Privacy policy

In effect from 7 September 2026

How Tomorrow Labs handles personal information in AdHub: what we collect, why we hold it, who else sees it, and what you can make us do about it.

1.Who we are

AdHub is an advertising management platform operated by Tomorrow Labs, a business established in the Republic of South Africa. This policy applies to the AdHub console, the client portal, the free tools at /tools, and the emails and reports we send as part of the service.

It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA). Where this policy uses the words responsible party and operator, they carry POPIA’s meaning — roughly what other laws call a controller and a processor.

2.Whose data, and who answers for it

AdHub holds two different kinds of personal information and our responsibility is not the same for both. Blurring them would send people to the wrong party with their questions, so we set them out separately.

We are the responsible party for the account information, billing records and security logs of the people who sign in to AdHub. If that is you — you sign in to AdHub — everything in this policy applies to you directly, and you can exercise your rights against us.

We are an operator for everything an agency loads into AdHub about its own clients — briefs, contact details, campaign records and creative files. There, the agency is the responsible party and we act on its instructions. If you are a client of an agency that uses AdHub and you want your information corrected or removed, ask the agency: they decide, and we carry it out. We will not act on such a request behind our customer’s back, and we will tell you to go to them rather than leave you waiting.

3.What we collect and why

We collect what the service needs to work, and we have tried to make this table specific enough to be checkable rather than broad enough to cover anything.

CategoryExamplesWhyKept for
Account informationName, work email address, password hash, agency and role, two-factor secret if you enable itTo create your account, sign you in and decide what you may changeFor as long as the account exists, then 90 days
Customer contentBriefs, deals, tasks, creative files, comments, QA checks and client records you enterIt is the service — this is the material AdHub exists to hold and organiseUntil you delete it, or 90 days after the account closes
Connected platform dataCampaign names, budgets, spend, impressions, clicks and conversions pulled from platforms you connectReporting, budget monitoring and the automation rules you configureRolling 25 months, matching the reporting windows the platforms themselves keep
Access tokensOAuth access and refresh tokens for the platforms, trackers and storage you connectTo keep a connection working without asking you to re-authorise dailyUntil you disconnect the integration, which deletes them
Technical and security logsIP address, browser user agent, sign-in times, and an audit record of changes made in the consoleSecurity, abuse prevention, and answering "who changed this budget?"12 months for security logs; audit records are kept for the life of the account
Free tool usageThe UTM links, briefs and pacing figures you type into the tools at /toolsTo return a result. Without an account these stay in your own browser and never reach usNot stored server-side unless you are signed in

We do not collect special personal information as POPIA defines it — health, biometrics, religious or political belief, race, trade union membership or criminal behaviour — and we ask you not to load it into free-text fields such as brief descriptions or task notes.

We do not sell personal information, and we do not share it with third parties for their own marketing.

4.Our grounds for processing

  • Performance of a contract — running your account, holding your briefs and campaigns, taking payment. Without this we cannot provide the service at all.
  • Legitimate interests — security logging, abuse prevention, and the audit record of who changed what. We have weighed these against your interests and consider a tamper-evident record of budget changes to be squarely in the interests of everyone using the account.
  • Consent — marketing email, and connecting a third-party platform. Both are opt-in and both can be withdrawn: unsubscribe, or disconnect the integration in your settings, which deletes the stored tokens.
  • Legal obligation — tax and company records we are required to keep.

5.Who else receives it

Most of the list below is under your control. AdHub talks to an advertising platform, a work tracker or a storage provider only once someone in your account connects it — an account that connects nothing has a much shorter list than this page might otherwise suggest.

Advertising platforms

Connected by you, per platform. AdHub reads campaign, spend and performance data, and writes the campaign changes you make in the console.

RecipientWhat goes to themOptional
Meta (Facebook & Instagram)Campaign management and performance reportingOnly if connected
Google AdsCampaign management and performance reportingOnly if connected
TikTok AdsCampaign management and performance reportingOnly if connected
LinkedIn AdsCampaign management and performance reportingOnly if connected
Snapchat AdsCampaign management and performance reportingOnly if connected
Pinterest AdsCampaign management and performance reportingOnly if connected
X (Twitter) AdsCampaign management and performance reportingOnly if connected

Work trackers

Connected by you. AdHub mirrors briefs and tasks outward only — it never reads your board back into AdHub.

RecipientWhat goes to themOptional
NotionA copy of the brief title, description, deal lines and task listOnly if connected
AsanaA copy of the brief title, description, deal lines and task listOnly if connected
Monday.comA copy of the brief title, description, deal lines and task listOnly if connected
ClickUpA copy of the brief title, description, deal lines and task listOnly if connected
TrelloA copy of the brief title, description, deal lines and task listOnly if connected
JiraA copy of the brief title, description, deal lines and task listOnly if connected

Archive and storage targets

Connected by you. Uploaded creative files are moved to your own storage when your account approaches its quota.

