Privacy Policy (Advize)
Effective Date: 16/04/2025
App Name: Advize
Legal Entity: Advize Creative Analytics Private Limited
Contact: contact@getadvize.ai
1) Introduction & Scope
This Privacy Policy explains how Advize (“Advize,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our website and the Advize platform (the “Service”). By using the Service, you agree to this Policy. If you do not agree with any part of these policies, you may not use the App.
What we do: With your explicit authorization, Advize connects to your Meta (Facebook and Instagram), LinkedIn, and Google accounts to analyze creative assets and performance data. Where you have engaged us for these services, Advize may also create, manage, and optimize advertising campaigns, publish, schedule, and boost organic content, and upload creative assets and reports to your connected Google Drive, on your behalf, strictly within the scope you authorize. We do not collect your customers’/consumers’ personal data as part of our Service.
2) Roles (Controller vs. Processor)
- Controller (about you and your account): For your account/profile, billing, support communications, site analytics, and operational telemetry, Advize is the Data Controller.
- Processor (data you connect): For data retrieved from Meta, LinkedIn, and Google that you authorize (e.g., ad account data, campaign data, organic page/content data, performance metrics), Advize processes it on your behalf to provide the Service, including managing campaigns and publishing or boosting content where you have specifically authorized us to do so.
3) Information We Collect
We only access the platforms and permissions below with your explicit authorization, and only to the extent needed to provide the services you’ve engaged us for.
From Meta (Facebook & Instagram):
- Pages & Content: Pages and Instagram Business/Creator accounts you manage; content, posts, comments, and reactions; engagement and performance metrics (e.g., via scopes such as
pages_show_list, pages_read_engagement, instagram_basic). - Publishing & Boosting: Where authorized, permission to publish, schedule, edit, and delete organic posts on connected Facebook Pages and Instagram accounts, and to boost or promote existing posts (e.g., via scopes such as
pages_manage_posts, pages_manage_engagement, instagram_content_publish). - Ad Accounts & Campaigns: Ad accounts, campaigns, ad sets, ads, creative metadata, budgets, and performance metrics. Where authorized, permission to create, launch, edit, pause, and manage advertising campaigns on your behalf (e.g., via scopes such as
ads_read and ads_management).
From LinkedIn:
- Authentication (OAuth): We use LinkedIn OAuth to securely authenticate your account and connect your authorized LinkedIn Pages, Ad Accounts, and related resources.
- Community API: With your authorization, Advize may access and manage LinkedIn Company Pages, including retrieving page information, organic posts, engagement metrics, comments, and publishing or managing content where permitted by LinkedIn.
- Advertising API: With your authorization, Advize may access and manage LinkedIn Campaign Manager accounts, including campaigns, ads, creatives, budgets, audiences, targeting, reporting, and performance analytics. This includes creating, editing, optimizing, pausing, and managing advertising campaigns on your behalf.
From Google:
- Google Ads: With your authorization, Advize may access and manage your Google Ads accounts, campaigns, ad groups, ads, keywords, budgets, and performance metrics. This includes permission to create, edit, optimize, pause, and manage advertising campaigns on your behalf.
- Google Drive (upload-only): With your authorization, Advize may create and upload files to your Google Drive using Google’s restricted
drive.file scope — for example, to save creative assets, reports, and campaign documents generated within the platform. This scope only grants access to files that Advize itself creates or uploads; we cannot read, browse, or access your other existing files or folders in Drive.
From You (directly):
- Account & Contact: Name, work email, company, role, and authentication identifiers (including SSO profile attributes, if used).
- Support & Feedback: Messages and attachments you send to us.
Automatically (Service operation and security):
- Technical/Telemetry: IP address, device/browser type and version, timestamps, event logs, referrers, error diagnostics, and similar operational data.
- Cookies/Local Storage: Strictly necessary cookies (session/auth), and—if enabled—preference/analytics cookies.
We do not intentionally collect special categories of personal data (e.g., health, biometric) and we do not ingest your end-customer PII through the Service.
4) How We Use Information
- Provide the Service:
- Authenticate you, connect to Meta, LinkedIn, and Google per your authorization, retrieve and display data, analyze creatives and campaigns, and generate insights and reports.
- Manage Campaigns: Create, launch, edit, pause, optimize, and report on advertising campaigns across Meta, LinkedIn, and Google Ads on your behalf, per your instructions and the account permissions you grant.
- Publish & Boost Content: Publish, schedule, edit, and boost organic content on Facebook and Instagram accounts you authorize, and manage organic content on LinkedIn Company Pages you authorize.
- Deliver & Store Assets: Create and upload creative assets, reports, and campaign documents to your authorized Google Drive to support creative workflows, campaign management, reporting, and collaboration. We do not read or access your other existing Drive files.
- Maintain & Improve: Operate, secure, debug, and improve the Service; monitor performance; develop features.
