Privacy Policy
Effective date: July 23, 2026
This Privacy Policy explains how Adsu (“Adsu,” “we,” “us”) collects, uses, and shares information when you use our website and ad-attribution service (the “Service”). It covers both visitors to adsu.ai and the gym businesses (“Customers”) who use the product.
Information we collect
Information you give us. Your name, email, company, and anything you share when you book a demo or contact us.
Customer-connected data. When a Customer connects their tools, we process the data needed to attribute revenue to advertising — for example advertising click and spend data (including click identifiers) from Meta and Google, contact and lead records from GoHighLevel, and payment and membership records from Stripe and Mindbody. We use this data to match an ad click to the in-person membership it produced and to compute per-location performance.
Tracking data collected on Customer websites.As part of the Service, Customers place an Adsu tracking snippet on their own websites and landing pages (served from Adsu or from a Customer-configured subdomain of the Customer’s own domain). On the Customer’s behalf, that snippet collects visitor data used for ad attribution — advertising click identifiers, page and referrer URLs, IP address, device and browser information, and the contact details a visitor submits in the Customer’s forms. We process this data solely as the Customer’s processor, to attribute that Customer’s advertising, and never to build cross-customer profiles. Customers are responsible for the privacy disclosures and consents on their own websites (see our Terms).
Automatic data. Limited technical and usage data — such as device and browser information, IP address, and interactions with our site — collected via essential cookies and similar technologies.
Our role: processor for Customer data
For the contact, lead, and payment data a Customer connects, the Customer is the data controller and Adsu acts as a data processoron their behalf, handling that data only to provide the Service and on the Customer’s instructions. Each Customer’s data is kept logically isolated from other Customers’. We do notpool one Customer’s point-of-sale data (including Mindbody data) with another’s. Mindbody-derived data is additionally kept ephemeral by design: it is retained for no more than 48 hours and continuously re-derived from the connected Mindbody account rather than stored long-term.
How we use information
- To provide, operate, secure, and improve the Service.
- To compute ad attribution and per-location revenue performance.
- To respond to your requests and provide support.
- To send service-related and, where permitted, marketing communications.
- To comply with legal obligations and enforce our terms.
Service providers & sub-processors
We share data only with providers that help us run the Service, under contracts that limit their use of it — including our hosting, database, background-processing, and email providers (such as Vercel, Neon, Inngest, and Resend) and the advertising, CRM, and point-of-sale platforms a Customer chooses to connect (such as Meta, Google, GoHighLevel, Stripe, Mindbody, and PushPress). We do not sell personal information. We may disclose information where required by law or to protect our rights and the safety of others.
Google user data
When a Customer connects a Google Ads account, Adsu accesses Google user data through Google’s OAuth consent flow using the https://www.googleapis.com/auth/adwords scope. Specifically:
- What we access. Google Ads campaign cost and performance data (spend, campaign and ad identifiers, clicks, impressions) for the specific Google Ads account the Customer authorizes, via read-only reporting calls to the Google Ads API. We do not read Gmail, Drive, Contacts, or any other Google service.
- How we use it. Solely to compute and display ad attribution and return-on-ad-spend reporting to that same Customer inside the Service. We do not use Google user data for advertising, for training machine-learning models, or for any purpose unrelated to providing the Customer-facing reporting features described here.
- How we store it.OAuth tokens are encrypted at rest; retrieved cost and performance data is stored in the Customer’s logically isolated workspace and protected with the safeguards described under Security.
- How we share it. We do not sell Google user data, do not share it with other Customers or third parties, and do not transfer it except to the hosting sub-processors that run the Service (listed above) or where required by law.
- Deletion. Disconnecting a Google Ads account revokes our access; Customers may also revoke access at any time via their Google account security settings (myaccount.google.com/permissions), and may request deletion of previously retrieved Google Ads data as described under Data retention & deletion.
Adsu’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention & deletion
We retain information for as long as needed to provide the Service and for legitimate business or legal purposes, then delete or anonymize it. Customers may request export or deletion of their connected data, and we will action such requests consistent with applicable law and our agreement with the Customer.
Security
We use reasonable administrative, technical, and physical safeguards to protect information, including encryption in transit (TLS) and encryption of connected credentials at rest. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us below; if your data was connected by a Customer, we may refer your request to that Customer as the controller. We will respond consistently with applicable law.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date above and, for material changes, provide additional notice where required.
Contact
Questions about this policy or your data? Email hello@adsu.ai.