Skip to content

AdSpark · Legal information

Privacy policy

This policy explains how AdSpark collects, uses, stores, secures and shares the personal data needed to operate the service, including OAuth connections to social accounts.

Last updated: July 23, 2026

These pages are published to inform users and support OAuth reviews with social platforms. The French version remains the legal reference.

Data controller

  • Controller: RAFFALLI LAURENT , BERNARD, individual entrepreneur.
  • Address: 47 RUE VIVIENNE, 75002 PARIS, FRANCE.
  • SIREN: 521 250 183.
  • Privacy contact: privacy@getadspark.com.

Data we collect

  • Account data: name, email, session identifiers, language and professional profile information.
  • OAuth connection data: connected social account identifier, public name, authorized scopes, connection and expiry dates, access and refresh tokens where required.
  • Content data: drafts, posts, media, calendars, AI-generated variants, links and related statistics.
  • Free-tool data: email address requested and verified to provide the result, language, tool used, and timestamps. Public business information selected through Google Places is displayed temporarily and is not stored with your access. Text entered to generate the result stays in the browser.
  • Usage data: in-app actions, technical errors, security logs, IP address, browser and timestamps.
  • Billing data: plan, subscription status, payment references and invoices when paid plans are enabled.

Google API Data Use

AdSpark's use and transfer to any other app of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically for Gmail access: the AdSpark application requests send permission (scope gmail.send) solely to allow you to send emails, newsletters, and campaign messages that you explicitly approve in AdSpark through your connected Gmail account. AdSpark does not read, store, or have any access to the contents of your inbox. Your Google connection data is never shared, sold, or transferred to third parties for marketing or advertising purposes. AdSpark does not use raw or derived Google Workspace API data to develop, improve, or train generalized AI or ML models, and does not transfer such data to AI providers for model training.

Google Maps Platform information

When you search for a business during onboarding or in a free tool, AdSpark queries Google Places and temporarily displays the public information you select. This use is subject to the Google Maps Platform Terms and Google's Privacy Policy. AdSpark does not cache this content beyond what Google permits.

LinkedIn API Data Use

AdSpark uses LinkedIn only when the user voluntarily connects their LinkedIn account through OAuth. The permissions currently requested are openid, profile, email and w_member_social. They are used to identify the connected profile, display the associated name or email when needed, verify that publishing permission is active, and publish to the user's LinkedIn profile the content and images the user has explicitly approved in AdSpark. AdSpark does not read LinkedIn messages, does not scrape LinkedIn, does not sell LinkedIn data, does not rent it, does not use it for advertising targeting, and does not publish anything without the user's action or approval. LinkedIn tokens are retained only to maintain the connection and perform authorized actions. The user can revoke access from AdSpark or from LinkedIn's authorized applications settings.

Purposes and legal bases

  • Provide the AdSpark service and perform the contract with the user.
  • Provide free-tool results, verify the requested address, and limit abuse based on performance of the requested service and legitimate security interests. Marketing tips require a separate, optional consent.
  • Connect social accounts through OAuth with the user's explicit consent.
  • Publish, schedule and track content approved by the user.
  • Measure performance, detect errors and secure the application based on legitimate interest.
  • Manage billing and accounting obligations based on legal obligations.
  • Send product or marketing communications where the user consented or can opt out.

Social accounts, OAuth and tokens

AdSpark never asks for third-party platform passwords. Connections to Facebook, Instagram, LinkedIn, Google Business Profile or other platforms use OAuth or the official authorization mechanism of the platform. Tokens are used only for actions authorized by the user, such as listing a connected account, publishing approved content, retrieving status or reading authorized analytics. Tokens are stored securely, encrypted at rest where technically applicable, and are never intentionally logged in clear text.

Processors

  • Application hosting and backend providers: website hosting, database, server functions and required technical services.
  • Social publication infrastructure provider: selected social connections, scheduling and multi-network publication.
  • AI generation or orchestration providers: assistance with text or visual content creation.
  • Payment provider: payments, subscriptions and invoicing.
  • Monitoring provider: error diagnosis and technical supervision.
  • Transactional email provider: service, security and support emails.
  • Media storage provider: storage for images and files used in posts.

Connected social platforms

When the user connects or uses a social platform, certain data and content is sent to that platform to perform the requested action. Meta Platforms Ireland, LinkedIn Ireland, Google Ireland and other connected platforms act under their own privacy policies and terms.

International transfers

Some processors or platforms may process data outside the European Union. Where this happens, AdSpark relies on available mechanisms such as the Data Privacy Framework, Standard Contractual Clauses, or appropriate contractual and technical safeguards.

Retention periods

  • User account: for the duration of service use.
  • OAuth tokens: until disconnection, expiry, revocation or account deletion.
  • Drafts and posts: for the duration of the account unless deleted by the user.
  • Technical and security logs: up to 12 months unless required for security or legal reasons.
  • Billing records: 10 years to comply with accounting obligations.
  • Prospects and waitlist: up to 3 years after the last active contact.
  • Free-tool access without marketing opt-in: up to 12 months after the last verification to measure usage and limit abuse.

Your rights

You may request access, rectification, erasure, restriction, portability or objection to the processing of your data. You may also withdraw consent where processing is based on consent. To exercise your rights, contact privacy@getadspark.com from the address linked to your account. We respond within 30 days unless the request is complex.

Security

  • HTTPS on public pages and endpoints.
  • Encryption of sensitive data where technically applicable.
  • Access controls limited to what is strictly necessary.
  • Webhook signature verification when platforms provide it.
  • Security event logging without intentionally exposing tokens or secrets.
  • Backups and incident response process.

Complaints

If you believe your rights are not respected, contact AdSpark at privacy@getadspark.com. You may also contact the French data protection authority, CNIL, at cnil.fr.

Question about your data or rights?

Contact us from the email address linked to your account so we can process the request correctly.

Email privacy@getadspark.com