Privacy Policy
Effective: 19 September 2026 · Cookies section updated 5 October 2026
What changed on 19 September 2026: section 2 now describes the conversion-tracking code you can choose to install on your own website — Google's tag plus a few lines from PivotAd that report to Google only. Nothing about your visitors reaches PivotAd, as before.
PivotAd, operated by Kreativ Group from Gærdesmuttevej 10, Hørsholm, Denmark ("PivotAd", "we"), is the data controller for the personal data described in this policy. It explains what we collect when you visit pivotad.ai or use the PivotAd service (the "Service"), why we collect it, who sees it, and the rights you have over it. We wrote it to be read, not skimmed past.
The short version
- We collect what we need to build and run your Google Ads campaigns — nothing more.
- No analytics or advertising tags inside your account. On our public pages we measure our own advertising with Google, Meta and LinkedIn tags — only if you accept them in the cookie banner. Nothing about your website's visitors ever reaches us: the conversion-tracking code you may choose to install reports to Google only.
- We never sell your data, and your advertising payments never touch us — they go directly to Google.
1. What we collect
- Waitlist. Your email address, used only to tell you about beta access — nothing else.
- Account details. If you create a beta account: your email address and a securely hashed password — we never store the password itself.
- Google Ads administrator email. If you ask us to create a Google Ads account for you: the email address you name as its administrator, which we pass to Google so that Google can send you the invitation, and whether it was accepted.
- Intake answers. What you tell us about your business: business and legal name, registration number, business address, website address, contact email, what you sell, where you serve customers, your daily budget, how customer inquiries reach you, and your business phone number if calls are one of them. Google requires the legal details for advertiser verification.
- Your website. A snapshot of your website's public pages, which we read in order to write your ads. We never log in to anything of yours.
- Campaign data. The campaigns we build for you and their performance data — impressions, clicks, costs, conversions — from the Google Ads API.
- Billing. If you subscribe to a paid plan: your subscription's status, plan and renewal date, and the reference numbers Stripe assigns to you. Your card details go straight to Stripe and never reach us.
- Approval records. When you approve a campaign plan on the review screen, we record that approval. It is your authorisation to launch, so we keep proof of it.
- Campaign demo. If you try the demo at pivotad.ai/demo without an account: the website address you enter, a short-lived copy of that website's public pages (removed within 24 hours), and the business summary and campaign plan we generate from them (removed after 7 days unless you create an account and keep the plan). To stop abuse we keep a keyed, non-reversible hash of your connection for 24 hours — not the address itself. We count the steps of the demo (page shown, address entered, campaign shown, account created) without cookies of our own, IP addresses or any personal data, only to see whether the demo is useful.
- Technical logs. Like nearly every website, our servers record IP address, browser type and pages requested. We use these to keep the Service secure (including rate-limiting abusive traffic), to troubleshoot, and to keep things working.
2. What we don't collect
- Nothing about your customers or your website's visitors. PivotAd never installs anything on your website. If you choose to set up conversion tracking, PivotAd shows you a block of code that you — or the person who looks after your site — paste in yourself. That block is Google's own Google Ads tag plus a few lines written by PivotAd that notice when a contact form is sent, or a phone, WhatsApp or Telegram button is tapped, and tell Google Ads. Those lines report to Google only, under Google's terms: they contact no PivotAd server, set no cookies of their own, and never read what your visitors type. PivotAd receives nothing about your visitors. From Google we read only totals and dates — how many results Google counted and when Google last saw your tag.
- No card details. Your card details never reach PivotAd. Subscription payments are handled by Stripe, our payment processor (section 5), which stores the card and sends us only the subscription status, plan, renewal date and its own reference numbers. Your advertising budget is separate again: you pay it directly to Google in Google's own billing system, and it never passes through us.
3. How we use it
- To provide the Service — building, launching and managing your campaigns, and supporting you. Legal basis: performance of our contract with you.
- To keep the Service secure and working — logs, rate limits, fixing what breaks. Legal basis: our legitimate interests, balanced against yours.
- To email the waitlist about beta access. Legal basis: your consent — withdraw it any time by replying or emailing us, and we'll remove you.
We don't use your data to advertise to you, we don't build profiles of you, and we never sell it.
4. AI processing
To generate your campaign plan, we send your intake answers and your website snapshot to our AI provider, Anthropic, whose model drafts the keywords and ads under PivotAd's rules. Anthropic processes this data to provide the generation service and is not permitted to use it to train its models. The result is shown to you for review before anything goes live.
5. Who we share it with
Only what's needed to run the Service, with providers acting on our instructions:
- Google — to create and manage campaigns in your Google Ads account, at your instruction, through the official Google Ads API; and, if you ask us to create a Google Ads account for you, to create it under our manager account and to invite your email address as its administrator.
- Anthropic — AI campaign generation, as described above.
- Stripe — payments for paid plans. Stripe receives your email address, name, card details and billing address directly on its own pages, and sends receipts and invoices on our behalf. See Stripe's privacy policy.
- Meta and LinkedIn — advertising measurement on our public pages, only after your consent in the cookie banner, as described in section 6. See Meta's privacy policy and LinkedIn's privacy policy.
