Legal

Privacy Policy

This policy explains what personal data Insight Driven Ads collects, why we hold it, who processes it on our behalf, and how you can see, correct or delete it. It describes the service as it actually runs — the processors and cookies named here are the ones the product really uses.

Last updated
September 9, 2026
Effective
September 9, 2026
Applies to
Insight Driven Ads

The short version

A summary for orientation only. The numbered sections below are the binding text.

We never see your card details

Payments run entirely through Stripe. Card numbers are submitted to Stripe directly and never reach our servers or database.

No advertising or tracking cookies

We set four strictly necessary cookies. Our analytics are self-hosted and cookieless, so there is no consent banner to dismiss.

We do not sell your data

We have never sold or shared personal information for cross-context behavioural advertising, and we do not intend to.

You can delete everything yourself

Deleting your account from Settings removes your records and your stored files. It is not a request queue — it happens immediately.

1.Who we are

Insight Driven Ads (“we”, “us”, “our”) provides e-commerce research and ad-creative tools through this website. We are the controller of the personal data described in this policy, meaning we decide why and how it is processed.

We operate from the State of Florida, United States. For any privacy question, request or complaint, contact info@insightdrivenads.com.

This policy covers the website and the signed-in application. It does not cover third-party sites you reach through our tools — including any storefront you ask us to analyse, which remains governed by that site’s own policies.

2.Data we collect

We collect only what the service needs to function, bill correctly and stay secure.

Account data
Your email address, display name, and a password stored only as a bcrypt hash — we cannot read or recover your password. If you sign in with Google, we receive your email address and a Google account identifier instead of a password.
Subscription and credit data
Your plan, billing interval, renewal and cancellation state, credit balance, and a ledger of every credit granted or spent. The ledger exists so a disputed balance can be reconstructed.
Payment data
Handled by Stripe. We store your Stripe customer and subscription identifiers so we can match a payment to your account. We do not receive or store full card numbers.
Content you submit
The store and landing-page URLs you ask us to analyse, product details, review text, uploaded images and video, and the prompts you write. Whatever you put into a tool, we hold in order to run it and to show you the result later.
Output we generate
Analyses, ad copy, and generated images and video, together with the metadata needed to serve them back to you — file type, size, duration and which model produced them.
Technical and usage data
IP address, browser type, timestamps, the tools you run, and error diagnostics. IP address is used for rate limiting and abuse prevention, and appears in error reports.
Communications
Emails you send us, and our replies. If you subscribe to the newsletter we store your email address and subscription state until you unsubscribe.
Administrative records
If an operator acts on your account — a manual credit grant, a plan change — we log who did it and why, so account changes are auditable.

Please do not upload other people's personal data

Our tools are built for commercial and product material. Do not upload identifiable images or video of other people without their permission, and do not submit special-category data (health, biometrics, political or religious views, sexual orientation) or anyone’s payment or government-identification details. We do not ask for that data, and content you submit is sent to the AI providers listed below in order to process it.

3.How we use it

  • Running the service — authenticating you, executing the tool you asked for, storing the result and showing your history.
  • Billing — taking payment, applying and expiring credits, refunding credits when a generation fails, and handling cancellations.
  • Support — answering your messages and investigating problems on your account.
  • Security and abuse prevention — rate limiting, bot detection on sign-up and sign-in, and detecting misuse of the platform.
  • Service email — address verification, password reset, and notices about billing or material changes. These are not marketing and cannot be unsubscribed from while your account is open.
  • Improving the product — aggregate, de-identified usage statistics that tell us which tools are used and where they fail.
  • Legal compliance — tax and accounting records, and responding to lawful requests.

What we do not do with your content

We do not use the content you submit to train our own models, we do not sell it, and we do not publish it. Where we produce public trend or benchmark material, it is built from aggregated figures with identifiers removed, and never reproduces your submissions or results.

5.AI processing

Our tools work by sending the material you submit to third-party AI models. This is the part of the service most people want to understand precisely, so:

  • Text analysis and copy generation run on DigitalOcean’s serverless inference platform.
  • Video you upload to Ad Vision is analysed by Google Gemini, because it is the video-capable model in our stack.
  • Video generated by the UGC Ad Creator and Ad Launch Kit is produced by OpenAI.
  • Pages you ask us to analyse are fetched through ScraperAPI, which receives the URL you submitted.

These providers process the material to return a result and under their own terms. We do not grant them the right to use your content to train their models, and we do not train on it ourselves. AI output is generated automatically, can be wrong, and has no legal or similarly significant effect on you — we make no automated decisions about you in the sense of Article 22 of the GDPR.

6.Who we share it with

We do not sell personal data. We share it with the processors below, each of which is bound to use it only to provide their service to us:

Processor

DigitalOcean

What it does

Managed Postgres database, Spaces object storage, and the serverless inference endpoint that runs most text analysis

Data involved

Account records, submitted content, generated assets, analysis prompts and outputs

Location

United States / EU

Processor

Stripe

What it does

Payment processing, subscription billing and the customer billing portal

Data involved

Name, email, billing address, card details (collected by Stripe directly), transaction history

Location

United States

Processor

OpenAI

What it does

Video generation for the UGC Ad Creator and Ad Launch Kit

Data involved

Generation prompts and any reference images or product details you supply

Location

United States

Processor

Google

What it does

Sign-in with Google (OAuth) and Gemini video analysis for Ad Vision

Data involved

Email address and profile identifier for sign-in; uploaded video for analysis

Location

United States

Processor

ScraperAPI

What it does

Retrieving publicly accessible pages you ask us to analyse

Data involved

The URLs you submit

Location

United States

Processor

SMTP2GO

What it does

Transactional email (verification, password reset, billing and service notices)

