Privacy Policy
Last updated: 6 August 2026
Този документ е на английски език
Правният преглед на българската версия все още не е приключил, затова документът се показва на английски. Обвързваща е английската версия. Ако имате въпроси, пишете ни на support@busby.digital.
Who we are
Busby is a product of Parkor Ltd, a company registered in England and Wales. When this policy refers to “Busby”, “we”, “us” or “our”, it means Parkor Ltd.
For privacy-related questions or requests, contact us at privacy@busby.digital.
What data we collect
Account data — your name, email address, and profile information provided when you sign up via Google OAuth (handled by Clerk).
Business data — your website URL, brand assets (colours, fonts, images), business name, target audience, and campaign objectives that you provide during onboarding.
Campaign data — ad copy, images, videos, budgets, performance metrics, and spend records for campaigns you create and run through Busby.
CRM data — lead contact information, pipeline stages, activity logs, and email engagement data for leads that flow through your Busby account.
Payment data — wallet top-up amounts and transaction history. Card details are handled entirely by Stripe and never stored by Busby.
Usage data — pages visited, features used, and interactions within the Busby dashboard, collected to improve the product.
How we use your data
Providing the service — to run your ad campaigns on Google and Meta, generate AI creative assets, deliver email journeys, and maintain your CRM pipeline.
AI model improvement — unless you opt out, anonymised and aggregated campaign performance data (which may include metrics from your connected Google Ads and Meta accounts) may be used to improve Busby's own narrow, task-specific AI models (for example, campaign-performance prediction) and to compute anonymised, industry-level benchmarks. We do this on the basis of our legitimate interest in improving the product; you have the right to object and can opt out at any time from Settings → Privacy. This is never used to train generalised or foundational AI models. Enterprise plan accounts have data isolation by default and are never used for this. See Google user data below for how data from the Google Ads API specifically is handled.
Billing — to process wallet top-ups and maintain accurate transaction records via Stripe.
Communications — to send transactional emails (campaign alerts, billing receipts) and, where you have opted in, product updates. You can unsubscribe at any time.
Legal compliance — to comply with applicable law, including UK GDPR and financial regulations.
Legal basis for processing
We process your data on the following legal bases under UK GDPR:
- Contract — processing necessary to deliver the Busby service you have signed up for.
- Legitimate interests — improving our product (including using anonymised, aggregated performance data to improve our narrow prediction models and industry benchmarks), preventing fraud, and maintaining security. You can object to the product-improvement use at any time by opting out in Settings → Privacy.
- Consent — marketing communications. You may withdraw consent at any time.
- Legal obligation — where we are required to retain data by law.
Third-party services
Busby uses the following sub-processors to deliver the service:
- Clerk — authentication and user management
- Stripe — payment processing and wallet top-ups
- Neon (PostgreSQL) — primary database hosting
- Cloudflare R2 — file and asset storage
- Google Gemini / Imagen — AI text and image generation
- Amazon Web Services (SES) — transactional email delivery
- Google Ads API — campaign creation and management on Google
- Meta Marketing API — campaign creation and management on Meta
- Vercel — application hosting and edge delivery
Each sub-processor is bound by data processing agreements consistent with UK GDPR.
Google user data (Google Ads)
If you choose to link your own Google Ads account, Busby uses Google OAuth to request a single permission — the Google Ads scope (https://www.googleapis.com/auth/adwords). We request no other Google scopes and access no other Google data.
What we access — using the access token you grant, Busby reads the Google Ads accounts you have access to (account ID, descriptive name, and currency), and creates, updates, and reads the advertising campaigns and their performance metrics (such as spend, clicks, and impressions) within the account you select.
How we use it — first, to create and manage advertising campaigns and report their performance, on your behalf and at your explicit direction from the Busby dashboard. Second, unless you opt out (see AI model improvement above; opt out at any time in Settings → Privacy, and excluded by default on Enterprise plans), anonymised and aggregated performance metrics derived from this data may be used on the basis of our legitimate interest to improve Busby's narrow, task-specific models — such as campaign-performance (ROAS) prediction — and to compute anonymised, industry-level benchmarks (for example, typical click-through and cost-per-acquisition ranges by industry). We do not use it for any other purpose.
Storage and sharing — we store the resulting OAuth tokens securely and use them only to operate your own Google Ads account. The industry benchmarks above are aggregated across many advertisers and never expose your individual account data to anyone else. We do not sell this data, share it with data brokers, use it for credit-worthiness decisions, or use it to train or improve generalised or foundational AI or machine-learning models.
Data protection — this sensitive data (the OAuth tokens and the Google Ads account data above) is transmitted only over encrypted connections (HTTPS/TLS) and stored on infrastructure that encrypts data at rest. Access is restricted to the systems that operate your account: every request is authenticated and checked against your ownership before any data is read or written, and the tokens are never included in data exports. See How we protect your data below for the full set of safeguards.
Withdrawing access — you can disconnect your Google Ads account at any time from the connection settings. Doing so revokes the token with Google. Stored tokens are also deleted when you delete your Busby account.
Limited Use — Busby's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
We use technical and organisational measures designed to protect your data — including sensitive data such as the OAuth tokens and Google Ads account data described above — against unauthorised access, disclosure, alteration, or loss:
- Encryption in transit — all data moves over encrypted connections (HTTPS/TLS).
- Encryption at rest — data is stored on infrastructure that encrypts it at rest, including our database (Neon PostgreSQL) and file storage (Cloudflare R2).
- Access control & tenant isolation — every record is scoped to the account that owns it, and every request is authenticated and verified against that ownership before any data is read or written, so one customer can never access another's data.
- Secret handling — OAuth access and refresh tokens and other secrets are stored securely, used only to operate your own connected account, never sold or shared, and excluded from data exports. You can revoke them at any time by disconnecting the account, and they are deleted when you delete your account.
- Vetted sub-processors — the third parties listed above are bound by data processing agreements and receive only the data needed to perform their function.
- Retention limits — data is kept only as long as needed and then deleted (see Data retention below).
If you believe your account or data has been compromised, contact us immediately at privacy@busby.digital.
Data retention
We retain your data for as long as your account is active. If you cancel, we delete your personal data within 90 days, except where we are legally required to retain records (e.g. financial transaction records, which are kept for 7 years under UK law).
You can request earlier deletion by emailing privacy@busby.digital.
Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Portability — receive your data in a machine-readable format
- Restriction — ask us to limit how we process your data
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, without affecting prior processing
To exercise any of these rights, email privacy@busby.digital. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
We use cookies and similar technologies to operate the service. For full details, see our Cookie Policy.
Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or an in-app notice at least 14 days before they take effect. The date at the top of this page always shows when it was last updated.