This Privacy Policy explains how Programz collects, uses, shares and protects personal data in connection with AdCharter: our website at https://adcharter.app, the AdCharter application, and the emails and integrations that come with it. It applies to our customers and their users, to people who work with our customers through AdCharter without an account (such as client approvers, freelance editors and content creators), and to visitors to our website.
In short
- AdCharter is a tool for businesses. What an organisation puts into AdCharter belongs to that organisation, and we process it on its behalf.
- We collect what we need to run the service: your account, billing details and technical logs.
- Our website sets no cookies and uses no analytics or tracking. The application uses only strictly necessary cookies.
- We never sell personal data and never use it for advertising.
- Data from Meta, Google and Slack is used only for the features you choose to connect, and you can have it deleted at any time.
- You can access, correct, export or delete your data. Just email [to be provided: privacy email address].
1. Who we are
AdCharter is operated by [to be provided: company legal name], a Wyoming [to be provided: type of company] (“Programz”, “we”, “us” or “our”). Our postal address is [to be provided: company address].
For the personal data we handle as a controller (see section 2), [to be provided: company legal name] is the controller under the EU General Data Protection Regulation (“GDPR”) and the UK GDPR. If you have any question about this policy or your personal data, email [to be provided: privacy email address].
Our representatives in the EU and the UK
We are based in the United States. Because we offer AdCharter to people in the European Union and the United Kingdom, we have appointed representatives under Article 27 of the GDPR and of the UK GDPR. You can contact them, instead of us or as well as us, about anything relating to your personal data:
- EU representative: [to be provided: EU representative]
- UK representative: [to be provided: UK representative]
2. Our two roles
When we are the controller
We decide how and why the following personal data is used, and we are responsible for it:
- account and sign-in data, including data we receive through “Sign in with Google”;
- organisation and billing data;
- messages you send us and our replies;
- technical and log data from our website and application;
- the data we need to secure the service, prevent misuse and meet our legal obligations.
When we are a processor
Organisations that subscribe to AdCharter (our “customers”) use it to plan, brief, produce, approve and launch ads. Everything a customer and its users put into AdCharter or connect to it is “Customer Data”: briefs, storyboards, comments, approvals, uploaded images and videos, product information, content creator profiles, ad copy, launch settings, data from the customer's Meta ad accounts and Slack workspace, and performance data. Customer Data can include personal data about the customer's team, clients and content creators, and about people who appear in images and videos.
For Customer Data, the customer is the controller and we are its processor. We process Customer Data only on the customer's instructions, under our Data Processing Agreement. The customer decides what goes into AdCharter and is responsible for having a lawful basis for it.
If an organisation has added your details to AdCharter, or has uploaded content that shows you, please contact that organisation first. If you contact us instead, we will pass your request on to the organisation and help it respond.
Sections 5 and 7 describe the Meta and Slack data we process, including data we process for customers, because those platforms require it and because you should be able to find it in one place.
3. Data we collect
Account and sign-in data
- Your name, email address and preferred language.
- Your password, stored only as a secure one-way hash, never in readable form.
- If you turn on two-step sign-in, the settings it needs, such as the key shared with your authenticator app and your recovery codes.
- If you use “Sign in with Google”, the data described in section 6.
- The organisations and brands you belong to, and your role in each.
Organisation and billing data
- Organisation name, company name, billing address, VAT or tax ID and billing contact.
- Plan, subscription status, invoices, payments and any discount code used.
- Card and other payment details are entered on Stripe's pages and held by Stripe. We never receive or store your full card number or security code (see section 8).
Content and activity in AdCharter
As a processor (section 2), we store the Customer Data that your organisation and its users create or upload, together with a history of who did what and when (for example who approved a creative, who commented or who uploaded a file). This history is part of the service: organisations rely on it to follow their work.
People who act through a task link
Organisations can involve people who don't have an AdCharter account, such as client approvers, freelance editors and content creators. When someone at an organisation invites you or assigns you a task, they give us your name and email address. We then:
- create an inactive user for you within that organisation;
- email you a personal link to the task, valid for 7 days and only while the task is open;
- record what you do through the link (for example an approval, a comment or an upload) under your name.
The same email invites you to activate an account. You don't have to.
Communications with us
When you email us or contact us through our website, we keep your name, your email address, the content of your message and our reply.
Technical and log data
When you use our website or application, our servers record technical information: IP address, date and time, the page or address requested, browser and device type (user agent) and error details. We use it to keep the service secure and working, not to track you or build profiles.
