Privacy Policy
Last updated: July 21, 2026Bridge24 ("Bridge24", "we", "us") is an advertising management application that helps businesses create, publish and analyze advertising campaigns on Meta platforms (Facebook and Instagram). This policy explains what data we collect, why we collect it, how we protect it, and the rights you have over it. It applies to the Bridge24 web application and this website.
We only collect what the product needs to work, we never sell your data, ad spend is billed by Meta — never by us — and you can delete everything at any time from inside the app or by emailing [email protected].
1. Who is responsible for your data
The data controller is Bridge24 Ltd, a private limited company registered in England and Wales under company number 17078326, with its registered office at 86-90 Paul Street, London EC2A 4NE, United Kingdom. For any privacy question or request, contact us at [email protected]. We respond to all requests within 30 days.
2. Data we collect
2.1 Account data you give us
- Email address and password (the password is stored only as a salted hash — we cannot read it).
- Content you create in the app: campaign names, budgets, targeting choices, ad copy and media you upload.
2.2 Meta Platform Data (via the Meta Marketing API)
When you connect your Meta account, you authorize Bridge24 to access, through Meta's official APIs and strictly on your behalf:
- Your ad accounts (name, ID, currency, timezone) and connected pages;
- Campaigns, ad sets and ads in those accounts, including their configuration, status and review state;
- Performance metrics (spend, impressions, clicks, conversions and similar aggregated statistics);
- Pixels associated with the ad account;
- Ad previews rendered by Meta.
Access tokens issued by Meta are encrypted at rest with AES-256-GCM and are never exposed to your browser or to third parties, except back to Meta itself to perform the actions you request.
We process Meta Platform Data solely to provide the service you asked for, in accordance with the Meta Platform Terms and Developer Policies. We do not sell Platform Data, use it for advertising of our own, build profiles unrelated to the service, or provide it to data brokers.
2.3 Technical data
- Standard server logs (IP address, timestamps, requested pages) kept for security and debugging;
- Strictly necessary session information to keep you signed in. We do not use advertising or cross-site tracking cookies on this website.
3. Why we process your data (legal bases)
- To provide the service (performance of a contract): connecting your ad account, publishing campaigns, showing metrics and previews.
- AI campaign analysis (performance of a contract): when you click "AI analysis", a snapshot of the selected campaign's configuration and aggregated metrics is processed by our AI provider (Anthropic) to generate the analysis. The snapshot contains no passwords, tokens, or payment data, and is not used by the provider to train models.
- Security and abuse prevention (legitimate interest): server logs, encryption, access controls.
- Legal obligations: accounting and compliance records where required by law.
4. Who we share data with
We share data only with processors necessary to run the service, each bound by contractual confidentiality and data-protection obligations:
- Meta Platforms, Inc. — to execute the campaign actions you request through the Marketing API;
- Anthropic — to generate AI campaign analyses you explicitly request;
- Our hosting provider — infrastructure on which the application and database run.
We never sell personal data or Platform Data, and we do not share it with advertisers, ad networks or data brokers.
5. How long we keep data
- Account and campaign data: for as long as your account exists.
- Meta Platform Data: refreshed from Meta as needed for the service, and deleted when you disconnect your Meta account or delete your Bridge24 account.
- Server logs: up to 12 months.
- After a deletion request, all personal data and Platform Data is erased within 30 days, except minimal records we are legally required to keep.
6. How we protect data
- All traffic is encrypted in transit (TLS).
- Meta access tokens are encrypted at rest with AES-256-GCM.
- Passwords are stored as salted hashes.
- Access to production systems is restricted and logged.
- If we become aware of a data breach affecting your data, we will notify you and the competent authority without undue delay, and we will report any breach of Meta Platform Data to Meta as required by the Platform Terms.
7. Your rights
Depending on your location (including under the UK GDPR and the EU GDPR), you have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. To exercise any right, email [email protected]. You also have the right to lodge a complaint with your local data-protection authority.
To delete your data, see our data deletion instructions — you can do it yourself from inside the app in one click.
8. International transfers
Our processors may store data in the United Kingdom, the European Union and/or the United States. Where data leaves the UK or the EEA, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision.
9. Children
Bridge24 is a business tool and is not directed at children. You must be at least 18 years old (and old enough to run ads under Meta's own terms) to use the service.
10. Changes to this policy
If we make material changes, we will update the date above and notify you in the app or by email before the changes take effect.
11. Contact
Bridge24 Ltd · 86-90 Paul Street, London EC2A 4NE, United Kingdom — [email protected]
