Security and your data
What we store, where it comes from, who can see it, and how you leave.
Where the competitor data comes from
Every competitor ad on the shelf comes from Meta’s public Ad Library, the register Meta publishes so anyone can see what advertisers run. We store the ad, its copy, its media and the dates we saw it running. We do not scrape private accounts, and nothing on the shelf came from a customer’s connection.
What we store about you
- Your email, your plan, the brands you star, and your connector key.
- If you connect Meta: an encrypted access token for the ad account you chose, and the daily performance rows we pull for it. Tokens are encrypted at rest with a key that lives only in the worker’s secrets, never in the database.
- If you connect Shopify: daily order and revenue totals, never customer records.
Who can see it
The shelf is shared: every account reads every tracked brand. Your own data is not. Your ad account, your spend, your connections and your stars are visible to your account and, on team plans, the seats you invite. Founders can view a workspace read-only to support it, and that access is logged.
How Adshelf touches your ad account
Reads by default. The one write path, the Campaigns view and the connector’s create and status tools, works only on your explicit instruction, creates ads paused, and cannot launch anything live on its own. There is no path that changes billing, payment methods or who has access to your account; those sit behind Meta’s Manage role, which Adshelf never asks for.
Infrastructure
Adshelf runs on Cloudflare Workers with D1 (SQLite) and R2 storage. Traffic is TLS only. Sign-in is a one-time code to your email or Google, with no passwords stored. Connector access uses OAuth with per-account keys you can rotate at any time.
Subprocessors
Companies that handle data on our behalf, and what each one sees:
- Cloudflare (US): hosts the service, the database and the media archive. Everything above lives here.
- Stripe (US): billing. Card details go to Stripe directly and never touch our servers; we hold a customer id and the plan.
- Resend (US): transactional email, such as sign-in codes and the Monday Shelf Report. Sees your email address and the message.
- Meta and Shopify: only when you connect them, through their official APIs, with the scopes you approve.
- An ad-transparency data provider: reads Meta’s public Ad Library on our behalf. It receives brand names and public page ids, never anything about you or your account.
- Google: optional sign-in with Google, and GA4 on the marketing site (not inside the app).
Compliance, plainly
- Data processing agreement: available on request for paid plans; email us and we send our standard DPA for signature.
- SOC 2: not yet. Adshelf is a small team on managed infrastructure; the Cloudflare and Stripe layers hold their own SOC 2 reports. We will publish a date when there is one.
- Data residency: United States.
- Breach notice: affected customers are told by email within 72 hours of our confirming an incident.
Leaving
You can download everything on your account as JSON at any time from Account → Export my data, read everything the connector can see as JSON, disconnect Meta or Shopify in one click, and delete your account and its data from the data deletion page. Competitor ads are shared public history and stay on the shelf.
If Adshelf ever shut down: you get at least 60 days’ notice by email, the export stays open for the whole period, and the shared shelf is published as a bulk download before the lights go out. There is no lock-in to lose.
Reporting a problem
Email hello@adshelf.app. A founder reads it the same day.
Adshelf is operated by Life Vitamin Co. LLC. The privacy policy and terms are the binding documents; this page is the plain-English version.