Privacy Policy

Effective Date: September 11, 2026 | Version 2.0 (GDPR & CCPA Compliant)

1. Scope and Roles Under Data Protection Law

This Privacy Policy governs the processing of information by AdSentry ("we", "us", or "our"). Depending on the nature of the data and your interaction with our service:

  • Data Controller: We act as an independent data controller with respect to account registration details, direct customer communications, and billing administration.
  • Data Processor: When performance marketing agencies or DTC brands submit landing page URLs, ad creative identifiers, and redirect parameters for synthetic monitoring, we process that telemetry strictly on their behalf as a data processor pursuant to Article 28 of the General Data Protection Regulation (GDPR).

2. Categories of Data Collected

A. Account & Profile Data: Email address, workspace organization name, and authentication identifiers provided during sign-up.

B. Synthetic Monitoring Telemetry: Target ad destination URLs, HTTP response codes, latency metrics, server redirect hops, HTML DOM stock status indicators, and tracking tokens (such as UTM parameters and Google/Meta click identifiers like gclid or fbclid).

C. Payment Information: All billing, invoicing, credit card, and sales tax compliance are handled exclusively by our Merchant of Record, Paddle.com. AdSentry does not ingest or store payment card numbers on our infrastructure.

D. Technical & Log Data: Origin IP addresses, request timestamps, and browser user-agent metadata logged during dashboard interactions for application security and DDoS prevention.

3. Legal Bases for Processing (GDPR Article 6)

We process personal data only when permitted by applicable law:

  • Performance of Contract (Art. 6(1)(b)): To operate the synthetic inspection engine, execute automated uptime verification, and deliver real-time incident notifications to your configured Slack or email endpoints.
  • Legitimate Interests (Art. 6(1)(f)): To secure our network, prevent abusive or unauthorized scraping, optimize inspection performance, and improve product heuristics.
  • Compliance with Legal Obligations (Art. 6(1)(c)): To maintain corporate records, enforce our Terms of Service, and satisfy statutory tax and reporting requirements.

4. Data Retention & 90-Day Telemetry Policy

We enforce strict data minimization and finite retention windows across all monitoring telemetry:

  • Raw Inspection Telemetry: Point-in-time HTTP responses, redirect hops, and raw headers are retained for a rolling 90-day window, after which they are automatically expunged or aggregated into anonymized uptime statistics.
  • Audit Snapshots: Publicly shareable incident summaries are retained for 180 days or until manually deleted by the organization.
  • Account Records: Active account credentials remain active until workspace termination. Upon verified account closure, customer personal data is purged from our production databases within 30 days.

5. International Transfers & Sub-Processors

AdSentry utilizes trusted third-party cloud infrastructure to deliver high-availability monitoring. Data may be processed in the United States and the European Union by our verified sub-processors:

  • Hosting & Edge Routing: Vercel Inc. (USA)
  • Database & Authentication: Supabase Inc. (AWS EU/US regions)
  • Merchant of Record & Payments: Paddle.com Market Ltd (UK / USA)
  • Transactional Email: Resend Inc. (USA)

Where personal data originating in the European Economic Area (EEA) or UK is transferred to third countries, we ensure appropriate safeguards through the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.

6. Your Statutory Rights (GDPR & UK GDPR)

Under European and UK data protection frameworks, you are entitled to:

  • Access & Portability: Request confirmation and export copies of your personal data;
  • Rectification & Erasure: Correct inaccuracies or request complete deletion of your records ("Right to be Forgotten");
  • Restriction & Objection: Object to processing predicated on legitimate interests or request processing restrictions;
  • Withdrawal of Consent: Withdraw consent at any time where processing was consent-based.

7. California Consumer Privacy Notice (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, California residents have the right to know what personal information is collected, request deletion, and request correction.

Notice of Non-Sale: AdSentry does not sell, rent, or share personal information with third parties for cross-context behavioral advertising.

8. Data Processing Addendum (DPA)

For marketing agencies, DTC enterprises, and enterprise advertisers requiring a formal Data Processing Addendum incorporating Standard Contractual Clauses (SCCs) to satisfy client governance requirements, please submit a request to our legal team.

9. Contact & Supervisory Authorities

To exercise your privacy rights or request data erasure, contact our Data Protection Lead:

AdSentry Privacy Operations
Email: support@adsentry.online
Data Protection Inquiries: Contact & Support Portal

If you are located in the EEA or UK, you also possess the statutory right to lodge a complaint with your local supervisory data protection authority (e.g., the UK Information Commissioner's Office at ico.org.uk).