Privacy Policy
Data controller: SmartFlow LLC (Belarus), privacy@roasr.com. Covers Meta/Google Ads (read-only; the Yandex Direct integration was discontinued, §02.4) and optional consent-only analytics: PostHog, plus Google Analytics 4 and Yandex Metrica on public pages, without session recording (§08). §03 — GDPR and Limited Use; §09 — Google API Services User Data Policy; §10 — Meta data deletion; §11–12 — GDPR rights.
General Provisions
1.1This Privacy Policy (the "Policy") governs how information that the User submits when using the RoASr service (the "Service") is processed and protected.
1.2The data controller and operator of the Service is SmartFlow LLC (ООО "СмартФлоу"), UNP 491397820, registered address: 7 Nikolskaya St., office 1-2, Gomel, Gomel Region, 246014, Republic of Belarus; phone +375 29 237-68-72. Data-protection contact: privacy@roasr.com.
1.3By using the Service, the User confirms acceptance of this Policy. If the User does not agree with its terms, the User must stop using the Service.
Information We Collect
2.1The Service may collect the following types of data:
- account identifiers (email, workspace ID, etc.);
- technical information (IP address, browser, device, and operating system data);
- history of interactions with the Service.
2.2Facebook/Meta Ads data: when a User connects a Facebook/Instagram ad account, the Service requests the ads_read permission and retrieves reporting data in read-only mode only (performance metrics, campaign/ad set/ad names and IDs, ad copy and URLs, campaign status). No changes are made to ad accounts; no Facebook audience personal data is collected or stored.
2.3Google Ads data: when a User connects a Google Ads account, the Service accesses data via the OAuth scope https://www.googleapis.com/auth/adwords in read-only mode (campaigns, ad groups, ads, keywords, and performance metrics) solely to provide analytics within the Service.
2.4The Yandex Direct and Yandex Metrica integration was discontinued on 05.10.2026: a Direct account or a Metrica counter can no longer be connected as a data source, the Service retrieves no data from them and makes no changes to ad accounts. Previously retrieved data is deleted within the periods set out in section 05; earlier deletion is available on request to privacy@roasr.com.
2.5The Service does not require the User to provide passport data, documents, photographs, or other personal information beyond what is minimally necessary for its operation.
Use of Information and Legal Bases
3.1The Service uses the information it receives for the following purposes, with the corresponding legal basis under GDPR Art. 6:
- operating the Service’s functionality (audit, AI chat, spy tool, reports) and account maintenance — basis: performance of a contract (Art. 6(1)(b) GDPR);
- communicating with the User (notifications, support) — basis: performance of a contract (Art. 6(1)(b) GDPR);
- security, abuse prevention, and analysis and improvement of the Service — basis: legitimate interest (Art. 6(1)(f) GDPR);
- optional analytics — product analytics (PostHog) and web analytics of public pages (Google Analytics 4, Yandex Metrica) — and marketing notifications — basis: separate consent (Art. 6(1)(a) GDPR).
3.2Limited Use: ad account data (Meta Ads, Google Ads) is used solely to provide the Service’s analytics features to the authorizing User. We do not share it with other users, advertisers, or third parties for their benefit; do not use it for ad targeting, personalized or retargeted advertising; do not sell it or transfer it to data brokers; do not use it to train machine-learning models beyond delivering results to the User; and do not use it for credit assessment.
Disclosure to Third Parties
4.1The Administration does not disclose the data it receives to third parties, except to the following categories of recipients and in the following cases:
- infrastructure providers (hosting, database) — to keep the Service running;
- PostHog — product analytics provider: only after separate consent, it receives explicit funnel events (with the referring site’s domain, source class and utm_source tag), SDK technical properties, and pseudonymous account/workspace IDs; autocapture and session replay are disabled;
- Google (Google Analytics 4; Google Ireland Limited / Google LLC) — web analytics of public pages (home and blog): only after separate consent, it receives page views, referral source and UTM tags, technical browser/device data, and a pseudonymous cookie identifier; Google Signals and ad personalization are disabled;
- YANDEX LLC (Yandex Metrica) — web analytics of public pages (home and blog): only after separate consent, it receives page views, referral source and UTM tags, clicks and link clicks, technical browser/device data, and a pseudonymous cookie identifier; Webvisor (session recording) is disabled;
- payment providers — to process payments;
- the AI/LLM provider — to generate the audit and AI-chat responses based on data the User has initiated (data is transmitted only to return the result to the User and is not used by the provider to train models);
- where required by law;
- where the User has given their own consent.
4.2The Service may use providers located outside the User’s country; such transfers are made with appropriate data-protection safeguards. Google Analytics data may be processed in the USA, Yandex Metrica data in the Russian Federation.
Data Retention and Protection
5.1Retention periods by data category:
- Meta/Google ad account data (metrics, names, ad copy) — no longer than 90 days after the corresponding ad account is disconnected from the Service;
- account data (email, workspace ID) — until the workspace is deleted or consent is withdrawn, but no more than 12 months after the User’s last activity;
- access tokens for advertising platforms — deleted immediately upon the User revoking access;
- payment records (invoices) — for the period required by accounting legislation;
- technical logs — no more than 90 days.