Our website
Our public website sets no cookies, uses no local storage and has no analytics, advertising or tracking pixels. It loads nothing from third parties: our fonts are hosted on our own servers. Apart from the server logs described above, we don't collect data about website visitors unless you contact us. See our Cookie Policy.
Where the data comes from
We collect personal data:
- from you, when you create an account, use AdCharter or contact us;
- from your organisation and its users, for example when an admin invites you, a colleague assigns you a task or @mentions you, or a brand admin creates a content creator profile about you;
- from Google, if you choose “Sign in with Google” (section 6);
- from Meta and Slack, when a customer connects them (sections 5 and 7);
- from Stripe, which tells us about payments and the billing details entered in Stripe Checkout (section 8);
- automatically, through our server logs.
What you need to give us
To create an account, you need to give us your name and email address, and either set a password or use “Sign in with Google”. To subscribe, an organisation needs to provide billing details. Without this information we can't provide an account or a subscription. Everything else is up to you and your organisation.
4. How we use data and our legal bases
This section covers the personal data for which we are the controller. For each purpose, we name our legal basis under the GDPR and the UK GDPR. For Customer Data, we act on the customer's instructions and the customer determines the legal basis.
- Providing AdCharter: creating and running accounts, signing you in (including with Google and two-step sign-in), giving you access to the right organisations and brands, and delivering the features your organisation subscribed to. Legal basis: performance of our contract with you or, where the contract is with your organisation, our legitimate interest in providing the service your organisation asked for.
- Invitations and task links: emailing invitations, personal task links and notifications on behalf of an organisation, and recording what is done through a link. Legal basis: our legitimate interest, shared with the organisation, in letting teams work with clients, freelancers and creators who don't have an account.
- Service messages: sending email confirmations, password resets, security alerts, notifications and important information about the service or our terms. Legal basis: performance of a contract; our legitimate interest in keeping users informed about the service they use.
- Billing: managing subscriptions, calculating tax, issuing invoices, collecting payments and keeping accounting records. Legal basis: performance of a contract; compliance with our legal obligations under tax and accounting law.
- Support: answering your questions and requests. Legal basis: performance of a contract; our legitimate interest in helping the people who use or ask about AdCharter.
- Security and reliability: keeping logs, detecting and preventing fraud, misuse and attacks, investigating errors, and making and restoring backups. Legal basis: our legitimate interest in keeping AdCharter, our customers and their users safe and the service working; for some records, compliance with our legal obligations.
- Improving AdCharter: understanding where errors occur and which features need work, using our own records and logs (we don't use analytics tools). Legal basis: our legitimate interest in building a better product.
- Legal matters: complying with the law, responding to lawful requests from public authorities, enforcing our Terms of Service, and establishing, exercising or defending legal claims. Legal basis: compliance with our legal obligations; our legitimate interest in protecting our rights and those of others.
- Business changes: sharing data with the parties to a merger, acquisition or sale of assets, under confidentiality (section 10). Legal basis: our legitimate interest in running and developing our business.
Where we rely on legitimate interests, we have balanced them against your interests and rights, and you can object (section 14).
We don't send marketing emails, and we don't use personal data for advertising or profiling. If we ever want to do something that needs your consent, such as sending marketing emails or using non-essential cookies, we will ask first, and you can withdraw your consent at any time.
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
5. Meta (Facebook and Instagram) data
AdCharter can launch ads on Facebook and Instagram and report how they perform. This is optional: it only happens when a brand admin at a customer connects a brand to Meta using Facebook Login for Business. Meta's own handling of your data, for example when you log in with Facebook, is governed by Meta's Privacy Policy.
What we receive
Depending on the permissions granted, we receive and store:
- Connection details: an access token issued by Meta, the ID and name Meta provides for the person or business that connected, and the permissions granted.
- Ad accounts and business assets: the names and IDs of the ad accounts, businesses, Facebook Pages, Instagram accounts and Meta pixels you choose to use with AdCharter, and the settings needed to run ads from them, such as currency and time zone.
- Campaigns, ad sets and ads: the names, IDs, status and settings of campaigns, ad sets and ads in those ad accounts (including ad sets that AdCharter copies at your request), and Meta's review results, such as the reason an ad was rejected.
- Creatives and media: the images, videos, text and links AdCharter sends to Meta to create ads, and the IDs Meta gives them; if you reuse an existing post as an ad, the post's ID and content.