RecipientWhat goes to themOptional
Google DriveCreative files archived out of AdHub's own storageOnly if connected
OneDriveCreative files archived out of AdHub's own storageOnly if connected
DropboxCreative files archived out of AdHub's own storageOnly if connected
BoxCreative files archived out of AdHub's own storageOnly if connected
Amazon S3Creative files archived out of AdHub's own storageOnly if connected

Analytics

Connected by you, and read-only. AdHub pulls aggregate figures by day and campaign tag; it does not read individual visitor records.

RecipientWhat goes to themOptional
Google Analytics 4Aggregate sessions, conversions and revenue by campaignOnly if connected

Service providers we use ourselves

These operate for every account and are not optional. Each is bound by contract to process personal information only on our instructions.

RecipientWhat goes to themOptional
StripeSubscription billing. Card details go to Stripe directly and are never stored by AdHub.Always
Resend / your own SMTP serverTransactional email — invitations, alerts and scheduled reportsAlways
AnthropicThe optional AI features: brief drafting and creative angle extraction. Prompts carry the brief or ad text you asked us to work on.Only if connected
Our hosting and database providerRunning the service and storing your account dataAlways

We will also disclose personal information where the law requires it, or to establish or defend a legal claim. If we are compelled to hand over your data we will tell you, unless we are legally barred from doing so.

6.Where it is processed

Your account data is stored on servers operated by our hosting provider. Several of the service providers listed above operate outside the Republic of South Africa — this is unavoidable for a product built on the advertising platforms’ own APIs, since those platforms are not hosted locally.

Section 72 of POPIA permits such transfers where the recipient is bound by a law, binding rules or a contract that upholds principles substantially similar to POPIA’s. We rely on contractual terms with each provider to meet that standard, and we do not transfer personal information to a provider that will not accept them.

7.How it is protected

  • Traffic between you and the service is encrypted in transit (TLS).
  • Passwords are stored as salted hashes. We cannot read your password, and neither can anyone who obtains the database.
  • OAuth tokens for your connected platforms are encrypted at rest with a key held in the deployment environment, not in the database. A stolen database backup does not hand anyone your ad accounts.
  • Two-factor authentication is available on every account and we recommend enabling it, particularly for owner and admin roles.
  • Every account is scoped to its agency at the query level, and client users are additionally scoped to their own client record.
  • Changes to budgets, campaign status and account settings are written to an audit log.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information we will notify you and the Information Regulator as section 22 of POPIA requires, in writing and as soon as reasonably possible after establishing the scope.

8.How long we keep it

Retention periods are listed per category in clause 3. In general: we keep customer content until you delete it or for 90 days after an account closes, whichever comes first; security logs for 12 months; and financial records for the period our tax obligations require.

Deleting an integration deletes its stored tokens immediately. Deleting a brief, campaign or client removes it from the service; residual copies may persist in encrypted backups for up to 30 days before they age out.

9.Your rights

If we are the responsible party for your information — see clause 2 — you have the following rights, and exercising them costs nothing and will not affect your account.

RightWhat it means
AccessAsk what personal information we hold about you and be given a record of it.
CorrectionHave information that is inaccurate, misleading or out of date corrected.
DeletionHave information deleted where we no longer have grounds to keep it. Records we must keep for tax or legal reasons are the exception, and we will say so.
ObjectionObject to processing carried out on the basis of our legitimate interests.
Direct marketingTell us to stop sending marketing at any time. Service and security emails are not marketing and continue.
ComplaintComplain to the Information Regulator. You do not have to come to us first, though it is usually faster.

Write to privacy@tomorrowlabs.co.za. We will respond within 30 days. We may ask you to confirm your identity first — not as an obstacle, but because handing someone else’s data to whoever asks for it is the failure this whole policy exists to prevent.

10.Children

AdHub is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child’s information has reached us, tell us and we will delete it.

11.Cookies and the free tools

The console sets a session cookie when you sign in, and a small number of preference cookies. These are strictly necessary — the service cannot keep you signed in without them — so they are not subject to an opt-in banner.

The free tools at /tools work without an account. When you are not signed in, what you type into them stays in your own browser’s storage and is never sent to us. Signing in is what moves that history onto our servers, and it is entirely your choice.

The public tool pages may display advertising from a third-party ad network, which sets its own cookies under its own policy. Advertising never appears inside the console.

12.Changes to this policy

When we change this policy we change the effective date at the top. For a change that materially reduces your rights or widens what we do with your information, we will tell account owners by email at least 14 days before it takes effect, rather than relying on you to re-read the page.

13.Contacting us and the Regulator

Questions, requests and complaints: privacy@tomorrowlabs.co.za.

You have the right to complain to the supervisory authority, and you do not have to raise it with us first:

Information Regulator (South Africa)

enquiries@inforegulator.org.za · https://inforegulator.org.za/