Legal

Privacy Policy

This policy explains what information AdCare Digital collects when you use our website and the AdCare client dashboard, why we collect it, who we share it with, and how you can have it deleted.

Last updated: 8 August 2026

1. Who we are

AdCare Digital(“AdCare”, “we”, “us”) is a sole proprietorship owned by Nurus Shifa Rihan and registered in Bangladesh under Dhaka South City Corporation trade licence no. TRAD/DSCC/007948/2026, with its place of business at 31 Mitali Road, Hazaribagh, Dhaka 1209, Bangladesh. We are the data controller for the information described in this policy.

This policy covers our website at adcaredigital.com and the client dashboard at app.adcaredigital.com(together, the “Platform”). It does not cover Meta’s own products — when you use Meta Ads Manager or Meta Business Suite directly, Meta’s privacy policy applies to that activity.

2. Information we collect

2.1 Information you give us when you register

Registration is open to businesses and to individual marketers, and the fields differ slightly between the two:

  • All clients: email address, password, phone number, monthly advertising budget, product category, and a link to the Facebook Page you advertise.
  • Company accounts:additionally the company name, the name of the contact person, and that person’s role in the company.
  • Marketer accounts: additionally your own name.

Your password is never stored in readable form. We store only a bcrypt hash of it.

2.2 Financial and deposit information

  • Your internal wallet balance, the USD exchange rate applied to your account, and a full ledger of deposits, top-ups and rebalancing entries.
  • For manual deposits: the transaction ID you enter and the payment screenshot you upload (JPEG, PNG or WebP, up to 5 MB). Screenshots are stored on our server and are visible to our administrators for verification.
  • For online deposits: the invoice ID, payment method and transaction reference returned by our payment gateway.

We never receive or store your full card number, mobile wallet PIN, or banking credentials.Online payments are completed on the payment gateway’s own hosted checkout page.

2.3 Advertising account information

  • The Business Portfolio ID (Meta Business ID) you supply so that we can share an ad account with your business.
  • The ad account identifiers, account names, account status, spend cap, amount spent, balance and currency that we read from the Meta Marketing API for the accounts we manage for you.

2.4 Technical information collected automatically

  • Server and application logs, which include the IP address, request path, response status, timestamp and browser user-agent for requests to the Platform.
  • Audit records of actions taken in the Platform — deposit approvals, top-up approvals, status changes and the raw response returned by Meta — so that every financial change has a traceable history.

Our public website does not run advertising trackers or third-party analytics.

3. Cookies

The dashboard sets two strictly necessary cookies to keep you signed in. Both are HttpOnly, meaning they cannot be read by JavaScript in your browser:

CookiePurposeLifetime
access_tokenKeeps your session authenticated15 minutes
refresh_tokenRenews your session without a new login7 days

We set no advertising, profiling or cross-site tracking cookies. Because these two cookies are essential to signing in, the dashboard cannot function if you block them.

4. Why we use your information

  • To provide the service — creating your account, provisioning your wallet, requesting and assigning ad accounts, and adjusting spending limits through the Meta Marketing API.
  • To verify payments — matching your transaction ID and screenshot, or a gateway confirmation, against your deposit request before crediting your wallet.
  • To approve registrations — reviewing new sign-ups before granting access, which reduces fraudulent use of ad accounts.
  • To support you — responding to questions over email or WhatsApp.
  • To keep the Platform secure and accountable — detecting abuse, debugging faults, and maintaining the audit trail required for financial integrity.
  • To meet legal and accounting obligations in Bangladesh.

We process this information because it is necessary to perform our contract with you, because we have a legitimate interest in operating the Platform securely, or because you have consented — and, where the law requires it, to comply with a legal obligation. We do not sell personal information, and we do not use it for advertising targeting of our own.

5. How we handle Meta Platform Data

AdCare uses the Meta Marketing API to manage advertising accounts on behalf of clients. Specifically:

  • We authenticate using a System User access token belonging to our own Meta Business Manager. We never ask you for your Facebook password, and we do not log in to your personal Facebook account.
  • We read ad account metadata (status, spend cap, amount spent, currency) and write the spend cap when a top-up is approved. We do not read your message inbox, friend lists, or personal profile data.
  • Data obtained from Meta is used solely to operate the accounts we manage for you. We do not sell it, transfer it to data brokers, or use it to build advertising or credit profiles.
  • Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.

6. Who we share information with

We share only what is needed, only with the following categories of recipient:

RecipientWhat they receiveWhy
Meta PlatformsAd account IDs, your Business Portfolio ID, spend cap valuesTo assign accounts and apply spending limits
Payment gateway (ZiniPay)Your name, email address and the deposit amountTo create and verify a hosted checkout invoice
Hosting providerAll Platform data, as stored on our serverTo host the application and database
Log and monitoring providerApplication and access logs, including IP addressesTo detect errors and keep the Platform reliable
Professional advisers and authoritiesOnly what is legally requiredTo comply with law or defend legal claims

Some of these providers operate servers outside Bangladesh, which means your information may be processed abroad. We choose established providers and share the minimum necessary.

7. How long we keep it

  • Account details — for as long as your account is open, and then as described in section 9.
  • Financial records — deposits, top-ups and ledger entries are kept for at least the period required by tax and accounting rules in Bangladesh, even after account closure.
  • Payment screenshots — retained with the associated deposit record; removed when the deposit record is deleted.
  • Logs — kept for a limited operational period and then discarded automatically.

8. How we protect your information

  • All traffic to the Platform is encrypted with HTTPS/TLS.
  • Passwords are stored only as bcrypt hashes.
  • Meta credentials held on your behalf are encrypted at rest in the database.
  • Sessions use short-lived tokens in HttpOnly cookies, and access is separated by role so that clients cannot see other clients’ data or our internal billing configuration.
  • Secrets such as access tokens are redacted from our logs before they are written.

No system is perfectly secure. If a breach affects your information, we will notify you and any regulator required by law without undue delay.

9. Your rights and how to delete your data

You may ask us to:

  • give you a copy of the personal information we hold about you;
  • correct information that is wrong or out of date;
  • delete your account and associated personal information;
  • stop sending you non-essential messages.

Full instructions, including what we can and cannot delete, are on our Data Deletion page. To make any request, email privacy@adcaredigital.com from the address registered to your account. We respond within 30 days.

10. Children

The Platform is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Platform changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights, we will notify active clients by email before it takes effect.

12. Contact us