Data involved

Email address and message content

Location

United States / EU

Processor

Cloudflare

What it does

Turnstile bot protection on unauthenticated forms, and network delivery

Data involved

IP address and browser signals used to tell humans from automated traffic

Location

Global edge network

Processor

Umami (self-hosted)

What it does

Aggregate traffic analytics, run on infrastructure we control

Data involved

Cookieless, aggregated page-view counts with no cross-site identifier

Location

Operated by us

Processor

Bugsink (self-hosted)

What it does

Error and crash diagnostics, run on infrastructure we control

Data involved

Technical error reports, with authentication cookies and credentials scrubbed before transmission

Location

Operated by us

We may also disclose personal data:

  • To professional advisers — lawyers, accountants, auditors — under a duty of confidence.
  • Where required by law, or to establish, exercise or defend legal claims.
  • To protect the rights, property or safety of our users, the public or ourselves, including to prevent fraud and abuse.
  • To a buyer or successor in a merger, acquisition or sale of assets, in which case we will give notice before your data becomes subject to a different policy.

7.International transfers

We are based in the United States, and the processors above are largely US-based. If you use the service from outside the United States, your personal data will be transferred to and processed in the United States, where privacy laws differ from those in your country.

Where we transfer personal data out of the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, together with the safeguards our processors maintain. You can request details of the mechanism used for a particular transfer by writing to info@insightdrivenads.com.

8.How long we keep it

Data

Account and profile

Kept for

While your account is open; erased when you delete it

Data

Submitted content, analyses and generated assets

Kept for

While your account is open, so your history stays available. Deleting the account deletes the stored files with it

Data

Credit batches

Kept for

30 days from the date granted — unused credits expire on that schedule

Data

Credit ledger and billing records

Kept for

Up to 7 years after the transaction, to meet tax and accounting obligations

Data

Email verification and password reset tokens

Kept for

Until used or expired — hours, not days

Data

Session cookies

Kept for

7 days at most (see the Cookie Policy)

Data

Error diagnostics

Kept for

A rolling window for troubleshooting, then discarded

Data

Newsletter subscription

Kept for

Until you unsubscribe

After account deletion, limited records may persist where we are legally required to keep them — principally invoices and payment records held by us or by Stripe — and in routine encrypted backups until those rotate out.

9.Security

The measures below are the ones actually in place, not aspirations:

  • Passwords are stored only as bcrypt hashes. A breach of our database would not reveal them.
  • Traffic is served over TLS, and the database connection is encrypted.
  • Session cookies are HttpOnly and SameSite, and carry the __Secure- and __Host- prefixes over HTTPS, so page scripts cannot read them and they cannot be set by another site.
  • A Content Security Policy restricts which origins the browser may talk to.
  • Sign-up, sign-in and password reset are rate limited per IP and per email, and protected by a bot check.
  • Authentication cookies and credentials are scrubbed out of error reports before they are transmitted.
  • Administrative actions on accounts are written to an audit log.

No system is perfectly secure, and we cannot guarantee absolute security. Use a strong, unique password, keep it to yourself, and tell us promptly at info@insightdrivenads.com if you believe your account has been compromised. Where the law requires it, we will notify you and the relevant regulator of a personal data breach without undue delay.

10.Your rights

Depending on where you live, you have some or all of the following rights:

  • Access — a copy of the personal data we hold about you.
  • Correction — to fix data that is inaccurate or incomplete.
  • Deletion — to have your personal data erased.
  • Portability — a machine-readable copy of the data you provided.
  • Restriction and objection — to limit or object to processing based on legitimate interests.
  • Withdraw consent — where processing rests on consent, at any time.
  • Non-discrimination — we will not degrade your service because you exercised a privacy right.

How to exercise them

You can delete your account and its stored files yourself at any time from Settings — that is the fastest route to erasure and needs no request. For anything else, email info@insightdrivenads.com from the address on your account. We respond within 30 days, and will tell you if we need longer or need to verify your identity first. Using an authorised agent is fine; we will ask for proof of their authority.

If you are in the UK or EEA and think we have handled your data badly, we would like the chance to fix it — but you may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner’s Office.

11.US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have the rights listed above, exercised the same way. Under the California Consumer Privacy Act you may also request the categories of personal information we collected, the sources, the business purpose, and the categories of third parties we disclosed it to — all of which are set out in sections 2, 3 and 6 of this policy.

Florida residents. The Florida Digital Bill of Rights applies by its terms only to a narrow class of very large businesses, which we are not. We honour the access, correction, deletion and portability requests described above for Florida residents regardless.

Where a state law provides a right to appeal a refused request, you may appeal by replying to our decision. We will respond in writing with our reasoning.

12.No sale of personal data

We do not sell or share personal information

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the twelve months preceding the date of this policy. We do not offer financial incentives in exchange for personal information, and we do not knowingly sell the personal information of anyone under 16.

Because there is nothing to opt out of, we do not operate a “Do Not Sell or Share My Personal Information” mechanism. We honour Global Privacy Control signals as an opt-out where they apply.

13.Children

The service is a business tool intended for adults. It is not directed to children, and you must be at least 18 to hold an account. We do not knowingly collect personal data from anyone under 13, and if we learn that we have, we will delete it promptly. A parent or guardian who believes a child has given us data should contact info@insightdrivenads.com.

14.Changes and contact

We update this policy when the service changes. The revision date at the top always reflects the current version. If a change materially affects your rights, we will give notice by email or in the application before it takes effect. Continuing to use the service after that means you accept the updated policy.

This policy is governed by the laws of the State of Florida, United States, without regard to its conflict-of-laws rules.

Questions about this policy?

Privacy requests, questions about a processor, or anything in this document that is not clear — write to us and a person will answer.

info@insightdrivenads.com

See also Privacy Policy · Terms of Service · Cookie Policy