Privacy Policy
How Adveron handles personal data — both our customers' and that of the people and brands our customers research.
Effective date: August 19, 2026
1. Who we are
Adveron is operated by Curiosities, Inc., 11700 Preston Rd. #660-290, Dallas, TX 75230 (“ Adveron”, “we”, “us”). Adveron is a paid business-to-business service: a data API and a web console that organisations use to research brands, categories, creators, and audiences. This policy explains what personal data we process, why, and what rights you have.
This policy covers two different groups of people, and the difference matters throughout: our customers — the people who hold an Adveron account — and third parties, whose publicly available or vendor-sourced information is processed through the platform when a customer runs a query.
2. Data we collect from customers
- Account and contact data. Name, work email address, organisation and team membership, role, and the invitations you send or accept.
- Authentication data. Password hashes (never the password itself), session records, multi-factor enrolment, API key metadata, and — if you sign in with Google or Microsoft single sign-on — the identifier, name, email address, and profile image those providers return to us.
- Usage and telemetry. Requests made to the API and console, endpoints called, credits consumed, timestamps, IP address, browser and device information, and error and performance diagnostics. We use this to operate, secure, meter, and improve the service.
- Billing data. Subscription and credit records, invoices, billing contact details, and tax identifiers. Payments are processed by Stripe. We do not receive or store full payment card numbers; we hold only the limited identifiers and summaries Stripe returns to us, such as card brand, last four digits, and payment status.
- Support and correspondence. Messages you send us and the content you choose to include in them.
3. Third-party and enriched data the product processes
Adveron ingests and stores information about brands, companies, creators, and social or other public profiles, obtained from publicly available sources and from licensed data vendors. Where that information relates to an identifiable individual — for example a creator’s public profile, handle, biography, follower counts, or public posts — it is personal data, and this policy applies to it.
We process that data to deliver the service our customers ask for: resolving an entity, enriching a profile, and returning analysis about brands, categories, and audiences. We do not sell this data as a standalone list, and we do not use it to build advertising profiles of individuals. Our customers decide which entities to research and are responsible for using the results lawfully.
If your information has been processed through our platform and you want to exercise a privacy right, contact support@adveron.com and we will handle your request under section 10 — you do not need to be an Adveron customer.
4. Data from accounts you connect
You can connect third-party accounts you already own so that your own first-party data is available alongside the rest of the platform. Connecting an account is optional, is done by an administrator of your organisation, and can be undone at any time.
Where you connect an account with a provider (Google, LinkedIn, or Meta), we request read-only access to the one service being connected, and read only the single site, property, or ad account your administrator selects. LinkedIn Ads is the one connection that can be granted more than that, and only if your administrator chooses it:
- Google Search Console — search performance for the selected site: the queries it appeared for, and the clicks, impressions, click-through rate, and average position of each.
- Google Analytics — traffic and engagement for the selected property, such as sessions, users, and engagement rate, grouped by the dimensions you ask for.
- Google Ads — read-only access to the one ad account your administrator selects, through the https://www.googleapis.com/auth/adwords permission: its campaigns, their budgets and delivery settings, and how those campaigns performed (impressions, clicks, spend, and conversions). We never create, edit, or pause anything in the account.
- Meta Ads — read-only access to the ad accounts your administrator selects, through the ads_read permission: their campaigns, budgets and delivery settings, and how those campaigns performed (impressions, clicks, spend, reach, and purchases). We also read the name of the Facebook user who connected it. We never create, edit, or pause anything in the account, and Meta issues this authorization for about 60 days at a time — after that an administrator re-authorizes it, and until they do we can read nothing.
- LinkedIn Ads — read-only access to the connected ad account, through the r_ads, r_ads_reporting, and r_basicprofile permissions: its campaigns and their delivery settings, the performance of those campaigns (impressions, clicks, spend, conversions, and leads), and the name of the LinkedIn member who connected it. Read-only is the default. Write access (the rw_ads permission) is requested only when your workspace administrator chooses “Read and manage” at the moment of connecting, and is what a workspace that will manage its LinkedIn campaigns through Adveron grants deliberately.
Unless your administrator chose “Read and manage” for LinkedIn Ads, the access we request is read-only: we cannot change anything in your Google account, submit sitemaps, affect how your site appears in Google Search, or create, edit, pause, or spend against a Google Ads, LinkedIn, or Meta campaign. Google Ads and Meta Ads are always read-only.
These reads happen when you ask for them and pass straight back to you. We do not copy the results into our own storage, and we do not use them to train models, to build advertising profiles, or to enrich any other customer’s data. About the connection itself we retain only the identity of the connected account (the Google account’s address, or the name of the LinkedIn member or Facebook user), which site, property, or ad account was selected, the access it was granted, who connected it, and when it was last read. That identity is deleted when the connection is disconnected. The credential that lets us make these requests is encrypted at rest and is destroyed when the account is disconnected, when the workspace is archived, or when the organisation closes.
