Privacy Policy
Last updated: September 17, 2026
CentralAD — Multi-Platform Ad Campaign Management
1. Introduction
This Privacy Policy describes how ORCA-AD LTD ("the Company", "we", "us", "our"), a company incorporated under the laws of the State of Israel, collects, uses, stores, and protects your personal information when you use CentralAD ("the Platform", "the Service") at https://central.ad.
We are committed to protecting your privacy in accordance with the Israeli Privacy Protection Law, 5741-1981 ("the Privacy Law"), the Israeli Privacy Protection Regulations (Data Security), 5777-2017, and the EU General Data Protection Regulation (GDPR) where applicable.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
ORCA-AD LTD Email: privacy@central.ad Website: https://central.ad
3. Information We Collect
3.1. Information You Provide Directly
| Data Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, email address, password | Account creation and authentication |
| Organization Information | Company name, business type, industry | Service personalization and tenant setup |
| Payment Information | Billing address, payment method details | Subscription billing (processed by our payment provider) |
| Business Content | Business descriptions, brand assets, logos, product information | Ad content generation |
| Communication Data | Support tickets, emails, feedback | Customer support and service improvement |
3.2. Information Collected Automatically
| Data Category | Examples | Purpose |
|---|---|---|
| Usage Data | Pages visited, features used, clicks, session duration | Service improvement and analytics |
| Device Information | Browser type, operating system, screen resolution | Technical support and optimization |
| Log Data | IP address, access times, error logs | Security monitoring and debugging |
| Cookies and Similar Technologies | Session cookies, preference cookies | Authentication and user experience |
3.3. Information from Third-Party Platforms
When you connect your advertising accounts (e.g., Meta/Facebook, Instagram, Google Ads, TikTok, LinkedIn, and other connected ad platforms), we receive:
| Data Category | Examples | Purpose |
|---|---|---|
| Ad Account Data | Account IDs, account names | Platform integration |
| Campaign Metrics | Impressions, clicks, spend, reach, CTR | Performance analytics and dashboards |
| Ad Creative Data | Published ad content, creative IDs | Campaign management |
We access this data solely to provide the Service and do not sell, share, or distribute it to any third party. The Meta (Facebook and Instagram) connection is described permission by permission in Section 3.4; the TikTok sign-in connection is described in Section 3.5.
3.4. Meta (Facebook and Instagram) Connection
CentralAD connects to your Facebook Page, your Instagram business account and your Meta ad accounts through Facebook Login for Business, started from inside your signed-in CentralAD Account. CentralAD does not offer sign-in with Facebook. When you connect, Meta asks you to grant the permissions below, and we receive:
| Permission | Data Received | Purpose |
|---|---|---|
pages_show_list |
The Facebook Pages you manage: Page ID, name, category, profile picture, and a Page access token | Choosing the Page your ads run under and showing it in CentralAD |
pages_read_engagement |
No additional data. Meta defines this permission as reading the content your Page posts, its followers and its metadata; CentralAD reads none of your Page's posts, comments, followers or Page insights, and the Page details it uses are the ones listed under pages_show_list. Meta requires this permission for the Instagram insights read described under instagram_manage_insights |
Meeting Meta's requirement for the Instagram organic figures on your Stats page |
pages_manage_metadata |
A lead-notification subscription on your Page; each notification carries the Page ID, form ID, lead ID and submission time | Receiving new leads as they are submitted |
pages_manage_ads |
The ability to create and manage ads that use your Page as their identity | Publishing ads under your Page |
instagram_basic |
The Instagram business account linked to your Page, read from the Page's instagram_business_account field: its ID, username and profile picture |
Showing the connected account; Instagram placements and ad previews |
instagram_manage_insights |
Instagram account insights: views and accounts engaged over the selected date range | The Instagram organic figures on your Stats page |
ads_read |
Your ad accounts (ID, name, currency, account status, business name); campaign, ad set and ad status; performance metrics (impressions, clicks, spend, reach, CTR, daily trend) | Dashboards, campaign status and analytics |
ads_management |
The ability to create, pause, resume, stop and delete campaigns, ad sets, ads and ad creatives, fetch ad previews and set delivery schedules in your ad account | Publishing and managing the ads you create in CentralAD |
business_management |
Your Business Manager ID and name and the ad accounts it owns | Selecting the ad account |
leads_retrieval |
Lead submissions from your Instant Forms: lead ID, submission time, form ID and name, the ad, ad set and campaign IDs and names, and the form answers (typically full name, email and phone number) | Showing your leads in CentralAD (Section 3.6) |
We store the access tokens Meta issues (encrypted at rest), the permissions you granted, and the identifiers and names above in your connection record. We use this data only to provide the Service. We do not publish organic posts to your Page or Instagram account (the pages_manage_posts and instagram_content_publish permissions are not requested), do not read your personal profile, friends, messages or content, and do not sell or share Meta data with anyone (Section 5). Meta processes the data on its side as an independent controller under the Meta Privacy Policy, which we do not control.
