Privacy Policy
Effective date: 25 August 2026
AdHub.plus (the "Service", "we", "us") values your privacy and is committed to protecting personal data. This Privacy Policy explains what information we collect, why we collect it, how we use it, who we may share it with, and what rights you have.
1. Information we collect
- Account information: email address. Passwords are stored securely as hashes.
- Payment records: records of balance top-ups and payment transactions. We do NOT store full payment card details on our servers unless explicitly handled by a payment provider in the checkout flow.
- Telegram account data: information you provide when connecting Telegram accounts.
- Campaigns and ad content: ad texts, buttons, URLs, campaign metadata, targeting parameters, sending limits and statuses; images and media uploaded via Cloudinary or other CDNs — we store links/IDs and related metadata.
- Aggregated and statistical data: delivery reports, metrics, impression/click counters and internal statistics (models like CampaignStat etc.).
- Device and access information: IP address, country reported by our network provider, User-Agent, device type, device brand and model when reported by the browser, browser, operating system and version, browser language, time zone, screen dimensions, a persistent first-party browser identifier, and the dates and times when a device or browser was seen. The browser identifier is randomly generated, contains no account ID, and is stored on our servers only as a cryptographic digest.
- Logs and events: technical logs, moderation events, operational records and first-party activity history such as balance top-ups and user-initiated campaign or advert changes, together with delivery errors, IP addresses and timestamps for debugging, fraud prevention and account analytics.
- Cache data: runtime structures used for delivery and accounting (chat queues). Some of these are periodically synchronized.
- Third-party integrations: Google Analytics (gtag), Cloudinary, payment providers (Oxapay) and the Telegram API — these services process data according to their own policies.
- Cookies and similar technologies: session identifiers, CSRF tokens, analytics cookies (Google Analytics), and a signed first-party browser identifier used for account security and manual multi-account review.
2. How we use your information
- Account registration, authentication and security.
- Processing payments, billing and balance management.
- Creating, storing and delivering advertising campaigns and content via Telegram (campaign management, queueing and message delivery).
- Aggregating statistics and reports for paid services (delivery, spend and performance reports).
- Moderating ad content and enforcing platform policies.
- Detecting and preventing fraud, ensuring stability and debugging (logs, errors, monitoring).
- Identifying technical matches that may indicate multiple accounts are operated by the same person. These signals are shown to authorized administrators for manual review and do not automatically merge accounts.
- Showing users and authorized administrators summaries of user-initiated account activity by date and local hour.
- Analytics and service improvements using aggregated/anonymous data and third-party analytics tools.
- Communicating with users (email and telegram notifications, support responses, system messages).
3. Who we share information with
- Third-party service providers necessary to provide functionality: payment processors (Oxapay), cloud storage/CDN (Cloudinary), analytics (Google Analytics) and Telegram API — we share only the data necessary to perform the service.
- Employees and contractors who perform support, moderation or payment processing — only when necessary and under confidentiality obligations.
- Authorities or in response to legal requests if we are required to disclose information by law.
4. How we protect information
- We use encryption for data in transit (HTTPS) and follow standard security practices for password storage.
- We restrict staff access to data on a need-to-know basis and maintain access logs.
- We regularly back up and synchronize data and apply security updates to dependencies.
5. Data retention
We retain data for as long as necessary to provide services, comply with legal obligations, and resolve disputes. Device and access information used for account-security and multi-account investigations, including browser identifier digests, is retained until the related account is deleted, except where longer retention is required by law or necessary to prevent fraud. The browser cookie expires after 400 days and its expiry is renewed after a successful authenticated device-information collection. Some aggregated metrics and logs may be retained for longer in anonymized form. If you request deletion, see the "Your rights" section below.
6. Your rights
- Access: you may request a copy of your personal data.
- Correction: you may request correction of inaccurate information.
- Deletion: you may request deletion of your account and related personal data (subject to retained information required by law or to prevent fraud).
- Restriction/objection: in certain circumstances you may ask us to restrict or object to processing.
To exercise these rights, please contact support via the in-app support page or the contact method indicated in the FAQ.
7. Cookies and analytics
We use cookies and similar technologies for sessions, security and analytics. Our signed first-party browser identifier is inaccessible to page scripts, remains after sign-out, and helps authorized administrators identify possible multi-account use for manual review; it does not automatically merge accounts. You may delete it using your browser settings. Google Analytics collects aggregated visit data — you may disable such trackers using browser settings or extensions.
8. International data transfers
Certain services (Cloudinary, Google) may process data on servers located in other countries. We take measures to ensure an adequate level of protection when data is transferred internationally.
9. Children's data
The Service is not intended for children under 16.
10. Policy updates
We may update this policy from time to time. Material changes will be announced in the app and the effective date at the top will be updated.
11. Contact
If you have questions or requests about your data, please use the in-app support (FAQ / Contact) or file a request through the appropriate section. We will respond within a reasonable time.
Last updated: 25 August 2026