Privacy Policy
Effective: 2026-04-21 · Last updated: 2026-07-31
1. Who we are
Dynamic Ad (“we,” “our,” “us”) is an AI marketing operating system based in Tel Aviv, Israel. We operate the website at dynamicad.ai and the Dynamic Ad platform at app.dynamicad.ai, which our clients use to run and measure their advertising.
This policy covers both. Sections 2 to 6 describe data we collect from visitors to this website, where we are the data controller. Section 7 describes advertising platform data we process on behalf of our clients through the Dynamic Ad platform, where the client is the controller and we act as their processor.
2. What data we collect
When you submit a form on our site, we collect:
- Identity data: full name, company name
- Contact data: email address
- Business data: website URL, monthly ad spend range, primary ad channels, goals, and any notes you provide
- Technical data: IP address hash (not full IP), browser type, referring URL, UTM parameters
- Usage data: pages visited, time on page, scroll depth (collected via GA4 and Vercel Analytics)
3. How we use it
We use your data to:
- Deliver your predictive audit and communicate about results
- Respond to contact or partnership inquiries
- Send newsletter emails (only if you subscribed)
- Analyze site usage to improve our service
- Measure and run advertising campaigns. Analytics tools (GA4) run only on your prior consent for analytics cookies. Advertising tools (Meta Pixel and Conversions API, LinkedIn Insight Tag, TikTok Pixel, Microsoft UET, Reddit Pixel) run only on your prior consent for advertising cookies.
We do not sell your data. We do not use it for AI training.
4. Third-party processors
We share data with the following processors:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Lead and form data storage | US (AWS) |
| Resend | Transactional email delivery | US |
| Vercel | Web hosting and analytics | US/Global (edge) |
| Google Analytics 4 (GA4) | Analytics, consent-gated (_ga, _ga_*) | US |
| Meta (Facebook) Pixel and Conversions API | Advertising measurement and remarketing, consent-gated (_fbp, _fbc) | US |
| LinkedIn Insight Tag | Advertising measurement and remarketing, consent-gated (li_fat_id, lidc, bcookie) | US |
| TikTok Pixel | Advertising measurement and remarketing, consent-gated (_ttp) | US |
| Microsoft (Bing) UET | Advertising measurement and remarketing, consent-gated (MUID, _uetsid, _uetvid) | US |
| Reddit Pixel | Advertising measurement and remarketing, consent-gated (_rdt_uuid) | US |
| Cal.com | Booking scheduling (on /book page) | US |
| Cloudflare Turnstile | Bot/spam protection | US/Global (edge) |
5. Cookies
We set the following cookies:
- Consent preference cookie (da_consent_v1): stores your cookie consent choice. 365-day expiry. Functional.
- Analytics cookies (_ga, _ga_*): Google Analytics 4. Set only if you consent to analytics cookies. 2-year expiry.
- Advertising cookies: set only if you consent to advertising cookies. These include Meta Pixel (_fbp, _fbc), LinkedIn Insight Tag (li_fat_id, lidc, bcookie), TikTok Pixel (_ttp), Microsoft UET (MUID, _uetsid, _uetvid), and Reddit Pixel (_rdt_uuid). Durations range from one day to 13 months.
- Cal.com cookies: set when you visit /book and use the scheduler. Session-based.
Analytics and advertising cookies are denied by default and set only after you opt in. You can change or withdraw consent at any time using the “Cookie settings” control in the footer. See our Cookie Policy for full details.
6. Your rights
Depending on your jurisdiction, you may have the right to:
- Access: request a copy of data we hold about you
- Deletion: request that we delete your data
- Portability: receive your data in a structured format
- Objection: object to processing for marketing purposes
To exercise any right, email privacy@dynamicad.ai. We respond within 30 days.
7. Advertising platform data we process for clients
This section applies to the Dynamic Ad platform at app.dynamicad.ai, not to this website. It describes data we access from advertising platforms when a client engages us to operate their advertising.
Our role. The client owns their advertising accounts and remains the controller of the data in them. We act as their processor and service provider, and we process that data only to deliver the services the client has engaged us for and on their instructions.
How we obtain access. A client authorizes us through the advertising platform’s own consent flow (OAuth), or by granting our identity access to their advertising account. We never ask for a client’s platform password. A client can revoke our access at any time from inside the platform itself, for example LinkedIn Campaign Manager, Google Ads, or Meta Business Manager, or by asking us to disconnect.
What we access. Through authorized API connections to advertising platforms including LinkedIn, Google Ads, Meta and Microsoft Advertising, we access:
- Advertising account and campaign structure: campaigns, ad groups, ads, budgets, bids and targeting settings
- Aggregated performance and reporting data: impressions, clicks, spend, conversions and platform-provided breakdowns
- Creative assets and ad copy belonging to the client
- Conversion and measurement identifiers needed to attribute results to the campaigns that produced them
- Where a client enables lead generation forms, the contact details a person submits to that client’s form. Those leads belong to the client and are delivered to the client.
What we use it for. Solely to plan, launch, measure and optimize that client’s advertising, and to report results back to that client. Actions that change spend or campaign state require human approval before they are applied.
What we do not do. We do not:
- Sell, rent, license or otherwise make advertising platform data available to any third party
- Build or offer any data enrichment, data resale, lead database or contact database product
- Scrape any platform, or obtain data by any means other than the platform’s official API with the client’s authorization
- Combine one client’s advertising platform data with another client’s, or pool it into any shared dataset or published benchmark
- Use advertising platform data, including LinkedIn data, to train machine learning models, and we do not authorize any provider we use to do so
- Access member profile, connection or messaging data, or use advertising APIs to collect member profile information
Where we process data obtained from the LinkedIn Marketing APIs, we do so in accordance with the LinkedIn Marketing API Program terms.
Retention and deletion. We retain a client’s advertising platform data for as long as we operate their advertising, and for no more than 90 days after the engagement ends or the connection is disconnected, after which we delete it. Stored access credentials are deleted when a connection is removed or revoked. A client may request earlier deletion at any time by emailing privacy@dynamicad.ai, and we action it within 30 days.
Security. Platform access credentials, including OAuth access and refresh tokens, are encrypted at rest using AES-256-GCM. Client data is segregated per client account and protected by row-level access controls. Access is limited to personnel who need it to operate the account.
Sub-processors. The platform is hosted on Vercel and stores data in Supabase. We use AI model providers to generate advertising creative and landing page content under terms that do not permit them to train on our data. We do not share advertising platform data with any other third party except where required to deliver the service to that client or where required by law.
8. Governing law
This policy is governed by the laws of the State of Israel, including the Israeli Privacy Protection Law, 1981 and its regulations. For users in the European Economic Area and the United Kingdom, we also comply with the General Data Protection Regulation (GDPR) and UK GDPR where applicable. Disputes will be resolved in the courts of Tel Aviv, Israel, unless local law grants you mandatory rights to proceed elsewhere.
9. Contact us
Privacy questions: privacy@dynamicad.ai