indian tax and accounting law)
Support communications2 years from last correspondence
Usage and error logs12 months, then aggregated or deleted
BackupsRolling 30-day window, purged cyclically

8. Data Security

We implement reasonable technical and organizational measures to protect your information:

  • Encryption in transit: All communication with the Service uses HTTPS / TLS 1.2+.
  • Encryption at rest: Meta access tokens and sensitive fields in the Dashboard database are encrypted with AES-256. Backups are encrypted.
  • Access controls: Role-based access to production systems; principle of least privilege; multi-factor authentication for administrative accounts.
  • Authentication: Secure password hashing (bcrypt); rate limiting on login; email verification required before account activation.
  • Row-Level Security: Our Supabase database enforces row-level security policies so that each user can only access their own data.
  • Dependency monitoring: We track security advisories for the libraries we use and patch promptly.

No system is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and the relevant supervisory authorities in accordance with applicable law (including within 72 hours under GDPR).

9. Account Deletion

You can request deletion of your Dashboard account and all associated personal data at any time:

  1. Self-service: From the Dashboard, go to Settings → Account → Delete Account. This permanently removes your account within 30 days.
  2. Email request: Email support@adbloop.com from the email address associated with your account with the subject “Account Deletion Request.” We will confirm identity and process the request within 30 days.

For the Add-on: uninstall via Google Workspace Marketplace. This revokes all permissions. Your spreadsheet data remains yours — it’s never held on our servers. If you also had paid licensing associated with the Add-on, email support@adbloop.com to have the licensing record deleted.

Exceptions to deletion: we may retain billing records for 7 years as required by Indian tax law, and anonymized aggregated usage data that cannot be linked back to you.

10. Google API Services User Data Policy

Adbloop’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  1. We only request the OAuth scopes strictly necessary for the features you use.
  2. We do not use Google user data (including Google Sheets™ content and Drive files) for advertising purposes.
  3. We do not transfer Google user data to third parties except as necessary to provide the Service (e.g., sending authenticated API requests back to Google on your behalf), or as required by law.
  4. We do not use Google user data for serving ads, including retargeting, personalized advertising, or interest-based advertising.
  5. We do not use Google user data to develop, improve, or train generalized AI/ML models.
  6. Humans do not read Google user data unless (a) you give explicit consent for us to do so (e.g., to debug a specific issue you reported); (b) it is required for security, including to investigate abuse; (c) it is necessary to comply with applicable law; or (d) it is aggregated and anonymized for internal operations.

11. Third-Party Services

The Service integrates with third-party services. Your use of those services is governed by their respective privacy policies:

We are not responsible for the privacy practices of these third parties.

12. Cookies and Local Storage

The Dashboard uses cookies and browser local storage for:

  • Essential functionality: maintaining your login session, storing UI preferences (theme, dismissed banners)
  • Security: CSRF protection, session management

We do not use third-party tracking cookies, cross-site advertising cookies, or analytics cookies that build profiles of your behavior across other websites.

The Add-on does not use cookies; it runs entirely within the Google Apps Script runtime.

The Website (adbloop.com) may use minimal first-party analytics in the future (e.g., privacy-respecting tools like Plausible or Fathom). If added, this policy will be updated accordingly.

13. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child, please contact us immediately at support@adbloop.com and we will delete it.

14. International Data Transfers

Adbloop is operated from India. Our primary data hosting (Supabase / AWS) is in the ap-south-1 region (Mumbai, India). Some of our service providers (Google, Meta, Stripe, Brevo) operate globally and may process data outside India, including in the United States and European Economic Area.

For EEA/UK users, where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.

15. Grievance Officer (DPDP Act, 2023)

In accordance with the Digital Personal Data Protection Act, 2023, our Grievance Officer is:

Nishith Pandya

Adbloop (sole proprietor)

Ahmedabad, Gujarat, India

Email: support@adbloop.com

You may contact the Grievance Officer with any concerns about the processing of your personal data. We will acknowledge receipt within 7 days and resolve grievances within 30 days.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the “Last Updated” date at the top
  • For material changes: notify registered users by email at least 30 days before the changes take effect
  • Post the updated policy at adbloop.com/privacy-policy and app.adbloop.com/privacy-policy

Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Privacy Policy.

17. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or our data practices:

Email: support@adbloop.com

Website contact form: https://adbloop.com/contact

Postal address: Nishith Pandya, Ahmedabad, Gujarat, India (available on request)

© 2026 Adbloop by Nishith Pandya. All rights reserved.