Privacy Policy
How we collect, use, and protect your information
📅 Last updated: October 2026🔒 LOJA VIRTUAL, LLC, a limited liability company organized under the laws of the State of Wyoming, United States of America, with an office at 7345 W Sand Lake Road, Ste 210, Office 3332, Orlando, Florida 32819, United States, operating under the trade name DirectAds, presents its Privacy Policy, which observes the applicable data protection law.
🛠️ Joint technical operation: The technical infrastructure of the DirectAds application registered with Meta (Facebook App ID 1395417868828787, Business Manager ID 1184559826033357) is maintained by METAVERSO INTELIGENCIA ARTIFICIAL LTDA (CNPJ 26.272.559/0001-64), as a Data Operator, pursuant to an agreement with LOJA VIRTUAL, LLC, which remains the Data Controller. To exercise your personal data rights, please contact the Controller through the channels in the "Contact and Data Protection Officer" section.
Concepts and Definitions
For the purposes of this Privacy Policy, the following definitions apply:
- User: Company or professional (a legal entity, or an individual carrying out an economic activity) that uses the DirectAds platform for uploading and managing advertising campaigns.
- Personal Data: Information related to an identified or identifiable natural person.
- Controller: Individual or legal entity that makes decisions about the processing of personal data (DirectAds, regarding data of its users).
- Operator: Individual or legal entity that processes data on behalf of the controller.
- Processing: Any operation performed with personal data (collection, storage, use, sharing, etc.).
Data Collected and Purposes
We collect the following data to execute our bulk advertising campaign upload services:
- Registration Data: Full name, email, phone, billing data, for account management, support, and billing.
- Meta Access Credentials: OAuth tokens from Facebook Login for Business, explicitly authorized by the USER during consent, containing the following permissions used strictly for the declared purposes: email, public_profile, ads_management, ads_read, business_management, catalog_management, pages_show_list, pages_read_engagement.
- Google Access Credentials (optional): When you connect Google Drive, Google OAuth tokens with a read-only scope (drive.readonly), explicitly authorized by you, used exclusively to list and import images and videos as creatives for your ads. Details in the "Google Drive Access and Use of Google User Data" section.
- Usage Data: Activity logs, campaigns created, usage metrics, for service improvement and technical support.
- Payment Data: Credit card or bank information, processed by secure payment gateway.
- Marketing and Analytics Data: We capture data during pre-registration and while you use our platform: name, email, phone, UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), advertising click IDs (fbclid from Facebook, gclid from Google, ttclid from TikTok), IP address, user-agent, and referrer URL. We use this data for campaign attribution, fraud detection, and marketing optimization.
- Security and Fraud-Prevention Data: To protect the platform and ensure fair conditions among users, we process IP address, access network provider and type, approximate geographic location, technical characteristics of the device and browser, and technical identifiers of the payment method. We use this data to prevent fraud, free-trial abuse (when a free trial is offered), creation of multiple accounts, and other misuse of the platform.
📋 Legal Basis: Data processing is based on contract execution and legitimate interest for providing our bulk ad upload services.
Google Drive Access and Use of Google User Data
🟢 This section specifically describes how DirectAds accesses and uses data from your Google account when you choose to connect Google Drive. Connecting Google Drive is optional and happens only with your explicit authorization through Google OAuth login.
1. What we access and why. When you connect your Google account, DirectAds requests the read-only scope https://www.googleapis.com/auth/drive.readonly. This access is used solely to list and import the images and videos you select from your Google Drive, for use as creatives in your own ads. Access is strictly read-only: DirectAds does not create, modify, or delete any files in your Google Drive.
2. How we use Google data. The images and videos you select are imported into your media library within DirectAds and used exclusively to create and manage the ads of your own account. This data is:
- not used to train generalized artificial intelligence models;
- not sold, rented, or transferred to third parties;
- not shared with third parties, except as strictly necessary to operate the feature (for example, sending the media to the Meta/Facebook advertising platforms at your instruction) or when required by law;
- not read by our staff, except in the cases permitted by Google's policy (for security, to comply with a legal obligation, or with your explicit consent, such as in a support request you initiate).
3. Compliance and Limited Use. DirectAds' use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
📜 "DirectAds' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."
4. Storage and retention. Google OAuth authorization tokens (access and refresh tokens) are stored in encrypted form on our servers and used only to maintain the connection you authorized. Imported images and videos become part of your media library in DirectAds and follow the platform's general media retention policy described in the "Security and Storage" section.
5. How to disconnect and revoke access. You may revoke authorization at any time, which stops any further access by DirectAds to your Google Drive:
- by disconnecting the Google account in your DirectAds account settings; and/or
- by visiting https://myaccount.google.com/permissions and removing the access granted to DirectAds.
After revocation, DirectAds no longer accesses your Google Drive. Media already imported remains in your library, within your DirectAds account, until you delete it, following the general media retention policy.
DirectAds as Data Operator
When you use DirectAds to upload advertising campaigns, the platform acts as a Data Operator regarding third-party data processed:
- Ad creatives (images, videos, texts)
- Target audiences configured for campaigns
- Destination URLs and landing pages
In these cases, you (User) are the Controller of this data and must ensure you have authorization to use it in advertising campaigns. DirectAds only processes this data according to your instructions for uploading to advertising platforms.
