Privacy policy
In effect from 7 September 2026
How Tomorrow Labs handles personal information in AdHub: what we collect, why we hold it, who else sees it, and what you can make us do about it.
1.Who we are
AdHub is an advertising management platform operated by Tomorrow Labs, a business established in the Republic of South Africa. This policy applies to the AdHub console, the client portal, the free tools at /tools, and the emails and reports we send as part of the service.
It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA). Where this policy uses the words responsible party and operator, they carry POPIA’s meaning — roughly what other laws call a controller and a processor.
2.Whose data, and who answers for it
AdHub holds two different kinds of personal information and our responsibility is not the same for both. Blurring them would send people to the wrong party with their questions, so we set them out separately.
We are the responsible party for the account information, billing records and security logs of the people who sign in to AdHub. If that is you — you sign in to AdHub — everything in this policy applies to you directly, and you can exercise your rights against us.
We are an operator for everything an agency loads into AdHub about its own clients — briefs, contact details, campaign records and creative files. There, the agency is the responsible party and we act on its instructions. If you are a client of an agency that uses AdHub and you want your information corrected or removed, ask the agency: they decide, and we carry it out. We will not act on such a request behind our customer’s back, and we will tell you to go to them rather than leave you waiting.
3.What we collect and why
We collect what the service needs to work, and we have tried to make this table specific enough to be checkable rather than broad enough to cover anything.
| Category | Examples | Why | Kept for |
|---|---|---|---|
| Account information | Name, work email address, password hash, agency and role, two-factor secret if you enable it | To create your account, sign you in and decide what you may change | For as long as the account exists, then 90 days |
| Customer content | Briefs, deals, tasks, creative files, comments, QA checks and client records you enter | It is the service — this is the material AdHub exists to hold and organise | Until you delete it, or 90 days after the account closes |
| Connected platform data | Campaign names, budgets, spend, impressions, clicks and conversions pulled from platforms you connect | Reporting, budget monitoring and the automation rules you configure | Rolling 25 months, matching the reporting windows the platforms themselves keep |
| Access tokens | OAuth access and refresh tokens for the platforms, trackers and storage you connect | To keep a connection working without asking you to re-authorise daily | Until you disconnect the integration, which deletes them |
| Technical and security logs | IP address, browser user agent, sign-in times, and an audit record of changes made in the console | Security, abuse prevention, and answering "who changed this budget?" | 12 months for security logs; audit records are kept for the life of the account |
| Free tool usage | The UTM links, briefs and pacing figures you type into the tools at /tools | To return a result. Without an account these stay in your own browser and never reach us | Not stored server-side unless you are signed in |
We do not collect special personal information as POPIA defines it — health, biometrics, religious or political belief, race, trade union membership or criminal behaviour — and we ask you not to load it into free-text fields such as brief descriptions or task notes.
We do not sell personal information, and we do not share it with third parties for their own marketing.
4.Our grounds for processing
- Performance of a contract — running your account, holding your briefs and campaigns, taking payment. Without this we cannot provide the service at all.
- Legitimate interests — security logging, abuse prevention, and the audit record of who changed what. We have weighed these against your interests and consider a tamper-evident record of budget changes to be squarely in the interests of everyone using the account.
- Consent — marketing email, and connecting a third-party platform. Both are opt-in and both can be withdrawn: unsubscribe, or disconnect the integration in your settings, which deletes the stored tokens.
- Legal obligation — tax and company records we are required to keep.
5.Who else receives it
Most of the list below is under your control. AdHub talks to an advertising platform, a work tracker or a storage provider only once someone in your account connects it — an account that connects nothing has a much shorter list than this page might otherwise suggest.
Advertising platforms
Connected by you, per platform. AdHub reads campaign, spend and performance data, and writes the campaign changes you make in the console.
| Recipient | What goes to them | Optional |
|---|---|---|
| Meta (Facebook & Instagram) | Campaign management and performance reporting | Only if connected |
| Google Ads | Campaign management and performance reporting | Only if connected |
| TikTok Ads | Campaign management and performance reporting | Only if connected |
| LinkedIn Ads | Campaign management and performance reporting | Only if connected |
| Snapchat Ads | Campaign management and performance reporting | Only if connected |
| Pinterest Ads | Campaign management and performance reporting | Only if connected |
| X (Twitter) Ads | Campaign management and performance reporting | Only if connected |
Work trackers
Connected by you. AdHub mirrors briefs and tasks outward only — it never reads your board back into AdHub.
| Recipient | What goes to them | Optional |
|---|---|---|
| Notion | A copy of the brief title, description, deal lines and task list | Only if connected |
| Asana | A copy of the brief title, description, deal lines and task list | Only if connected |
| Monday.com | A copy of the brief title, description, deal lines and task list | Only if connected |
| ClickUp | A copy of the brief title, description, deal lines and task list | Only if connected |
| Trello | A copy of the brief title, description, deal lines and task list | Only if connected |
| Jira | A copy of the brief title, description, deal lines and task list | Only if connected |
Archive and storage targets
Connected by you. Uploaded creative files are moved to your own storage when your account approaches its quota.
