Privacy Policy
Last updated: 2026-09-24
Admetry (the “Service”) is operated by 傳鑑數位有限公司 (Taiwan Business ID 90833047; “we”, “us”). We comply with Taiwan’s Personal Data Protection Act. This policy explains what we collect, how we use and protect it, who we share it with, and how you can exercise your rights. Step-by-step deletion instructions are on our Data Deletion page.
1. Information we collect
- Account information: name, email address, password (stored only as a salted hash), organization name and member role, and two-factor settings. If you sign in with Google or LINE, the basic profile those services share (name, email address, profile picture).
- Data from platforms you connect: read through the authorization or credentials you provide on the Connectors page; see section 2 for exactly what each platform shares.
- Content you upload: CSV/Excel report files and images you submit for creative analysis.
- Billing information: plan, amount, date, transaction and invoice numbers, and the tax ID and email needed to issue e-invoices. Card payments are processed by ECPay; we never receive or store full card numbers.
- Usage and technical data: page views and feature usage (Google Analytics 4, which does not log visitors’ IP addresses), error and performance logs (Sentry), IP address (sign-in and security audit logs), browser and device information.
2. What each connected platform shares and why
On every platform the Service only reads data. It never creates, edits, pauses or deletes your ads, posts, messages or store data. We request read-only scopes wherever the platform offers them, with two exceptions stated plainly: the Google Ads API has a single full-access scope (adwords), which we use only for reporting queries; and the Google Sheets export (drive.file) creates and writes the spreadsheets you export, without access to any other file (older authorizations are an exception; see the table). The data is used only to show performance in your dashboards, reports and alerts, and is visible only within your organization unless you share it as described in section 6.
| Platform | Access and scopes | Data read and how it is used |
|---|---|---|
| Google Ads | Google OAuth (adwords). This is the only scope the Google Ads API offers, so the consent screen shows full management access; Admetry uses it only for reporting queries | The list of Google Ads accounts you can access (including accounts under a manager account) and, for the account you select, campaign, ad group and ad performance (impressions, clicks, cost, conversions, conversion value by date and device) with their names, statuses, ad types and final URLs. Reporting queries only; Admetry never creates, edits or pauses anything. |
| Google Analytics 4 | Google OAuth (analytics.readonly) | Aggregated reports for the GA4 property you specify: sessions, users, page views, engagement rate, conversions and similar metrics by date and channel. |
| Google Search Console | Google OAuth (webmasters.readonly) | Search performance for the site you specify: clicks, impressions, CTR and average position by date, query and page. |
| Google Sheets(匯出/export) | Google OAuth (drive.file, userinfo.email), only if you use the export | Creates and writes only the new spreadsheets you export from Admetry; it cannot open any other file in your Drive. Your Google account email is read only to show which account is connected. If you authorized the export before Admetry narrowed this permission (the consent screen then said Admetry could see and edit all your Google Sheets spreadsheets), that authorization uses the broader spreadsheets scope, although Admetry only writes its export files. To switch to the smaller scope above, remove Admetry's access in your Google Account (myaccount.google.com/connections), export again from the Reports page and, when prompted, reconnect your Google account. |
| Meta Ads | Facebook Login (ads_read) | Performance insights for the ad account you specify (spend, impressions, clicks, conversions, purchases, video and similar metrics) at campaign, ad set or ad level. Read-only; Admetry never creates or edits ads. |
| Facebook Page | Facebook Login (pages_read_engagement, pages_show_list, pages_read_user_content) | Posts of the Page you specify (text, time, link) and their engagement counts (reactions, number of comments, shares). Only comment counts are read, never comment text; Admetry never publishes. Read when you connect and sync, but not yet stored in reports or shown on dashboards (in development). |
| Facebook Login (instagram_basic, instagram_manage_insights, pages_read_engagement) | Media of the Instagram professional account you specify (caption, type, link, time, like and comment counts) and, for the latest 50 posts, reach, views, saves, shares and total interactions. No publishing or comment moderation. Read when you connect and sync, but not yet stored in reports or shown on dashboards (in development). | |
