Privacy Policy
Last updated: June 19, 2026
Overseer ("we," "us," or "our") operates the overseerads.com website and the Overseer platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, and the rights you have over your personal data. It applies to all users of the Service worldwide.
For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), Overseer acts as a data controller for personal data relating to our account holders and website visitors, and as a data processor for the creative assets and campaign data you submit through the Service on behalf of your own clients. Where we act as a processor, our processing is also governed by our Data Processing Addendum (see Section 12).
1. Information We Collect
1.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, company name, and billing information.
- API Credentials: To connect your ad platform accounts (TikTok, Meta, Snapchat, X), you provide access tokens and account identifiers, or authorize access via OAuth. These are encrypted at rest and in transit using AES-256 and TLS 1.2+ and stored in AWS Secrets Manager.
- Creative Assets: You may upload or provide access to images, videos, and ad copy for processing through our Service. We process these assets solely to fulfill your requests.
- Communications: When you contact us, we retain your email address and message content to respond and improve our Service.
1.2 Information Collected Automatically
- Usage Data: API call logs, request timestamps, response codes, and platform interactions for debugging and service improvement. Credentials are stripped from these logs.
- Device and Browser Data: IP address, browser type, operating system, and referring URL when you access our website.
- Cookies: We use strictly necessary cookies for authentication and session management. We do not use advertising or cross-site tracking cookies. Because we use only essential cookies, no consent banner is required under the ePrivacy Directive; see Section 9.
2. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases to process your personal data:
- Performance of a contract: to provide the Service, authenticate you, process creatives, and publish ads on your behalf.
- Legitimate interests: to secure and improve the Service, prevent abuse, and communicate operationally with you, balanced against your rights and freedoms.
- Legal obligation: to comply with tax, accounting, and other legal requirements.
- Consent: where we ask for it specifically (for example, optional product communications). You may withdraw consent at any time without affecting prior processing.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service, including processing ad creatives and managing campaigns on your behalf.
- Authenticate your identity and authorize access to connected ad platform accounts.
- Monitor usage for billing, rate limiting, and capacity planning.
- Detect, prevent, and address technical issues, abuse, or security incidents.
- Communicate with you about service updates, security alerts, and support inquiries.
- Comply with legal obligations and enforce our agreements.
We do not use your creative assets, campaign data, or credentials to train machine-learning models, and we do not sell your personal information.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
- Ad Platforms: We transmit your creative assets and campaign data to TikTok, Meta, Snapchat, and X as necessary to fulfill your publishing requests. Each platform's own privacy policy governs their use of that data.
- Sub-processors: We use the vendors listed in Section 5 to operate the Service. Each is bound by contractual confidentiality and data-protection obligations.
- Business transfers: If Overseer is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you and honor the commitments in this policy.
- Legal Requirements: We may disclose information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Sub-processors
We engage the following third parties to process data on our behalf. We require each to provide a level of data protection consistent with this policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, and credential storage (Secrets Manager) | United States |
| Vercel | Website hosting and content delivery | United States |
| Clerk | Authentication and identity management | United States |
| Sentry | Error monitoring (configured to exclude personal data) | United States |
We will provide notice before adding or replacing a sub-processor that materially affects the processing of your data. To request the current list or object to a new sub-processor, email privacy@overseerads.com.
6. Data Security
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- API credentials and access tokens are stored in AWS Secrets Manager with strict IAM access controls, are never written to logs, and are never returned in API responses.
- We enforce role-based access control and maintain audit logs for all credential access.
- We conduct regular security reviews, dependency audits, and automated guardrail testing.
- Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data Breach Notification
We maintain an incident-response process for security events. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, and we will notify affected customers without undue delay.
8. Data Retention
- Account Data: Retained for the duration of your account plus 30 days after a deletion request.
- Creative Assets: Processed transiently. We do not permanently store your creative assets after they have been successfully deployed to the target platforms, unless you explicitly configure asset storage.
- Usage Logs: Retained for up to 90 days for debugging and billing purposes, then aggregated or deleted.
- API Credentials: Deleted immediately upon account termination or when you revoke platform access.
- Billing Records: Retained as required by tax and accounting law, typically up to seven years.
9. Cookies
We use only strictly necessary, first-party cookies for authentication and session management. We do not use advertising, analytics-profiling, or cross-site tracking cookies, and we do not share cookie data with advertising networks. Because these cookies are essential to delivering the Service you request, they do not require prior consent under applicable law. You can block cookies in your browser settings, but the Service may not function correctly if you do.
10. Your Rights
10.1 GDPR / UK GDPR
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of your personal data, subject to legal retention requirements.
- Object to or restrict processing of your personal data.
- Request data portability (receive your data in a structured, machine-readable format).
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection authority. We ask that you contact us first so we can try to resolve your concern.
10.2 California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined under the CCPA/ CPRA, and we do not use or disclose sensitive personal information for purposes other than providing the Service. You may exercise these rights, including through an authorized agent, by contacting us below.
To exercise any of these rights, contact us at privacy@overseerads.com. We will verify your request and respond within the timeframe required by applicable law (generally 30–45 days). These rights are free to exercise.
11. International Data Transfers
Our Service is hosted in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and other legally approved mechanisms, together with supplementary technical measures such as encryption, to ensure adequate protection.
12. Data Processing Addendum
Where we process personal data on your behalf as a processor (for example, data relating to your own clients contained in creative assets or campaign data), our Data Processing Addendum ("DPA") applies and forms part of our agreement with you. The DPA sets out the subject matter, duration, nature, and purpose of processing, the types of personal data and categories of data subjects, and the security and sub-processor terms. To request a signed copy, email privacy@overseerads.com.
13. Children's Privacy
Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
14. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal data.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. For significant changes, we will provide additional notice via email or a prominent notice on our Service.
16. Contact Us
If you have questions about this Privacy Policy or our data practices, or to exercise your rights, contact us at:
- Privacy & data requests: privacy@overseerads.com
- General inquiries: contact@overseerads.com