Privacy Policy
1. Who we are
AdPilot ("AdPilot", "we", "us") is a software product operated by Shuhai Marketing, a sole proprietorship based in Calgary, Alberta, Canada (the "Operator"). You can reach our privacy team at office@shuhaimarketing.ca.
This Policy applies to the AdPilot web application at manager.shuhaimarketing.com, the marketing site, and any related emails or APIs (together, the "Service").
2. What we collect
2.1 Information you give us
- Account info: name, work email, password hash (if you sign up with email) or Google profile (if you sign in with Google).
- Workspace info: organization name, industry, brand profile fields (colors, fonts, logo, target audience, products/services you advertise).
- Payment info: billing contact, last 4 of card and country (collected and stored by Stripe; we do not store full card numbers).
- Uploads: images, logos, and any reference photos you upload for creative generation.
- Support messages: emails and chat threads you send us.
2.2 Information we get from Meta when you connect
When you connect a Facebook/Instagram ad account via Meta's "Facebook Login for Business", AdPilot receives a system-user access token and the following data from Meta's Marketing API:
- Ad account IDs, names, currency, and timezone
- Pages and Instagram accounts assigned to you
- Active and paused campaigns, ad sets, ads, and creatives
- Ad performance data: impressions, clicks, reach, spend, conversions, purchases, frequency, CPM, CTR, and similar metrics
- Lead form metadata (form names and IDs) — we do not ingest the personal data of leads submitted through your lead forms unless you explicitly enable lead routing
- Custom and lookalike audiences metadata (size, name, type)
We do not request, ingest, or store the personal data of consumers who interact with your ads or fill out your lead forms, except where you separately enable a lead-routing integration and explicitly authorize it.
2.3 Information collected automatically
- Service usage: pages visited, features used, errors encountered, approximate device/browser type, timestamps.
- Audit log: every change AdPilot makes to your Meta account on your behalf (pause/resume, budget change, creative swap), including which user triggered it.
- Cookies: see Section 9.
3. Why we use it
- To run the Service: read your ad data, generate creatives, push changes to Meta when you confirm them.
- To generate insights and recommendations using AI models (Google Gemini, Kie for image generation). Brand profile and ad performance data are sent to these processors only as needed to fulfil your request.
- To bill you via Stripe.
- To support you via email and product notifications.
- To secure the Service — detect abuse, prevent fraud, investigate incidents.
- To improve the product — usage analytics in aggregated form. We do not sell your data to advertisers and we do not use your ad performance data to train shared AI models.
4. Lawful basis (for EEA/UK visitors)
We rely on (a) contract — to deliver the Service you signed up for, (b) legitimate interests — to keep the Service secure and to communicate with customers, and (c) consent — for optional cookies and marketing emails, which you can withdraw at any time.
5. Sharing with sub-processors
We use a small number of trusted vendors. The current list is maintained at /legal/subprocessors. Each is bound by a written agreement with confidentiality and security obligations.
6. International transfers
AdPilot stores its primary database in the United States (Neon, AWS US-East-2). When personal data is transferred from Canada, the EEA, or the UK to the United States, we rely on the recipient's contractual commitments and on Standard Contractual Clauses where applicable.
7. How long we keep data
- Account and workspace data: while your account is active, then 30 days after cancellation. After that we hard-delete unless we are legally required to keep it longer.
- Audit log: 12 months from the action date, then purged.
- Stripe billing records: 7 years (Canadian tax requirement).
- Backups: rolling 30-day window.
- Uploaded creatives and logos: until you delete them or close your account.
8. Your rights
You can ask us to:
- access the personal data we hold about you,
- correct it if it's wrong,
- delete your account and the data tied to it,
- export your data in a machine-readable format,
- restrict or object to certain processing,
- file a complaint with the Office of the Privacy Commissioner of Canada or your local data-protection authority.
Email office@shuhaimarketing.ca and we'll respond within 30 days. For deletion specifically — including data obtained through Facebook Login — see Data Deletion Instructions, which sets out exactly what is erased and what we must keep.
9. Cookies
AdPilot uses three categories of cookies:
- Strictly necessary — session, CSRF, and load-balancer cookies. Cannot be turned off; without them the Service does not work.
- Analytics — first-party PostHog cookies that measure which features get used. Off by default; opt in via the cookie banner.
- Marketing — none. AdPilot does not run third-party advertising trackers on its own site.
10. Children
AdPilot is not directed at people under 16. If you believe a minor has given us personal data, email us and we will delete it.
11. Security
Data is encrypted in transit (TLS 1.2+) and at rest (database-level encryption at our infrastructure providers). Access to production systems is restricted, multi-factor authenticated, and logged. Sub-processor security is reviewed on onboarding. No system is perfect; we will notify affected customers without undue delay (and within 72 hours where required) if a breach affecting their data occurs.
12. Changes to this Policy
We'll post material changes here and email account owners at least 30 days before they take effect. The current version date is shown at the top of this page.
13. Contact
Shuhai Marketing
Calgary, Alberta, Canada
office@shuhaimarketing.ca