This Privacy Policy explains how TBSS Labs, LLC (“Adrails”, “we”, “us”, or “our”) collects, uses, stores and protects personal data when you visit adrails.thomasbail.com, use the Adrails platform or use related services (the “Service”).
Adrails is a business service for paid media teams. It connects to advertising, commerce and analytics accounts that a customer chooses to authorize. This policy is intended to meet applicable data protection requirements, including the GDPR and UK GDPR where they apply.
1. Our role
Our role depends on the data involved:
- Controller. We decide how to process account, authentication, waitlist, support, security and service usage data.
- Processor or service provider. A customer controls the advertising, commerce and analytics data it connects to Adrails. We process that data on the customer's instructions to provide the Service.
2. Data we collect
2.1 Visitors and waitlist members
If you join the waitlist, we store your email address and the form from which you joined. We may also receive ordinary request information such as an IP address, browser type, device information and timestamps in infrastructure and security logs.
2.2 Account and workspace data
We store your name, email address, profile image, authentication method, session information, workspace name, workspace membership, role, team membership and invitations. A session may include an IP address and user agent. If you sign in with Google, we receive the profile details Google makes available for authentication. We do not receive your Google password.
2.3 Meta advertising data
When an authorized workspace member connects Meta, we receive the Meta user identifier and name, granted permissions, access token and token expiry. We also receive information for the ad accounts the person may access, including account identifiers, names, currency, timezone and account status.
To build, monitor and explain campaigns, Adrails may process campaign, ad set, ad and creative identifiers and settings; budgets, targeting, delivery and review information; creative metadata and source URLs; and performance metrics such as impressions, spend, frequency, clicks, results and attributed revenue. Adrails does not permanently store the underlying image or video files fetched from Meta.
Meta access tokens are encrypted before they are stored. The Service requests ads_read to read account structure and performance, and ads_management to create or change advertising objects. A write is prepared in Adrails and requires an explicit approval from an authorized workspace member before it is sent to Meta.
2.4 Commerce and analytics integrations
The exact data depends on the services you connect. Current integrations can include:
- Shopify: store identity, products, prices, stock, orders, order lines, refunds, and selected store analytics. Customer records can include a Shopify identifier, name, country, order count and total spent. We do not request payment card details, phone numbers or full postal addresses. Customer email addresses are converted to a one-way fingerprint before storage.
- Klaviyo: aggregated campaign and flow metrics such as sends, opens, clicks, unsubscribes and attributed revenue. The connection uses a read-only private key supplied by the customer.
- Triple Whale: aggregated advertising and commerce metrics such as spend, return on ad spend, acquisition cost and net margin. Adrails does not request customer journeys from Triple Whale.
Integration tokens and private keys are encrypted at rest. Adrails keeps references to product and creative media where required, not copies of those media files. Provider webhook payloads are held temporarily for processing and are scheduled for deletion after 30 days.
2.5 Conversations, approvals and agent memory
We store prompts, answers, selected data sources, tool activity and generated artifacts so a workspace can reopen its conversation history. If a user asks Adrails to remember a preference or policy, that memory is stored for the workspace until an authorized user removes it. We also keep approval records showing who approved an account change, what was proposed, whether it was applied and whether it was reverted.
2.6 Usage and operational data
We process records needed to operate and secure the Service, including connection status, synchronization timestamps, error codes, security events, audit records and AI usage totals. We do not put integration credentials or full webhook bodies in audit records.
3. Why we use data
We use the data described above to:
- create accounts, authenticate users and manage workspaces;
- connect, synchronize and display authorized advertising data;
- prepare campaigns, findings and account changes for approval;
- answer questions using the workspace data selected by the user;
- maintain conversation history, auditability and service security;
- provide support and send important service or security notices;
- detect abuse, investigate errors and comply with legal obligations;
- manage the public waitlist and notify members when access opens.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on:
- Contract, when processing is necessary to provide the Service requested by a customer or user.
- Legitimate interests, for service security, fraud and abuse prevention, support, product reliability and the operation of a business service, balanced against individual rights.
- Consent, where a user joins a waitlist or where local law requires consent for a specific activity. Consent can be withdrawn at any time.
