← Adsome Suite

Privacy Policy

Last updated: 31 July 2026

1

Who we are

Adsome Suite is operated by Stromberg Media AB, org.nr 559387-6591, registered in Stockholm, Sweden. We are the data controller for the personal data described here. Contact: carl@adsome.io.

2

Meta Platform Data

Some of what we process is Platform Data — data we receive from Meta through the Marketing API. We handle it as follows.

What we receive

Ad account, campaign, ad set and ad metadata; creative content including image and video references, primary text, headlines and calls to action; and performance metrics such as impressions, reach, frequency, clicks, spend, conversions, conversion value and video view-through rates. Where you connect via Facebook Login we also receive your Meta user id, name and email, and the list of ad accounts and Pages you administer.

Why we receive it

Solely to operate this platform for you: to report on advertising performance, to generate analysis and creative recommendations, and to create or amend advertising at your instruction.

What we never do with it

We do not sell it, rent it, or share it with any third party for their own purposes. We do not use it for advertising of our own, to build profiles of individuals, to make decisions about credit, employment, housing or insurance, or to attempt to identify the individuals who saw your ads. We do not combine it with data from other sources to enrich profiles.

Which permissions we request and why

ads_read to retrieve performance data; ads_management to create and amend ads at your instruction; business_management to list the ad accounts in your business portfolio; pages_show_list and pages_read_engagement to identify the Page an ad is published from. We request nothing beyond these.

Where it is processed

In the EU. See sub-processors below.

We process Platform Data in accordance with Meta's Platform Terms and Developer Policies. If our access is revoked or the app is removed from your Meta settings, we stop processing immediately and delete what we hold.

3

Other data we collect

  • Account identity — your name and email, to authenticate you and determine which ad accounts you may view.
  • Access tokens — encrypted at rest, used only to retrieve the data above on your behalf.
  • Operational logs — a record of the API requests we make, so we can monitor our own use of the Meta API responsibly and detect problems early.

We do not use cookies for advertising or analytics. The only cookie we set is the one that keeps you signed in.

4

Legal basis

We process this data to perform our contract with you or with the agency acting on your behalf (GDPR Article 6(1)(b)), and where relevant on the basis of our legitimate interest in operating and securing the platform (Article 6(1)(f)). We do not rely on consent for advertising purposes, because we do not process your data for advertising.

5

Sub-processors

Each processes data only on our instruction, under a data processing agreement:

  • Cloudflare — application hosting and content delivery.
  • Supabase — database, authentication and file storage, hosted in the EU.
  • Anthropic — the model that generates performance analysis and creative recommendations. Aggregated metrics and creative copy are sent for this purpose. They are not used to train models.
6

Retention

Platform Data and advertising metrics are retained while your account is active and for 90 days after it closes, then deleted. Access tokens are deleted immediately on disconnection or revocation. Operational logs are retained for 12 months. Records we are legally required to keep, such as invoices under Swedish accounting law, are retained for the statutory period and contain billing details only.

7

Your rights

Under the GDPR you may access, rectify, erase, restrict processing of, and port your personal data, and object to processing. To exercise any of these, email carl@adsome.io. We respond within one month.

You can request deletion of everything associated with your Meta account at any time from our data deletion page. Removing Adsome Suite in your Meta settings triggers the same deletion automatically. You may also complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority.

8

Security

All traffic is served over HTTPS with HSTS. Access tokens are encrypted at rest and never exposed to the browser. Client data is isolated at two independent layers — an authorisation check in the application and row-level security enforced by the database — so one client cannot read another's data even if an application check were missed. Access is role-scoped and least-privilege. We do not store passwords; authentication is handled by our authentication provider. Every API request we make is logged, and we monitor our own rate-limit usage to avoid degrading the platforms we depend on.

9

Children

Adsome Suite is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

10

Changes and contact

Material changes to this policy will be communicated to account holders by email before taking effect. Questions: carl@adsome.io, or write to Stromberg Media AB, Stockholm, Sweden.

Terms of ServiceData deletionSign in