Privacy Policy
Effective date: 2 September 2026
Last updated: 2 September 2026
1. About this Policy
This Privacy Policy describes how Australian Internet Advertising Pty Ltd (ABN 90 166 082 186, trading as "AIA" or "Campaign Brain") collects, holds, uses, discloses, and protects personal information and business data through its Campaign Brain platform (the "Platform"), accessible at campaignbrain.io.
We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), and applicable international standards including the EU General Data Protection Regulation (GDPR) where it applies.
2. Who this Policy applies to
Campaign Brain is a subscription advertising-management platform offered to business customers. A customer subscribes at campaignbrain.io, connects their own advertising accounts, and Campaign Brain manages, reports on, and optimises campaigns within those accounts on the customer's instruction and with the customer's approval.
This Policy describes:
- How we handle data belonging to Campaign Brain customers, being the businesses whose advertising accounts are connected to the Platform
- How we handle the personal information of the individual users who create a Campaign Brain account or sign in with a Google Account
- How we handle data belonging to AIA staff and contractors who operate and support the Platform
- How we interact with third-party platforms including Google, Meta (Facebook and Instagram), Klaviyo, Shopify, and OpenAI
Campaign Brain is available to external customers who are not employees of AIA. A customer connects a Google Ads account by signing in with their own Google Account and granting Campaign Brain access through Google's OAuth consent screen. That grant is voluntary, is limited to the single scope described in Section 5, and can be revoked by the customer at any time from within Campaign Brain or at myaccount.google.com/permissions.
End consumers, meaning people who view or interact with our customers' advertisements, do not interact with the Platform directly. Their personal information is governed by the privacy policies of our customers and of the underlying advertising platforms.
3. What information we collect
3.1 From Campaign Brain customers
- Business name, contact details, and billing information
- The name and email address of each individual user who signs in to the Platform
- Access tokens or credentials granting Campaign Brain permission to manage the customer's Google, Meta, Klaviyo, Shopify, or analytics accounts
- Brand assets including logos, colours, fonts, ad creatives, and copy guidelines
- Historical campaign performance data, audience definitions, and conversion events
3.2 From the Google Ads API
With the customer's authorisation, granted through Google's OAuth consent screen, the Platform reads from and writes to the Google Ads accounts the customer has connected, including:
- Account, campaign, ad group, keyword, and creative metadata
- Performance metrics and conversion data
- Search term reports for the connected accounts
- Budget, bidding, location, and audience settings
The Platform does not access the customer's Gmail, Google Drive, contacts, calendar, or any other Google service. The only Google scope Campaign Brain requests is the Google Ads scope described in Section 5.
3.3 From the Meta Marketing API
With the customer's authorisation, the Platform reads from and writes to the customer's Meta ad account, including:
- Ad account, campaign, ad set, and ad metadata and performance metrics
- Creative assets (images, videos, copy) used in the customer's advertising
- Audience definitions including custom and lookalike audiences
- Pixel and conversion event configuration
- Page and Instagram account references for ad delivery
The Platform does not access the personal Facebook or Instagram profiles of individual users, private messages, friend lists, any non-advertising user content, or the data of individuals who have not interacted with our customers' advertising.
3.4 From Klaviyo and Shopify (via Windsor.ai connectors)
With the customer's authorisation:
- Aggregated email marketing performance metrics
- E-commerce sales totals, order counts, and revenue figures
- Product catalogue information for ad-targeting purposes
3.5 From AIA staff operating the Platform
- Email addresses, names, and authentication tokens
- Email content and attachments sent to Platform aliases (facebookads@, googleads@, ai@, design@) when staff use the Platform via email
- Activity logs recording which user or staff member triggered which campaign change, and when
3.6 Cookies and analytics
The Platform uses essential cookies to maintain authenticated sessions, and basic analytics to monitor uptime and error rates. We do not use advertising cookies on the Platform itself.
4. How we use information
We use the information described above for the following purposes:
- Service delivery: to operate, monitor, and improve the Platform, and to execute advertising-management tasks such as creating, updating, pausing, and reporting on campaigns, at the instruction of the customer or of authorised staff acting on the customer's behalf.
- AI-assisted automation: to draft ad copy, generate creative imagery, summarise performance, and recommend optimisations for the customer's own accounts.
- Customer reporting: to produce performance reports, dashboards, and email summaries delivered to the customer.
- Service improvement: to identify bugs, anomalies, and opportunities to improve the Platform.
- Legal compliance: to meet our obligations under Australian and applicable international law.
We do not sell personal information. We do not use data derived from a customer's connected advertising account for any purpose other than managing and reporting on that same customer's advertising.
5. Google user data and Limited Use
When a customer connects a Google Ads account, Campaign Brain requests a single Google OAuth scope:
https://www.googleapis.com/auth/adwords — See, edit, create, and delete your Google Ads accounts and data.
We request this scope because the Platform's core function is to read the performance of the Google Ads accounts a customer connects and to apply the campaign changes that customer approves. No narrower Google Ads scope exists that permits both the reporting and the campaign management the Platform provides.