How We Use Your Information
We use the collected information to:
- Execute the bulk advertising campaign upload service
- Process payments and manage your subscription
- Provide technical support and customer service
- Send communications about updates, news, and maintenance
- Improve the platform and develop new features
- Prevent fraud, abuse, and the creation of multiple accounts, ensuring platform security
- Comply with legal and regulatory obligations
Security and Storage
We implement technical and organizational measures to protect your data:
- SSL/TLS encryption on all data transmissions
- Access tokens stored in encrypted form
- Servers protected with firewalls and 24/7 monitoring
- Restricted access only to authorized employees
- Regular backups with geographic redundancy
🛡️ Retention: We keep your data only as long as necessary. After account cancellation, data is kept according to the criteria below, and you may request deletion at any time, as described in the Your Rights section.
The platform's technical records, such as access, audit and request logs and the individual ad publishing detail, are kept for as long as necessary for operations, security and fraud prevention, and may be deleted periodically; consolidated usage records, such as the daily counts of ads published per ad account, are kept for an indefinite period. In any event, records of purchase, payment, acceptance of these Terms, and platform usage are retained for as long as necessary to comply with legal or regulatory obligations and to exercise rights, including payment dispute procedures before a financial institution or card network, and until the definitive conclusion of such procedure.
If your account is terminated under the Acceptable Use clause of the Terms of Use, your identification data (name, email, phone number and identifiers of the ad profile and payment method) are kept for up to 5 (five) years from termination, solely to prevent a new contract.
Data Sharing
Your data may be shared with:
- Meta/Facebook: For executing campaign uploads to connected ad accounts.
- Payment Processors: Stripe Inc. (USA) for secure processing of subscriptions and transactions.
- Infrastructure Providers: DigitalOcean LLC (servers), Cloudflare Inc. (CDN, protection and media storage), Railway Corp. (auxiliary services), all under confidentiality agreements.
- Artificial intelligence: Anthropic, OpenAI and Voyage AI (USA), which process the messages, audio and images sent to support (to transcribe, understand and answer requests and to find help articles) and the content sent to the platform's artificial intelligence features, such as ad copy generation.
- Messaging: Whapi.Cloud (WhatsApp) and Twilio SendGrid (email), to send and receive support messages and account communications.
- Monitoring: Sentry and Better Stack, to record errors and monitor the operation of the platform.
- Bot protection: Google reCAPTCHA, on sign-up and pre-registration, which receives the IP address and browser data to tell people apart from automated access.
- Authorities: When required by law, court order, or investigation.
We never sell your personal data to third parties.
Compliance with Meta policies: DirectAds operates in compliance with the Meta Platform Terms and Developer Policies, processing Meta Platform Data exclusively as authorized by the USER via Facebook Login for Business.
Measurement and advertising tools: The partners listed in the "Cookies and Tracking Technologies" section receive browsing data from the public pages of the directads.ai website, as described in that section.
Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep your session authenticated on the platform
- Remember your language and theme preferences
- Analyze platform usage for improvements
- Ensure security and prevent fraud
Measurement and advertising: On the public pages of the directads.ai website we use third-party measurement and advertising tags (Google Tag Manager, Google Analytics, Google Ads, Meta Pixel, Microsoft Clarity, UTMify and ConverteAI, the page's video player) to count visits, understand navigation and measure the results of our campaigns. These partners may process data from your browser under their own policies. You can block these cookies in your browser settings without affecting your use of the platform.
You can configure your browser to refuse cookies, but this may affect platform functionality.
Your Rights
You have the right to:
- Confirmation: Know if we process your personal data
- Access: Request a copy of the data we hold
- Correction: Correct incomplete or outdated data
- Anonymization/Blocking: For unnecessary or excessive data
- Portability: Receive your data in a structured format
- Elimination: Request data deletion (respecting legal obligations)
- Revocation: Withdraw consent at any time
We commit to responding to requests within 2 business days.
🔒 Deletion of data linked to Facebook login: To request deletion of data associated with your Facebook authorization, you may either (a) remove the DirectAds application in Facebook Settings → Apps and Websites, or (b) email [email protected]. In either case, deletion will be processed within 30 days and confirmation will be sent by email.
Minors
DirectAds is intended exclusively for users 18 years of age or older. We do not intentionally collect data from minors. If you believe a minor has provided data to the platform, please contact us for immediate removal.
Policy Changes
This Privacy Policy may be updated periodically. Significant changes will be communicated by email or notification on the platform. The date of the last update will always be visible at the top of this document.
We recommend reviewing this page periodically.
Contact and Data Protection Officer
For questions about this Privacy Policy or to exercise your rights:
- Email: [email protected]
- WhatsApp: +55 (11) 95254-6214
Applicable Law: The controller of the data processed on this platform is LOJA VIRTUAL, LLC, organized in the State of Wyoming, United States of America. Processing observes the applicable data protection law. Data is stored and processed on servers located in the United States and in the countries of the providers listed in the "Data Sharing" section, and this international transfer takes place for the performance of the agreement entered into with the USER.