Legal
Privacy Policy
This policy explains what personal data Insight Driven Ads collects, why we hold it, who processes it on our behalf, and how you can see, correct or delete it. It describes the service as it actually runs — the processors and cookies named here are the ones the product really uses.
- Last updated
- September 9, 2026
- Effective
- September 9, 2026
- Applies to
- Insight Driven Ads
The short version
A summary for orientation only. The numbered sections below are the binding text.
We never see your card details
Payments run entirely through Stripe. Card numbers are submitted to Stripe directly and never reach our servers or database.
No advertising or tracking cookies
We set four strictly necessary cookies. Our analytics are self-hosted and cookieless, so there is no consent banner to dismiss.
We do not sell your data
We have never sold or shared personal information for cross-context behavioural advertising, and we do not intend to.
You can delete everything yourself
Deleting your account from Settings removes your records and your stored files. It is not a request queue — it happens immediately.
1.Who we are
Insight Driven Ads (“we”, “us”, “our”) provides e-commerce research and ad-creative tools through this website. We are the controller of the personal data described in this policy, meaning we decide why and how it is processed.
We operate from the State of Florida, United States. For any privacy question, request or complaint, contact info@insightdrivenads.com.
This policy covers the website and the signed-in application. It does not cover third-party sites you reach through our tools — including any storefront you ask us to analyse, which remains governed by that site’s own policies.
2.Data we collect
We collect only what the service needs to function, bill correctly and stay secure.
- Account data
- Your email address, display name, and a password stored only as a bcrypt hash — we cannot read or recover your password. If you sign in with Google, we receive your email address and a Google account identifier instead of a password.
- Subscription and credit data
- Your plan, billing interval, renewal and cancellation state, credit balance, and a ledger of every credit granted or spent. The ledger exists so a disputed balance can be reconstructed.
- Payment data
- Handled by Stripe. We store your Stripe customer and subscription identifiers so we can match a payment to your account. We do not receive or store full card numbers.
- Content you submit
- The store and landing-page URLs you ask us to analyse, product details, review text, uploaded images and video, and the prompts you write. Whatever you put into a tool, we hold in order to run it and to show you the result later.
- Output we generate
- Analyses, ad copy, and generated images and video, together with the metadata needed to serve them back to you — file type, size, duration and which model produced them.
- Technical and usage data
- IP address, browser type, timestamps, the tools you run, and error diagnostics. IP address is used for rate limiting and abuse prevention, and appears in error reports.
- Communications
- Emails you send us, and our replies. If you subscribe to the newsletter we store your email address and subscription state until you unsubscribe.
- Administrative records
- If an operator acts on your account — a manual credit grant, a plan change — we log who did it and why, so account changes are auditable.
Please do not upload other people's personal data
Our tools are built for commercial and product material. Do not upload identifiable images or video of other people without their permission, and do not submit special-category data (health, biometrics, political or religious views, sexual orientation) or anyone’s payment or government-identification details. We do not ask for that data, and content you submit is sent to the AI providers listed below in order to process it.
3.How we use it
- Running the service — authenticating you, executing the tool you asked for, storing the result and showing your history.
- Billing — taking payment, applying and expiring credits, refunding credits when a generation fails, and handling cancellations.
- Support — answering your messages and investigating problems on your account.
- Security and abuse prevention — rate limiting, bot detection on sign-up and sign-in, and detecting misuse of the platform.
- Service email — address verification, password reset, and notices about billing or material changes. These are not marketing and cannot be unsubscribed from while your account is open.
- Improving the product — aggregate, de-identified usage statistics that tell us which tools are used and where they fail.
- Legal compliance — tax and accounting records, and responding to lawful requests.
What we do not do with your content
We do not use the content you submit to train our own models, we do not sell it, and we do not publish it. Where we produce public trend or benchmark material, it is built from aggregated figures with identifiers removed, and never reproduces your submissions or results.
4.Legal bases (UK and EEA users)
If you are in the UK or the European Economic Area, we rely on the following legal bases under the UK GDPR and EU GDPR:
- Performance of a contract
- Creating and running your account, executing the tools you request, and taking payment. Without this data we cannot provide the service.
- Legitimate interests
- Securing the platform, preventing fraud and abuse, keeping error diagnostics, and understanding aggregate usage to improve the product. We balance these against your rights and use the least data that achieves the purpose.
- Legal obligation
- Retaining financial records and responding to lawful requests from authorities.
- Consent
- Newsletter subscriptions only. You can withdraw consent at any time using the unsubscribe link, without affecting anything else.
5.AI processing
Our tools work by sending the material you submit to third-party AI models. This is the part of the service most people want to understand precisely, so:
- Text analysis and copy generation run on DigitalOcean’s serverless inference platform.
- Video you upload to Ad Vision is analysed by Google Gemini, because it is the video-capable model in our stack.
- Video generated by the UGC Ad Creator and Ad Launch Kit is produced by OpenAI.
- Pages you ask us to analyse are fetched through ScraperAPI, which receives the URL you submitted.
These providers process the material to return a result and under their own terms. We do not grant them the right to use your content to train their models, and we do not train on it ourselves. AI output is generated automatically, can be wrong, and has no legal or similarly significant effect on you — we make no automated decisions about you in the sense of Article 22 of the GDPR.
