Skip to content
Passiv logoPassiv
  • Home
  • About
  • Features
  • Contact
  • Log In
Log In Get Started
Legal

Privacy Policy

Version 2.1 Effective August 23, 2026 Last updated August 23, 2026
Contents
  • 1. Scope, Our Roles, and How They Change
  • 2. Information We Collect
  • 3. How We Use Information
  • 4. Disclosure and Sharing
  • 5. Data We Do Not Accept
  • 6. Security
  • 7. Retention and Deletion
  • 8. Your Rights and Choices
  • 9. Security Incident Notification
  • 10. Children's Privacy
  • 11. Geographic Scope
  • 12. Changes to This Policy
  • 13. Contact

This Privacy Policy describes how Passiv Solutions LLC ("Company," "we," "us," or "our") collects, uses, discloses, and protects information gathered through the passiv.app website, the Passiv application, the Passiv pixel gateway, and related tools (collectively, the "Service"). This Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

01Scope, Our Roles, and How They Change

1.1 Scope and Territory

This Policy applies to personal and business data collected directly by our platform and to end-user data passed through our pixel gateway. The Service is intended exclusively for businesses operating in permitted jurisdictions, primarily the United States. It is not directed to, offered to, or intended for data subjects located in the European Economic Area, the United Kingdom, or Switzerland. See Section 11.

1.2 Our Roles

Our legal role differs depending on which data is involved. This distinction determines who is responsible for what, so it is set out explicitly rather than left implied.

DataOur roleWhat that means
Account Data — your account details, billing information, and User Content you uploadController / BusinessWe decide why and how it is processed, and we are directly accountable for it.
Gateway Data — end-user data ingested through the pixel gateway and routed to Ad Network APIsProcessor / Service ProviderWe process it only on your instructions. You are the controller and are accountable for the lawfulness of its collection.
Service Data — campaign configurations, performance metrics, and execution logs generated by your use of the ServiceController, under the licence in Terms of Service Section 4.4We process it to operate and improve the Service. It generally does not identify any individual.
Aggregated Data — statistical data derived from Service Data across multiple customersController and owner, under Terms of Service Section 4.5Once data is aggregated and de-identified it is no longer personal data, and it is ours.

1.3 Where Our Role Changes

Data can move between these categories. Gateway Data we process for you, and Service Data generated by your campaigns, may be aggregated and de-identified into Aggregated Data. At the point of aggregation the data ceases to be personal data and ceases to be processed on your behalf; it becomes our own data under Terms of Service Section 4.5, and it is not returned or deleted when your account closes. We disclose this transition here because it is the one place where our commercial rights and your privacy expectations meet, and it should not be buried.

1.4 Your Consent Warranty

Customers deploying our pixel gateway represent and warrant, on an ongoing basis, that they have established a lawful basis, provided all required privacy notices, obtained all end-user consents required by applicable law, and implemented a mechanism to honor withdrawal of consent and applicable opt-out preference signals, before transmitting any conversion data through the Service. This mirrors Terms of Service Section 5.2. If you have not done this, do not deploy the gateway.

02Information We Collect

2.1 Information You Provide

  • Account information: name, business email address, telephone number, company name, and website URL.
  • Credentials: passwords, which are stored only as salted cryptographic hashes and are never stored or transmitted by us in plaintext.
  • Billing information: billing address and payment card details, which are collected and processed by our PCI-DSS compliant payment processor. Raw card numbers are never stored on our systems; we retain only a payment token and the last four digits.
  • User Content: marketing strategy text, business descriptions, prompts, creative brief inputs, uploaded assets, and asset metadata.

2.2 Information Collected Automatically

  • Technical logs: device type, operating system, IP address, browser type, system diagnostics, and timestamped error logs.
  • Strictly necessary cookies: we set an authentication cookie on app.passiv.app to keep you signed in. Our hosting and security providers may also set cookies used to protect the Service against automated abuse. These cannot be disabled without preventing the Service from working.
  • Analytics cookies: we use Mixpanel to understand how the Service is used and to improve it. Mixpanel sets a cookie across passiv.app and app.passiv.app recording a device identifier, your browser and interface language, the platform you are using, and the page or site you arrived from. We use this for product analytics only.
  • We do not use advertising or retargeting cookies on our own websites. Neither passiv.app nor app.passiv.app sets a cookie for the purpose of advertising to you or of building an advertising profile of you.
  • Meta software development kit on app.passiv.app: the application loads Meta's JavaScript SDK on every page so that you can connect your Meta advertising account. Loading the SDK transmits a page-view event to Meta identifying our application, and Meta may set a cookie in your browser when you connect a Meta account. Because the SDK loads on every application page, this transmission can occur on the sign-in, sign-up, and agreement pages, and therefore before you have signed in or accepted this Policy. Meta processes that information under its own privacy policy, over which we have no control.