You can revoke access at any time in CentralAD (Settings > Platforms > Meta > Disconnect, which deletes the connection record and removes the lead-notification subscription) or on Facebook (Settings > Business Integrations > remove CentralAD); we then delete the Meta-sourced connection data within 30 days. Campaigns, ads and leads you created remain in your Account under the retention rules in Section 7.3 until you delete them or your Account.
3.5. TikTok Sign-In (Login Kit)
CentralAD lets you sign in with, or verify, your TikTok account using TikTok's Login Kit. When you verify with TikTok, we request:
| Permission Scope | Data Received |
|---|---|
user.info.basic |
Your TikTok Open ID and Union ID (anonymized identifiers), display name, and avatar (profile picture) |
user.info.profile |
Your TikTok @username and verified-account status |
We use these fields only to confirm which TikTok account you have linked and to display it in CentralAD so the correct account can be verified before it is used to publish or deliver ads. We do not collect your TikTok password, videos, followers, messages, or private content, and we never post on your behalf. We do not use this data for profiling, behavioral advertising, or sale to third parties.
We retain this data while your Account is active. You can revoke access at any time in the TikTok app (Settings > Privacy > Apps and Websites) or by deleting your CentralAD Account; we then delete the TikTok-sourced data within 30 days. TikTok's own sign-in process may independently collect technical data (such as IP address and browser type) under TikTok's Privacy Policy, which we do not control.
3.6. Lead Data (Processed on Behalf of Your Business)
If you run lead-generation campaigns through the Service, Third-Party Platforms deliver to us the lead submissions collected by your ads (for example: a lead's name, contact details, and answers to your lead form questions). On Meta, these are the submissions to the Instant Forms attached to your ads on your Facebook Page: Meta notifies us of each new lead through the lead-notification subscription described in Section 3.4, and we retrieve the submission itself with the leads_retrieval permission.
- Roles. For lead data, you are the data controller (or "owner of the database" under Israeli law) and we act as your processor: we receive, store, and display leads to you solely so that you can follow up with them.
- Our use. We do not use lead data for our own purposes, do not enrich or profile leads, and do not share lead data with anyone other than you and the infrastructure providers that operate the Platform (Section 5.2(c)).
- Your responsibilities. You are responsible for having a lawful basis to contact your leads, for honoring their privacy rights, and for complying with the lead-data terms of the originating platform.
- Retention. Lead data follows the same retention rules as Ad Content (Section 7.3) and is deleted when your Account is deleted.
4. How We Use Your Information
We use your personal information for the following purposes:
4.1. Service Delivery
- Creating and managing your Account.
- Generating ad content using AI tools.
- Managing and publishing advertising campaigns.
- Displaying campaign performance analytics.
- Receiving lead submissions from your lead-generation campaigns and delivering them to you.
- Processing payments and managing Subscriptions.
4.2. Service Improvement
- Analyzing usage patterns to improve features and user experience.
- Identifying and fixing technical issues.
- Developing new features based on aggregated, anonymized usage data.
4.3. Communication
- Sending service-related notifications (e.g., account verification, subscription updates, security alerts).
- Responding to support requests and inquiries.
- Sending product updates and announcements (with opt-out option).
4.4. Security and Compliance
- Detecting and preventing fraud, abuse, and unauthorized access.
- Complying with legal obligations and regulatory requirements.
- Enforcing our Terms of Service.
4.5. Legal Basis for Processing (GDPR)
For Users in the European Economic Area (EEA), our legal bases for processing are:
| Legal Basis | Applies To |
|---|---|
| Contract Performance | Account management, service delivery, payment processing |
| Legitimate Interest | Service improvement, analytics, security, fraud prevention |
| Consent | Marketing communications, optional cookies |
| Legal Obligation | Tax records, regulatory compliance, law enforcement requests |
5. Data Sharing
5.1. We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to any third party.
5.2. Limited Sharing
We share your data only in the following circumstances:
(a) Payment Processing. Payment information is shared with our authorized payment provider solely for transaction processing. We do not store full payment card details on our servers.
(b) Third-Party Platforms (User-Initiated Only). When you explicitly choose to publish or share Ad Content (e.g., by clicking "Share" or "Publish"), the content is sent to the selected Third-Party Platform. This action is always initiated by you and never automatic. Once data is sent to a Third-Party Platform, that platform processes it as an independent data controller under its own terms and privacy policy, which we do not control. Please note that advertising platforms may make certain information about advertisers - such as your business name, brand identity, and ad content - publicly visible through ad-transparency and ad-library features.
(c) Infrastructure Providers. We use third-party hosting and infrastructure services to operate the Platform. These providers process data on our behalf under strict contractual obligations.
(d) Legal Requirements. We may disclose information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, safety, or property.
(e) Business Transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
(f) AI Sub-Processors. When you use the Platform's AI-powered features (Section 6), your input data — including business descriptions, brand assets, prompts, and generated content — is forwarded to specialized AI providers for processing. These categories of recipients include:
- OpenAI — text and image generation.