| Threads | Threads authorization (threads_basic, threads_manage_insights) | Your posts (text, type, link, time) and, for the latest 50 posts, views, likes, replies, reposts, quotes and shares. Admetry never publishes or replies. Read when you connect and sync, but not yet stored in reports or shown on dashboards (in development). |
| TikTok Ads | TikTok authorization (permissions set in the TikTok developer portal: advertiser info and reporting, read-only) | Daily campaign reports for the advertisers you authorize (spend, impressions, clicks, CPC, CPM, CTR, conversions). |
| LINE 官方帳號/LINE Official Account | The long-lived channel access token you paste | Follower counts and message delivery statistics (LINE Messaging API insights). Admetry does not send messages on your behalf. Read when you connect and sync, but not yet stored in reports or shown on dashboards (in development). |
| Shopify | Shopify OAuth (read_orders) | Admetry keeps only each order's number, date, amount, currency, order/payment/fulfilment status and item count, to calculate revenue and ROAS. No customer data is kept: names, email addresses, phone numbers, postal addresses and customer IDs are discarded even if the platform returns them. Requests name only the fields needed; if the platform still returns more, only the fields above are kept. Orders that are cancelled, failed or fully refunded at the time of sync are not counted; orders awaiting payment are counted. Orders counted earlier and cancelled or refunded later are not deducted automatically yet, and partially refunded orders count at their original amount. |
| WooCommerce | A REST API key. With one-click authorization Admetry requests Read access only; if you paste a key yourself, create it with Read permission — whatever the key allows, Admetry sends only read (GET) requests to your store | Admetry keeps only each order's number, date, amount, currency, order/payment/fulfilment status and item count, to calculate revenue and ROAS. No customer data is kept: names, email addresses, phone numbers, postal addresses and customer IDs are discarded even if the platform returns them. Requests name only the fields needed; if the platform still returns more, only the fields above are kept. Orders that are cancelled, failed or fully refunded at the time of sync are not counted; orders awaiting payment are counted. Orders counted earlier and cancelled or refunded later are not deducted automatically yet, and partially refunded orders count at their original amount. |
| CYBERBIZ | The API key you provide | Admetry keeps only each order's number, date, amount, currency, order/payment/fulfilment status and item count, to calculate revenue and ROAS. No customer data is kept: names, email addresses, phone numbers, postal addresses and customer IDs are discarded even if the platform returns them. |
| 91APP | The API key you provide | Admetry keeps only each order's number, date, amount, currency, order/payment/fulfilment status and item count, to calculate revenue and ROAS. No customer data is kept: names, email addresses, phone numbers, postal addresses and customer IDs are discarded even if the platform returns them. |
| SHOPLINE | SHOPLINE OAuth (orders.read) | Not yet available. When available: Admetry keeps only each order's number, date, amount, currency, order/payment/fulfilment status and item count, to calculate revenue and ROAS. No customer data is kept: names, email addresses, phone numbers, postal addresses and customer IDs are discarded even if the platform returns them. |
| LINE 廣告/LINE Ads (LAP) | LINE OAuth (ads.read) | Not yet available. When available: ad performance reports (spend, impressions, clicks, conversions). |
3. How we use information
- To provide the Service: consolidate cross-platform performance, build dashboards and reports, run AI analysis and send alerts you set up.
- Billing: subscriptions, payments and e-invoices.
- Security and operations: abuse detection, debugging and reliability.
- Support: answering your questions and requests.
- Product improvement: aggregated, de-identified usage statistics about which features are used.
We do not sell personal information, and we do not use data read from connected platforms for advertising or resale.
4. AI features
The Service’s AI features (insights, natural-language questions, report commentary and creative analysis) are powered by Google’s Gemini API. When you use them, the performance figures and campaign names relevant to your request, the question you type, or the image you submit for analysis are sent to the Gemini API to generate the result. We do not use your data, including data received from Google APIs, to train AI models.
5. Google user data: Limited Use disclosure
Admetry’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide or improve user-facing features that you see and use in Admetry.
- We do not sell it, use it to serve advertisements (including retargeting or personalized ads), or use it to determine credit-worthiness or for lending purposes.
