Marketing Operator
Features
Loading...

Privacy Policy

Last updated April 27, 2026

DRAFT — requires legal review before launch. This is template seed copy from a public SaaS source; it has not been reviewed by counsel. Do not rely on it as legal advice.

1. Who we are

Marketing Operator (pre-incorporation — not a registered entity) ("we", "us", "our") operates Marketing Operator (the "Service"). For the purposes of the EU General Data Protection Regulation ("GDPR"), the UK Data Protection Act 2018, and the California Consumer Privacy Act ("CCPA") / California Privacy Rights Act ("CPRA"), we are the data controller for personal data we collect about you when you use the Service.

You can reach us at support@marketingoperator.ai. Our data-controller mailing address is: Postal address not yet published — contact support@marketingoperator.ai for data-subject requests.

2. What we collect

We collect personal data in three buckets:

  • Account information you provide directly: email address, password (hashed), display name, organisation / team affiliation, billing address (when you subscribe), and any preferences you set in your account.
  • Usage data generated as you use the Service: IP address, device and browser metadata, request timestamps, pages visited, features used, credit consumption, and aggregated performance metrics.
  • Customer Content you submit: the URLs you ask the Service to scrape for site-content import or research, the URLs you submit for Meta ad-library research, the prompts you provide to AI generation, the brand assets and product photos you upload, ratings and feedback you give to generated outputs, and any text or media you create in the Service.

3. Why we use it

We process the personal data above to:

  • Provide the Service — authenticate you, render your dashboard, generate ads and research collections you request, deliver downloads and exports.
  • Bill and administer your subscription — record credit usage, charge subscription fees, prevent fraudulent transactions, comply with tax law.
  • Support you — answer support tickets, investigate errors, restore deleted data within the grace period.
  • Secure the Service — detect and respond to abuse, rate-limit endpoints, audit privileged actions, comply with our security obligations to other customers.
  • Improve the Service — measure feature adoption, debug performance regressions, and (with your consent) analyse aggregated usage patterns to plan the roadmap.

The legal basis for this processing under GDPR is one of: performance of our contract with you (Art. 6(1)(b)), our legitimate interests in operating and securing the Service (Art. 6(1)(f)), your consent for analytics and marketing cookies (Art. 6(1)(a)), and compliance with legal obligations (Art. 6(1)(c)).

4. Third-party processors and subprocessors

We share personal data with the following third parties strictly to deliver the Service. Each is bound by a Data Processing Agreement that limits processing to the purpose for which we disclose the data:

  • OpenRouter — AI text and image generation routing.
  • Replicate — AI video and image model hosting.
  • Polar.sh — payment processing, subscription billing, refund handling.
  • PostHog — product analytics (only after you grant cookie consent — see Section 7).
  • Termly — geo-aware cookie consent management; renders the consent banner.
  • Cloudflare R2 — encrypted object storage for media you upload and we generate.
  • Resend — transactional email (sign-in confirmations, billing receipts, support replies).
  • Railway — application hosting, managed PostgreSQL database, log retention.

Internal scraper disclosure

We operate our own internal scraper service that fetches URLs you provide for site-content import — including competitor or public websites you submit for ad research — and Meta ad libraries on your behalf for research collections. This scraper runs inside our infrastructure (we do not delegate scraping to a third-party vendor). It honours robots.txt directives and the rate-limit signals of the sites it fetches. The data it returns to your account is treated as Customer Content (see Section 2) and is subject to the same retention and deletion rules.

5. International transfers

Your personal data may be transferred to, stored, and processed in countries outside your country of residence, including the United States. Where we transfer personal data from the EU/EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses ("SCCs") and apply additional safeguards as required by case law.

6. Retention

We retain personal data while your account is active. When you delete your account, your data enters a thirty (30) day grace period during which sign-in restores it. After the grace period, we permanently delete the personal data we hold about you, except for:

  • Records we are legally required to retain (e.g. invoices, tax records — typically 7 years).
  • Aggregated, anonymised analytics that no longer identify you.
  • Security audit logs (typically 90 days), which retain a hashed identifier rather than your email or name.

Your generation records — the provenance of each output we generate for you, including the prompts you submit and references to the product media you upload — together with the ratings you leave on those outputs and your download history, are retained for the life of your account. They carry no separate auto-expiry: we keep them so your generation history stays available to you, and we remove them when you delete your account. On deletion these records are erased as part of the same account-purge cascade described above, within the thirty (30) day grace window.

Backups are overwritten on a rolling thirty (30) day cycle; deleted data persists in the most recent backup until that cycle completes.

7. Cookies and similar technologies

We use cookies and similar storage technologies for two purposes:

  • Essential — required to operate the Service (authentication session, CSRF protection, theme preference). These cookies are set without your consent because the Service cannot function without them.
  • Analytics — PostHog cookies that help us measure feature adoption and debug regressions. These are set only after you opt in via the cookie consent banner.

Our cookie banner is provided by Termly and adapts to your jurisdiction (opt-in for GDPR/UK regions, opt-out for California). You can change your preferences at any time from the "Privacy & Cookies" panel in your account settings. See our Cookie Policy for the full list of cookies we use.

8. Your rights (GDPR, UK GDPR, CCPA / CPRA)

Subject to the law that applies to you, you have the right to:

  • Access the personal data we hold about you. You can download a structured JSON copy of your account data from Settings → Export my data.
  • Rectify inaccurate or incomplete personal data. Edit your profile in Settings.
  • Delete your account. From Settings → Danger zone. Subject to the thirty (30) day grace described in Section 6.
  • Object to processing based on legitimate interests, including direct marketing.
  • Restrict processing in certain circumstances. Contact support@marketingoperator.ai.
  • Portability — receive your data in a structured, commonly used, machine-readable format. The Settings export delivers JSON.
  • Withdraw consent for analytics cookies. Manage from the cookie preferences panel in Settings.
  • Lodge a complaint with your local data protection authority (e.g. the Irish Data Protection Commission for EU residents, the UK Information Commissioner's Office for UK residents).

California residents additionally have the right to know, delete, and correct their personal information, and to opt out of "sale" or "sharing" of personal information for cross-context behavioural advertising. We do not sell personal information; for opt-out of "sharing", use the cookie preferences panel.

To exercise any right, email support@marketingoperator.ai. We will respond within thirty (30) days, extendable to ninety (90) days for complex requests as permitted by law.

9. Security

We use industry-standard technical and organisational measures to protect your personal data, including TLS in transit, encryption at rest for Customer Content (Cloudflare R2 server-side encryption), hashed and salted passwords (bcrypt), least-privilege access controls, audit logging, and routine vulnerability management. No method of transmission or storage is perfectly secure; if you believe your account has been compromised, contact support@marketingoperator.ai immediately.

10. Children

The Service is not directed to children under the age of digital consent in their jurisdiction (16 in the EU/EEA, 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact support@marketingoperator.ai and we will delete the data.

11. Changes

We may update this Privacy Policy from time to time. Material changes will be announced by email to your registered address and by an in-app notice at least thirty (30) days before the change takes effect.

12. Contact

Privacy questions, GDPR / CCPA requests, or DPA negotiation: email support@marketingoperator.ai.

Back to top
Marketing Operator

Research Meta ads, import your site, ship AI-generated ads in minutes.

Product

  • Features
  • Pricing
  • FAQ
  • Contact
  • About

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • Refund Policy
  • Data Processing Agreement
© 2026 Marketing Operator (pre-incorporation — not a registered entity). All rights reserved.