Privacy Policy
Effective date: June 8, 2026 · Version 1.1
1. Who we are
AdsVitals ("AdsVitals", "we", "us", "our") is a service operated by MGBB COMERCIO LLC, a limited liability company organized in the State of New Mexico, USA, with registered address at 412 W 7th St Ste 962, Clovis, NM 88101, USA. We are the data controller responsible for the personal data described in this policy.
For any privacy question or to exercise your rights, contact us at privacy@adsvitals.com.
2. Scope
This policy explains what personal data we collect, why, how we use and share it, and the rights you have, when you use the AdsVitals website and application at adsvitals.com (the "Service"). It does not cover third-party websites we link to (for example, our partners' sites), which have their own privacy policies.
3. Data we collect
We collect only what we need to run the Service.
a) Account and identity data. When you sign in, we process your email address. If you sign in with Google, we also receive the profile information Google returns through OAuth — typically your name, profile picture, and Google account identifier. Our authentication provider keeps standard sign-in security metadata, including your account identifier, account creation time, last sign-in time, and IP address of sign-in events.
b) Diagnostic data you enter. When you run a diagnosis, you provide campaign metrics. If you are signed in, each diagnosis is saved to your account, including: an optional campaign name you type (free text); the full set of metrics you enter — niche, country, campaign structure, currency, days of data, spend, revenue, ROAS, CTR, CPM, CPC, CPA, target CPA, frequency, hook/hold rates, campaign age, budget trend, last creative refresh, and funnel counts (link clicks, landing page views, add-to-carts, initiate checkouts, purchases); and the resulting diagnosis report and summary fields (score, status, niche, currency). This is advertising/business data tied to your account. Saved diagnoses power your saved history (and upcoming timeline features for Pro users).
c) Payment data. Paid (Pro) subscriptions are processed by Stripe. Stripe collects your name, email, billing address, and card details directly. We never receive or store your card number. We store only the Stripe customer ID, subscription ID, and subscription status to manage your plan.
d) Technical and log data. Like any web service, our hosting and infrastructure providers automatically process technical data such as IP address, browser/user-agent, and requested URLs in their server logs. Note that, in the current version, the metrics you enter are passed to the results screen through the page URL, so they may appear in those access logs. We plan to change this in a future update.
e) Advertising and measurement data (Meta Pixel). With your consent — or, outside the EU, UK, and Brazil, unless you opt out (see Section 12) — we use the Meta Pixel in your browser and Meta's Conversions API on our server to measure how our ads perform and to show relevant ads. When active, these collect data about your interactions with our site (such as pages viewed, sign-up, and Pro subscription events) together with technical identifiers (cookies set by Meta, IP address, and browser/user-agent), and, for subscription events sent from our server, a hashed (irreversible) version of your email address. This data is shared with Meta Platforms (see Section 7). If you do not consent — or you opt out where opt-out applies — the Meta Pixel does not load and these events are not sent.
Apart from the Meta advertising tools described in (e) above — which run only with your consent (or, where opt-out applies, until you opt out) — we do not use general analytics tools or other third-party trackers.
4. How we collect it
- Directly from you — when you log in, type campaign data, or subscribe.
- Automatically — technical/log data generated by your use of the Service.
- From Google — profile data returned when you choose "Sign in with Google".
5. How we use your data
We use your data to:
- provide the diagnostic Service and show your results;
- save your diagnoses and build your history;
- authenticate you and keep your account secure;
- process and manage your Pro subscription;
- send transactional emails (such as your login link);
- send the Weekly Checkup product email only if you have explicitly opted in;
- measure and improve our advertising, and show relevant ads, using the Meta Pixel and Conversions API — only with your consent (or, where opt-out applies, until you opt out);
- comply with legal obligations and prevent abuse.