Adveron’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect a connected account at any time from your workspace settings, which destroys the stored credential. Where the provider offers a way to hand the grant back we use it as well — Google does; LinkedIn and Meta publish none, so with those the grant stays listed at the provider until you remove it. You can do that at any provider yourself: from your Google account’s security settings, under Permitted Services in your LinkedIn settings, or under Apps and Websites in your Facebook settings.
5. How we use personal data
- To provide, maintain, and support the service, including authentication, org and team access control, and the API.
- To meter usage, allocate and consume credits, invoice, and collect payment.
- To secure the platform: abuse and fraud prevention, rate limiting, audit logging, and incident investigation.
- To debug, monitor, and improve reliability, coverage, and data quality.
- To communicate about your account, service changes, security notices, and — where permitted — relevant product updates you can opt out of at any time.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use customer content to train publicly available foundation models.
6. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the service to the organisation you belong to, and to bill for it.
- Legitimate interests — to secure and improve the service, to prevent abuse, and to process publicly available and vendor-sourced business and profile data for brand and market intelligence, balanced against the interests of the people concerned.
- Consent — for optional marketing communications and any non-essential analytics, which you can withdraw at any time.
- Legal obligation — for tax, accounting, and lawful requests.
For enriched third-party data we are typically the controller of the processing described in section 3, acting on the legitimate-interests basis; our customers are separately responsible for their own use of the results. Because that data is not collected from the individual directly, we may rely on the GDPR’s exemption from individual notification where providing notice would be impossible or involve disproportionate effort — this policy serves as the public notice of that processing. You may object to it at any time by contacting support@adveron.com.
7. Sharing and sub-processors
We do not sell personal data. We share it with service providers who process it on our behalf under contract, and only as needed to run the service:
- Stripe — payment processing, subscriptions, and invoicing.
- Amazon Web Services — cloud hosting, databases, and storage.
- Google and Microsoft — single sign-on, where you choose to use it.
- Resend — transactional email (verification, invitations, notifications).
- Licensed data vendors — providers of public profile, social, and advertising data used for enrichment.
Our current list of sub-processors is available on request from support@adveron.com. We may also disclose personal data to professional advisers, in connection with a merger or acquisition, or where required by law or valid legal process.
8. International transfers
We and our service providers operate in the United States and other countries, so personal data may be transferred outside your home country. Where data is transferred out of the EEA, the UK, or Switzerland, we rely on an appropriate transfer mechanism — generally the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) — together with additional technical and organisational safeguards. A copy of the relevant mechanism is available on request.
9. Retention
We keep account, billing, and audit records for as long as the account is active and afterwards for the period we need to meet legal, accounting, tax, and security obligations. Usage and telemetry records are kept for a limited operational period and then deleted or aggregated. Enriched third-party data is refreshed and retained only while it remains useful to the service and permitted by our vendor agreements and applicable law. When a customer closes an account, we delete or de-identify their data within a reasonable period, except where retention is legally required.
10. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to its processing, withdraw consent, port it to another provider, and be free from discrimination for exercising these rights. Under the GDPR and UK GDPR you may also lodge a complaint with your supervisory authority.
Under the CCPA/CPRA, California residents may request to know, delete, and correct personal information, and may opt out of any sale or sharing of personal information and of targeted advertising. We do not sell or share personal information as those terms are defined by the CPRA, and we do not use or disclose sensitive personal information beyond the purposes permitted by it. Similar rights apply under other US state privacy laws.
To exercise a right, email support@adveron.com. We will verify your request, respond within the period the applicable law requires, and tell you if we need to refuse a request in whole or part and why. If we process your data as a service provider on a customer’s behalf, we will refer you to that customer or act on their instructions.
11. Security
Adveron operates a SOC 2 controlled environment. Our program covers access control, encryption of data in transit and at rest, audit logging of privileged and destructive actions, change management and code review, vendor review, and incident response. No system is perfectly secure, so we do not promise that ours is; we do commit to maintaining these controls and to notifying affected parties of a breach as the law requires. Report a suspected vulnerability or incident to support@adveron.com.
12. Children
Adveron is a business service and is not directed to children. You may not create an account if you are under 18, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact support@adveron.com and we will delete it.
13. Changes to this policy
We may update this policy as the service and the law change. We will post the revised version here with a new effective date and, for material changes affecting customers, notify account owners by email or in the console.
14. Contact
Privacy questions and rights requests: support@adveron.com. Postal mail: Curiosities, Inc., 11700 Preston Rd. #660-290, Dallas, TX 75230. Our Terms of Service govern your use of Adveron.