Effective Date: June 25, 2026
Last Updated: June 25, 2026
1. Introduction
Cass ("we," "us," "our") respects your privacy. This Privacy Policy explains what personal data and business data we collect, why we collect it, how we use it, and what rights you have when you use Cass, our website, application, integrations, communication workflows, and paid plans (together, the "Service").
Data Controller:
Marek Dąbrowski, conducting business as AdLume
NIP: 1133071063
ul. Stawki 2a/38, 00-193 Warsaw, Poland
Email: hello@heycass.co
This Policy is intended to support compliance with the General Data Protection Regulation (GDPR) (EU 2016/679), applicable Polish data protection law, and other privacy rules that may apply to our users.
This Policy does not replace any data processing agreement, platform-specific terms, or additional agreement we may sign with business customers.
2. Data We Collect
2.1 Account and Profile Data
When you create an account, buy a plan, contact us, or use the Service, we may collect:
- name;
- email address;
- company, project, or business name;
- role or team information;
- login and authentication data;
- password credentials where applicable, stored in hashed form;
- settings, preferences, and plan details.
2.2 Payment and Billing Data
Payments are processed by Stripe. We do not store your full credit card number. We may receive:
- customer ID and payment status;
- plan, subscription, renewal, refund, and transaction details;
- billing name, billing email, billing address, country, tax status, and VAT or tax information where applicable;
- invoices, receipts, and payment history.
2.3 Connected Ad, Analytics, Marketing, and Ecommerce Data
When you connect or authorize third-party accounts, the Service may access and process data from supported tools such as Google Ads, GA4, Search Console, Google Tag Manager, Google Merchant Center, LinkedIn Ads, Microsoft Ads, Amazon Ads, X Ads, Snapchat Ads, Shopify, Klaviyo, and similar tools. Meta Ads is currently marked as planned or coming soon unless explicitly enabled for your account.
Depending on the integration and permissions you approve, this may include:
- account identifiers, account names, workspace names, and account hierarchy data;
- campaign names, settings, structure, status, budgets, bids, audiences, keywords, search terms, placements, assets, creatives, and targeting data;
- performance metrics such as impressions, clicks, spend, conversions, revenue, CPA, ROAS, CTR, conversion rate, and similar metrics;
- analytics, attribution, conversion, tracking, tag, event, and landing page context;
- ecommerce, product, order, customer journey, email marketing, or CRM-style data where connected and necessary for the Service;
- historical decisions, recommendations, approvals, scopes, actions, logs, and outputs generated by or through the Service.
We do not ask for your Google password or other third-party account passwords. Where available, access is granted and revoked through the provider's OAuth, API, workspace, or authorization system.
2.4 Communication Tool Data
If you use Cass inside Slack, Teams, Telegram, WhatsApp, Twilio/SMS, or another supported communication tool, we may process:
- workspace, channel, chat, or phone identifiers;
- user names, handles, profile information, and team information made available by the communication provider;
- messages, commands, approvals, files, and interaction history related to the Service;
- timestamps, delivery status, and operational metadata.
2.5 AI Input and Output Data
To provide AI-powered analysis and recommendations, we may process:
- prompts, instructions, business context, connected account data, and user messages;
- AI-generated summaries, recommendations, plans, explanations, tasks, and proposed actions;
- feedback, approvals, rejections, corrections, and operating scope decisions.
We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI model providers.
2.6 Usage, Device, and Technical Data
We may automatically collect:
- pages, features, buttons, and workflows used;
- session duration, frequency, referring pages, and conversion events;
- browser type, device type, operating system, IP address, approximate location, language, and time zone;
- logs, diagnostics, error reports, security events, and performance data.
2.7 Website, Analytics, and Marketing Data
We may use analytics, advertising, and tracking tools such as GA4, PostHog, Meta Pixel, and similar tools to understand website usage, improve the Service, measure campaigns, and support marketing. Depending on your settings and consent requirements, this may include cookies, pixels, device identifiers, event data, page views, referral data, and campaign attribution.
If you subscribe to our newsletter or marketing communications, we may process your email address, preferences, sign-up source, campaign engagement, and related metadata through MailerLite.
