AdLegion · AdHangar

Privacy Policy

Last updated 11 September 2026 (v1.2) · Terms of service

1. Who we are

AdHangar is a creative trafficking service operated by Adlegion Limited, a company registered in England and Wales (company number 12418118, VAT GB 341 4597 00), registered office Apperley House, The Green, Apperley, Gloucestershire, GL19 4DQ, United Kingdom ("AdLegion", "we", "us"). This policy covers the AdHangar product; Adlegion's consultancy business and website are covered by the Adlegion privacy policy. This policy explains what information we handle when you use AdHangar at app.adhangar.ai and its API, and when you visit adhangar.ai.

Privacy contact: admin@adlegion.com.

2. Our two roles

As a processor. Our customers (advertisers and their agencies) use AdHangar to store creative files, organise them into ads, get them approved and push them to advertising platforms. The campaign data, creative assets and platform account data involved belong to the customer. We process them on the customer's instructions, under our terms of service and a data processing agreement, and the customer is the controller.

As a controller. We are the controller for the account details of the people who sign in to AdHangar, for our own security logs, for our correspondence with you, and for visitors to adhangar.ai.

3. What we process, and why

DataExamplesPurpose and legal basis
Account data (controller)Name, work email, password (stored as a hash), two-factor authentication secret, role and business membership, sign-in times, IP address and browser in security logsTo provide and secure the service and meet our contract with your organisation (contract; legitimate interest in security)
Creative and campaign data (processor)Image and video files, file names, ad copy, landing page URLs, tracking parameters, naming conventions, campaign and ad set names, approvals, feedback and version historyTo provide the service on the customer's instructions
Advertising platform data (processor)Ad account identifiers, Facebook Page and Instagram identifiers, campaign, ad set and ad identifiers and names, ad status, and aggregated performance figures the customer asks the assistant to readTo build, preview and push ads and to read account state, on the customer's instructions, within the access the customer granted
Integration credentials (processor)Meta system-user access tokens, Google OAuth refresh tokens for Google Sheets and YouTube, customer API keys (stored as hashes), webhook signing secretsTo act on the customer's accounts as authorised. Tokens and secrets are encrypted at rest.
Approver contact data (processor)Names and emails of the people a customer assigns as approvers, and the feedback they writeTo route approvals and keep an audit trail, on the customer's instructions
Website visitor data (controller)Server access logs (IP address, pages requested, browser). No analytics or advertising cookies.Security and operation of the site (legitimate interest)

We do not collect personal information from consumers who see the advertisements our customers run. Performance data we read from advertising platforms is aggregated and does not identify individuals.

4. How the AI features handle your data

AdHangar uses large language models, provided by Anthropic, to compose ads from delivered files and metadata, to diagnose naming problems, to answer questions about the product, and, when a customer switches it on, to operate the Meta Ads command-line tool on the customer's behalf.

5. Advertising platforms

Meta

Customers connect Meta through Facebook Login for Business and grant AdHangar access to specific ad accounts and Pages. We use the Meta Marketing API to upload creative to media libraries, create ads (always paused), read campaign, ad set and ad state, and, where the customer has enabled the assistant's command-line tool, create paused campaigns and ad sets and read aggregated performance. We use this data only to provide the service, in accordance with Meta's Platform Terms and Developer Policies. We do not use Meta platform data to build or train models, to build profiles, or for any purpose other than serving the customer that granted access. The assistant's platform actions are recorded in an audit log the customer can see; the record holds the command, its outcome and timing, never the access token.

Google (Google Sheets and YouTube)

Customers may connect a Google account so AdHangar can read a spreadsheet they choose (scope: drive.file, limited to files picked in Google's own dialog; read-only) and, separately, upload videos to a YouTube channel they administer (scopes: youtube.upload and youtube.readonly). AdHangar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. AdHangar uses YouTube API Services; by connecting a channel you also agree to the YouTube Terms of Service, and Google's Privacy Policy applies to Google's handling of your data. You can revoke AdHangar's access at any time from the connection settings in AdHangar or from your Google account permissions.

TikTok

TikTok for Business is being added. When it is available, customers will authorise AdHangar through TikTok's own login and grant access to specific advertiser accounts. We will use the TikTok Marketing API to upload creative to the customer's media library, read campaign, ad group and ad names and status so ads can be placed in the right ad group, create ads (always paused), and read the delivery status of those ads. We will not read TikTok user data, audience lists or individual-level performance data, and we will not use TikTok data for any purpose other than trafficking the customer's own ads. Access tokens are stored encrypted per advertiser and deleted when the customer disconnects. We will update this section before the integration goes live.