- PostHog product analytics events and related pseudonymous IDs — no more than 12 months; withdrawing consent stops new collection, and previously collected data can be deleted by request to privacy@roasr.com.
- Google Analytics 4 data — no more than 14 months (GA4 retention setting); Yandex Metrica data — for the periods set by Yandex; withdrawing consent stops new collection.
5.2Access tokens for ad accounts and provider keys are stored in encrypted storage and are not displayed in plain text.
5.3The Administration takes reasonable technical and organizational measures to protect data, but does not guarantee the absolute security of information transmitted over the internet.
Disclaimer
6.1The User understands and agrees that transmitting information over the internet always carries certain risks.
6.2The Administration takes reasonable protective measures and bears liability to the extent established by applicable law. This Policy does not limit any rights of the data subject guaranteed by law.
Changes to the Policy
7.1We may update this Policy. When changes affect how Google or Meta data is used, users are notified by email and/or in-app at least 7 days before the changes take effect, with the option to withdraw consent.
7.2Continued use of the Service after the changes take effect constitutes acceptance of the new version. If you do not agree with changes affecting Google data, revoke OAuth access at https://myaccount.google.com/permissions; for Meta data, do so in your Facebook account’s Business Integrations settings.
Cookies
8.1The Service uses the following first-party cookies:
- pg_lang2 — selected interface language (retention: up to 1 year);
- technical session/authentication cookies — required for signing in and operating the Service;
- only after consent and only on public pages (third-party cookies): _ga, _ga_<ID> (Google Analytics, up to 2 years); _ym_uid, _ym_d and other service cookies prefixed _ym (Yandex Metrica, up to 1 year).
8.2Technical cookies are not used for tracking. Optional analytics starts only after separate consent in the banner. PostHog stores its state in localStorage and receives only explicit funnel events (with the referring domain and utm_source), SDK technical properties, and pseudonymous account/workspace IDs; autocapture and session replay are disabled. Google Analytics 4 and Yandex Metrica load only on public pages (home and blog), set their own cookies (§8.1) and collect page views, traffic source, clicks and link clicks; Webvisor, Google Signals and ad personalization are disabled. Without consent, Google and Yandex scripts are not loaded. Consent can be withdrawn or granted again below on this page; a counter already running on an open page stops after the page is reloaded.
Use of Google API Data (Limited Use)
9.1RoASr’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See https://developers.google.com/terms/api-services-user-data-policy
Deletion of Meta (Facebook) Data
10.1If you connected a Facebook/Instagram ad account to the Service, you may request deletion of all data associated with your Meta account through one of the following methods:
- in-app: Settings → Workspace → "Delete workspace";
- by email: send a request to privacy@roasr.com with the subject "Meta Data Deletion Request", including your Meta User ID or the Facebook account email — we will confirm deletion within 30 days;
- automatically: when you delete your Facebook account, Meta notifies us and the associated data is deleted within 30 days.
10.2You can check the status of a deletion request at roasr.com/data-deletion/status?code=YOUR_CODE (the code is issued for automatic requests).
Data Subject Rights (GDPR)
11.1Under the EU General Data Protection Regulation (GDPR) you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — you may request confirmation of whether we process your data and obtain a copy.
- Right to rectification (Art. 16 GDPR) — you may request correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17 GDPR) — you may request deletion of your data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
- Right to data portability (Art. 20 GDPR) — you may receive your data in a machine-readable format (JSON) and transfer it to another service.
- Right to object (Art. 21 GDPR) — you may object to processing of your data for direct marketing or based on legitimate interest.
11.2How to exercise your rights:
- Data export (portability) — available immediately: Settings → Security → "Export all data (.json)".
- Workspace deletion (erasure) — Settings → Workspace → Danger zone → "Delete workspace". The workspace and associated data will be deleted in accordance with our retention policy.
- Access, rectification, or objection requests — email privacy@roasr.com with subject "GDPR Request". We will respond within 30 days.
11.3If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority in your country of residence.
Data Subject Rights (GDPR)
12.1Under the EU General Data Protection Regulation (GDPR) you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — you may request confirmation of whether we process your data and obtain a copy.
- Right to rectification (Art. 16 GDPR) — you may request correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17 GDPR) — you may request deletion of your data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
- Right to data portability (Art. 20 GDPR) — you may receive your data in a machine-readable format (JSON) and transfer it to another service.
- Right to object (Art. 21 GDPR) — you may object to processing of your data for direct marketing or based on legitimate interest.
12.2How to exercise your rights:
- Data export (portability) — available immediately: Settings → Security → "Export all data (.json)".
- Workspace deletion (erasure) — Settings → Workspace → Danger zone → "Delete workspace". The workspace and associated data will be deleted in accordance with our retention policy.
- Access, rectification, or objection requests — email privacy@roasr.com with subject "GDPR Request". We will respond within 30 days.
12.3If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority in your country of residence.