Privacy Policy

Effective Date: June 25, 2026
Last Updated: June 25, 2026


1. Introduction

Cass ("we," "us," "our") respects your privacy. This Privacy Policy explains what personal data and business data we collect, why we collect it, how we use it, and what rights you have when you use Cass, our website, application, integrations, communication workflows, and paid plans (together, the "Service").

Data Controller:
Marek Dąbrowski, conducting business as AdLume
NIP: 1133071063
ul. Stawki 2a/38, 00-193 Warsaw, Poland
Email: hello@heycass.co

This Policy is intended to support compliance with the General Data Protection Regulation (GDPR) (EU 2016/679), applicable Polish data protection law, and other privacy rules that may apply to our users.

This Policy does not replace any data processing agreement, platform-specific terms, or additional agreement we may sign with business customers.


2. Data We Collect

2.1 Account and Profile Data

When you create an account, buy a plan, contact us, or use the Service, we may collect:

2.2 Payment and Billing Data

Payments are processed by Stripe. We do not store your full credit card number. We may receive:

2.3 Connected Ad, Analytics, Marketing, and Ecommerce Data

When you connect or authorize third-party accounts, the Service may access and process data from supported tools such as Google Ads, GA4, Search Console, Google Tag Manager, Google Merchant Center, LinkedIn Ads, Microsoft Ads, Amazon Ads, X Ads, Snapchat Ads, Shopify, Klaviyo, and similar tools. Meta Ads is currently marked as planned or coming soon unless explicitly enabled for your account.

Depending on the integration and permissions you approve, this may include:

We do not ask for your Google password or other third-party account passwords. Where available, access is granted and revoked through the provider's OAuth, API, workspace, or authorization system.

2.4 Communication Tool Data

If you use Cass inside Slack, Teams, Telegram, WhatsApp, Twilio/SMS, or another supported communication tool, we may process:

2.5 AI Input and Output Data

To provide AI-powered analysis and recommendations, we may process:

We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI model providers.

2.6 Usage, Device, and Technical Data

We may automatically collect:

2.7 Website, Analytics, and Marketing Data

We may use analytics, advertising, and tracking tools such as GA4, PostHog, Meta Pixel, and similar tools to understand website usage, improve the Service, measure campaigns, and support marketing. Depending on your settings and consent requirements, this may include cookies, pixels, device identifiers, event data, page views, referral data, and campaign attribution.

If you subscribe to our newsletter or marketing communications, we may process your email address, preferences, sign-up source, campaign engagement, and related metadata through MailerLite.

2.8 Support and Communications Data

If you contact us by email, chat, form, social media, or another channel, we may retain the content of that communication, related metadata, and any follow-up actions.


3. How We Use Your Data

We use data to:

We do not sell your personal data.


4. Legal Bases for Processing

For users in the EU/EEA, UK, or other jurisdictions with similar legal basis requirements, we rely on the following bases:

| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Service | Account data, connected tool data, communication data, AI inputs/outputs | Contract performance (Art. 6(1)(b)) |
| Payments, renewals, refunds, invoicing | Payment and billing data | Contract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Product security, abuse prevention, logs | Usage, technical, security data | Legitimate interests (Art. 6(1)(f)) |
| Product improvement and internal analytics | Usage data, feature data, support data | Legitimate interests (Art. 6(1)(f)) or consent where required |
| Website analytics and advertising pixels | Cookies, event data, attribution data | Consent where required; legitimate interests where allowed |
| Marketing emails | Email, preferences, engagement data | Consent (Art. 6(1)(a)) or legitimate interests where allowed for existing customer communications |
| Legal, tax, accounting, compliance | Billing, contracts, support, logs | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |


5. Third-Party Services and Processors

We use third-party service providers to operate the Service. They process data only for the purposes we authorize and subject to their own contracts, policies, and applicable law.

| Provider / Category | Purpose | Notes |
|---|---|---|
| Google services | Google Ads, GA4, Search Console, GTM, Merchant Center, OAuth/API access, analytics where enabled | May involve processing in the USA or other regions |
| OpenAI | AI model inference and analysis | Used to generate recommendations and outputs |
| Stripe | Payments, subscriptions, refunds, invoices, tax and billing support | Payment card data is handled by Stripe |
| MailerLite | Email marketing and newsletter communications | Used for opted-in or permitted email communications |
| Slack, Microsoft Teams, Telegram, WhatsApp, Twilio | Communication workflows, approvals, alerts, messages, and notifications | Only where enabled or connected |
| Ad and marketing platforms such as LinkedIn Ads, Microsoft Ads, Amazon Ads, X Ads, Snapchat Ads, Shopify, Klaviyo | Connected account analysis, recommendations, and actions where supported | Scope depends on authorization and plan |
| Analytics and advertising tools such as GA4, PostHog, Meta Pixel | Website/product analytics, attribution, performance measurement, remarketing where enabled | Consent may be required depending on jurisdiction |
| Cloudflare | Public website hosting, delivery, DNS, security, and related web infrastructure | Used for the public website |
| Railway | Application/backend hosting, database/storage, logs, secrets, and related infrastructure | Hosted in Amsterdam, Netherlands, according to current launch information |