2.3 Ad Network API Data

  • Account metadata: ad account identifiers, Business Manager authorizations, OAuth access tokens, and tracking configurations.
  • Performance metrics: impressions, clicks, conversion events, CTR, CPC, CPA, ROAS, and advertising spend.
  • Aggregated audience attributes: age range and gender breakdowns of the audiences that engaged with your advertising, as reported in aggregate by the Ad Networks. We receive these only as aggregate statistics and do not receive attributes about any identified individual.

2.4 Pixel Gateway Data

When you deploy our pixel gateway on your properties, it ingests and transmits the following about your site visitors:

  • Customer identifiers, including email address, telephone number, name, city, and postal code where you have configured their capture. These are hashed using SHA-256 in the visitor's browser before transmission. We receive them only in hashed form, we do not reverse them, and we reject any identifier that does not arrive as a valid hash.
  • Advertising click identifiers, such as fbclid, gclid, ttclid, and sccid.
  • Browser user-agent string, IP address, page URL, and event payload attributes describing the conversion action.

Conversion data uploaded to the Service directly, rather than through the pixel, is hashed on receipt before it is stored.

This data belongs to your site visitors, not to you or to us. We process it solely to transmit conversion measurement events to the Ad Networks you have authorized. See Section 1.4 for your obligations regarding it.

03How We Use Information

3.1 Operating the Service

To create and manage advertising campaigns, transmit conversion events to Ad Network APIs, authenticate you, process recurring and overage billing, provide support, and deliver operational account alerts.

3.2 Artificial Intelligence and Automated Processing

The Service uses artificial intelligence to generate advertising copy, creative briefs, and campaign recommendations, and to make automated budget allocation decisions across advertising platforms.

Your prompts, business descriptions, and campaign inputs are transmitted to third-party artificial intelligence model providers acting as our subprocessors, by way of the model routing layer described in Section 4.2. Output may be inaccurate and must be reviewed by you before publication, as set out in Terms of Service Section 6.4. Automated budget allocation decisions affect how your advertising funds are spent but do not produce legal or similarly significant effects on any individual, and we do not use automated decision-making to profile or evaluate individuals.

3.3 Analytics, Machine Learning, and Product Improvement

We analyze Service Data to operate, monitor, secure, and troubleshoot the Service, to detect fraud, to verify billing, and to develop, train, test, and improve our models and algorithms. Where we use data for machine learning and published analytics, we use Aggregated Data that has been de-identified and does not identify you, your business, or any individual. See Section 7.3 for what this means for deletion.

3.4 Security and Fraud Prevention

To detect platform abuse, enforce our Terms of Service, prevent fraudulent transactions, investigate security incidents, and verify account integrity.

3.5 Communications

To send transactional notices, billing and usage warnings, security alerts, and service announcements, by email and, where you have enabled them, by push notification to a device you have registered. You can disable push notifications at any time in your device or browser settings. We may send product updates and marketing communications, from which you can unsubscribe at any time using the link in every such message. Consent to receive email from us does not extend to SMS, text, or other telephonic communications; we send those only with your separate express written consent, which you may revoke at any time. This mirrors Terms of Service Section 13.10.

04Disclosure and Sharing

We do not sell your personal data or your end-users' conversion data, and we do not share it for cross-context behavioral advertising as those terms are defined under California law. Section 4.6 explains why our transmissions to Ad Networks do not constitute a sale or share. Data is disclosed only as described in this Section.

4.1 Ad Networks

We transmit campaign data and conversion payloads to the Ad Network APIs you have authorized — Meta, Google, TikTok, and Snapchat — for the purpose of running and measuring your advertising. Each Ad Network processes that data under its own terms and privacy policy, over which we have no control. Once data reaches an Ad Network, that Ad Network determines how it is used.

4.2 Subprocessors

We use the following third-party providers to operate the Service. Each is bound by contractual data protection obligations, and we remain responsible for their performance under Terms of Service Section 5.5.

A current list of subprocessors is available on request at privacy@passiv.app. We will update this Policy when we add or replace a subprocessor that processes personal data.

ProviderFunctionData involved
Base44Primary application platform — hosts the Passiv application including its frontend, backend, authentication, and database, and provides the model routing layer that directs prompts to third-party AI model providersAccount Data, User Content, Service Data
Third-party AI model providers, accessed via the Base44 model routing layerGeneration of advertising copy, creative briefs, and recommendationsUser Content, prompts, business descriptions
VercelHosting for the passiv.app marketing website and for the pixel gatewayTechnical logs, Gateway Data in transit
UpstashManaged cache used for pixel gateway event deduplicationGateway Data — hashed identifiers and event payloads, transiently
StripePayment processing and subscription billingBilling information, payment tokens
ResendTransactional and notification email deliveryName, email address, message content
MixpanelProduct analytics — measuring how the Service is used so that we can improve itDevice identifier, browser and interface language, platform, referring page, and in-product actions
MetaProvider of the JavaScript software development kit loaded by the application to support Meta account connection, as described in Section 2.2Application page-view events, and a Meta cookie identifier where you connect a Meta account

4.3 Legal and Compliance

We may disclose information to comply with valid legal process such as a court order, subpoena, or statutory inquiry; to establish, exercise, or defend legal claims; or to protect the rights, safety, and infrastructure of the Company, our customers, or the public. Where we are legally permitted to do so, we will notify you before disclosing your data in response to legal process.