What we do with Google user data
- Read campaign, ad group, keyword, ad, search term, budget, and conversion data from the Google Ads accounts the customer has connected
- Create, update, and pause campaigns, ad groups, keywords, and ads within those same accounts, on the customer's instruction or after the customer approves a recommendation
- Produce reports, dashboards, and email summaries for that customer about those same accounts
What we do not do with Google user data
- We do not sell Google user data.
- We do not transfer Google user data to any third party except as necessary to provide or improve the user-facing features of the Platform, for security purposes, or to comply with applicable law.
- We do not use Google user data to serve advertising, including retargeted, personalised, or interest-based advertising.
- We do not use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models. Where task-specific data is sent to an AI provider in order to produce output for that same customer, those providers are contractually prevented from training on it. See Section 6.
- We do not allow humans to read Google user data unless we have the customer's explicit consent to read specific data, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and de-identified for internal operations such as capacity planning.
Campaign Brain's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access
A customer may disconnect a Google Ads account from within the Campaign Brain settings at any time, or revoke Campaign Brain's access directly at myaccount.google.com/permissions. On revocation we stop accessing the account immediately and delete the stored access and refresh tokens for it. Campaign data already used to produce reports is deleted in line with Section 11.
6. AI processing and data handling
The Platform sends limited, task-specific data to third-party AI providers:
- OpenAI: when generating ad creative imagery or drafting ad copy, we send the relevant brief text and any reference images supplied by the customer or by staff on the customer's behalf. OpenAI's data handling is governed by its enterprise data policy. We do not enable training on our prompts or outputs.
- Anthropic (Claude) and Lovable AI (Gemini): used to extract structured intents from incoming emails and to summarise account performance. The minimum necessary text is sent. Training is not enabled.
Where AI providers act as our processors, we have configured them not to use Platform data for model training. AI-generated outputs such as ad copy and images are reviewed and approved before being published to any live ad account.
7. How we store and protect information
- Hosting: the Platform's application backend is hosted on Supabase (managed Postgres and edge functions) and Cloudflare (edge networking and email routing). All data is stored encrypted at rest and transmitted over TLS.
- Access controls: access to customer data is restricted to authenticated users and to authorised AIA staff with assigned permissions. OAuth tokens and service-role keys are stored as encrypted secrets and are never exposed to client-side code.
- Retention: active customer data is retained for the duration of the subscription plus a reasonable period thereafter for legal and business-records purposes, typically seven years per Australian record-keeping requirements. Inbound email attachments are retained for 30 days unless a longer retention period is requested. OAuth tokens are deleted on disconnection or account closure.
- Breach response: in the event of a data breach affecting personal information, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
8. Data sharing and disclosure
We disclose information only as necessary to:
- Authorised AIA staff and contractors under appropriate confidentiality obligations
- The customer themselves, in the form of reports and dashboards covering their own data
- Service providers acting as our processors (Supabase, Cloudflare, Resend, Windsor.ai, OpenAI, Anthropic, Google, Meta) under appropriate data-processing terms
- Government, regulatory, or law-enforcement bodies where required by law
We do not sell, rent, or share data with third parties for their independent marketing purposes.
9. International transfers
Some of our service providers are based outside Australia, including in the United States and the European Union. Where data is transferred internationally, we take reasonable steps to ensure recipients are bound by privacy obligations substantially similar to the Australian Privacy Principles, or that the transfer is otherwise permitted under the Privacy Act.
10. Your rights
If you are a Campaign Brain customer, an AIA staff member, or an individual whose personal information we hold, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate, incomplete, or out of date
- Request deletion of your personal information, subject to legal retention requirements
- Withdraw consent for any processing that depends on consent, including revoking Campaign Brain's access to a connected Google or Meta account
- Lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au) if you believe we have breached the Australian Privacy Principles
To exercise any of these rights, contact us using the details in Section 13.
11. Data deletion instructions
To have personal information or business data deleted, email privacy@aiad.com.au with the subject line "Data deletion request" and include:
- Your name and the entity you represent, if applicable
- The Google Ads customer ID, Meta ad account ID, or other account identifier, if applicable
- A description of the data you wish to be deleted
We will acknowledge the request within 5 business days and complete the deletion, or provide a reason it cannot be completed, within 30 days. Deleting a Campaign Brain account deletes the stored Google and Meta OAuth tokens and the campaign data we hold for that account.
12. Children
The Platform is not directed to or intended for use by individuals under the age of 18, and we do not knowingly collect personal information from children.
13. Contact us
For privacy enquiries, data access requests, or complaints:
Australian Internet Advertising Pty Ltd
ABN 90 166 082 186
Suite 502, 657 Pacific Highway, St Leonards, NSW 2065, Australia
Email: privacy@aiad.com.au
Web: campaignbrain.io
14. Changes to this Policy
We may update this Policy from time to time. The effective date at the top reflects the most recent version. Material changes will be communicated to active customers and posted at campaignbrain.io/privacy.
© 2026 Australian Internet Advertising Pty Ltd. Campaign Brain is a product of Australian Internet Advertising Pty Ltd.