- Anthropic — text generation.
- Google (incl. Veo and Gemini) — text, image, and video generation.
- fal.ai — image and video generation.
- ElevenLabs — speech synthesis (voice-overs).
These providers operate under enterprise/API terms that prohibit using your data to train their models or expose it to other customers. We do not transmit your data to any AI provider for training purposes.
5.3. No Advertising or Analytics Third Parties
We do not share your data with third-party advertisers, analytics companies, or data brokers.
6. AI and Content Generation
6.1. The Platform uses artificial intelligence models to generate Ad Content based on information you provide (business descriptions, brand assets, preferences).
6.2. Input data provided for content generation is processed solely for the purpose of generating your requested content.
6.3. We may use aggregated, anonymized data from content generation to improve our AI models and Service quality. This data cannot be used to identify you or your organization.
6.4. No training on your data. Our AI providers (see Section 5.2(f)) operate under contractual terms that prohibit using your business information, brand assets, or generated content to train their models or expose it to other customers. We do not transmit your data to any AI provider for training purposes.
7. Data Storage and Transfers
7.1. Storage Location
Your data is stored on servers located in Israel.
7.2. International Data Transfers
If you are located outside Israel, your data is transferred to and processed in Israel. We ensure appropriate safeguards for international data transfers through:
- The European Commission's adequacy decision for Israel (Commission Decision 2011/61/EU), which recognizes Israel as providing an adequate level of data protection for transfers from the EEA.
- Compliance with the Israeli Privacy Protection Law and the Privacy Protection (Transfer of Data Abroad) Regulations, 5761-2001, regarding cross-border data transfers.
- Contractual obligations with our infrastructure providers and AI sub-processors (Section 5.2(f)) to maintain adequate data protection standards.
7.3. Data Retention
We retain your data for as long as necessary to provide the Service and fulfill the purposes described in this Policy:
| Data Type | Retention Period |
|---|---|
| Account Information | Deleted within 30 days of request; backups purged within 90 days |
| Payment Records | 7 years (Israeli tax law requirement) |
| Usage Logs | 24 months |
| Ad Content | Duration of Account + 30 days after deletion |
| Support Communications | 36 months after resolution |
| Security Logs | 12 months |
After the retention period, data is permanently deleted or irreversibly anonymized.
8. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL.
- Encryption at Rest: Sensitive data stored in our databases is encrypted.
- Access Controls: Role-based access controls limit data access to authorized personnel only.
- Authentication Security: Passwords are hashed using industry-standard algorithms. We support secure authentication methods.
- Infrastructure Security: Our hosting environment is secured with firewalls, intrusion detection, and regular security audits.
- Incident Response: We maintain an incident response plan and will notify affected Users and relevant authorities of data breaches as required by law.
While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of your data.
9. Cookies and Tracking Technologies
9.1. Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Authentication, session management, security | Session / 30 days |
| Preference Cookies | Language settings, UI preferences, theme | 1 year |
9.2. What We Do NOT Use
- We do not use third-party advertising cookies.
- We do not use cross-site tracking pixels.
- We do not use social media tracking widgets.
9.3. Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies may affect your ability to use the Service.
10. Your Rights
10.1. Rights Under Israeli Law
Under the Israeli Privacy Protection Law, you have the right to:
- Access your personal data held by us.
- Correct inaccurate or incomplete data.
- Delete your data (subject to legal retention requirements).
- Object to processing of your data.
- Withdraw consent where processing is based on consent.
10.2. Additional Rights for EEA Residents (GDPR)
If you are located in the EEA, you additionally have the right to:
- Right to Erasure (Article 17) — request the deletion of your personal data, subject to legal retention requirements.
- Data Portability (Article 20) — receive your data in a structured, machine-readable format.
- Restriction of Processing (Article 18) — request that we limit how we process your data.
- Object to Processing (Article 21) — object to processing based on legitimate interests.
- Lodge a Complaint — file a complaint with your local Data Protection Authority.
10.3. Exercising Your Rights
To exercise any of these rights, contact us at:
Email: privacy@central.ad
We will respond to your request within 30 days. We may request identity verification before processing your request.
10.4. Account Deletion
You may request complete deletion of your Account and associated data by:
- Using the Account deletion feature in your settings, or
- Emailing privacy@central.ad.
Upon receiving a deletion request, we will:
- Delete your Account and personal data within 30 days.
- Retain only data required by law (e.g., payment records for tax purposes).
- Permanently delete or anonymize all remaining data.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will promptly delete such data.
If you believe a child has provided us with personal information, please contact us at privacy@central.ad.
12. Changes to This Policy
12.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
12.2. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.
12.3. The "Last Updated" date at the top of this page indicates when the Policy was last revised.
12.4. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ORCA-AD LTD Data Protection Contact Email: privacy@central.ad Website: https://central.ad
For general inquiries: support@central.ad For legal matters: legal@central.ad
This Privacy Policy is effective as of September 17, 2026.