| Recipient | What goes to them | Optional |
|---|---|---|
| Google Drive | Creative files archived out of AdHub's own storage | Only if connected |
| OneDrive | Creative files archived out of AdHub's own storage | Only if connected |
| Dropbox | Creative files archived out of AdHub's own storage | Only if connected |
| Box | Creative files archived out of AdHub's own storage | Only if connected |
| Amazon S3 | Creative files archived out of AdHub's own storage | Only if connected |
Analytics
Connected by you, and read-only. AdHub pulls aggregate figures by day and campaign tag; it does not read individual visitor records.
| Recipient | What goes to them | Optional |
|---|---|---|
| Google Analytics 4 | Aggregate sessions, conversions and revenue by campaign | Only if connected |
Service providers we use ourselves
These operate for every account and are not optional. Each is bound by contract to process personal information only on our instructions.
| Recipient | What goes to them | Optional |
|---|---|---|
| Stripe | Subscription billing. Card details go to Stripe directly and are never stored by AdHub. | Always |
| Resend / your own SMTP server | Transactional email — invitations, alerts and scheduled reports | Always |
| Anthropic | The optional AI features: brief drafting and creative angle extraction. Prompts carry the brief or ad text you asked us to work on. | Only if connected |
| Our hosting and database provider | Running the service and storing your account data | Always |
We will also disclose personal information where the law requires it, or to establish or defend a legal claim. If we are compelled to hand over your data we will tell you, unless we are legally barred from doing so.
6.Where it is processed
Your account data is stored on servers operated by our hosting provider. Several of the service providers listed above operate outside the Republic of South Africa — this is unavoidable for a product built on the advertising platforms’ own APIs, since those platforms are not hosted locally.
Section 72 of POPIA permits such transfers where the recipient is bound by a law, binding rules or a contract that upholds principles substantially similar to POPIA’s. We rely on contractual terms with each provider to meet that standard, and we do not transfer personal information to a provider that will not accept them.
7.How it is protected
- Traffic between you and the service is encrypted in transit (TLS).
- Passwords are stored as salted hashes. We cannot read your password, and neither can anyone who obtains the database.
- OAuth tokens for your connected platforms are encrypted at rest with a key held in the deployment environment, not in the database. A stolen database backup does not hand anyone your ad accounts.
- Two-factor authentication is available on every account and we recommend enabling it, particularly for owner and admin roles.
- Every account is scoped to its agency at the query level, and client users are additionally scoped to their own client record.
- Changes to budgets, campaign status and account settings are written to an audit log.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information we will notify you and the Information Regulator as section 22 of POPIA requires, in writing and as soon as reasonably possible after establishing the scope.
8.How long we keep it
Retention periods are listed per category in clause 3. In general: we keep customer content until you delete it or for 90 days after an account closes, whichever comes first; security logs for 12 months; and financial records for the period our tax obligations require.
Deleting an integration deletes its stored tokens immediately. Deleting a brief, campaign or client removes it from the service; residual copies may persist in encrypted backups for up to 30 days before they age out.
9.Your rights
If we are the responsible party for your information — see clause 2 — you have the following rights, and exercising them costs nothing and will not affect your account.
| Right | What it means |
|---|---|
| Access | Ask what personal information we hold about you and be given a record of it. |
| Correction | Have information that is inaccurate, misleading or out of date corrected. |
| Deletion | Have information deleted where we no longer have grounds to keep it. Records we must keep for tax or legal reasons are the exception, and we will say so. |
| Objection | Object to processing carried out on the basis of our legitimate interests. |
| Direct marketing | Tell us to stop sending marketing at any time. Service and security emails are not marketing and continue. |
| Complaint | Complain to the Information Regulator. You do not have to come to us first, though it is usually faster. |
Write to privacy@tomorrowlabs.co.za. We will respond within 30 days. We may ask you to confirm your identity first — not as an obstacle, but because handing someone else’s data to whoever asks for it is the failure this whole policy exists to prevent.
10.Children
AdHub is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child’s information has reached us, tell us and we will delete it.
12.Changes to this policy
When we change this policy we change the effective date at the top. For a change that materially reduces your rights or widens what we do with your information, we will tell account owners by email at least 14 days before it takes effect, rather than relying on you to re-read the page.
13.Contacting us and the Regulator
Questions, requests and complaints: privacy@tomorrowlabs.co.za.
You have the right to complain to the supervisory authority, and you do not have to raise it with us first:
Information Regulator (South Africa)
enquiries@inforegulator.org.za · https://inforegulator.org.za/