2.8 Support and Communications Data
If you contact us by email, chat, form, social media, or another channel, we may retain the content of that communication, related metadata, and any follow-up actions.
3. How We Use Your Data
We use data to:
- create and manage your account;
- provide, personalize, secure, maintain, and improve the Service;
- connect to and process data from tools you authorize;
- generate AI-powered recommendations, summaries, plans, alerts, and approved actions;
- run recurring or scheduled tasks within approved operating scopes;
- process payments, renewals, refunds, invoices, taxes, and billing support;
- send transactional messages, service notices, security alerts, billing messages, and support replies;
- send marketing communications where allowed by law or consent;
- measure website, product, and campaign performance;
- detect, prevent, and investigate fraud, abuse, unauthorized access, security incidents, and policy violations;
- comply with legal, accounting, tax, platform, and regulatory obligations;
- enforce our Terms of Use and protect our rights.
We do not sell your personal data.
4. Legal Bases for Processing
For users in the EU/EEA, UK, or other jurisdictions with similar legal basis requirements, we rely on the following bases:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Service | Account data, connected tool data, communication data, AI inputs/outputs | Contract performance (Art. 6(1)(b)) |
| Payments, renewals, refunds, invoicing | Payment and billing data | Contract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Product security, abuse prevention, logs | Usage, technical, security data | Legitimate interests (Art. 6(1)(f)) |
| Product improvement and internal analytics | Usage data, feature data, support data | Legitimate interests (Art. 6(1)(f)) or consent where required |
| Website analytics and advertising pixels | Cookies, event data, attribution data | Consent where required; legitimate interests where allowed |
| Marketing emails | Email, preferences, engagement data | Consent (Art. 6(1)(a)) or legitimate interests where allowed for existing customer communications |
| Legal, tax, accounting, compliance | Billing, contracts, support, logs | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
5. Third-Party Services and Processors
We use third-party service providers to operate the Service. They process data only for the purposes we authorize and subject to their own contracts, policies, and applicable law.
| Provider / Category | Purpose | Notes |
|---|---|---|
| Google services | Google Ads, GA4, Search Console, GTM, Merchant Center, OAuth/API access, analytics where enabled | May involve processing in the USA or other regions |
| OpenAI | AI model inference and analysis | Used to generate recommendations and outputs |
| Stripe | Payments, subscriptions, refunds, invoices, tax and billing support | Payment card data is handled by Stripe |
| MailerLite | Email marketing and newsletter communications | Used for opted-in or permitted email communications |
| Slack, Microsoft Teams, Telegram, WhatsApp, Twilio | Communication workflows, approvals, alerts, messages, and notifications | Only where enabled or connected |
| Ad and marketing platforms such as LinkedIn Ads, Microsoft Ads, Amazon Ads, X Ads, Snapchat Ads, Shopify, Klaviyo | Connected account analysis, recommendations, and actions where supported | Scope depends on authorization and plan |
| Analytics and advertising tools such as GA4, PostHog, Meta Pixel | Website/product analytics, attribution, performance measurement, remarketing where enabled | Consent may be required depending on jurisdiction |
| Cloudflare | Public website hosting, delivery, DNS, security, and related web infrastructure | Used for the public website |
| Railway | Application/backend hosting, database/storage, logs, secrets, and related infrastructure | Hosted in Amsterdam, Netherlands, according to current launch information |
6. Google API and Google Ads Data Notice
When you connect Google services, our use and transfer of data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.
We use Google user data only to provide and improve user-facing features of the Service, including account analysis, recommendations, approved actions, reporting, monitoring, support, and security.
We do not use Google user data for:
- selling to third parties;
- advertising unrelated third-party products;
- training general-purpose AI models outside the Service;
- determining creditworthiness, lending, employment, housing, insurance, or other sensitive eligibility decisions.
We do not share Google Ads data except as needed to provide the Service, comply with law, protect security, or as described in this Policy.
You may revoke Google access through your Google Account settings or through the Service where supported.
7. AI Providers and Model Training
We may send relevant prompts, business context, account data, and user instructions to AI model providers such as OpenAI to generate outputs for the Service.
We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI providers.
Your connected account data is not intentionally used to train general AI models for unrelated third-party use. Where an AI provider offers enterprise, API, or business data controls, we aim to use configurations that restrict provider training on customer data.
AI outputs may be incomplete, inaccurate, or inappropriate for your specific situation. Our Terms of Use explain your responsibility for reviewing, approving, and monitoring recommendations and automated actions.
8. International Data Transfers
We are based in Poland, but some providers and connected platforms may process data outside the EU/EEA, including in the United States.
Where required, we rely on appropriate transfer mechanisms such as:
- Standard Contractual Clauses approved by the European Commission;
- adequacy decisions;
- provider data processing terms and transfer safeguards;
- other legally recognized transfer mechanisms.
Details of applicable transfer mechanisms are available on request where required by law.
9. Data Retention
We keep data only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Type | Typical Retention |
|---|---|
| Account and profile data | While your account is active and for up to 2 years after closure or last activity, unless earlier deletion is required or requested |
| Connected ad, analytics, marketing, ecommerce, and communication data | While needed to provide the Service; typically deleted or de-identified within 30 days after account closure or revocation, unless needed for security, legal, billing, or dispute purposes |
| AI inputs, outputs, recommendations, approvals, and action logs | While needed to provide history, auditability, support, security, and product improvement; typically up to 24 months unless otherwise agreed |
| Payment, invoice, tax, and accounting records | As required by Polish accounting and tax law, typically 5 years or longer if required |
| Website and product analytics | Typically up to 24 months, unless configured differently or anonymized |
| Marketing email data | Until you unsubscribe or request deletion, subject to suppression lists and legal recordkeeping |
| Support and email communications | Typically up to 3 years, unless needed for legal, security, or dispute purposes |
| Security logs and technical diagnostics | Typically up to 24 months, unless needed for investigation or compliance |
If you request deletion, we will delete or anonymize eligible data unless retention is required for legal, billing, security, fraud prevention, dispute resolution, or legitimate business purposes.
10. Cookies and Tracking
We use cookies and similar technologies to:
- keep you signed in;
- secure the Service;
- remember preferences;
- understand website and product usage;
- measure marketing campaigns;
- support analytics, attribution, and advertising where enabled.
Types of cookies and similar technologies may include:
| Type | Purpose |
|---|---|
| Essential | Authentication, security, session management, checkout, and core functionality |
| Analytics | Product and website usage analysis, diagnostics, performance measurement |
| Marketing / advertising | Attribution, remarketing, campaign measurement, audience building where allowed |
| Preferences | Remembering settings and interface choices |
Where required by law, we ask for consent before using non-essential cookies or tracking technologies. You can also manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.
11. Your Rights
Depending on where you live, you may have rights to:
- access personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict or object to certain processing;
- receive a copy of your data in a portable format;
- withdraw consent where processing is based on consent;
- opt out of marketing communications;
- complain to a data protection authority.
To exercise your rights, contact us at hello@heycass.co.
If you are in the EU/EEA and are not satisfied with our response, you may lodge a complaint with the Polish Data Protection Authority (UODO): https://uodo.gov.pl.
12. Marketing Communications
You may unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting hello@heycass.co.
We may still send transactional or service-related messages, including account, billing, security, integration, policy, and support messages.
13. Security
We use technical and organizational measures designed to protect data, including:
- encrypted transport for production traffic;
- OAuth and provider authorization flows where available;
- access controls for production systems;
- separation of customer data where technically supported;
- avoiding logging raw credentials, OAuth tokens, API keys, and sensitive payloads where possible;
- security monitoring, backups, and operational safeguards appropriate to the stage of the Service.
No system is 100% secure. If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority where required by law.
14. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor, we will delete it where required.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice by email, in-app message, website notice, or another appropriate method.
The current version is available at https://heycass.co/privacy.
16. Contact
For privacy questions or rights requests:
Marek Dąbrowski, conducting business as AdLume
ul. Stawki 2a/38, 00-193 Warsaw, Poland
NIP: 1133071063
Email: hello@heycass.co
Website: https://heycass.co
This Privacy Policy was last reviewed on June 25, 2026.