- Railway — cloud hosting for the Service and its database.
- PostHog (EU, Frankfurt) — product analytics for account holders, as described in section 6: which features you use inside your account, sent from our servers under your account number, never your email or name, with no cookie or script in your browser. See PostHog's privacy policy.
- Cloudflare — the check that tells people from automated programs on the free-demo and sign-up forms (Turnstile). When it is on, your browser loads a small script from Cloudflare, which receives your IP address and browser details for that check only. See Cloudflare's privacy policy.
- Content-delivery network. Our pages load their font from Google Fonts; your browser sends its IP address to that service when it fetches the font files.
We may also disclose information if the law requires it, to protect the Service or its users from fraud or abuse, or — under the same protections as this policy — as part of a merger or sale of the business. We never sell your personal data.
6. Cookies
Necessary cookies (always on): a session cookie, so the intake wizard remembers your answers between steps; a security cookie that protects forms against forgery; and one cookie that remembers your cookie choice for 12 months.
Optional cookies, on our public pages only and only after you accept them in the banner: Google Analytics (how people use our public pages), Google Ads, Meta (Facebook and Instagram) and LinkedIn (to measure whether our advertising brought you here and to show our ads to people like our visitors). Each provider processes this data under its own privacy policy. You can change your choice any time under "Cookie settings" in the footer; "Only necessary" means none of these ever load.
If you have accepted, we also report four moments to Meta and LinkedIn from our own servers — a sign-up, a form you send us, a booking, and the start of a paid plan — so that the report reaches them even when your browser blocked the tag. Such a report carries the click identifier from their own cookie, your IP address and browser type, and a one-way hashed form of your email address (never the address itself), and the same event number as the browser tag, so it is counted once. If you chose "Only necessary", nothing is reported.
Inside your account we record which features you use (for example that a plan was approved or ads were switched on) on our own servers, without cookies, tied to your account number, to improve the product. This is part of providing the Service and is deleted with your account. We never sell this data.
6a. Marketing pages and calls
If you arrive at one of our marketing pages from an advert, the link may carry campaign labels (UTM tags) and a Google click identifier. We keep them in your session for that visit, pass the campaign labels to Calendly when you book a call, and record which campaign led to a booking. If you book from a Google advert, we report that booking to Google Ads through its API so we can measure our own advertising; advertising cookies are set only with your consent, as described in section 6. Calls are scheduled through Calendly, whose own privacy policy applies to the booking details you enter there. If you fill in a form on a marketing page, we keep the details you enter (name, e-mail, website, the platform and budget you selected) so we can contact you about PivotAd. We keep them for up to twelve months, or until you become a user, and delete them earlier on request to contact@pivotad.ai.
6b. Company pages
PivotAd publishes pages about businesses at pivotad.ai/company/… — a summary of what the business offers, the audience it can reach, marketing opportunities and an example Google Ads campaign. Each page is written by our AI from the public pages of the business's own website, uses only facts stated there, and goes live after automated checks and our review. These pages describe businesses, not people: we do not publish pages whose business name is a person's name, and we do not collect or publish personal data on them. We keep the business's logo and social image from its website to show on the page. If a page is about your business and you want it corrected or removed, use the "This is my company — update or remove" link on the page or write to contact@pivotad.ai: we act within five working days, and a removed page is never published again. Legal basis: our legitimate interest in showing what PivotAd does with real examples, balanced against the business's interests — which the removal route protects.
7. Where your data lives
PivotAd operates from Denmark. Our hosting and AI providers are US companies, so your data may be processed in the United States. Where personal data leaves the European Economic Area, we rely on safeguards approved by the European Commission — Standard Contractual Clauses, or the EU-US Data Privacy Framework where the provider is certified.
8. Your rights
Wherever you live, we offer everyone the rights the GDPR provides: ask for a copy of your data, correct it, delete it, receive it in a portable format, object to or restrict its processing, and withdraw consent at any time. Email contact@pivotad.ai and we'll respond within a month, as the GDPR requires — we may first need to verify that you are you. If you're unhappy with our answer, you can complain to the Danish Data Protection Agency (Datatilsynet) or to your local supervisory authority.
9. How long we keep it
We keep your data while you use the Service and delete or anonymise it when it is no longer needed. Two things we hold longer: approval records, as proof that a launch was authorised, and anything the law requires us to keep, such as accounting records — including invoices for paid plans, which bookkeeping law makes us keep for five years. Deletion requests are honoured except for those.
10. Security
Access to your data is restricted, credentials and API keys are kept out of the application code, and connections to the Service are encrypted. No internet service can promise absolute security, so we won't — but if a breach ever affects your personal data, we will notify you and the authorities as the GDPR requires.
11. A service for businesses
PivotAd is built for businesses advertising on Google. It is not directed at children, and we do not knowingly collect data from anyone under 16.
12. Changes to this policy
As the Service evolves, this policy will be updated so it keeps telling the truth. Material changes will be announced on the Service or by email — never silently — and the current version always lives at pivotad.ai/privacy.
13. Contact
PivotAd · Gærdesmuttevej 10, Hørsholm, Denmark · contact@pivotad.ai. Questions, requests and complaints are all welcome.