AdLyticsSign In

Privacy Policy

Effective date: May 6, 2026

1. Who We Are

AdLytics is a media intelligence platform operated by FYM Labs, LLC, an Illinois limited liability company ("we", "us", "our"). AdLytics helps marketing teams consolidate advertising data and measure cross-channel performance. This Privacy Policy explains how we collect, use, and protect data when you use AdLytics.

2. Data We Collect

We collect the following categories of data:

  • Account data: Name, email address, and organization name provided during sign-up via Clerk authentication.
  • Advertising data: Campaign metrics, spend, impressions, conversions, and audience data fetched from connected ad platforms on your behalf.
  • Usage data: Feature interactions, API call volumes, and error logs used to monitor service health and improve the product.
  • Identity data (optional, legacy):Hashed customer identifiers for cross-channel attribution. These are tokenized using HMAC-SHA-256 and never stored as plain hashes. Workspaces created from September 2026 onward do not accept them at all — identity analysis for those runs inside the customer's own clean room, where the identity key never leaves their environment.

3. Basis for Processing

AdLytics is operated from the United States and our privacy controls are built around the CCPA/CPRA. Analysis that uses identity data runs only where a workspace administrator has recorded a basis for that specific purpose — purpose limitation under CPRA §1798.100(c). Workspaces that record under GDPR instead are held to Art. 5(1)(b), which states the same obligation, and may assert any of the following bases:

  • Contract: To provide the AdLytics service you have subscribed to.
  • Legitimate interests: To improve the platform, prevent fraud, and ensure security.
  • Consent: For optional identity data processing (you control this via the Privacy settings page).

4. How We Use Your Data

  • Provide and operate the AdLytics platform.
  • Generate attribution, halo analysis, and optimization reports.
  • Monitor service reliability and security via Sentry error tracking.
  • Send transactional communications related to your account and billing.

We do not sell your data to third parties. Where a workspace has asked us to export its own data to its own warehouse, identities that have exercised a do-not-sell opt-out under CCPA §1798.120 are excluded from that export for as long as the opt-out stands.

5. Data Retention

Advertising metrics are retained for the duration of your subscription plus 90 days. Account data is retained until you request deletion. Identity tokens are erased on request — see Your Rights for how to submit one.

6. Sub-Processors

We use the following sub-processors:

  • Clerk — Authentication and user management
  • Railway / Render — Cloud hosting (PostgreSQL, Redis, API)
  • Stripe — Payment processing
  • Anthropic — AI-powered insights generation
  • Sentry — Error monitoring (PII masking enabled)

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest. Advertising credentials are encrypted using AES-256-GCM with per-workspace encryption keys. We apply differential privacy (Laplace mechanism) to identity query results to prevent individual re-identification.

8. Your Rights

Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal data. To exercise these rights, email [email protected].

Deletion and do-not-sell requests for identity data are submitted as pre-hashed identifiers through the privacy API — POST /api/v1/privacy/erasure-request and POST /api/v1/privacy/do-not-sell — rather than through a form, because the identifiers come from your own systems. Workspace administrators can review recorded opt-outs, and lift one, under Settings → Privacy. If you are an individual rather than an AdLytics customer, contact us at the address above and we will route your request to the relevant workspace.

9. Contact

For privacy questions or to submit a Data Subject Request, contact us at [email protected].