Privacy Policy
Last updated: August 23, 2026
This Privacy Policy describes how Adshelf ("Adshelf," "we," "us," or "our") — a service of Life Vitamin Co. LLC, California, USA — collects, uses, discloses, and protects information in connection with the Adshelf websites, applications, and services (collectively, the "Service"). By using the Service you agree to the practices described here. For personal information we hold about you as an account holder, Adshelf is the data controller. Contact: privacy@adshelf.app.
1. Information we collect
- Account information. Your email address, sign-in method (email code or a third-party identity provider such as Google), and account settings. If you sign in with Google, we receive only your verified email address — never your password or profile contents.
- Authentication data. One-time sign-in codes and session tokens, which we store only in cryptographically hashed form, and an essential session cookie.
- Connected platform data. When you choose to connect an advertising or commerce account (such as Meta or Shopify), we access the data you authorize through that platform's official interfaces — for example your ad creatives, spend, impressions, clicks, conversion metrics, and your store's aggregate order and revenue figures — solely to provide analytics to you. Access tokens are stored encrypted and are never sold, shared with other customers, or used for our own advertising.
- Public advertising data. The Service collects and displays advertisements that advertisers have published in public ad-transparency archives (such as the Meta Ad Library). This is public commercial content published by businesses; it is not consumer personal data, and we do not use it to profile individuals.
- Payment information. When paid subscriptions launch, payments will be handled by a PCI-compliant payment processor. We will receive limited billing metadata (such as plan, status, and the last four digits of a card) but never full card numbers.
- Usage and log data. Standard technical logs — IP address, browser type, pages viewed, timestamps, and error events — used for security, abuse prevention, and product improvement.
- Product analytics and session replay. We use Microsoft Clarity to understand how the Service is used — which pages people reach, where they click and scroll, and where they get stuck — so we can fix what is confusing. Clarity records a reconstruction of the page and your interactions with it. Inside the dashboard we mask text before it is recorded, so your spend, revenue, ROAS and the ad copy you research are not captured; what remains is layout, clicks and scrolling. Clarity also collects standard device and network attributes and, in common with such tools, an IP address. We do not use it for advertising and it never receives your connected-platform credentials.
- Traffic analytics. We use Google Analytics 4 to count visits and see which pages and referrers bring people to Adshelf. It records page URLs, referrer, approximate location derived from IP, and coarse device attributes. We do not send it your email address, account identifiers, or any connected-platform data, we have not enabled Google Signals or advertising personalisation, and we do not use it to build advertising audiences.
- Communications. If you contact us, we keep the correspondence so we can respond and improve support.
2. How we use information
- To provide, operate, maintain, and secure the Service;
- To authenticate you and send transactional email (sign-in codes, receipts, service notices) from an Adshelf sending domain;
- To generate analytics and automated (AI-assisted) summaries of advertising content. AI features process ad content and metadata; we do not use your private connected-account data to train machine-learning models;
- To respond to support requests and communicate about the Service;
- To monitor, prevent, and address fraud, abuse, and security incidents;
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not share your connected-account data with other customers or use it for interest-based advertising.
3. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data: to perform our contract with you (providing the Service); for our legitimate interests (securing and improving the Service) balanced against your rights; with your consent where required (e.g., optional integrations); and to comply with legal obligations.
4. How we share information
- Service providers (subprocessors). We use vetted infrastructure providers that process data on our behalf under contractual confidentiality and security commitments — including Cloudflare, Inc. (hosting, storage, and AI inference), Resend (transactional email delivery), Microsoft Corporation (Clarity product analytics and session replay), and Google LLC (Google Analytics traffic measurement).
- Platform interfaces. Data from connected accounts is retrieved via each platform's official interfaces, subject to that platform's terms and permissions you grant.
- Legal requirements. We may disclose information if required by law, subpoena, or to protect the rights, safety, and property of Adshelf, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction; this policy would continue to apply.
5. Cookies
Essential cookies. A session cookie that keeps you signed in, and short-lived cookies used during sign-in (for example, to protect against cross-site request forgery).
Analytics cookies. Microsoft Clarity and Google Analytics each set first-party cookies to recognise a returning session and stitch page views into a single visit, as described in section 1. You can opt out at any time by enabling Global Privacy Control or “Do Not Track” in your browser — we honour those signals for both, and neither tag loads at all when one is set — or by using your browser's cookie controls to block them. The Service works normally either way.
We do not use advertising cookies, and we do not allow cross-site tracking for advertising purposes.
6. Data retention
Account and connected-platform data are retained while your account is active and deleted within 30 days of a verified deletion request. Security and operational logs are retained for a limited period. Public advertising-archive content is retained as part of the Service's research library; it is business content not tied to your identity. You can disconnect any platform at any time, which immediately stops further collection from it.
7. Security
All traffic is encrypted in transit (the .app domain enforces HTTPS). Access credentials and tokens are stored encrypted; sign-in codes and session tokens are stored only as cryptographic hashes; platform permissions follow least-privilege (read-only wherever possible); and internal access to production data is restricted. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.
8. International transfers
We are based in the United States and process data on infrastructure located in the United States and other countries via our providers' global networks. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses implemented by our subprocessors.
9. Your rights and choices
Depending on your location, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have the rights provided by the CCPA/CPRA, including the right to know, delete, and correct — and we do not sell or "share" personal information as defined by that law. To exercise any right, email privacy@adshelf.app; we will verify your request via your account email and respond within the time required by law. We will not discriminate against you for exercising your rights. EEA/UK residents may also lodge a complaint with their supervisory authority.
10. Advertisers and rights holders
If your business's public advertisements appear in the Service and you wish to have them removed, contact privacy@adshelf.app. See our Terms of Service for the removal process.
11. Children
The Service is for business use and is not directed to, and may not be used by, anyone under 18. We do not knowingly collect information from minors.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a revised "Last updated" date, and for material changes we will provide additional notice (such as email). Continued use of the Service after changes take effect constitutes acceptance.
13. Contact us
Adshelf · privacy@adshelf.app · hello@adshelf.app
Adshelf is a service of Life Vitamin Co. LLC.