- Performance insights: aggregated results per ad, such as spend, impressions, outbound clicks, reach, purchases and purchase value, refreshed about every hour.
We don't receive or store information about the individual people who see or interact with the ads. AdCharter does not collect comments, messages or follower lists from your Pages or Instagram accounts.
Permissions we ask for
ads_management: create, copy and edit campaigns, ad sets, ads and creatives, upload images and videos, and receive ad status updates.ads_read: read ad accounts, ads, their status and performance insights.business_management: access the business assets, such as client ad accounts, that your business has given AdCharter access to.pages_show_list: list the Facebook Pages you can run ads for.pages_read_engagement: read Page posts so you can reuse an existing post as an ad.pages_manage_ads: create ads for your Pages.instagram_basic: list Instagram accounts and their posts, so ads can run from them and posts can be reused.
The final set depends on Meta's app review. If it changes, we will update this list.
How and why we use it
We use Meta data only to provide AdCharter to the customer that connected it:
- to show the ad accounts, Pages, Instagram accounts, pixels, campaigns and ad sets you can launch to;
- to create, copy, schedule, start and pause ads exactly as your team set them up in AdCharter;
- to tell your team when Meta rejects an ad, and why;
- to link ads to briefs through the identifier at the start of the ad name, and to report their results.
Performance insights are aggregated campaign metrics. We use them only to show the advertiser that owns the ad account the results of its own campaigns, within its own AdCharter organisation. We never share one advertiser's data with another advertiser or combine data across advertisers.
How we protect it
- Access tokens are encrypted before they are stored, are used only by our servers and are never sent to your browser.
- Our servers sign every request to Meta with our app secret.
- Only the organisation's users with access to that brand can see its Meta data, according to their role.
- We check every day that each connection is still valid. When access is removed, we stop using it.
What we never do
We do not, and will not:
- sell, license, rent or trade Meta data, or buy it;
- use it to build profiles of individual people, or to track or monitor people;
- use it to make decisions about anyone's eligibility for housing, employment, credit, insurance, education, healthcare or similar opportunities, or to discriminate against anyone;
- act as a data broker, or share Meta data with data brokers, advertising networks or other data resellers;
- use it for our own advertising or marketing;
- share it with anyone except as described in this section.
Who else can process it
Only the service providers that help us run AdCharter, such as DigitalOcean for hosting and BuildCharter Assets for file storage (section 10). Each of them is bound by a written agreement that requires it to use the data only to provide its service to us and to protect it at least as strictly as Meta's terms require of us. We may also disclose Meta data where the law requires it (section 10).
How to have Meta data deleted
- A brand admin can disconnect Meta in the brand's settings in AdCharter.
- You can remove AdCharter in your Facebook settings. Meta then tells us automatically, and we delete the data.
- You can email [to be provided: privacy email address].
Step-by-step instructions, what is deleted and how quickly are on our Data Deletion Instructions page.
6. Sign in with Google
“Sign in with Google” is optional. If you use it, Google shares with us, with your permission, only basic profile information (we request only the openid, email and profile scopes):
- your name;
- your email address, and whether Google has verified it;
- a link to your profile picture;
- your Google account ID.
We don't ask for access to your Gmail, Google Drive, Calendar, contacts or any other Google data.
How we use it
We use this information only to sign you in, to create your AdCharter account or link it to an existing one, and to show your name and profile picture to you and the people you work with in AdCharter. We link Google to an existing account only when Google confirms that the email address is verified.
How we store and protect it
We store this information with your account in our database, hosted at [to be provided: hosting location], and protect it as described in section 13. We keep it until you delete your account (section 12).
How we share it
We don't sell Google user data, use it for advertising, or share it with third parties, except with the service providers that host AdCharter (section 10) or where the law requires. We don't use it to develop, improve or train artificial intelligence or machine learning models. Our staff don't look at it, except where needed for security, for support you have asked for, or to comply with the law.
How to remove it
You can remove AdCharter's access at any time in your Google Account. To have the Google information we hold deleted, delete your AdCharter account or email [to be provided: privacy email address]. If you want to keep your account, set a password first so that you can still sign in.
Limited Use
AdCharter's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Slack
Connecting Slack is optional and done per brand. When a brand admin adds the AdCharter app to a Slack workspace, we receive and store:
- the workspace's ID and name, and a bot access token, which we encrypt before storing;
- the ID of the channel the admin picks for updates (we read the channel list only so that the admin can choose);
- the Slack user IDs of people we match to AdCharter users. To match, we look up the email addresses of the brand's AdCharter users in the workspace. We store only the Slack user ID of each match, not other members' details.
