Legal

Privacy Policy

Effective date: 1 July 2026

This policy explains how MAVA Design EOOD (“RoasProof”, “we”, “us”) handles personal data. Because we operate a conversion-tracking service, we wear two hats: we act as a processor for data our customers ask us to handle, and as a controller for data we collect for our own purposes (accounts, billing, this website).

1. Who we are

MAVA Design EOOD provides server-side conversion tracking: we capture ad-click data first-party on our customers' websites, match it to users and orders, and deliver conversion events to advertising platforms such as Meta, Google and TikTok on our customers' behalf. You can reach us at [email protected].

RoasProof is a product of MAVA Design EOOD, a company registered in Bulgaria at Bukova polyana 112, Smolyan, Bulgaria, company registration number 204539189, VAT BG204539189. You can also write to us at that address.

2. Data we process on behalf of customers (as processor)

When a business (the “customer”) uses RoasProof on its website or store, we process the following categories of data about that customer's end users, acting on the customer's documented instructions:

  • Click and campaign data: click identifiers (such as fbclid, gclid, ttclid), UTM parameters, landing page URL, referrer.
  • Visitor and session data: a first-party visitor identifier, session timestamps, device and browser information (user agent), IP address.
  • Customer and order data: email address, phone number, name and address fields, order identifiers, order value and currency, as provided by the customer's store or API.
  • Derived identifiers: SHA-256 hashes of identifiers such as email and phone number, prepared for transmission to advertising platforms.

For this data, the customer is the controller and RoasProof is the processor. Processing is governed by our Data Processing Agreement. If you are an end user of a website that uses RoasProof, please direct privacy requests to that website's operator. We will assist them in responding.

3. Data we collect for our own purposes (as controller)

  • Account data: name, email address, password hash, workspace settings, when you register for RoasProof.
  • Billing data: plan, invoices and payment status. Card details are handled by our payment processor and never stored by us.
  • Usage and log data: product usage events, API request logs, IP addresses and security logs, used to operate, secure and improve the service.
  • Website data: analytics on this marketing site, the ad click that brought you here if you allow marketing cookies, and any information you send us by email.

4. Hashed identifiers

Before conversion events leave our servers for an advertising platform, direct identifiers such as email addresses and phone numbers are normalized and hashed with SHA-256. Platforms receive hashes for matching purposes (not raw values), except for fields the platforms specify must be sent unhashed (for example IP address and user agent, where enabled by the customer).

5. Subprocessors and recipients

We share data with the following categories of recipients, only as needed to provide the service:

  • Advertising platforms: Meta Platforms (Conversions API), Google (Google Ads conversion APIs) and TikTok (Events API), strictly as directed by the customer whose site generated the data.
  • Infrastructure providers: cloud hosting, storage and content delivery. Customer data is hosted with OVHcloud in Limburg, Germany, inside the EU.
  • Operational vendors: payment processing, transactional email and customer-support tooling. These see account and billing data, not the conversion data we process for customers.

The current, complete subprocessor list is maintained in our DPA. We notify customers before adding or replacing subprocessors.

6. Legal bases

Where the GDPR applies to processing we control, we rely on: performance of a contract (providing your account), legitimate interests (service security, product improvement, defending legal claims), legal obligations (tax and accounting), and consent where required (for example marketing communications).

7. Retention

Event and click data processed on behalf of customers is retained for the period configured by the customer and deleted or anonymized afterwards, and in any case deleted following termination of the customer's contract in accordance with the DPA. Account and billing data is kept for as long as your account exists plus any period required by law.

Where a customer sets no shorter window, our defaults are 90 days for conversion and visitor events and 180 days for visitor records. Any workspace can lower these. After a subscription ends we delete Customer Data within 30 days, as set out in the DPA.

8. International transfers

Where personal data is transferred outside the EU/EEA, including to advertising platforms, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.

9. Your rights

If you are in the EU/EEA or another jurisdiction with similar laws, you may have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to lodge a complaint with a supervisory authority. To exercise rights over data we control, contact [email protected]. For data we process on behalf of a customer, contact that customer. We will support their response.

10. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest, hashing of direct identifiers, role-based access controls and audit logging. A fuller description is in the DPA.

11. Cookies on this website

When you arrive, this website sets only the cookies it needs to work: your cookie choice itself, an affiliate referral code if you came through a partner link, and the live-chat widget so you can reach support. Nothing else loads until you say so.

Analytics cookies load only after you accept them in the consent banner, which also lets you accept or reject each category separately. You can change your mind at any time through Cookie settings in the footer. Every cookie we set, what it does and how long it lasts is listed in the Cookie Policy.

12. Google user data and Google API Services

When a customer connects their Google Ads account, we request the minimum access we need: the adwords scope, to read that account's campaign structure and daily performance metrics and to upload the customer's own offline conversions, plus openid and email, to identify which Google account was connected so that reconnecting updates the same record instead of creating a duplicate. We store account, campaign, ad group and ad names, their statuses, and daily figures such as impressions, clicks, cost, conversions and conversion value, so the customer can see Google spend beside their Meta and TikTok spend and the revenue we attribute to each ad.

We never create, edit, pause or delete campaigns, ads, budgets or bidding strategies. Access and refresh tokens are encrypted at rest and deleted when the customer disconnects the account in RoasProof or revokes access from their Google account settings.

RoasProof's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, we do not sell it, and we do not let humans read it except with the customer's explicit consent, where needed for security purposes, or where required by law.

13. Meta and TikTok advertising data

When a customer connects a Meta or TikTok advertising account, we receive that account's advertising data through that platform's marketing APIs: the ad accounts the connecting person can access, campaign, ad set and ad names and statuses, creative assets and their images, and daily figures such as impressions, clicks, spend and reported conversions. We also receive the connecting person's platform user identifier and, on Meta, their name and email, so we can show which account is connected and keep one record per person rather than a duplicate on every reconnection.

We use this data only to provide the Service to the customer whose account it is: showing their spend and return on ad spend beside the revenue we attribute to each ad. We do not sell it, we do not use it to target advertising or build profiles of individuals, and we do not share it with other customers or with third parties beyond the infrastructure providers listed in section 5. We never create, edit, pause or delete campaigns, ads or budgets.

Access tokens are encrypted at rest and deleted when the customer disconnects the account in RoasProof or removes our access from the platform's own business or app settings. The advertising data itself is retained as described in section 7 and deleted when the account is disconnected or the subscription ends. Our handling of data received from Meta follows the Meta Platform Terms, and our handling of data received from TikTok follows the TikTok for Business developer terms.

How to delete this data. Disconnect the account inside RoasProof, on the Meta Ads or TikTok Ads page of your workspace. That deletes the stored access tokens immediately and stops all further collection. You can also remove our access from Meta Business settings or from your TikTok for Business account, which has the same effect on future collection. To have the advertising data we already hold erased as well, email us at [email protected] from the address on your account and we will delete it within 30 days.

14. Changes and contact

We will post updates to this policy on this page and, for material changes, notify customers by email. Questions: [email protected].