PRIVACY POLICY
Privacy policy
How AdPilot uses and retains information, how to manage authorization, and how to request access, correction or deletion.
Service and operator
This policy covers the AdPilot website and advertising management service. The operator and privacy contact are listed at the top of this page.
Advertisers provide their own privacy notices for their websites, Facebook Pages and instant forms. AdPilot's policy does not replace an advertiser's notice about collecting leads.
Information and purposes
- Account and organization
The registration email, name, organization details, member roles and service usage records you provide.
Used for sign-in, team collaboration and organization access control.
- Meta authorization and assets
User IDs, names, permissions and credentials, ad accounts, Pages, linked Instagram accounts, Pixels, form metadata, ad objects and performance statistics obtained through the Meta API you authorize.
Used to connect assets, carry out requested advertising operations and display reports.
- Media and advertising settings
Images and videos you upload, ad copy, audiences, budgets and publishing plans.
Used to store media, create ads and run publishing tasks.
- Orders and payments
Subscription orders, payment status, and settlement amounts, networks, addresses and transaction hashes in payment notifications.
Used to confirm payments, activate service, reconcile records and investigate payment exceptions. Your wallet private key is not needed.
- Operations and security
Audit records, request IP addresses, browser or client identifiers (User-Agent), and necessary error and security logs.
Used to investigate faults, record important actions and protect accounts.
Personal lead downloads from instant forms are not integrated into this service. Creating a form does not mean AdPilot has downloaded the names, phone numbers or other personal lead details entered into it.
Browser storage
The workspace uses browser localStorage for access credentials, refresh credentials and the selected organization identifier to maintain your login and organization context. This is local storage, not a Facebook login cookie. AdPilot does not ask you to provide Facebook browser cookies.
Signing out of AdPilot clears this local login information. You can also clear this site's storage in your browser settings, after which you will need to sign in again. This does not delete server-side business data or revoke Meta authorization.
Providers and data flows
After you authorize a Meta connection, AdPilot reads assets and statistics within that authorization through the Meta API and sends media and advertising settings to Meta as requested by your operations. Meta independently processes data on its platform.
Business records are stored in databases, and media in file or object storage. The application and storage run in the configured hosting environment. When USDT payments are enabled, the BEpusdt payment gateway receives order and settlement requests and returns payment results.
The specific hosting providers, server locations and backup regions still need to be verified against the actual deployment. A US launch does not mean all data is stored in the US. Contact the privacy email for provider and processing details.
Storage and protection
Meta access credentials are encrypted in the database. Business access is controlled by authentication and organization permissions. Do not send Facebook passwords, Meta tokens or wallet private keys to support.
Retention and cleanup
General business data is retained for 3 months after deactivation or account closure. Individual deletion requests and any earlier deletion required by Meta or applicable law are handled separately; this retention period is not a waiting period for deletion requests. Specific retention periods for logs, order records and backups have not yet been finalized. Any data that must be retained and the reasons will be explained when handling a request.
Subscription expiry is not automatically treated as voluntary deactivation or account closure. There is currently no general automatic cleanup on expiry. Staff verify and handle retention and deletion requests.
Access, correction and deletion
Contact the privacy email to request access, correction or deletion. Include your registration email, organization name or ID, and the data involved. Do not attach identity documents, passwords or tokens in your initial message. Staff will verify your identity and the scope, then reply with the arrangements and outcome.
Successfully disconnecting Meta revokes authorization and clears that connection's saved credentials. It does not automatically delete historical assets, reports or audit records. Deleting data stored by AdPilot does not automatically delete ads, Pages or forms on Meta.
Requests involving shared organization data require checks of ownership and organization permissions. One member's request cannot by itself authorize deletion of other members' or customers' data. Sending an email does not mean a request has been accepted or data has been deleted.
Data deletion process
Staff verify and handle deletion requests. Sending an email does not immediately delete an account, organization or Meta ads.
Submit a request
Where possible, send your request from your AdPilot registration email. Include the organization name or ID, the data you want deleted, and related Meta connection or asset IDs if known. If you cannot sign in, explain your situation to the contact email.
Do not attach passwords, tokens, complete identity documents or wallet private keys to your initial request. The button only opens your email app; you must send the email to submit the request. Keep a copy of your sent message.
Verify identity and scope
Staff will verify the requester's identity, asset ownership and organization permissions by email, then confirm the scope and processing arrangements. Shared organization data will not be deleted based solely on an unverified email.
You can also revoke authorization in Meta's app or business integration settings. Neither this action nor disconnecting within AdPilot replaces a request to delete historical data.
Processing and confirmation
After verification, staff handle data stored by the service within the agreed scope and reply in the original email thread with the result. They will explain the scope and reasons for any data retained by law, involving other users or still within a backup retention period.
Deleting data stored by AdPilot does not automatically delete ads, Pages or forms on Meta. Changes to those remote assets require separate, explicit authorization.
Your email app sends the message. Sending does not mean a request has been accepted or data has been deleted. Keep your correspondence.
Policy updates
This page shows the policy date; after formal publication it is the effective date. When data purposes or processing change, we update this page and provide further notice or obtain necessary authorization as appropriate to the change. Editing this policy does not automatically expand Meta permissions.
Contact AdPilot
- Customer support
- support@adpilot.rest
- Privacy and data requests
- support@adpilot.rest
Your email app sends the message. Sending does not mean a request has been accepted or data has been deleted. Keep your correspondence.