We use this to post updates about briefs (such as state changes) to the chosen channel, and to send direct messages about task assignments, @mentions and ads rejected by Meta. Messages contain, for example, the name of a brief, what changed and a link to AdCharter. Once posted, messages are stored by Slack under the customer's own agreement with Slack. AdCharter cannot read messages in your workspace.
The app asks Slack for these permissions (scopes):
chat:write: post updates to the channel and send direct messages.channels:readandgroups:read: list public channels, and private channels the app has been added to, so an admin can pick one.im:write: open direct messages with matched users.users:readandusers:read.email: match workspace members to AdCharter users by email address.
If you uninstall the AdCharter app from your workspace, or a brand admin disconnects Slack in AdCharter, we stop sending messages and delete the Slack token and user matches within 14 business days. Messages already posted stay in Slack and are managed by the workspace.
8. Payments (Stripe)
Subscriptions are paid through Stripe. Stripe Checkout and the Stripe Customer Portal are hosted by Stripe: you enter card and billing details on Stripe's pages, and they never pass through our servers. Stripe also calculates tax (Stripe Tax) and issues invoices.
- What Stripe collects: payment details, and your organisation's company name, billing address, VAT or tax ID and billing email.
- What we receive and keep: the company name, billing address and VAT or tax ID (also stored on your organisation in AdCharter), Stripe's customer and subscription IDs, plan, subscription and payment status, and invoices. We never see your full card number or security code.
- Stripe's roles: Stripe processes payments for us as our processor. For its own purposes, such as preventing fraud and meeting its legal and regulatory obligations, Stripe acts as an independent controller under the Stripe Privacy Policy.
If your organisation is invoiced manually rather than through Stripe Checkout, we keep the billing contact and invoice records ourselves.
9. Email (Resend)
We use Resend to deliver the emails AdCharter sends: invitations, task links, email address confirmations, password resets, notifications when Slack is not available, and alerts to our own team about the service. Resend receives the recipient's name and email address and the content of each email, and acts as our processor.
We don't send marketing emails, and we don't use open or click tracking in our emails.
10. Who we share data with
Service providers
We use a small number of service providers (sub-processors) to run AdCharter:
- DigitalOcean: hosting of the application, database and encrypted database backups. Location: [to be provided: hosting location].
- BuildCharter Assets (bcassets): storage and delivery of uploaded files, operated by [to be provided: operator of BuildCharter Assets], a company in our group. Location: [to be provided: file storage location].
- Stripe: payments, invoices and tax calculation. Location: USA and EU.
- Resend: delivery of transactional email. Location: USA.
These are used only when a customer or user chooses to connect them:
- Slack: notifications in a customer's Slack workspace. Location: USA.
- Meta: launching ads and reading ad performance in the customer's own ad accounts. Location: USA and Ireland.
- Google: “Sign in with Google”. Location: USA.
Each service provider is bound by a written contract that limits its use of the data to providing its service to us and requires it to keep the data confidential and secure. The full list, with the legal entities and how we announce changes, is on our Sub-processors page.
Other recipients
- Within your organisation: other users of your organisation see your name, role, comments, approvals and activity according to their permissions. People acting through a task link see what their task needs.
- Professional advisers: lawyers, accountants and auditors, under a duty of confidentiality.
- Public authorities: when the law requires it, for example in response to a valid court order. Where the law allows, we tell the affected customer first.
- Business transfers: if we are involved in a merger, acquisition or sale of assets, personal data may be transferred to the parties involved, who must keep protecting it as described in this policy. We will tell you before your data becomes subject to a different privacy policy.
- Anyone else, on your instructions: for example when you or your organisation connect an integration.
We never sell personal data, and we don't share it for cross-context behavioural advertising.
11. International transfers
Programz is based in the United States, and our team may access personal data from there. Several of our service providers are also in the United States. When personal data from the European Economic Area (EEA) or the UK is transferred to a country that doesn't have an adequacy decision, we rely on these safeguards:
- From the EEA: the EU-US Data Privacy Framework, where the recipient is certified under it; otherwise the European Commission's Standard Contractual Clauses.
- From the UK: the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”), where the recipient is certified under it; otherwise the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses.
When we receive Customer Data from a customer in the EEA or the UK, the transfer is covered by the Standard Contractual Clauses and the UK Addendum included in our Data Processing Agreement. Our application and database are hosted at [to be provided: hosting location], and uploaded files are stored at [to be provided: file storage location].
