Skip to content
adplainly
  • Product
  • Pricing
  • Security
  • Contact
Sign inContact us

Privacy policy

Privacy policy

Effective 27 August 2026 · Limited Liability Company "Simplicity"

Adplainly is a read-only analytics service for Meta advertising accounts. This policy explains what data we handle, why, where it is stored, for how long, and how you can have it deleted. It is written to be read, not skimmed; if anything is unclear, e-mail us.

On this page

  1. Who we are
  2. What this policy covers
  3. Meta Platform Data
  4. Account data
  5. Contact-form and support data
  6. Technical data and logs
  7. Cookies
  8. Legal bases
  9. Sharing and subprocessors
  10. International transfers
  11. Retention
  12. Deleting your data
  13. Security measures
  14. Your rights
  15. Children
  16. Changes to this policy
  17. Contact

1. Who we are

The controller of the personal data described in this policy is Limited Liability Company "Simplicity" (Товариство з обмеженою відповідальністю «Сімплісіті»), a company registered in Ukraine.

Registered address8 Molodizhnyi Lane, Lubny, Poltava oblast, 37503, Ukraine
Registration number (ЄДРПОУ)[ЄДРПОУ — to be inserted]
E-mailsupport@adplainly.com
ServiceAdplainly — adplainly.com, app.adplainly.com

In this policy "we", "us" and "Adplainly" refer to this company; "you" refers to the person or organisation using the service or visiting this site.

2. What this policy covers

This policy applies to:

  • the marketing site at adplainly.com;
  • the customer dashboard at app.adplainly.com and the API at api.adplainly.com;
  • data we receive from Meta Platforms when you connect your advertising accounts;
  • e-mails and forms you send us.

Adplainly is intended for business use. Where our customers are companies, the personal data we handle is mostly that of their staff (names, work e-mail addresses) and identifiers of their advertising assets.

3. Meta Platform Data

"Meta Platform Data" means data we obtain from Meta Platforms, Inc. and Meta Platforms Ireland Ltd ("Meta") through the Meta Marketing API on your behalf. This section describes it in full, because it is the core of the service.

3.1 What we collect

  • Ad account identifiers and names — the act_… id, display name, currency, time zone and status of each ad account you choose to connect.
  • Business portfolio identifier — the id (and name, where returned) of the Meta business portfolio that owns or is granted access to those ad accounts.
  • Campaign-level performance metrics — for each connected ad account, per campaign and per day: impressions, reach, frequency, clicks, spend, results and conversions with their values, cost per result, return on ad spend, and the same figures broken down by age band, gender, placement, country and device platform. Campaign names, ids, objectives and statuses are collected so that metrics can be labelled.
  • Your Meta user id and the scopes granted to the access token, used to verify permissions and to match Meta's deauthorisation and deletion callbacks to your connection.
  • An access token issued by Meta that allows the read access described above.

We do not collect ad creatives, audiences, custom audience membership, individual-level data about the people who saw or clicked your ads, page content, messages, or any data from personal profiles.

3.2 Why we collect it

Solely to provide the analytics service you requested: to collect your campaign metrics daily, store their history, and show them to you and the colleagues you invite as time series, comparisons and breakdowns. We do not use Meta Platform Data for advertising, profiling, building audiences, training models, or any purpose other than providing and supporting the service to you.

3.3 How we obtain it

You connect Adplainly through Facebook Login for Business. Meta asks you to confirm the permissions ads_read and business_management and to choose which business portfolio and ad accounts Adplainly may see. Only after you confirm does Meta issue a token to us. Both permissions are read-only: Adplainly cannot create, edit, pause or delete campaigns, budgets, audiences or creatives, and its code contains no calls that would do so.

Collection then runs automatically, once per day, for the ad accounts you selected, until you disconnect them or delete your data.

3.4 Where it is stored

Meta Platform Data is stored and processed on Amazon Web Services in the eu-central-1 (Frankfurt, Germany) region. It is encrypted in transit (TLS) and at rest (AWS KMS-managed keys). Access tokens are stored in AWS Secrets Manager under a dedicated encryption key and are never written to logs or shown in the dashboard.

3.5 Retention

Meta Platform Data is kept for the duration of your subscription so that your history remains available. When you disconnect an ad account, we stop collecting for it. When you close your account or ask for deletion, all Meta Platform Data is deleted as described in section 12 — at the latest within 30 days.