7.International transfers
We are based in the United States, and the processors above are largely US-based. If you use the service from outside the United States, your personal data will be transferred to and processed in the United States, where privacy laws differ from those in your country.
Where we transfer personal data out of the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, together with the safeguards our processors maintain. You can request details of the mechanism used for a particular transfer by writing to info@insightdrivenads.com.
8.How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | While your account is open; erased when you delete it |
| Submitted content, analyses and generated assets | While your account is open, so your history stays available. Deleting the account deletes the stored files with it |
| Credit batches | 30 days from the date granted — unused credits expire on that schedule |
| Credit ledger and billing records | Up to 7 years after the transaction, to meet tax and accounting obligations |
| Email verification and password reset tokens | Until used or expired — hours, not days |
| Session cookies | 7 days at most (see the Cookie Policy) |
| Error diagnostics | A rolling window for troubleshooting, then discarded |
| Newsletter subscription | Until you unsubscribe |
Data
Account and profile
Kept for
While your account is open; erased when you delete it
Data
Submitted content, analyses and generated assets
Kept for
While your account is open, so your history stays available. Deleting the account deletes the stored files with it
Data
Credit batches
Kept for
30 days from the date granted — unused credits expire on that schedule
Data
Credit ledger and billing records
Kept for
Up to 7 years after the transaction, to meet tax and accounting obligations
Data
Email verification and password reset tokens
Kept for
Until used or expired — hours, not days
Data
Session cookies
Kept for
7 days at most (see the Cookie Policy)
Data
Error diagnostics
Kept for
A rolling window for troubleshooting, then discarded
Data
Newsletter subscription
Kept for
Until you unsubscribe
After account deletion, limited records may persist where we are legally required to keep them — principally invoices and payment records held by us or by Stripe — and in routine encrypted backups until those rotate out.
9.Security
The measures below are the ones actually in place, not aspirations:
- Passwords are stored only as bcrypt hashes. A breach of our database would not reveal them.
- Traffic is served over TLS, and the database connection is encrypted.
- Session cookies are HttpOnly and SameSite, and carry the __Secure- and __Host- prefixes over HTTPS, so page scripts cannot read them and they cannot be set by another site.
- A Content Security Policy restricts which origins the browser may talk to.
- Sign-up, sign-in and password reset are rate limited per IP and per email, and protected by a bot check.
- Authentication cookies and credentials are scrubbed out of error reports before they are transmitted.
- Administrative actions on accounts are written to an audit log.
No system is perfectly secure, and we cannot guarantee absolute security. Use a strong, unique password, keep it to yourself, and tell us promptly at info@insightdrivenads.com if you believe your account has been compromised. Where the law requires it, we will notify you and the relevant regulator of a personal data breach without undue delay.
10.Your rights
Depending on where you live, you have some or all of the following rights:
- Access — a copy of the personal data we hold about you.
- Correction — to fix data that is inaccurate or incomplete.
- Deletion — to have your personal data erased.
- Portability — a machine-readable copy of the data you provided.
- Restriction and objection — to limit or object to processing based on legitimate interests.
- Withdraw consent — where processing rests on consent, at any time.
- Non-discrimination — we will not degrade your service because you exercised a privacy right.
How to exercise them
You can delete your account and its stored files yourself at any time from Settings — that is the fastest route to erasure and needs no request. For anything else, email info@insightdrivenads.com from the address on your account. We respond within 30 days, and will tell you if we need longer or need to verify your identity first. Using an authorised agent is fine; we will ask for proof of their authority.
If you are in the UK or EEA and think we have handled your data badly, we would like the chance to fix it — but you may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner’s Office.
11.US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have the rights listed above, exercised the same way. Under the California Consumer Privacy Act you may also request the categories of personal information we collected, the sources, the business purpose, and the categories of third parties we disclosed it to — all of which are set out in sections 2, 3 and 6 of this policy.
Florida residents. The Florida Digital Bill of Rights applies by its terms only to a narrow class of very large businesses, which we are not. We honour the access, correction, deletion and portability requests described above for Florida residents regardless.
Where a state law provides a right to appeal a refused request, you may appeal by replying to our decision. We will respond in writing with our reasoning.
12.No sale of personal data
We do not sell or share personal information
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the twelve months preceding the date of this policy. We do not offer financial incentives in exchange for personal information, and we do not knowingly sell the personal information of anyone under 16.
Because there is nothing to opt out of, we do not operate a “Do Not Sell or Share My Personal Information” mechanism. We honour Global Privacy Control signals as an opt-out where they apply.
13.Children
The service is a business tool intended for adults. It is not directed to children, and you must be at least 18 to hold an account. We do not knowingly collect personal data from anyone under 13, and if we learn that we have, we will delete it promptly. A parent or guardian who believes a child has given us data should contact info@insightdrivenads.com.
14.Changes and contact
We update this policy when the service changes. The revision date at the top always reflects the current version. If a change materially affects your rights, we will give notice by email or in the application before it takes effect. Continuing to use the service after that means you accept the updated policy.
This policy is governed by the laws of the State of Florida, United States, without regard to its conflict-of-laws rules.
Questions about this policy?
Privacy requests, questions about a processor, or anything in this document that is not clear — write to us and a person will answer.
info@insightdrivenads.comSee also Privacy Policy · Terms of Service · Cookie Policy