You can ask for a copy of the safeguards we use by emailing [to be provided: privacy email address].
12. How long we keep data
We keep personal data only as long as we need it for the purposes in section 4, and then delete or anonymise it.
- Your account: for as long as your account exists. When you delete your account, we delete or anonymise your personal data within 30 days. Your name in the history of briefs and approvals becomes “Deleted user”; the briefs, comments and approvals themselves stay with the organisation, because they belong to it.
- Inactive users (task links): for as long as the organisation that added you uses AdCharter, or until it or you ask us to delete them. Each task link stops working after 7 days, or earlier when the task closes.
- Customer Data after cancellation: a cancelled subscription runs until the end of the billing period. The organisation then has 30 days of read-only access to view and export its data. After those 30 days, all its data is deleted unless the subscription is reactivated.
- Organisation deletion: when an organisation admin deletes an organisation, all its data, including files in BuildCharter Assets, is permanently deleted 30 days after the request.
- Backups: deleted data can remain in our encrypted backups for up to 30 days before it is overwritten.
- Server logs: up to 30 days.
- Billing records: for as long as tax and accounting laws require us to keep them.
- Support messages: for as long as we need them to handle your request and any follow-up.
- Slack data: deleted within 14 business days after the app is uninstalled or Slack is disconnected.
- Meta data: access tokens are deleted as soon as Meta is disconnected or we receive a deletion request; the rest of the Meta data from that connection is deleted within 30 days (see Data Deletion Instructions).
- Google data: until you delete your account, or until you ask us to remove it.
We may keep data for longer where the law requires it, or where we need it to establish, exercise or defend legal claims.
13. Security
We protect personal data with technical and organisational measures appropriate to the risk, including:
- encrypted connections (HTTPS) for our website, application and integrations;
- passwords stored only as secure one-way hashes;
- encryption of stored access tokens and secrets for Meta, Slack and Stripe;
- encrypted database backups, made continuously;
- optional two-step sign-in with an authenticator app, and confirmation of every email address;
- separation between customer organisations, enforced by the application on every database query, and role-based access for each brand;
- personal task links that expire after 7 days and work only while the task is open;
- card details handled only by Stripe;
- access to production systems limited to the people who need it;
- server logs and monitoring to detect problems and misuse.
No system is completely secure. If a personal data breach affects you, we will inform the customers concerned, the supervisory authorities and you, as the law requires.
14. Your rights
Under the GDPR and the UK GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict how we use your data;
- data portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another organisation;
- object to processing based on our legitimate interests;
- withdraw your consent at any time, where we rely on consent, without affecting processing that took place before.
You can update most account details yourself in AdCharter and delete your account from your account settings. Organisation admins can export their organisation's data and delete the organisation. For anything else, email [to be provided: privacy email address]. Exercising your rights is free. We may ask you to confirm your identity before we act on a request.
We reply within one month. If a request is complex, or if we receive many requests, we may extend this by up to two further months; we will tell you if we do.
If your request is about Customer Data, for which a customer is the controller (section 2), we will pass it on to that customer and help it respond.
15. Complaints
If you are unhappy with how we handle your personal data, please tell us first so that we can put it right. Email [to be provided: privacy email address], with “Complaint” in the subject line. We acknowledge every complaint within 30 days, look into it without undue delay and tell you the outcome. This follows the complaints process introduced in the UK by the Data (Use and Access) Act 2025, and we apply it to everyone.
You also have the right to complain to a data protection supervisory authority at any time:
- United Kingdom: the Information Commissioner's Office (ICO), ico.org.uk/make-a-complaint.
- France: the Commission nationale de l'informatique et des libertés (CNIL), cnil.fr.
- Other EU and EEA countries: the supervisory authority where you live, where you work or where the issue happened. See the list of EU authorities.
16. Children
AdCharter is a service for businesses. It is not directed at children, and no one under 16 may use it. If we learn that we have collected personal data from a child under 16, we will delete it. If you think this has happened, email [to be provided: privacy email address].
17. Changes to this policy
We may update this policy when AdCharter or the law changes. We publish every new version on this page with a new effective date. If a change is significant, we will also tell account holders by email or in the application before it takes effect.
18. Contact us
- Privacy questions and requests: [to be provided: privacy email address]
- Support: [to be provided: support email address]
- Post: [to be provided: company legal name], [to be provided: company address]
- EU representative: [to be provided: EU representative]
- UK representative: [to be provided: UK representative]