Legal
Privacy Policy
How AdOps collects, uses and stores account data, Meta ad-account data, rule execution records and billing information, and how to have that data removed. This page is the current AdOps Privacy Policy, effective 1 August 2026 and last updated 1 August 2026. It is a plain-language draft that has not been reviewed by qualified counsel.
Effective Last updated
Template notice. This document is a plain-language draft written to describe what the AdOps platform actually does with data. It has not been reviewed by qualified counsel, it is not legal advice, and it does not yet meet any specific regulatory standard. Have a lawyer review and adapt it before relying on it, publishing it as a binding policy, or presenting it to a customer.
AdOps is a Meta Ads rule-automation platform operated from Jakarta, Indonesia. This policy describes the data AdOps holds about an account holder, the Meta ad-account data AdOps reads and writes on that account holder’s instruction, the records AdOps keeps of every rule execution, and how to have any of it corrected or removed.
Who this policy applies to
This policy applies to people who create an AdOps account and to the ad-account data those people connect. It does not apply to the people who see the advertising bought through those ad accounts; AdOps holds no data about them.
Questions, requests and complaints go to admin@adops.id or support@adops.id.
What data does AdOps collect?
| Category | What it contains |
|---|---|
| Account | Full name, username, email address, a hashed password, role, account status, trial and active dates |
| Company profile | Company name, industry, and a monthly ad-budget band selected during onboarding |
| Meta connection | The access token you supply, plus the Facebook profile id, name, email and picture returned when that token is verified, and the connection and last-verified timestamps |
| Ad accounts | Account id, account name, whether you activated it in AdOps, and month-to-date spend with its currency and date range |
| Rules | Rule definitions — names, ad accounts, filters, tasks, conditions, schedules and status |
| Execution records | One record per campaign, per task, per run: the action, whether it executed, before and after values, every condition with the value it saw, the campaign snapshot and timing data; plus a summary row per batch |
| Custom metrics | Metric definitions and a cached copy of the rows read from the Google Sheet you point them at |
| AI generation logs | The goal text you type into the AI rule generator, the response, the response time and the confidence score |
| Billing | Invoices, plan, amounts in Rupiah, payment references, and a log of each call made to the payment gateway |
| A record of each transactional email sent, including recipients, subject, template and the mail server’s response | |
| Error logs | Normalised error messages with a stored sample of the parameters and responses involved |
Where does the data come from?
Four sources. From you, when you sign up, complete onboarding, connect Meta, and write rules. From Meta, when AdOps calls the Meta Graph API using the access token you supplied — campaign and ad set lists, insight metrics, budgets and names. From Google Sheets, when a custom metric you created points at a spreadsheet. From Duitku, when a payment is made and the gateway returns a status.
Why does AdOps process it?
To do the thing the account holder asked for, and for four supporting purposes:
- To run your rules. Reading metrics and writing budget, status and name changes to the campaigns your rules target is the core function of the platform.
- To show you what happened. Execution records, activity logs and the dashboard exist so an account holder can audit automated changes.
- To bill. Invoices, payment links and gateway calls run through Duitku, which requires the invoice and payment details listed above.
- To operate and debug the service. Error logs and timing data are kept so failures can be found and fixed.
AdOps does not sell personal data, does not share it for advertising purposes, and does not use customer ad-account data to train models.
What happens to the Meta access token?
The token you supply is stored on your account record in the AdOps database, because a server-side rule engine cannot call the Meta Graph API on your behalf without it. AdOps uses it only to read from and write to the ad accounts you have activated inside AdOps.
You can remove it yourself. Disconnecting Meta from the Integrations screen deletes every ad-account record stored for your account and clears the stored token, the connection flag and the Facebook profile metadata. Revoking the token on Meta’s side is a separate action, taken in Meta’s own settings, and it stops AdOps from acting whether or not the stored copy has been cleared.
Who else processes the data?
AdOps relies on the following third parties. Each receives only the data needed for its function.
- Meta Platforms — the source and destination of all ad-account data.
- Google (Sheets and Drive) — read access to spreadsheets referenced by custom metrics, through a Google service account.
- Anthropic — when the AI rule generator is used, the goal text and the metric catalogue are sent to Anthropic’s Claude API through the AdOps AI service.
- Duitku — payment processing for Indonesian payment methods.
- An SMTP email provider — delivery of transactional email.
- Infrastructure providers — hosting, container registries, the MongoDB database and the Redis queue that carry the platform.
Some of these providers operate outside Indonesia, so data may be processed abroad. A current list of providers is available on request from support@adops.id.
How long is data kept?
- Account, rule, custom metric and billing records are kept while the account exists, and after closure for as long as needed to resolve billing and legal matters.
- Execution records — rule results and batch summaries — are kept until deleted. Deleting a rule deletes its execution records, and a rule’s logs can be cleared on demand from the rule’s log screen.
- Dashboard figures are cached per user and per period for one hour, then expire automatically.
- Google Sheets rows cached for a custom metric are replaced on each successful read and removed when the metric is deleted.
AdOps does not currently publish a fixed retention period for every category above. A deletion request sent to support@adops.id covers all of them.
What choices does an account holder have?
You can access and correct your account data in the app, change your password from the Profile screen, disconnect Meta at any time, deactivate individual ad accounts so no rule touches them, and delete rules and their execution records. To request a copy of your data or its deletion, email support@adops.id from the address on the account.
How is the data protected?
AdOps signs in with an email address and a password that must contain an uppercase letter, a lowercase letter, a digit and a symbol; passwords are stored as hashes, not as text. API access uses a bearer token that expires 24 hours after it is issued, and requests without a valid token are rejected. Ad accounts discovered from Meta are stored inactive until an account holder explicitly activates them, so no rule can act on an account that has not been switched on.
No system is free of risk, and this policy makes no guarantee about the security of any transmission or storage. Report a suspected vulnerability or an unauthorised access to admin@adops.id.
Children
AdOps is a business tool. It is not directed at children and accounts should not be created by anyone under 18.
Changes to this policy
Material changes will be reflected in the effective and updated dates at the top of this page, and account holders will be notified by email where the change affects how their data is used.
Questions about this document
Legal, procurement and data-protection questions go to admin@adops.id. Include your company name and, if the question is about a specific account, the ad account ID.