Last updated 29 August 2026 · Effective [EFFECTIVE DATE]
Rigel reads advertising data you already own, normalizes it, and produces recommendations. We do not sell data, we do not build advertising profiles of individuals, and we do not use your advertising data to train models for other customers.
Rigel ("Rigel", "we", "us") is operated by [LEGAL ENTITY NAME], [COMPANY FORM AND REGISTRATION NUMBER], registered at [REGISTERED ADDRESS]. For the personal data described here we act as the data controller, except where stated otherwise in section 4.
Privacy questions and requests: [PRIVACY CONTACT EMAIL].
| Question | Short answer |
|---|---|
| Do you sell personal data? | No. We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising. |
| Do you use third-party analytics or ad trackers? | No. The Rigel web applications load no third-party analytics, tag managers or advertising pixels. |
| What is the sensitive data? | Your advertising platform access tokens and your campaign performance data. Tokens are encrypted at rest and never displayed back to you. |
| Can you delete everything? | Almost. See section 9 — a security audit log and financial records are retained by design, and we explain why. |
When you create an account or are invited to a workspace: email address, display name, a password verifier (never the password itself — see section 8), and, if you sign in through your organization's directory, the identifier that directory returns.
We also record sign-in activity so you can review it and so we can investigate abuse: session records, sign-in and sign-out events, failed sign-in attempts, the network address the request arrived from, and a coarse device label derived from your browser's user agent (for example "Chrome on Windows"). We do not store full user-agent fingerprints for tracking purposes.
Content you create in Rigel: workspaces and their settings, goals, funnel classification rules, onboarding progress, website domains you register for tracking, team members and their roles, and invitations you send (invitation and password-reset links are stored only as irreversible hashes).
When you connect an advertising account, Rigel retrieves data from that platform on your behalf. For Meta, we request these permissions and use them as follows:
| Permission | Why Rigel asks for it |
|---|---|
ads_read | Read campaigns, ad sets, ads and performance insights — the core of the analysis. |
ads_management | Apply changes you explicitly approve (budget, status and targeting adjustments). Rigel never changes a live campaign without your approval. |
business_management | Identify which business portfolio and ad accounts your connection covers, and diagnose missing access. |
pages_read_engagement | Attribute results to the Pages your ads run from. |
catalog_management | Relate catalogue-driven campaigns to the product sets they advertise. |
The data itself is business advertising data: ad account identifiers, currency and time zone, campaign / ad set / ad structure and settings, creative metadata, aggregate performance metrics (impressions, clicks, spend, conversions and similar), Page and pixel metadata, and the status of the permissions you granted. We also store the access token for the connection, encrypted (section 8).
We do not request, and do not want, individual-level data. Rigel does not collect customer lists, custom audience membership, or the personal data of the people your ads reach.
If you upload a CSV export instead of connecting an account, we parse it and store the resulting rows plus a summary of the import. The uploaded file itself is not retained after parsing. Anything you place in that file is data you have chosen to send us, so do not include personal data of individuals that the analysis does not need.
Your plan, entitlements, and metered usage counters for features that are limited by plan. Payment card details are never collected or stored by Rigel; [PAYMENT PROVIDER — CONFIRM BEFORE PUBLISHING] handles payment data directly.
Server logs, and an append-only audit log recording security-relevant and data-changing actions: who did what, to which object, when, with what result, and a correlation identifier. Audit entries carry sanitized detail only — secrets, tokens and credentials are excluded before an entry is written.
For your account and identity data (3.1) we are the controller. For workspace content and advertising platform data you bring into Rigel (3.2–3.4), you or your organization decide what is collected and why, and we process it on your instructions as a processor or service provider. If you join a workspace someone else owns, that workspace's owner can see your membership, role and activity in it.
| Purpose | Basis |
|---|---|
| Provide the service: sign-in, workspaces, analysis, recommendations, reports | Performance of our contract with you |
| Connect to an advertising platform and read your account data | Your explicit authorization, given through the platform's own consent dialog |
| Transactional email: verification, invitations, password reset, service notices | Performance of our contract |
| Security, abuse prevention, audit, incident investigation | Our legitimate interest in operating a secure service, and legal obligations |
| Billing, entitlements and quota enforcement | Performance of our contract; legal obligation for financial records |
| Improving Rigel's benchmarks and recommendation quality | Our legitimate interest — using aggregated, de-identified statistics only, never one customer's data to advise a competitor |
We do not use your advertising data for automated decision-making that produces legal or similarly significant effects on individuals. Recommendations are advisory and require a human to accept them.
Rigel uses no advertising cookies and no third-party analytics. What we do set:
| Name | Purpose | Lifetime |
|---|---|---|
__Host-rigel_sso | Single sign-on across the Rigel applications. Host-only, Secure, SameSite=Lax, and validated against our database on every use. It is not an API credential. | 8 hours, no sliding renewal |
| Browser local storage | Holds your API session token so the application can call our API. Cleared on sign-out. | Session lifetime |
We do not sell data. We share it only with the providers needed to run the service:
| Recipient | What for |
|---|---|
| Meta Platforms | The source of your connected advertising data. Requests are made with the token you authorized; approved changes are sent back to your ad account. |
| Microsoft | Delivery of transactional email (verification, invitations, password reset, service notices). |
| [HOSTING PROVIDER] | Hosting and storage of the application and its databases. |
| [PAYMENT PROVIDER] | Payment processing and invoicing, once paid plans are enabled. |
We may also disclose data where legally required, or to protect our rights, safety, or the integrity of the service. If we are ever party to a merger or acquisition, we will give notice before your data becomes subject to a different privacy policy.
No system is perfectly secure. If a breach affects your personal data we will notify you and any required regulator without undue delay.
| Data | Retention |
|---|---|
| Sign-in sessions | 8 hours; expired records purged |
| Verification codes, password-reset and invitation tokens | Minutes to hours, then purged |
| Raw advertising platform responses | 30 days by default, up to 180 depending on plan |
| Normalized campaign metrics | At least 24 months for paying accounts; fine-grained rollups may be trimmed sooner |
| Advertising access tokens | Until you disconnect, revoke access at the platform, or the token expires |
| Account and workspace records | For the life of the account, then deleted per section 10 |
| Audit log | Long-term and append-only; see the note below |
| Invoices and ledger records | Retained as long as financial and tax law requires |
Two categories survive a deletion request. The audit log is append-only by design — it is the record that shows whether anyone misused your data, and it would be worth nothing if it could be edited on request. It holds identifiers, actions and timestamps, not your advertising data or credentials. Financial records are retained because tax law requires it. Everything else is deleted.
You can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to a particular use; or provide it in a portable format. Where we rely on your authorization — the advertising platform connection — you can withdraw it at any time, in Rigel or at the platform, and that withdrawal does not affect processing already carried out.
Much of this is self-service. Your profile and sign-in history are editable in Settings; active sessions can be revoked individually or all at once; a connected ad account can be disconnected from the workspace's Connections page.
For anything else, write to [PRIVACY CONTACT EMAIL]. We respond within 30 days. Deletion is described step by step on our data deletion page.
Depending on where you live you may have additional rights, and a right to complain to your local data protection authority. Ours is [SUPERVISORY AUTHORITY, IF APPLICABLE].
Rigel is operated from [OPERATING COUNTRY], and the providers in section 7 may process data in other countries. Where personal data leaves your jurisdiction we rely on [TRANSFER MECHANISM — e.g. standard contractual clauses].
Rigel is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
We will post any change here and update the date at the top. If a change materially affects how we use your data, we will notify account holders by email before it takes effect.
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[PRIVACY CONTACT EMAIL]