YouTube Ads (Google Ads)

YouTube advertising is being added. When it is available, customers will authorise AdHangar through Google's own sign-in and grant access to specific Google Ads accounts (scope: adwords). We will use the Google Ads API to read campaign, ad group and ad names and status so ads can be placed in the right ad group, create video ads that reference videos on the customer's own YouTube channel (always paused), and read the review and delivery status of those ads. We will not read audience lists, user-level data or conversion data, and we will not use Google Ads data for any purpose other than trafficking the customer's own ads. Our use of Google Ads data is subject to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Ads API Terms of Service. Tokens are stored encrypted per advertiser and deleted when the customer disconnects or revokes access at their Google Account. We will update this section before the integration goes live.

Campaign Manager 360

Campaign Manager 360 (CM360) is being added. When it is available, customers will authorise AdHangar through Google's own sign-in and grant access to a specific CM360 user profile and advertiser (scope: dfatrafficking). We will use the Campaign Manager 360 API to upload creative assets to the customer's advertiser, read campaign, placement and ad names and status so creatives can be assigned to the right placements, create ads and creative assignments (always inactive), and read the status of those ads. We will not read reporting data at user or impression level, and we will not use CM360 data for any purpose other than trafficking the customer's own ads. Our use of CM360 data is subject to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Marketing Platform terms the customer holds. Tokens are stored encrypted per advertiser and deleted when the customer disconnects or revokes access at their Google Account. We will update this section before the integration goes live.

Other platforms

Each platform is described here before its integration launches. Where a platform's own terms require specific wording, that wording appears in the platform's section above.

6. Who we share data with

We use a small number of service providers to run AdHangar. Each processes data only on our instructions and under a contract.

ProviderWhat forLocation
DigitalOceanHosting: application servers and file storageUnited Kingdom (London)
AnthropicLarge language model API (see section 4)United States
Meta PlatformsAdvertising platform the customer connectsUnited States and EU
GoogleSheets and YouTube connections the customer makes; Google Ads and Campaign Manager 360 when availableUnited States and EU
TikTokAdvertising platform the customer connects, when availableSingapore, United States and EU
ResendTransactional email (invitations, sign-in codes, notifications)European Union (Ireland)
ImprovMXForwarding of email sent to our addressesEuropean Union

Customers also decide where their data goes when they configure the API, webhooks or automation tools (for example n8n, Zapier or Power Automate). Data sent to endpoints a customer configures is under the customer's control.

We do not sell personal data.

Requests from public authorities. We may disclose data where the law requires it, and we hold a written policy for how we handle those requests. We check that every request cites a legal power that actually reaches us, and we verify the authority through a published channel rather than the contact details in the request. We refuse or formally challenge requests that are unlawful, overbroad or improperly served. Where we do disclose, we disclose only the specific records named, for the period named, and nothing alongside them; access tokens are never disclosed, because a token is a live credential rather than a record. We keep a register of every request, what we disclosed or why we refused, the legal reasoning, and who decided. Where we hold the data as a processor, our default is to direct the authority to the customer who controls it. We notify an affected customer before disclosing unless we are legally prohibited from telling them or there is an immediate risk to someone's life. As at 18 September 2026 we have received no requests from any public authority relating to AdHangar, and have disclosed nothing to any. To ask about this policy, contact us at the address in section 1.

7. International transfers

Our servers are in London, United Kingdom. Where a provider processes data outside the United Kingdom, we rely on that provider's data processing agreement, which incorporates the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, or on a UK adequacy decision where one applies (for example for the European Union).

8. How long we keep data

9. Security

All traffic is encrypted in transit (TLS). Integration tokens and secrets are encrypted at rest with AES-256-GCM; passwords and API keys are stored only as hashes. Two-factor authentication is required for business owners and administrators. Each advertiser's data, credentials and integrations are isolated from every other advertiser's, including within the same business. Outbound webhooks are signed so recipients can verify their origin. Access to production systems is limited to named staff. If we become aware of a personal data breach affecting customer data, we will notify the affected customer without undue delay and, where required, within 72 hours.

10. Cookies and local storage

AdHangar sets one strictly necessary cookie (tp_session) to keep you signed in. It is not used for tracking. The application stores interface preferences (for example panel widths) in your browser's local storage. adhangar.ai sets no cookies and runs no analytics.

11. Your rights

If you are in the UK or EU you have the right to access, correct or erase your personal data, to restrict or object to its processing, to data portability, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office). Where we act as a processor, please direct requests to the customer that controls the data; we will help them respond. Otherwise contact us at the address in section 1.

12. Deleting your data

To delete data, do any of the following:

13. Children

AdHangar is a business service and is not intended for use by anyone under 18.

14. Changes to this policy

We will post changes here with a new "last updated" date and, for material changes, notify customers by email.

Adlegion Limited · company number 12418118 · Apperley House, The Green, Apperley, Gloucestershire, GL19 4DQ, United Kingdom