Privacy Policy - Ads Lord

Last updated: 19/04/2026

1. Who We Are

Arnon Nechmad (Osek Murshe), trading as ARO Flows ("we", "us", "our"), operates the Ads Lord platform, an advertising automation tool that helps marketing agencies and campaign managers upload and manage ads through Meta's Marketing APIs.

We act primarily as a Data Processor (or "Tech Provider") on behalf of marketing agencies and performance companies ("Agencies"). Access to Meta assets is granted by Agencies through Facebook Login for Business and Meta Business Integrations, after which Ads Lord performs automated actions on the Agency's behalf using a dedicated System User and access token.

The Agencies act as the Data Controllers regarding the data of their own clients ("End Clients").

2. Scope of This Policy

This Privacy Policy explains:

  • What data we access and process
  • How we use and store that data
  • With whom we share data
  • How long we keep data
  • Your choices and rights

This policy applies to:

  • Users of the Ads Lord platform (Agency admins and campaigners)
  • Data processed via our automations and integrations with Meta, Tally, Make.com, Notion, Base44, and related tools

3. Information We Access and Process

3.1 Data from Meta Platforms (via System User)

Access to Meta assets is granted through Facebook Login for Business. During this process, the Agency explicitly authorizes Ads Lord to access selected Business Manager assets. Once authorized, Ads Lord uses a System User and its associated access token to perform automated actions strictly within the scope approved by the Agency.

We may access and process:

  • Ad Account IDs, names, and timezones
  • Campaign, Ad Set, and Ad IDs and configuration details
  • Catalog and Product Set identifiers
  • Page IDs (Facebook Pages, Instagram accounts) and basic profile info for attribution
  • Business Manager hierarchy information required to assign assets to the System User

Important: We do not collect personal profile data of End Users (your customers' customers), such as their private messages, friend lists, or personal timelines. We do not access performance insights or reporting data unless explicitly configured by the Agency for operational validation.

3.2 Data from Agency Forms (Client Submissions)

Via forms (e.g., Tally or custom forms deployed by Ads Lord), we may receive:

  • Creative assets (images, videos, banners)
  • Ad copy (primary text, headlines, descriptions, CTAs)
  • Landing page URLs
  • Product information (names, pricing, descriptions)
  • Campaign instructions and configuration preferences
  • Business identifiers (e.g., page names, account nicknames)

All ads generated through Ads Lord are created in an Active state by default, but Agencies can change this to Paused at any time. Active ads may spend immediately upon campaign launch.

3.3 Account & Usage Data

When you use Ads Lord, we may collect:

  • Name and work email
  • Agency name and internal user role
  • Login data and session identifiers
  • Activity logs (e.g., submissions processed, campaigns created, error logs)

4. How We Use Data

We use the data solely to:

  • Upload, create, and manage ads on behalf of Agencies and their clients
  • Process form submissions into structured campaigns and creatives
  • Maintain and secure API connections to Meta via the System User
  • Provide Agencies with submission logs and operational visibility
  • Improve the reliability and performance of our automation flows

We do not sell data. We do not use your clients' creative content or Meta data for any purpose other than providing the Service. We do not use data obtained from Meta to build user profiles for our own tracking purposes.

5. Legal Basis (GDPR & Similar Jurisdictions)

Where applicable, we process data based on:

  • Performance of a contract: Providing the automation service to Agencies.
  • Legitimate interests: Ensuring security, preventing abuse, and improving platform stability.
  • Consent: Where the Agency has obtained valid consent from its End Clients. The Agency is responsible for ensuring it has a valid legal basis to provide us with data.

6. Data Storage & Retention

6.1 Submissions & Creative Data

Submission records and creative assets are stored in Ads Lord systems and/or integrated third-party tools (e.g., Notion, Tally, Make.com, Base44). By default, data is retained until:

  • A submission is marked as "Completed" by the Agency, or
  • The Agency manually deletes it or requests deletion.

Retention policies may be customized at the Agency level.

6.2 Access Tokens (System Users)

System User tokens are stored securely using enterprise-grade secret management tools (e.g., Doppler). These tokens are used strictly to authenticate API calls to Meta to manage your campaigns.

Tokens are rotated or revoked when:

  • The Agency revokes access via Meta Business Integrations
  • We receive a deletion / revocation request
  • Security policies require rotation

6.3 Logs

We retain technical logs (API calls, errors, processing status) only as long as necessary for debugging, security, and audit purposes (typically 30-90 days).

7. Data Sharing & Sub-Processors

We may use third-party service providers to operate the Service. These parties act as sub-processors and are bound by confidentiality and data protection obligations:

  • Make.com: Automation and workflow orchestration
  • Tally: Client-facing forms
  • Notion: Workflow organization (where configured)
  • Doppler: Secure storage of access tokens
  • Base44: Backend database and logic
  • Email Providers: Transactional notifications

We do not share data with unrelated third parties, and we do not sell data.

8. International Data Transfers

Data may be stored or processed in multiple regions (including EU, US, and Israel) depending on our cloud infrastructure providers. Where required by law, we implement appropriate safeguards (such as Standard Contractual Clauses) for international transfers.

9. Your Rights

As an Agency:

  • You may access the data we hold about your submissions.
  • You may request export or deletion of data.
  • You may revoke Ads Lord's access at any time via Meta Business Settings > Integrations > Connected Apps.

As an End Client: Please direct your requests (access, deletion, correction) to the Agency that manages your campaigns. We will assist the Agency in fulfilling valid requests.

10. Facebook User Data Deletion Instructions

Ads Lord uses Facebook Login to provide our services and connect to your Business Assets. We do not save your personal Facebook profile data on our servers. However, according to Facebook platform policy, we provide the following instructions for users who wish to explicitly remove the Ads Lord integration.

If you want to remove the app and its access to your data, you can follow these steps:

  1. Go to your Facebook Account.
  2. Navigate to Settings & Privacy > Settings.
  3. Look for Business Integrations (often under the "Security and Login" or "Permissions" section).
  4. Search for "Ads Lord" (or "ARO | marketing api") in the list of active business integrations.
  5. Select the app and click the Remove button.
  6. You have successfully removed the app and its access to your business assets.

Alternatively, you may email support@ads-lord.com with the subject "Data Deletion Request" to request the deletion of any service-related data we may hold (such as your account profile in our dashboard).

11. Security

We implement robust technical and organizational measures, including:

  • Encryption in transit (HTTPS/TLS)
  • Secure secret management for API tokens (Doppler)
  • Role-based access control
  • Workspace isolation (preventing data mix between Agencies)

12. Contact

For any privacy-related questions or requests:

Email: support@ads-lord.com
Subject line: "Privacy Request - Ads Lord"