AdKit Privacy Policy
Last updated: 16 September 2026
At https://adkit.so, we are committed to protecting the privacy of our users and customers. This Privacy Policy explains how we collect, use, and disclose personal information when you use our website
1. Information Collection
We collect information from you when you use our website or service, including:
- Device Information: When you visit our website, we collect information about your device, such as your IP address, browser type, and operating system. We also collect information about your browsing activity on our website, such as the pages you visit, the links you click, and the search terms you use.
- Log Data: We also collect log data when you access our website or service, which includes information about your device, browser, and internet service provider, as well as the date and time of your request.
- Cookies: We use cookies to improve your experience on our website and to remember your preferences. Cookies are small text files that are stored on your device when you visit a website.
- Google Analytics and Metrics: We use these services to track and analyze website traffic, usage, and behavior.
- Third-Party Services: We may also use third-party services such as Twitter for tracking and analyzing website traffic, usage, and behavior. These services may collect and share your personal information for their own uses and purposes. You can read more about Twitter's privacy policy here: https://twitter.com/en/privacy.
2. Use of Personal Information
We use the personal information we collect for the following purposes:
- To provide and improve our website and service
- To process your orders and payments
- To communicate with you about your account, orders, and other transactions
- To screen for potential risk or fraud
- To provide you with information or advertising relating to our products or services
- To comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
3. Disclosure of Personal Information
We do not sell or share your personal information with third parties for their own marketing or commercial use. However, we may share your personal information with third parties for the following purposes:
- Service Providers: We may share your personal information with third-party service providers who assist us with various aspects of our business operations, such as website hosting, data analysis, payment processing, and customer service.
- Compliance with Laws and Law Enforcement: We may disclose your personal information to government authorities or law enforcement officials in order to comply with applicable laws, regulations, or legal process.
- Protection of Rights and Safety: We may disclose your personal information to protect the rights, property, or safety of https://adkit.so, our users, or the public.
4. Meta Platform Data
If you connect your Meta (Facebook) advertising account to AdKit, the following applies:
- Data accessed: When you connect your Meta ad account, we access your ad account information, campaign data, ad performance metrics, Business Manager details, and Facebook Page names through the Meta Marketing API. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your Meta access token is encrypted using AES-256-GCM before being stored in our database and is only used server-side. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your Meta advertising data with any third parties. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your Meta account at any time from within the app or by removing AdKit from your Facebook Business Integrations settings. Upon disconnection, your stored token is deleted.
- Data deletion: When you disconnect your Meta account, your encrypted access token and the stored performance metrics for that account are deleted. If you request data deletion through Facebook, we process it the same way and confirm the request. You can also contact us at contact@adkit.so for any data-related requests.
5. Google Ads Data
If you connect your Google Ads account to AdKit, the following applies:
- Data accessed: When you connect your Google Ads account, we access your account information, campaigns, ad groups, ads, keywords, and performance metrics through the Google Ads API. We collect this data for two purposes: to provide campaign management and reporting to you within our interface, and to produce aggregated, anonymous industry benchmarks as described below.
- Data storage: Your OAuth refresh token is encrypted using AES-256-GCM before being stored in our database. Access tokens are short-lived, fetched on demand from Google's OAuth servers, and never stored. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your Google Ads data with any third parties. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your Google Ads account at any time from within the app or by removing AdKit from your Google Account permissions. Upon disconnection, your stored credentials are deleted.
- Data deletion: When you disconnect your Google Ads account, your encrypted refresh token and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
6. Google Merchant Center Data
If you connect your Google Merchant Center account to AdKit, the following applies:
- Data accessed: When you connect your Google Merchant Center account, we access your Merchant account information, product listings, product approval status, item-level product issues, affected countries, account issues, and Merchant report rows through the Google Merchant API. This data is used solely to display catalog health, product diagnostics, account issues, and reporting within our interface.
- Data storage: Your OAuth refresh token is encrypted before storage. Access tokens are short-lived, fetched on demand from Google's OAuth servers, and never stored. Merchant account, product, issue, and report data is fetched from Google's API as needed and is not sold or shared.
- Data sharing: We do not share your Google Merchant Center data with any third parties except service providers that help us operate AdKit under confidentiality and security obligations.
- Revoking access: You can disconnect your Google Merchant Center account at any time from within the app or by removing AdKit from your Google Account permissions. Upon disconnection, your stored Merchant Center credentials are deleted.
- Data deletion: When you disconnect your Google Merchant Center account, your encrypted refresh token and any remaining Merchant Center diagnostic data are deleted from our systems. You can also contact us at contact@adkit.so for any data-related requests.
7. TikTok Ads Data
If you connect your TikTok Ads account to AdKit, the following applies:
- Data accessed: When you connect your TikTok Ads account, we access your advertiser account information, campaigns, ad groups, ads, creatives, audiences when enabled, and performance metrics through TikTok API for Business. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your TikTok API credentials are encrypted using AES-256-GCM before being stored in our database. Access tokens are short-lived or refreshed according to TikTok's API requirements. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your TikTok advertising data with any third parties. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your TikTok Ads account at any time from within the app or by revoking access in TikTok's business settings. Upon disconnection, your stored credentials are deleted.
- Data deletion: When you disconnect your TikTok Ads account, your encrypted credentials and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
8. Reddit Ads Data
If you connect your Reddit Ads account to AdKit, the following applies:
- Data accessed: When you connect your Reddit Ads account, we access your Reddit ad account information, campaigns, ad groups, ads, creatives, audiences, conversion events, and performance metrics through the Reddit Ads API. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your OAuth refresh token is encrypted using AES-256-GCM before being stored in our database. Access tokens are short-lived, fetched on demand from Reddit's OAuth servers, and not stored long term. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your Reddit advertising data with any third parties except service providers that help us operate AdKit under confidentiality and security obligations. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your Reddit Ads account at any time from within the app or by revoking AdKit from your Reddit account's authorized applications. Upon disconnection, your stored Reddit credentials are deleted.
