Privacy Policy
Last updated: July 24, 2026
Adacavo (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our outdoor advertising CRM platform and related services (collectively, the “Service”). This policy complies with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
We collect the following categories of personal data to provide and improve the Service:
- Account Information: Your name, email address, company name, and account credentials when you register or use the Service.
- Billing Information: Payment details processed securely through Stripe. We do not store full credit card numbers on our servers.
- Usage Data: IP address, browser type, device information, pages visited, time spent on pages, and other diagnostic data collected automatically when you access the Service.
- Analytics Data: Product interaction events, feature usage patterns, and session recordings collected through PostHog to help us improve the Service.
- Support Communications: Information you provide when contacting our support team, including email correspondence and support tickets.
- Service Delivery: To provide, maintain, and operate the Service, including user authentication, data storage, and feature access.
- Customer Support: To respond to inquiries, troubleshoot issues, and provide technical assistance.
- Billing and Payments: To process subscriptions, manage billing accounts, and send transactional receipts.
- Product Improvement: To analyze usage patterns, identify bugs, and develop new features based on aggregated and anonymized data.
- Communication: To send service-related announcements, security alerts, and administrative messages. We do not use your data for marketing emails without your consent.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes, including responding to lawful requests from public authorities.
Under the GDPR, we rely on the following legal bases to process your personal data:
- Contractual Necessity: Processing required to fulfill our obligations under the Terms of Service and provide the Service you have requested.
- Legitimate Interest: Processing necessary for our legitimate business interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your data protection rights.
- Consent: Where you have given clear consent for specific processing activities, such as optional analytics or marketing communications. You may withdraw consent at any time.
- Legal Obligation: Processing required to comply with applicable laws, court orders, or governmental regulations.
We engage the following third-party service providers to process data on our behalf. Each subprocessor is contractually bound to data processing agreements that ensure GDPR-compliant handling of personal data.
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Clerk | Authentication and user management | United States |
| Neon | Database hosting (PostgreSQL) | United States |
| Cloudflare | CDN, DDoS protection, and R2 object storage | Global |
| Stripe | Payment processing and subscription management | United States |
| Sentry | Error tracking and application monitoring | United States |
| PostHog | Product analytics and usage insights | United States |
| AWS SES | Transactional email delivery | United States |
- Account Data: Retained for the duration of your account’s active status. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
- Billing Records: Retained for 7 years to comply with tax and accounting obligations.
- Usage Analytics: Raw event data retained for 24 months. Aggregated and anonymized reports may be retained indefinitely.
- Error Logs: Retained for 90 days in Sentry to support debugging and reliability monitoring.
- Support Communications: Retained for 3 years after your last interaction to maintain support history and improve service quality.
- Backups: Encrypted database backups are retained for 30 days on a rolling basis.
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request that we correct inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): You may request deletion of your personal data, subject to legal retention requirements.
- Right to Data Portability: You may request a copy of your data in a structured, machine-readable format for transfer to another service.
- Right to Object: You may object to processing based on legitimate interests, including profiling.
- Right to Restrict Processing: You may request that we limit how we process your data under certain circumstances.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at privacy@adacavo.com. We will respond within 30 calendar days. You also have the right to lodge a complaint with your local data protection supervisory authority.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer:
Email: privacy@adacavo.com
Address: Adacavo, 1234 Market Street, Suite 500, San Francisco, CA 94102, United States
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.