Privacy Policy
Effective August 7, 2026
NovaAds is an AI-run advertising service operated by Organic Skin Care Store Inc (“we”, “us”). It builds and manages Facebook and Instagram lead-generation campaigns in a business customer’s own Meta ad account. This policy explains what we collect, why, and the choices available to users. Questions can be sent to dave@ilift.com.
What we collect
- Account data — email address, sign-in records, notification preferences, and the business profile, website, service area, category, and offer details a customer provides or approves.
- Meta Platform Data — the connected Meta user, ad account, and Page identifiers; encrypted access tokens; campaign structure and delivery metrics such as spend, impressions, clicks, and cost per lead; and lead-form submissions such as name, email address, and phone number.
- Billing data — Stripe handles payment details. NovaAds stores subscription and invoice status but does not see or store full card numbers.
- Service data — actions, settings, security events, and technical logs needed to operate, protect, and troubleshoot the service.
How we use data
- Build, launch, and optimize campaigns within the budget caps and controls the customer sets. Campaigns are created paused and activate only after explicit approval.
- Deliver leads to the customer’s inbox and send requested email or optional SMS notifications and confirmations.
- Provide the dashboard, reports, activity records, billing, support, and security.
- Generate campaign strategy, copy, and creative. NovaAds excludes lead contact details, Meta access tokens, and connected-user IDs from AI prompts.
Meta Platform Data
We use Meta APIs under the Meta Platform Terms and act only on the ad account and Page the customer selects. Access tokens are encrypted. A customer can disconnect Meta from Settings at any time; NovaAds then removes the vaulted NovaAds Meta credentials, marks the connection disconnected, and stops campaign management. A Meta user can also use Meta’s data-deletion flow. Our signed callback removes that user’s credentials and connection reference and returns a confirmation-code status page.
Lead submissions belong to the business whose form collected them. A connected Meta user’s deletion callback does not erase that business’s lead book, because those leads came from other people. A business can request deletion of its account data and leads using the contact below.
Sharing and subprocessors
We share data only with providers needed to operate NovaAds, under contractual privacy and security commitments. Our Subprocessor List names each provider, its purpose, the data categories it receives, its processing location, and whether it receives Meta Platform Data. We do not sell personal information or share leads between customers.
Public-authority requests
We require legal review, challenge unlawful or overbroad requests, minimize any legally required disclosure, and document the request, reasoning, reviewers, and response. Our Government Data Request Policy describes these controls. We seek permission to notify affected users unless law prohibits notice or an emergency makes notice unsafe.
Retention and deletion
We retain account, campaign, and lead data while the business account is active and as needed to provide the service, resolve disputes, secure the platform, and meet legal or accounting duties. Disconnecting Meta removes NovaAds Meta credentials but does not close the NovaAds account. To close an account or request deletion, email dave@ilift.com. After we verify the request and the requester’s authority, we delete or de-identify data that is not subject to a legal retention requirement.
Security and international processing
We use access controls, encrypted credential storage, signed webhooks, and activity records to protect data. NovaAds’s primary application, database, and job-processing infrastructure is in the United States. Provider-specific locations appear in the Subprocessor List.
Changes
We will post material changes on this page and update the effective date. We review the processor list before allowing a new provider to receive Meta Platform Data.