6. Google API and Google Ads Data Notice

When you connect Google services, our use and transfer of data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

We use Google user data only to provide and improve user-facing features of the Service, including account analysis, recommendations, approved actions, reporting, monitoring, support, and security.

We do not use Google user data for:

We do not share Google Ads data except as needed to provide the Service, comply with law, protect security, or as described in this Policy.

You may revoke Google access through your Google Account settings or through the Service where supported.


7. AI Providers and Model Training

We may send relevant prompts, business context, account data, and user instructions to AI model providers such as OpenAI to generate outputs for the Service.

We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI providers.

Your connected account data is not intentionally used to train general AI models for unrelated third-party use. Where an AI provider offers enterprise, API, or business data controls, we aim to use configurations that restrict provider training on customer data.

AI outputs may be incomplete, inaccurate, or inappropriate for your specific situation. Our Terms of Use explain your responsibility for reviewing, approving, and monitoring recommendations and automated actions.


8. International Data Transfers

We are based in Poland, but some providers and connected platforms may process data outside the EU/EEA, including in the United States.

Where required, we rely on appropriate transfer mechanisms such as:

Details of applicable transfer mechanisms are available on request where required by law.


9. Data Retention

We keep data only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.

| Data Type | Typical Retention |
|---|---|
| Account and profile data | While your account is active and for up to 2 years after closure or last activity, unless earlier deletion is required or requested |
| Connected ad, analytics, marketing, ecommerce, and communication data | While needed to provide the Service; typically deleted or de-identified within 30 days after account closure or revocation, unless needed for security, legal, billing, or dispute purposes |
| AI inputs, outputs, recommendations, approvals, and action logs | While needed to provide history, auditability, support, security, and product improvement; typically up to 24 months unless otherwise agreed |
| Payment, invoice, tax, and accounting records | As required by Polish accounting and tax law, typically 5 years or longer if required |
| Website and product analytics | Typically up to 24 months, unless configured differently or anonymized |
| Marketing email data | Until you unsubscribe or request deletion, subject to suppression lists and legal recordkeeping |
| Support and email communications | Typically up to 3 years, unless needed for legal, security, or dispute purposes |
| Security logs and technical diagnostics | Typically up to 24 months, unless needed for investigation or compliance |

If you request deletion, we will delete or anonymize eligible data unless retention is required for legal, billing, security, fraud prevention, dispute resolution, or legitimate business purposes.


10. Cookies and Tracking

We use cookies and similar technologies to:

Types of cookies and similar technologies may include:

| Type | Purpose |
|---|---|
| Essential | Authentication, security, session management, checkout, and core functionality |
| Analytics | Product and website usage analysis, diagnostics, performance measurement |
| Marketing / advertising | Attribution, remarketing, campaign measurement, audience building where allowed |
| Preferences | Remembering settings and interface choices |

Where required by law, we ask for consent before using non-essential cookies or tracking technologies. You can also manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.


11. Your Rights

Depending on where you live, you may have rights to:

To exercise your rights, contact us at hello@heycass.co.

If you are in the EU/EEA and are not satisfied with our response, you may lodge a complaint with the Polish Data Protection Authority (UODO): https://uodo.gov.pl.


12. Marketing Communications

You may unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting hello@heycass.co.

We may still send transactional or service-related messages, including account, billing, security, integration, policy, and support messages.


13. Security

We use technical and organizational measures designed to protect data, including:

No system is 100% secure. If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority where required by law.


14. Children's Privacy

The Service is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor, we will delete it where required.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice by email, in-app message, website notice, or another appropriate method.

The current version is available at https://heycass.co/privacy.


16. Contact

For privacy questions or rights requests:

Marek Dąbrowski, conducting business as AdLume
ul. Stawki 2a/38, 00-193 Warsaw, Poland
NIP: 1133071063
Email: hello@heycass.co
Website: https://heycass.co


This Privacy Policy was last reviewed on June 25, 2026.