Privacy Policy
How we collect, use, and protect your information
📅 Last updated: August 2026🔒 A LOJA VIRTUAL LTDA, a private legal entity registered under CNPJ No. 28.980.311/0001-83, headquartered at Rua Ilicínia, 222, Room 4, Horto Florestal, São Paulo/SP, Brazil, CEP 02378-070, operating under the trade name DirectAds, presents its Privacy Policy in compliance with the Brazilian General Data Protection Law (LGPD - Law No. 13.709/18).
🛠️ Joint technical operation: The technical infrastructure of the DirectAds application registered with Meta (Facebook App ID 1395417868828787, Business Manager ID 1184559826033357) is maintained by METAVERSO INTELIGENCIA ARTIFICIAL LTDA (CNPJ 26.272.559/0001-64, headquartered in Brasília/DF, Brazil), as a Data Operator under Art. 5, VII, LGPD, pursuant to an agreement with A LOJA VIRTUAL LTDA, which remains the Data Controller (Art. 5, VI, LGPD). To exercise LGPD rights, please contact the Controller through the channels in the "Contact and Data Protection Officer" section.
Concepts and Definitions
For the purposes of this Privacy Policy, the following definitions apply:
- User: Individual or legal entity that uses the DirectAds platform for uploading and managing advertising campaigns.
- Personal Data: Information related to an identified or identifiable natural person.
- Controller: Individual or legal entity that makes decisions about the processing of personal data (DirectAds, regarding data of its users).
- Operator: Individual or legal entity that processes data on behalf of the controller.
- Processing: Any operation performed with personal data (collection, storage, use, sharing, etc.).
Data Collected and Purposes
We collect the following data to execute our bulk advertising campaign upload services:
- Registration Data: Full name, email, phone, billing data - for account management, support, and billing.
- Meta Access Credentials: OAuth tokens from Facebook Login for Business, explicitly authorized by the USER during consent, containing the following permissions used strictly for the declared purposes: email, public_profile, ads_management, ads_read, business_management, catalog_management, pages_show_list, pages_read_engagement.
- Google Access Credentials (optional): When you connect Google Drive, Google OAuth tokens with a read-only scope (drive.readonly), explicitly authorized by you, used exclusively to list and import images and videos as creatives for your ads. Details in the "Google Drive Access and Use of Google User Data" section.
- Usage Data: Activity logs, campaigns created, usage metrics - for service improvement and technical support.
- Payment Data: Credit card or bank information - processed by secure payment gateway.
- Marketing and Analytics Data: We capture data during pre-registration (WaitlistModal) and while you use our platform: name, email, phone, UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), advertising click IDs (fbclid from Facebook, gclid from Google, ttclid from TikTok), IP address, user-agent, and referrer URL. We use this data for campaign attribution, fraud detection, and marketing optimization.
- Security and Fraud-Prevention Data: To protect the platform and ensure fair conditions among users, we process IP address, access network provider and type, approximate geographic location, technical characteristics of the device and browser, and technical identifiers of the payment method. We use this data to prevent fraud, free-trial abuse, creation of multiple accounts, and other misuse of the platform.
📋 Legal Basis: Data processing is based on contract execution (Art. 7, V, LGPD) and legitimate interest (Art. 7, IX, LGPD) for providing our bulk ad upload services.
Google Drive Access and Use of Google User Data
🟢 This section specifically describes how DirectAds accesses and uses data from your Google account when you choose to connect Google Drive. Connecting Google Drive is optional and happens only with your explicit authorization through Google OAuth login.
1. What we access and why. When you connect your Google account, DirectAds requests the read-only scope https://www.googleapis.com/auth/drive.readonly. This access is used solely to list and import the images and videos you select from your Google Drive, for use as creatives in your own ads. Access is strictly read-only: DirectAds does not create, modify, or delete any files in your Google Drive.
2. How we use Google data. The images and videos you select are imported into your media library within DirectAds and used exclusively to create and manage the ads of your own account. This data is:
- not used to train generalized artificial intelligence models;
- not sold, rented, or transferred to third parties;
- not shared with third parties, except as strictly necessary to operate the feature (for example, sending the media to the Meta/Facebook advertising platforms at your instruction) or when required by law;
- not read by our staff, except in the cases permitted by Google's policy (for security, to comply with a legal obligation, or with your explicit consent, such as in a support request you initiate).
3. Compliance and Limited Use. DirectAds' use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
📜 "DirectAds' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."
