Privacy Policy
Last updated: May 7, 2026 · Effective immediately
1. Who We Are
SpendSentinel is a revenue protection service for performance marketing agencies. We compare Meta Ads spend data against your backend conversion data (Voluum, RedTrack, CRM exports) to detect attribution gaps, ghost campaigns, and pixel drift.
For any privacy-related matters, contact us at: privacy@spendsentinel.io
2. Data We Collect
When you submit an audit request, we collect:
- ▸Agency or company name
- ▸Email address (business)
- ▸Monthly Meta Ad spend range
- ▸Website URL
- ▸Submission timestamp
If you become a client and upload CSV exports for auditing, those files may temporarily contain campaign names, spend amounts, and conversion counts. We do not collect personal data of your end users, pixel data, or cookies from your websites.
3. How We Use Your Data
- ▸To process and respond to your audit request within 24–48 hours
- ▸To perform the historical attribution analysis you requested
- ▸To send you audit findings, Slack alerts, and service notifications
- ▸To communicate commercially about our subscription plans (you may opt out at any time)
- ▸To improve our normalization engine and detection accuracy (anonymized, aggregated only)
4. Data Sharing
We do not sell, rent, or share your data with third parties for marketing purposes. Ever.
We use the following sub-processors to operate our service:
- ▸MongoDB Atlas — Encrypted database storage (EU region)
- ▸Resend — Transactional email delivery
- ▸Railway — Backend API hosting (EU-compatible)
Each sub-processor is bound by appropriate data processing agreements. Your data is never used by them for their own marketing or analytics.
5. Data Retention
- ▸Audit request data (name, email, spend range, URL): retained for 12 months for commercial follow-up, then deleted.
- ▸CSV exports uploaded for audits: deleted within 30 days of audit completion, unless you subscribe to live monitoring (in which case they are retained for the duration of your subscription).
- ▸On cancellation: all client data is deleted within 60 days of subscription end, upon written request to privacy@spendsentinel.io.
6. Your GDPR Rights
If you are located in the EU/EEA, you have the following rights under GDPR:
- ▸Right of access — request a copy of the personal data we hold about you
- ▸Right to rectification — correct inaccurate personal data
- ▸Right to erasure — request deletion of your data ('right to be forgotten')
- ▸Right to restriction — limit how we process your data
- ▸Right to data portability — receive your data in a machine-readable format
- ▸Right to object — opt out of commercial communications at any time
To exercise any of these rights, email privacy@spendsentinel.io. We will respond within 30 days.
7. Cookies
SpendSentinel uses only essential cookies required to serve the website. We do not use advertising cookies, fingerprinting, or invasive tracking. No cookie consent banner is required for essential-only cookies under GDPR.
8. Security
All data is transmitted over TLS/HTTPS. Database access is restricted by IP allowlist and requires strong authentication credentials. CSV files are stored in encrypted form and access is restricted to authorized SpendSentinel personnel only.
9. Contact
For any privacy questions or GDPR requests: