Privacy Policy

last updated:

Spend Back AI LLC (d/b/a "SpendBack")
Effective Date: July 6, 2026
Last Updated: July 6, 2026

Spend Back AI LLC (d/b/a "SpendBack") Effective Date: July 6, 2026 Last Updated: July 6, 2026

Spend Back AI LLC ("SpendBack," "we," "us," or "our") provides AI-powered advertising and vendor spend auditing and recovery services (the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the Services and our website at spendback.ai (the "Site"), and describes the privacy rights available to you.

We serve clients and their end users globally. Where required, additional region-specific terms (for example, for the European Economic Area, the United Kingdom, and California) are set out below and control in the event of a conflict.

1. Our Role in Data Processing

Our role depends on the context:

  • As a service provider / processor. When we perform audit and recovery Services for a business client (a "Client"), including through our click-tracking pixel and related infrastructure deployed on that Client's advertising properties, we process data on behalf of and under the instructions of that Client. The Client is the controller (or business) responsible for that data. Our processing is governed by our agreement and any Data Processing Addendum with that Client.

  • As a controller. When you visit our Site, contact us, or register for an account, we act as the controller of that information and process it as described in this Policy.

If you are an end user (for example, a visitor to a Client's website) and have questions about how your data is handled, please contact the relevant Client in the first instance; we will support them in responding.

2. Information We Collect

2.1 Click-Tracking and Pixel Data (Audit Services)

To perform advertising audits, we deploy first-party click-tracking technology on Client properties. This technology captures event-level signals only and is designed not to capture directly identifying personal information. The data points collected include:

  • Click and event identifiers (including a first-party click-tracking cookie/identifier)

  • IP address and approximate location derived from it

  • Device, browser, and operating-system information

  • Timestamps and click/session event data

  • Advertising campaign parameters passed through ad URLs (for example, click IDs such as gclid/gbraid/wbraid and campaign, ad group, keyword, placement, network, device, and match-type parameters)

  • Referring and destination URLs

2.2 Audit and Billing Data

To audit spend and pursue recoveries, we access advertising, cloud, vendor, and related billing and usage data through credentials, tokens, or API connections that a Client authorizes. This may include account-level spend, invoices, usage records, and platform billing data.

2.3 Data Obtained from Advertising Platform APIs (Google, Meta, TikTok, and Others)

With a Client's authorization, we connect to advertising and vendor platforms — including the Google Ads API, Meta Marketing API, and TikTok Marketing API — via OAuth or platform credentials to perform the Services. In connection with these integrations:

  • What we access. Advertising account data authorized by the Client, such as account identifiers, campaign, ad group, ad and keyword settings, spend, billing and invoice data, delivery and performance metrics, and related reporting data. We request only the minimum scopes needed to provide the Services.

  • How we use it. Solely to provide and improve the audit and recovery Services for the authorizing Client — reconciling billed spend, identifying invalid or non-compliant charges, generating audit findings and evidence, and pursuing corrections, credits, and refunds. We do not use platform data for advertising, retargeting, or ad targeting; we do not use it to build profiles unrelated to the Services; and we do not use it to determine creditworthiness or for lending purposes.

  • How we store it. Platform data and OAuth tokens are stored on secured servers, encrypted in transit (HTTPS/TLS) and at rest, with access restricted to authorized personnel who need it to provide the Services.

  • How we share it. Only with sub-processors performing the Services on our behalf under confidentiality and data-protection obligations, with the relevant platform or vendor as needed to pursue recoveries on the Client's behalf, or as required by law. We do not sell platform data or transfer it to data brokers or advertising platforms for their own purposes.

  • Revoking access. Clients may revoke our access at any time through the relevant platform's security or business settings (for example, Google Account permissions, Meta Business Settings, or TikTok for Business settings) or by contacting us at privacy@spendback.ai.

Google user data. When a Client connects a Google Ads account, we receive an OAuth refresh token and the connecting Google account email via the Google Ads API scope the Client authorizes. We use this access solely to provide invalid-traffic auditing and spend-recovery services. Tokens are stored encrypted at rest, are never accessible from the browser, and are shared only with the contracted auditing provider described in "How We Share Information" (Section 6). When an account is disconnected, stored tokens are deleted automatically; access can also be revoked at any time from the Google Account permissions page (myaccount.google.com/permissions).

Meta Platform Data. When a Client connects a Meta (Facebook) ad account, we receive a long-lived access token and basic account identifiers via the ads_read permission the Client authorizes. We use this access solely to provide invalid-traffic auditing and spend-recovery services. Tokens are stored encrypted at rest, are never accessible from the browser, and are shared only with the contracted auditing provider described in Section 6. Meta access tokens expire automatically after approximately 60 days; when an account is disconnected, stored tokens are deleted immediately. Access can also be revoked at any time in Facebook settings under Business Integrations. To request deletion of your data, see Section 8 of this Policy.

Google API Services — Limited Use. SpendBack's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2.4 Account and Contact Data

When you register, request a demo, or contact us, we collect information such as name, business email, company name, role, and the contents of your communications.

2.5 Site Usage Data and Cookies

When you use our Site, we automatically collect usage data (IP address, device/browser type, pages viewed, session statistics) through cookies and similar technologies. See Section 5.

3. How We Use Information

We use information to:

  • Provide, operate, and improve the Services, including auditing spend and identifying and pursuing recoveries

  • Deploy and operate click-tracking and detect invalid, non-compliant, or overcharged activity

  • Communicate with Clients and users, provide support, and send service and administrative messages

  • Maintain the security and integrity of the Services and prevent fraud and abuse

  • Comply with legal obligations and enforce our agreements

  • With a lawful basis or where permitted, develop and improve our models and features using aggregated and de-identified insights that do not identify any individual, Client, or end user

We do not use the audit data of one Client to benefit another Client in any way that identifies the source.

4. Legal Bases for Processing (EEA/UK)

Where the GDPR or UK GDPR applies and we act as a controller, we rely on: (a) legitimate interests (operating and securing the Services, analytics, and business operations); (b) consent (for example, for certain cookies and marketing); (c) contract (to provide Services you or your organization request); and (d) legal obligation. Where we act as a processor, the Client is responsible for establishing the lawful basis and obtaining any required consents.

5. Cookies and Similar Technologies

We and our service providers use cookies and similar technologies, including:

  • Essential cookies required for click-tracking and core functionality (for example, a first-party click-tracking identifier that expires after approximately 30 days).

  • Analytics cookies used to understand and improve performance (these may anonymize IP addresses).

  • Advertising/measurement cookies used to attribute and analyze campaign activity.

On first visit we present a cookie notice. Where required by law, we obtain consent before setting non-essential cookies. You can manage preferences through our cookie tool and your browser settings. Disabling certain cookies may affect functionality.

6. How We Share Information

We share information with:

  • Service providers and sub-processors that perform audit, recovery, hosting, analytics, and support functions on our behalf, under contractual confidentiality and data-protection obligations. These providers are authorized to use the data only to provide services to us.

  • Advertising platforms, cloud providers, vendors, and other in-scope counterparties, solely as required to perform audits and pursue recoveries on a Client's behalf.

  • Legal and safety recipients, where required to comply with law, respond to lawful requests, or protect rights, safety, and property.

  • Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

To deliver the auditing and recovery Services, we share connected ad-account data and the access credentials a Client authorizes (OAuth tokens) with our contracted click-fraud auditing provider, which processes them on our behalf under a data-processing agreement, solely to perform audits, pursue refund and credit claims, and, where enabled and approved by the Client, apply protective invalid-traffic exclusions.

We do not sell personal information for money. Please also review Section 9 regarding "sharing" for cross-context behavioral advertising under California law.

7. International Data Transfers

We operate globally and may transfer, store, and process information in the United States and other countries whose laws may differ from those in your jurisdiction. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.

8. Data Deletion, Retention, and Security

Requesting deletion. You may request deletion of your data at any time by emailing privacy@spendback.ai with the subject "Data Deletion Request." We will confirm receipt and complete verified deletion requests within 30 days, except where retention is required by law. You may also disconnect our access to your advertising accounts at any time through the relevant platform's settings (for example, Google Account permissions, Meta Business Settings, or TikTok for Business settings); upon disconnection we cease collecting new data from that platform. Connected-account access credentials are deleted automatically when you disconnect the account from your dashboard.

We retain personal information only as long as necessary for the purposes described here, to provide the Services, and to comply with legal obligations, after which we delete or de-identify it. When we act as a processor, we delete or return Client and end-user data in accordance with our agreement with the Client (generally within 30 days of termination, unless retention is legally required).

We maintain administrative, technical, and physical safeguards designed to protect information. We engage service providers that maintain industry-recognized security standards (including SOC 2 Type II or equivalent). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to: (a) know/access the categories and specific pieces of personal information we collect; (b) delete personal information; (c) correct inaccurate personal information; (d) opt out of the "sale" or "sharing" of personal information; and (e) limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.

Notice at collection. In the past 12 months we may collect the category "Internet or other electronic network activity information" (for example, click and device data) and identifiers, as described in Section 2. We do not sell personal information for money; certain analytics/advertising cookies may constitute "sharing" for cross-context behavioral advertising, which you can opt out of via our "Your Privacy Choices" control.

To exercise rights, contact us at privacy@spendback.ai. You may use an authorized agent. We will verify your request as required by law.

10. EEA/UK Privacy Rights (GDPR)

Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority. Where we process your data as a processor for a Client, please direct requests to that Client; we will assist them.

11. Other U.S. State Rights

Residents of states including Virginia, Colorado, Connecticut, and Utah may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising, sale, and certain profiling. To exercise these rights, contact privacy@spendback.ai.

12. Children's Privacy

The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last Updated" date and, where required, provide additional notice.

14. Contact Us

Spend Back AI LLC (d/b/a SpendBack) 7901 4th St N, Ste 300, Saint Petersburg, FL 33702, USA Email: privacy@spendback.ai

LET’S GET STARTED

Ready to Get Your $pend Back?

Link your accounts to see what we can recover from PAST spending and secure FUTURE budget protection.