6. Legal bases (GDPR / LGPD)
Where the GDPR (EU/UK) or LGPD (Brazil) applies, we rely on:
- Performance of a contract — to provide the Service, your account, history, and billing;
- Legitimate interests — to keep the Service secure, prevent abuse, improve it, and — outside the EU, UK, and Brazil — to measure our advertising (you can opt out at any time), balanced against your rights;
- Consent — for the optional Weekly Checkup product emails, and for the Meta Pixel and Conversions API in regions where prior consent is required (EU, UK, and Brazil). You can withdraw your consent at any time;
- Legal obligation — where we must retain or disclose data by law.
7. Who we share it with (processors)
We do not sell your personal data. We share it only with service providers ("processors") that help us run AdsVitals, under appropriate data-processing terms:
- Supabase — database and authentication (account, saved diagnoses).
- Stripe — payment processing for Pro subscriptions.
- Resend — delivery of our emails (e.g., login link; Weekly Checkup if opted in).
- Vercel — application hosting and server logs.
- Cloudflare — DNS and email routing (messages sent to our privacy address pass through Cloudflare).
- Google — authentication, only if you choose "Sign in with Google".
- Meta Platforms (Facebook/Instagram) — advertising measurement and retargeting through the Meta Pixel (in your browser) and the Conversions API (from our server), active only with your consent (or, where opt-out applies, until you opt out).
We may also disclose data if required by law or to protect our rights, users, or the public.
8. International data transfers
We and our processors (including Meta Platforms) are based in or process data in the United States and other countries. Where data is transferred out of the EU/UK or Brazil, we rely on appropriate safeguards (such as Standard Contractual Clauses) provided by these processors.
9. Data retention
- Account data — kept while your account is active.
- Saved diagnoses — kept for as long as your account exists, so your history remains available.
- Account deletion — when your account is deleted, your profile and all saved diagnoses are deleted automatically (cascade).
- Logs — retained for the standard periods set by our infrastructure providers.
To request deletion, contact privacy@adsvitals.com.
10. Your rights
Depending on your location (e.g., under GDPR or LGPD), you have the right to access, correct, delete, export (portability), restrict, or object to the processing of your personal data, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority (for example, the ANPD in Brazil or your EU/UK supervisory authority).
To exercise any of these rights, email privacy@adsvitals.com. We will respond within the timeframe required by applicable law.
11. Security
We protect your data with row-level security (each user can only access their own records), encryption in transit (HTTPS), and the principle of not storing payment card data. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.
12. Cookies
We use a strictly necessary cookie to keep you signed in (our authentication session). It is always required for the Service to work and is not used for tracking.
With your consent, we also use advertising and measurement cookies through the Meta Pixel (for example, Meta's _fbp and _fbc cookies) to measure how our ads perform and to show you relevant ads. These are not strictly necessary, and we apply them on a geo-conditional basis:
- In the EU, the UK, and Brazil, the Meta Pixel and its cookies load only after you accept them in our cookie banner (opt-in).
- In other regions, they load by default, and you can refuse them at any time using the same banner (opt-out).
To remember your choice — and which banner to show — we store small first-party preference cookies on your device. You can change your decision at any time through the banner, and most browsers also let you block or delete cookies in their settings. If you refuse — or do not accept, where opt-in applies — the Meta Pixel does not load and no advertising cookies are set.
13. Children
AdsVitals is intended for users 18 years or older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
14. Affiliate disclosure
Some links on AdsVitals — for example, on our Partners page — are affiliate links (such as Shopify, through the Impact network). If you sign up or purchase through them, we may earn a commission at no extra cost to you. This does not influence our diagnoses, which are generated by transparent, rules-based logic. See our Partners page for details.
15. Changes to this policy
We may update this policy from time to time. We will revise the "Effective date" and version above, and, for material changes, provide a more prominent notice. This policy is published in English, Portuguese, and Spanish; in case of any discrepancy, the English version prevails.
16. Data Protection Officer
Given our small scale, the absence of large-scale monitoring, and the fact that we do not process special categories of sensitive data, we are not required to appoint a Data Protection Officer. Privacy requests are handled directly at privacy@adsvitals.com.
Contact
MGBB COMERCIO LLC — 412 W 7th St Ste 962, Clovis, NM 88101, USA · privacy@adsvitals.com