AdArchitect

A campaign structure for your Amazon PPC, explained in plain English.

← Back to homepage

Privacy Policy

Last updated: 27 August 2026. This is a plain-language description, written in good faith to reflect what actually happens in the app today.

Who this is

AdArchitect is operated by an individual based in Cyprus, not a registered company. Because the operator is established in Cyprus, this policy is written to meet EU/GDPR standards regardless of where you, the customer, are located.

What this policy covers

What personal data AdArchitect collects when you use the site, why it's collected, who it's shared with, how long it's kept, and the rights you have over it.

What personal data we collect

How and why we use it

Who we share it with

We don't sell your data. It's shared only with the services that make AdArchitect work, and only to the extent each one needs:

We may also disclose data if legally required to.

How we protect your data

There's no password to leak, since login is passwordless. Card data is handled entirely by Stripe's hosted checkout, never by our own server. Database queries are parameterized against injection. Login attempts are rate-limited, and forms are protected against cross-site request forgery.

Cookies

AdArchitect sets one strictly-necessary session cookie to keep you logged in. This one is always set, since the site can't function without it, and doesn't require consent.

We also set a separate, first-party site-journey cookie to measure the sequence of pages visitors use to move through the site (for example, which page most people land on first, and which page they're most often on when they leave), so we can find and fix real navigation and content problems. This is not the same as the Google Analytics/Meta cookies described below: it's set by AdArchitect directly, is never shared with Google, Meta, or anyone else, is never linked to your account, email, or a purchase, and is automatically deleted after 30 days. It's set automatically on your first visit unless your browser sends a Global Privacy Control or Do Not Track signal, in which case nothing is set at all. You can also opt out manually, regardless of what your browser sends, by visiting this opt-out link — doing so clears the cookie immediately and stops a new one being set in this browser.

Separately, if you land on our homepage, we set a cookie to randomly place you into one of a few page-design variants, so we can measure which one performs better (this is standard, common practice known as A/B testing). Unlike the site-journey cookie above, this one is associated with your purchase if you buy a plan, so we can tell which design led to it.

We also use Google Analytics to understand how the site's used, and the Meta Pixel (plus its server-side counterpart, the Meta Conversions API) to measure our Facebook and Instagram advertising, but both only if you accept via the cookie banner shown on your first visit. If you accept, Google Analytics sets its own cookies (_ga, _ga_*) to measure visits, and Meta sets its own (_fbp) to recognize your browser across visits; that same cookie is also what tells our server you've consented, which is what allows the server-side Conversions API calls described below to fire at all. If you reject or don't respond, no analytics or advertising cookies are set: Google receives only anonymized, cookie-free usage pings, and neither the Meta Pixel nor the Conversions API sends anything. The banner's Accept and Reject buttons cover both together; we don't offer a separate choice per vendor. You can change your choice at any time by clearing your browser's local storage for this site and revisiting; the banner will show again.

If you're logged in when you accept analytics cookies, we also send Google Analytics your internal account ID (an internal number, not your email) so a purchase can be linked to the visit that led to it, even if the payment confirmation happens on our server rather than in your browser. Likewise, if you take the free quiz, start checkout, or complete a purchase while logged in and have accepted, our server sends Meta a one-way cryptographic hash of your email address and of that same internal account ID (never the raw email, ID, name, or plan details) through the Conversions API, so that action can be matched to the ad click that led to it even if your browser blocks the Pixel itself or the purchase confirmation happens after you've left the page.

Children's data

AdArchitect is not intended for anyone under 18.

How long we keep your data

We keep your account and plan history for as long as your account is active, since viewing past plans is a real feature of the product. Email us to request deletion of your account and data.

Your rights

Under GDPR, you have the right to access, correct, or delete your personal data, restrict or object to its processing, request a copy in a portable format, and withdraw consent at any time. To exercise any of these, contact us below.

Right to complain

If you're unhappy with how we've handled your data, you can lodge a complaint with Cyprus's Office of the Commissioner for Personal Data Protection, the relevant authority given AdArchitect operates from Cyprus.

Changes to this policy

We may update this policy as the product changes. The "last updated" date above will always reflect the most recent revision.

Contact us

Questions about this policy, or requests about your data, can be sent to [email protected].