- Communicate: Send transactional notices (security, updates). With consent or legitimate interest, send product news/education (you can opt out).
- Compliance & Safety: Enforce terms and platform policies; detect, investigate, and prevent fraud, abuse, or security incidents; meet legal obligations.
We only publish, boost, or manage content and campaigns within the scope you explicitly authorize. We do not access private messages, personal inboxes, or content outside the accounts and pages you connect. We do not sell personal data.
5) Subprocessors and Third Parties
To run the Service, we use vetted vendors under written terms that require data protection and confidentiality. Typical categories include:
- Cloud Storage: AWS and Railway for storing processed creative assets and related files.
- Databases: Managed PostgreSQL for application data storage.
- Email & Communication: SMTP services for transactional and support-related emails.
- Error / Log Monitoring & Observability: Railway is used to monitor application logs, detect errors, track system performance, and ensure operational stability.
- Product Analytics: Tools used to understand feature usage, improve the Service, and enhance user experience.
- Authentication / SSO: Services used to provide secure login, identity verification, and single sign-on.
We also disclose information:
- To Meta, LinkedIn, and Google as necessary to authenticate your accounts, manage advertising campaigns, publish or manage content, upload files to your Google Drive, and provide the services you authorize;
- For legal reasons (court orders, lawful requests);
- With your consent or at your direction.
We do not sell personal data.
6) International Transfers & Data Residency
Your information may be processed in countries where we or our subprocessors operate. Where cross-border transfers are required, we implement appropriate safeguards (e.g., Standard Contractual Clauses where applicable) to protect personal data in line with applicable laws. You can email contact@getadvize.ai for details.
7) Security
We implement industry-standard measures, including:
- Encryption in transit and at rest (where supported);
- Principle of least privilege; role-based access; MFA for admin access, including access to connected ad and content management accounts;
- Network and data segregation; audit/event logging;
- Secure development practices and vulnerability management;
- Vendor risk reviews and contractual safeguards;
- Incident response procedures and notifications without undue delay where legally required.
No method is 100% secure; please protect your credentials and use SSO/MFA where available.
8) Data Retention
We retain information only as long as needed for the purposes in this Policy or as required by law. Default windows (unless your plan/contract specifies otherwise):
- Connected Meta, LinkedIn, and Google data (campaigns/creatives/organic content/metrics): retained for the duration of the active engagement, and up to 1 year after the engagement ends or access is revoked, whichever is earlier.
- Account/profile & configuration: for your account term plus 30 days after termination.
- System logs & security events: 60 days (longer if under investigation).
- Billing/transactional records: up to 3 years (legal/accounting).
- Files uploaded to your Google Drive: these files live in your own Google Drive storage, not ours, so once uploaded, their retention is governed by your Drive account and settings, not this Policy. Advize retains only an internal record of what was uploaded (e.g., file name/link) for the same period as your connected Google data, above.
Aggregated or de-identified data may be retained indefinitely.
9) Your Choices & Rights
- Disconnect / Revoke Access: Remove Advize’s permissions via Meta Business Manager, LinkedIn’s Company Page or Campaign Manager admin settings, Google’s third-party app access settings (myaccount.google.com/permissions), or disconnect within the Service at any time.
- Marketing Preferences: Opt out via unsubscribe links or by emailing us. Transactional/security notices will still be sent.
- Access/Correction/Deletion: Email contact@getadvize.ai. We will verify your request and respond within the timelines required by applicable laws.
- Cookies: Manage via our banner (where shown) and your browser settings.
10) Deletion Process
When you request deletion or when your account terminates:
- Your workspace is queued for deletion;
- Active data is deleted within 30 days;
- Remaining copies age out of backups within 35 days;
- We confirm completion upon request;
- Certain records (e.g., invoices) may be retained as required by law.
11) Cookies and Similar Technologies
We use:
- Strictly Necessary Cookies for authentication, sessions, and security;
- Preference/Analytics Cookies to improve the Service (only with consent where required).
You can adjust cookie settings in the banner (where presented) or in your browser. Blocking strictly necessary cookies may impair core functionality.
12) Children’s Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children. If you believe we have, contact us and we will remove it.
13) Changes to this Policy
We may update this Policy from time to time, including as we add new platform integrations. Material updates may be notified by email.
14) Future Platform Integrations
As Advize expands its service offerings, we may integrate with additional platforms (such as YouTube and others) to provide organic content management, advertising management, or reporting services. Any new platform integration will follow the same principles outlined in this Policy: data will only be accessed with your explicit authorization, only the minimum scopes necessary for the services you’ve engaged us for will be requested, and this Policy will be updated to describe the specific data collected and used for each new platform.
15) Contact
Company: Advize Creative Analytics Private Limited
Email: contact@getadvize.ai
Last updated: 17/07/2026