- No person reads it unless we have your affirmative consent for specific data, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data is aggregated and anonymized for internal operations.
- We do not use it to develop, improve or train generalized AI or machine-learning models.
- We transfer it to a third party only when necessary to provide those features (for example the Gemini API in section 4), under the same restrictions.
6. Sharing and service providers
Sharing you set up: if you create a share link for a report or dashboard (links can expire and can be revoked at any time), anyone with the link can view that report’s performance figures without signing in. Scheduled reports and alerts you configure send performance figures to the email, LINE or Telegram recipients or the webhook URL you specify. You choose these recipients; we do not share the data with anyone else.
These service providers help us run the Service and process data only as needed to do so:
- Google Cloud: application hosting and the analytics database (BigQuery), located in Taiwan (asia-east1).
- Supabase: hosted database for accounts, organizations and connection settings (including encrypted platform credentials).
- Google Gemini API: AI features (section 4).
- ECPay: payments and e-invoices.
- Resend: transactional and notification email.
- Sentry: error monitoring.
- Google Analytics 4: website usage analytics.
- LINE, Telegram: only if you enable them, for LINE sign-in and the notifications you configure.
- Cloudflare: DNS and network services for our domain.
Some providers may process data outside Taiwan. We disclose information to authorities only when required by law or a valid legal request, and only to the extent necessary.
7. Storage and security
- All connections use HTTPS (TLS).
- The authorization credentials, tokens and API keys you give Admetry when you connect a platform (including the Google Sheets export authorization) are encrypted with AES-128 (Fernet, with HMAC-SHA256 integrity checks) before they are written to the database. The sign-in tokens created when you sign in to Admetry with Google or LINE are not encrypted this way. Our cloud providers additionally encrypt the database at rest.
- Access is controlled by organization and role, and platform permissions follow least privilege (see section 2 for the exceptions).
8. Retention and deletion
- When you disconnect a platform on the Connectors page, the credentials and tokens we hold for that connection are deleted immediately.
- When you request account deletion you are signed out on every device within 5 minutes and can no longer sign in, whether by password, Google or LINE, and your LINE ID and email address are removed from the notification recipients of the organizations you belong to when you make the request (if that fails, they are removed at the latest when the account is deleted after 30 days); email us within the 30-day grace period to withdraw the request. After the grace period your user account and its linked data (sign-in methods, sessions, organization memberships and two-factor settings) are deleted.
- Connections belong to the organization, not to an individual: deleting your account does not disconnect the organization’s connections, and other members can keep using them. To stop Admetry reading platform data, disconnect on the Connectors page first, or have the organization owner email us as described next.
- An organization owner can email us to delete all of the organization’s connections and imported platform data; we verify the request, carry it out and confirm the result.
- Billing and invoice records are kept for the periods required by Taiwan’s Business Accounting Act (5 years for accounting vouchers, 10 years for books and financial statements).
See the Data Deletion page for step-by-step instructions, including how to remove Admetry’s access in your Google and Meta account settings.
9. Cookies
- Necessary cookies keep you signed in and protect the Service; they cannot be turned off.
- Preference cookies remember your language setting.
- Analytics cookies from Google Analytics 4 help us understand site usage; you can block cookies in your browser or install the Google Analytics Opt-out Browser Add-on.
10. Your rights
Under Article 3 of Taiwan’s Personal Data Protection Act you may request to access or review your personal data, obtain a copy, supplement or correct it, stop its collection, processing or use, and have it deleted. Use the Settings page or email service@c-chienads.com; we will respond within the statutory time limits.
11. Children
The Service is intended for business users aged 18 or over and is not directed to minors. We do not knowingly collect their personal data.
12. Changes to this policy
We will notify you of material changes by email or an in-app notice and update the “Last updated” date above.
13. Contact us
傳鑑數位有限公司 · Taiwan Business ID 90833047
Address: 4F-3, No. 48, Sec. 2, Keelung Rd., Xinyi Dist., Taipei City 110, Taiwan (R.O.C.)
Data protection contact: service@c-chienads.com
This English version is provided for convenience; if it differs from the Traditional Chinese version, the Chinese version prevails.