- Data deletion: When you disconnect your Reddit Ads account, your encrypted refresh token and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
9. LinkedIn Ads Data
If you connect your LinkedIn Ads account to AdKit, the following applies:
- Data accessed: When you connect your LinkedIn Ads account, we access your ad account information, campaign groups, campaigns, creatives, and performance metrics through the LinkedIn Marketing API. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your OAuth tokens are encrypted using AES-256-GCM before being stored in our database. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your LinkedIn Ads data with any third parties except service providers that help us operate AdKit under confidentiality and security obligations. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your LinkedIn Ads account at any time from within the app or by removing AdKit from your LinkedIn account permissions. Upon disconnection, your stored credentials are deleted.
- Data deletion: When you disconnect your LinkedIn Ads account, your encrypted tokens and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
10. Microsoft Advertising Data
If you connect your Microsoft Advertising account to AdKit, the following applies:
- Data accessed: When you connect your Microsoft Advertising account, we access your account information, campaigns, ad groups, ads, keywords, and performance metrics through the Microsoft Advertising API. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your OAuth refresh token is encrypted using AES-256-GCM before being stored in our database. Access tokens are short-lived and refreshed as needed. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your Microsoft Advertising data with any third parties except service providers that help us operate AdKit under confidentiality and security obligations. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your Microsoft Advertising account at any time from within the app or by removing AdKit from your Microsoft account permissions. Upon disconnection, your stored credentials are deleted.
- Data deletion: When you disconnect your Microsoft Advertising account, your encrypted refresh token and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
11. X Ads Data
If you connect your X Ads account to AdKit, the following applies:
- Data accessed: When you connect your X Ads account, we access your ad account information, campaigns, line items, promoted posts, creatives, and performance metrics through the X Ads API. This data is used to display and manage your advertising campaigns within our interface and for the benchmarks described below.
- Data storage: Your X API credentials are encrypted using AES-256-GCM before being stored in our database. Performance metrics are stored securely on our servers to power reporting and benchmarks.
- Data sharing: We do not share your X Ads data with any third parties except service providers that help us operate AdKit under confidentiality and security obligations. Anonymous, aggregated benchmarks are covered below.
- Benchmarks: To show you how your results compare with similar advertisers, performance metrics are combined across connected accounts into anonymous industry benchmarks shown in AdKit. No account, advertiser or customer is identifiable. You can turn benchmarks off at any time in your workspace settings.
- Revoking access: You can disconnect your X Ads account at any time from within the app or by removing AdKit from your X account connected apps. Upon disconnection, your stored credentials are deleted.
- Data deletion: When you disconnect your X Ads account, your encrypted credentials and the stored performance metrics for that account are deleted from our database. You can also contact us at contact@adkit.so for any data-related requests.
12. Google Analytics and Search Console Data
If you connect Google Analytics or Google Search Console to AdKit, the following applies:
- Data accessed and used: For Google Analytics, we access property names and read-only traffic source, landing page, session, active user, and key event data. For Search Console, we access verified sites and read-only query and page performance data, including clicks, impressions, click-through rate, and average position. We use this data only to display the reports you request in AdKit.
- Data storage: OAuth credentials are encrypted using AES-256-GCM and stored in a Secure, HttpOnly cookie for up to seven days. Google Analytics and Search Console report data is fetched on demand and is not retained by AdKit.
- Data sharing: We do not sell this data, share it with third parties for their own use, or use it for advertising, benchmarks, or AI model training. Service providers may process it only as needed to operate AdKit under confidentiality and security obligations.
- Read-only access: We request only the Google Analytics and Search Console read-only permissions needed to display these reports. AdKit cannot change your Google Analytics or Search Console data.
- Revoking access and deletion: You can disconnect either integration in AdKit or revoke access from your Google Account permissions. Disconnecting clears the related OAuth credentials, and report data is not retained. You can also contact us at contact@adkit.so for data-related requests.
- Google API policy: Our use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
13. Data Security
We implement the following measures to protect your data:
- Encryption in transit: All connections between your browser, our servers, and third-party APIs (including Google, Meta, TikTok, Reddit, LinkedIn, Microsoft, and X) are secured using HTTPS/TLS.
- Encryption at rest: Sensitive credentials such as OAuth tokens and API keys are encrypted using AES-256-GCM before storage. Encryption keys are managed separately from stored credentials and are never exposed to client-side code.
- Access controls: Authentication tokens are processed server-side and are never exposed to client-side JavaScript or the application interface. Access to production systems is restricted to authorized personnel.
- Data retention: Campaign drafts remain available so you can review past changes, and they are removed when you delete them. A limited activity history is available if you need to review or audit actions taken through AdKit.
- Least-privilege API scopes: We only request the minimum API permissions necessary to provide the functionality you use.
14. Your Rights
If you are a resident of certain countries, including those in the European Economic Area, you have certain rights in relation to your personal information, including the right to request access to, correct, update, or delete your personal information. If you would like to exercise any of these rights, please contact us at contact@adkit.so.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or to comply with legal or regulatory requirements.
16. Contact Us
If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us at contact@adkit.so or by mail at:
AdKit - 160 Robinson Road,#14-04 Singapore Business Federation Center, 068914, Singapore
We will make every effort to respond to your inquiry and address any concerns you may have.