- Legal obligation, when we must retain or disclose data to comply with applicable law.
5. Providers and disclosures
We disclose data only as needed to operate the Service, follow customer instructions, comply with law, or protect the Service and its users. The providers involved can include:
- Google for optional account authentication;
- Meta for authorized advertising account access and changes;
- Shopify, Klaviyo and Triple Whale for customer-authorized data;
- OpenRouter and the model provider selected through it for AI processing;
- hosting, database, cache, email delivery and security providers needed to run Adrails.
We may also disclose information in response to a valid legal request, during a corporate transaction subject to appropriate safeguards, or when necessary to protect rights, safety and service integrity. We do not sell personal data and do not share it for cross-context behavioral advertising.
6. Artificial intelligence
Adrails sends a user's prompt, relevant conversation history, workspace instructions and the tool results needed to answer the request to an AI provider. This can include advertising and aggregated commerce metrics selected for the conversation. Integration tokens, private keys and passwords are not sent to the model.
AI answers and proposed actions can be incomplete or inaccurate. They must be reviewed before use. Adrails does not treat an AI response as an approval to change an advertising account.
7. Cookies
Adrails uses first-party cookies and similar storage that are necessary for authentication, session security and request protection. The public landing page does not currently use advertising cookies or third-party behavioral tracking pixels. If that changes, we will update this policy and request consent where required.
8. Retention
We keep personal data only for as long as needed to provide the Service, meet contractual and legal obligations, resolve disputes and protect the Service. In particular:
- account, workspace and connected data are generally kept while the account or workspace remains active;
- disconnecting a supported integration stops future synchronization and removes the stored credential for that connection;
- temporary webhook payloads are scheduled for deletion after 30 days;
- waitlist data is kept until access opens, you unsubscribe, or you ask us to delete it;
- security and audit records may be retained longer where necessary to prevent abuse, establish what happened or meet a legal obligation.
When data is deleted from active systems, residual copies may remain in protected backups until those backups expire under the normal backup cycle.
9. Meta data and deletion
You can revoke Adrails' access at any time from your Facebook or Meta business settings. Revocation prevents future access, but it does not by itself tell us to delete data already imported into a workspace.
To request deletion of Meta data held by Adrails:
- Email support@adrails.thomasbail.com with the subject “Meta data deletion”.
- Include the email address used for Adrails and, if available, the name or identifier of the relevant workspace or ad account. Do not send an access token, password or private key.
- We may ask for information needed to verify identity and authority over the workspace before deleting data.
- Once verified, we will delete the applicable Meta token, Meta profile details, ad account metadata, snapshots, drafts, archived account objects and related conversation content from active systems, except for limited records we must retain by law or need to establish that the request was completed.
We will confirm receipt and respond within 30 days. For a full Adrails account or workspace deletion, use the same email address and state that broader scope in the request. The same instructions are available at our Data Deletion page.
10. Security
We use technical and organizational measures designed to protect data, including encryption in transit, encryption of Meta and integration credentials at rest, workspace-level access controls, server-side authorization, provider signature checks, rate limits and audit records. No system is completely secure, so users should protect their account and promptly report suspected unauthorized access.
11. International transfers
Adrails and its providers may process data in countries other than the country where a user or customer is located. Where required, we use recognized safeguards for international transfers, such as contractual protections, and assess provider security and confidentiality terms.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or receive a copy of personal data; object to certain processing; withdraw consent; and complain to a data protection authority. These rights may be subject to legal exceptions.
If Adrails processes data for one of our customers, please contact that customer first. We will support the customer in responding. For data we control, email support@adrails.thomasbail.com. We may need to verify your identity before completing a request.
13. Children
The Service is intended for business users and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided data to Adrails, contact us so we can investigate and delete it where required.
14. Changes to this policy
We may update this policy as the Service, integrations or legal requirements change. The date at the top shows the latest revision. We will provide additional notice before a material change takes effect where required.
15. Contact
Privacy questions and requests can be sent to support@adrails.thomasbail.com.
Service: Adrails
Operator: TBSS Labs, LLC
The contractual terms for using Adrails are available in our Terms of Service.