3.6 Sharing

Meta Platform Data is never sold, rented, or shared with advertisers, data brokers or other third parties. It is processed only by us and by the infrastructure subprocessor listed in section 9 (Amazon Web Services), acting on our instructions. It is shown only to users of your Adplainly organisation.

3.7 Deleting it

You can have all Meta Platform Data deleted in three ways, described in full on the data deletion page:

  1. in the dashboard, Settings → Delete my data;
  2. by e-mail to support@adplainly.com;
  3. by removing Adplainly from your Meta account or business settings. Meta then sends us a data deletion request, which we honour automatically; we return a confirmation code that you can check at adplainly.com/data-deletion.

If you revoke Adplainly's permissions in Meta without requesting deletion, we stop collecting immediately, disable the connection, and delete the access token; stored metrics remain until you delete your data or your subscription ends.

3.8 Meta's terms

Our use of Meta Platform Data is subject to the Meta Platform Terms and Developer Policies. Meta's own handling of your data is described in Meta's Privacy Policy.

4. Account data

When you or a colleague create an Adplainly login, we handle:

  • E-mail address — your login and the address we send service e-mails to (verification, reconnect reminders, deletion confirmations, invoices);
  • Password — stored only as a salted hash in Amazon Cognito; we never see or store the password itself. If you enable two-factor authentication, the authenticator secret is also stored in Cognito;
  • Organisation details — company name, billing address and VAT or registration number, as needed to issue invoices;
  • Usage records — when you signed in, which accounts you connected or disconnected, and requests you made (for example "Sync now" or "Delete my data"), so that we can support you and demonstrate that your instructions were carried out.

5. Contact-form and support data

When you use the contact form or e-mail us, we keep your name, e-mail address, company, the message and our reply so that we can respond and follow up. Contact-form submissions are sent to us by e-mail through Amazon SES and are stored in our mailbox; a short-lived per-address counter is kept to limit abuse of the form. Support correspondence is kept for up to 24 months after the last exchange, or for the duration of your subscription plus 12 months, whichever is longer.

6. Technical data and logs

  • CDN access logs — our sites are delivered by Amazon CloudFront. Its access logs (IP address, request time, URL, user agent, response code) are stored in the AWS us-east-1 region for up to 90 days and are used only for security and troubleshooting.
  • Application logs — structured logs of API requests (request id, path, status, timing, your organisation id) kept for up to 90 days. They contain no access tokens, no passwords and no metric rows.
  • Audit logs — AWS CloudTrail records administrative actions on our infrastructure.

There is no advertising tracking and no third-party analytics on adplainly.com or in the dashboard.

7. Cookies

We use strictly necessary cookies only.

WhereCookie / storagePurposeLifetime
adplainly.comnoneThe marketing site sets no cookies.—
app.adplainly.comAmazon Cognito session tokens (browser storage)Keep you signed in to the dashboard.Until sign-out; refresh token up to 30 days

Because these are strictly necessary, no consent banner is shown. We do not use advertising, analytics or social-media cookies.

8. Legal bases

ProcessingLegal basis (GDPR Art. 6)
Collecting and displaying Meta Platform Data; account data; invoicingContract (Art. 6(1)(b)) — necessary to provide the service you requested
Security logs, abuse prevention, service e-mails about your connectionLegitimate interests (Art. 6(1)(f)) — keeping the service secure and working
Replying to contact-form and support messagesLegitimate interests (Art. 6(1)(f)) and, where you asked us for a quote, steps prior to a contract (Art. 6(1)(b))
Anything optional we may add later (for example product news)Consent (Art. 6(1)(a)), which you can withdraw at any time
Retaining invoices and accounting recordsLegal obligation (Art. 6(1)(c)) under Ukrainian accounting law

Where the UK GDPR applies, the same bases apply under its Article 6. In Ukraine, processing is carried out under the Law of Ukraine "On Personal Data Protection" (No. 2297-VI), on the bases of contract, legitimate interest and, where applicable, consent.

9. Sharing and subprocessors

We share personal data only with the service providers below, who process it on our instructions under written terms, and with authorities where the law requires it. We do not sell personal data.

SubprocessorPurposeLocation
Amazon Web Services EMEA SARL (Luxembourg)Hosting, storage, processing, authentication (Cognito), CDN (CloudFront), transactional e-mail (SES)eu-central-1 (Frankfurt, Germany); CloudFront edge and its logs in us-east-1 (United States)
[E-mail provider — to be confirmed]Support mailbox for support@adplainly.com[to be confirmed]

We will update this table before adding a subprocessor that handles Meta Platform Data or account data.

10. International transfers

Our company is in Ukraine, and our infrastructure is in the European Union (Germany) with CDN delivery and access logs in the United States. Where personal data of EU/EEA or UK residents is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) included in our agreement with Amazon Web Services, and on Amazon's participation in the EU-US Data Privacy Framework. Access by our staff from Ukraine to data stored in the EU is covered by the same clauses in our customer agreement; a copy is available on request.

11. Retention

DataKept for
Meta Platform Data (metrics, account ids, tokens)Duration of the subscription; deleted on request or within 30 days of account closure
Account data (login, organisation details)Duration of the subscription; deleted on request or within 30 days of account closure
Invoices and accounting recordsAs required by Ukrainian law (currently 3 years after the tax year)
Support correspondenceUp to 24 months after the last exchange, or subscription plus 12 months
CDN and application logsUp to 90 days
Deletion records (confirmation code, timestamps, no content)12 months, so you can verify that deletion happened

12. Deleting your data

Deletion removes, for your organisation: Meta access tokens, all collected metrics and aggregates, ad account and business identifiers, dashboard logins and organisation details. Backups that may contain the data expire within 30 days. We keep a minimal record that the deletion was requested and completed (confirmation code and timestamps) and any invoices we are legally required to retain.

Full instructions, including the Meta route and the status check, are on the data deletion page.

13. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AWS KMS) for all stores.
  • Meta access tokens in AWS Secrets Manager under a dedicated key; never logged, never displayed.
  • Least-privilege IAM roles per component; human access via AWS SSO with multi-factor authentication.
  • Infrastructure defined as reviewed code; separate development and production environments.
  • Audit logging (AWS CloudTrail) and monitoring with alerts on failures and anomalies.
  • Read-only Meta permissions, so a compromise of Adplainly could not alter your campaigns.

If we become aware of a personal data breach affecting you, we will inform you without undue delay and, where required, the competent supervisory authority within 72 hours. See also the security overview.

14. Your rights

Under the GDPR, the UK GDPR and Ukrainian law you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate data;
  • erase your data (see section 12);
  • restrict or object to processing based on legitimate interests;
  • data portability — receive data you provided in a machine-readable form; your metrics can be exported from the dashboard;
  • withdraw consent where processing is based on consent, without affecting earlier processing;
  • lodge a complaint with a supervisory authority — in the EU, the authority of your country of residence; in the UK, the Information Commissioner's Office; in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.

To exercise a right, e-mail support@adplainly.com. We respond within one month; we may ask you to confirm your identity through the e-mail address of your account.

Where our customer is a company and you are its employee, the company is the controller of its own use of the service and we act as its processor for Meta Platform Data; please direct requests to your employer, who can instruct us.

15. Children

Adplainly is a business service and is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, e-mail us and we will delete it.

16. Changes to this policy

We may update this policy when the service or the law changes. The effective date at the top always shows the current version. For material changes we will notify account holders by e-mail at least 14 days before they take effect. Earlier versions are available on request.

17. Contact

Limited Liability Company "Simplicity"
8 Molodizhnyi Lane, Lubny, Poltava oblast, 37503, Ukraine
support@adplainly.com

Effective date: 27 August 2026 (version 1.0).

adplainly

Your Meta ads, written down every day. Read-only, always.

Limited Liability Company "Simplicity"
Товариство з обмеженою відповідальністю «Сімплісіті»
8 Molodizhnyi Lane, Lubny, Poltava oblast, 37503, Ukraine
support@adplainly.com

Product

  • What you get
  • Pricing
  • Security
  • Contact
  • Sign in

Legal

  • Privacy policy
  • Terms of service
  • Data deletion

© 2026 Limited Liability Company "Simplicity". All rights reserved.

Adplainly is an independent product and is not affiliated with or endorsed by Meta Platforms, Inc.