4. Storage and retention. Google OAuth authorization tokens (access and refresh tokens) are stored in encrypted form on our servers and used only to maintain the connection you authorized. Imported images and videos become part of your media library in DirectAds and follow the platform's general media retention policy described in the "Security and Storage" section.
5. How to disconnect and revoke access. You may revoke authorization at any time, which stops any further access by DirectAds to your Google Drive:
- by disconnecting the Google account in your DirectAds account settings; and/or
- by visiting https://myaccount.google.com/permissions and removing the access granted to DirectAds.
After revocation, DirectAds no longer accesses your Google Drive. Media already imported remains in your library, within your DirectAds account, until you delete it, following the general media retention policy.
DirectAds as Data Operator
When you use DirectAds to upload advertising campaigns, the platform acts as a Data Operator regarding third-party data processed:
- Ad creatives (images, videos, texts)
- Target audiences configured for campaigns
- Destination URLs and landing pages
In these cases, you (User) are the Controller of this data and must ensure you have authorization to use it in advertising campaigns. DirectAds only processes this data according to your instructions for uploading to advertising platforms.
How We Use Your Information
We use the collected information to:
- Execute the bulk advertising campaign upload service
- Process payments and manage your subscription
- Provide technical support and customer service
- Send communications about updates, news, and maintenance
- Improve the platform and develop new features
- Prevent fraud, abuse, and the creation of multiple accounts, ensuring platform security
- Comply with legal and regulatory obligations
Security and Storage
We implement technical and organizational measures to protect your data:
- SSL/TLS encryption on all data transmissions
- Access tokens stored in encrypted form
- Servers protected with firewalls and 24/7 monitoring
- Restricted access only to authorized employees
- Regular backups with geographic redundancy
🛡️ Retention: We keep your data only as long as necessary. After account cancellation, data is removed within 60 days, except when required by law.
Data Sharing
Your data may be shared with:
- Meta/Facebook: For executing campaign uploads to connected ad accounts.
- Payment Processors: Stripe Inc. (USA) for secure processing of subscriptions and transactions.
- Infrastructure Providers: DigitalOcean LLC (servers), Cloudflare Inc. (CDN and protection), Railway Corp. (auxiliary services), all under confidentiality agreements.
- Authorities: When required by law, court order, or investigation.
We never sell your personal data to third parties.
Compliance with Meta policies: DirectAds operates in compliance with the Meta Platform Terms and Developer Policies, processing Meta Platform Data exclusively as authorized by the USER via Facebook Login for Business.
Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep your session authenticated on the platform
- Remember your language and theme preferences
- Analyze platform usage for improvements
- Ensure security and prevent fraud
You can configure your browser to refuse cookies, but this may affect platform functionality.
Your Rights (LGPD)
According to LGPD (Art. 18), you have the right to:
- Confirmation: Know if we process your personal data
- Access: Request a copy of the data we hold
- Correction: Correct incomplete or outdated data
- Anonymization/Blocking: For unnecessary or excessive data
- Portability: Receive your data in a structured format
- Elimination: Request data deletion (respecting legal obligations)
- Revocation: Withdraw consent at any time
We commit to responding to requests within 2 business days.
🔒 Deletion of data linked to Facebook login: To request deletion of data associated with your Facebook authorization, you may either (a) remove the DirectAds application in Facebook Settings → Apps and Websites, or (b) email [email protected]. In either case, deletion will be processed within 30 days and confirmation will be sent by email.
Minors
DirectAds is intended exclusively for users 18 years of age or older. We do not intentionally collect data from minors. If you believe a minor has provided data to the platform, please contact us for immediate removal.
Policy Changes
This Privacy Policy may be updated periodically. Significant changes will be communicated by email or notification on the platform. The date of the last update will always be visible at the top of this document.
We recommend reviewing this page periodically.
Contact and Data Protection Officer
For questions about this Privacy Policy or to exercise your rights:
- Email: [email protected]
- WhatsApp: +55 (11) 95254-6214
Applicable Law: This policy is governed by Brazilian law, especially Law No. 13.709/18 (LGPD) and the Brazilian Civil Rights Framework for the Internet (Law No. 12.965/14).
Contact and Data Protection Officer
For questions about this Privacy Policy or to exercise your rights:
- Email: [email protected]
- WhatsApp: +55 (11) 95254-6214
Applicable Law: This policy is governed by Brazilian law, especially Law No. 13.709/18 (LGPD) and the Brazilian Civil Rights Framework for the Internet (Law No. 12.965/14).