4.4 Corporate Transfers

If the Company is involved in a merger, acquisition, financing, reorganization, asset sale, or bankruptcy, information may be transferred as part of that transaction. Any acquirer will remain bound by this Policy with respect to data transferred, unless and until you are notified of and consent to a different policy.

4.5 Service Provider Affirmation

For customers subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act, and to comparable state privacy statutes, the Company acts as a "service provider" or "processor" with respect to Gateway Data. We do not retain, use, or disclose Gateway Data for any purpose other than performing the Service specified in our Terms of Service, and we do not combine Gateway Data with personal information received from any other source except as permitted by law.

Scope of this affirmation. This affirmation applies to Gateway Data. It does not restrict our processing of Service Data and Aggregated Data under Terms of Service Sections 4.4 and 4.5, because that data is de-identified or aggregated and is not personal information. Section 1.3 explains this transition. We state the boundary explicitly so that this Policy and the Terms of Service do not contradict each other.

4.6 No Sale, No Share, and Opt-Out Preference Signals

We transmit hashed identifiers and conversion events to Ad Networks at your direction, for the purpose of measuring the performance of your own advertising. We receive no monetary or other valuable consideration for these transmissions, and they are made under service-provider terms rather than for cross-context behavioral advertising by us. On that basis these transmissions are not a "sale" or a "share" by the Company under applicable state law.

This does not resolve your own position. Whether your deployment of the gateway constitutes a sale or share by you depends on your configuration, your disclosures, and your relationship with the Ad Networks. You are responsible for that determination and for honoring opt-out preference signals such as Global Privacy Control on your own properties.

05Data We Do Not Accept

You must not transmit the following through the Service or the pixel gateway. This mirrors the prohibition in Terms of Service Section 5.3 and exists because we are not configured to protect these categories.

  • Protected health information subject to HIPAA.
  • Information subject to the Gramm-Leach-Bliley Act, and financial account or payment card numbers.
  • Government-issued identifiers, including Social Security numbers.
  • Biometric identifiers or biometric information, including facial geometry, fingerprints, voiceprints, retina or iris scans, and scans of hand or face geometry. We are an Illinois company and the Illinois Biometric Information Privacy Act carries a private right of action with statutory damages per violation. We do not collect biometric data and you must not transmit it to us.
  • Precise geolocation.
  • Information revealing racial or ethnic origin, religious or philosophical belief, sexual orientation, health status, or union membership.
  • Data of any individual known or reasonably believed to be under thirteen (13) years of age.

If we become aware that prohibited data has been transmitted to us, we may delete it, suspend the transmission, or suspend the account, and we will notify you.

06Security

6.1 Technical and Organizational Measures

We maintain administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature of the data and to the size and resources of the Company. These include encryption of data in transit and at rest as provided by our infrastructure providers, OAuth 2.0 authentication for Ad Network integrations, hashing of stored credentials, access controls limiting internal access to those who require it, and transmission of gateway identifiers in hashed form only.

6.2 Your Responsibilities

You are responsible for the security of your own systems, your account credentials, and your deployment of the pixel gateway. Your Passiv account holds live access to your advertising accounts, so a compromise of your credentials is a compromise of those accounts. Notify us immediately at support@passiv.app of any suspected unauthorized access.

6.3 No Guarantee

No system is completely secure. We do not represent or warrant that the Service is free from vulnerabilities or that unauthorized access will never occur.

07Retention and Deletion

7.1 Retention Schedule

CategoryRetention periodBasis
Account DataDuration of the subscription, then deleted from active production systems within thirty (30) days of terminationNecessary to provide the Service
User ContentDuration of the subscription, then deleted from active production systems within thirty (30) days of terminationNecessary to provide the Service
Gateway DataTransient. Retained only as long as required to deduplicate and transmit the conversion event, then discardedNecessary to perform conversion measurement
Service DataRetained under the licence in Terms of Service Section 4.4Service operation, security, billing verification, and product improvement
Aggregated DataRetained indefinitelyNo longer personal data; owned by the Company under Terms of Service Section 4.5
Uploaded creative filesRendered permanently inaccessible within thirty (30) days of termination; see Section 7.2Necessary to provide the Service
Financial and tax recordsSeven (7) yearsLegal, tax, and accounting obligations
Security, audit, and usage logsRetained for the life of the account and deleted with Account Data. We do not currently apply a fixed retention period to these logsSecurity monitoring, incident investigation, and billing verification
Request payloadsNot logged by our application codeConversion events are stored as hashed entity records under the rows above. Platform-level access logs may exist at our hosting provider; their retention is set by that provider and is not controlled by us
Credit usage recordsDuration of the subscription, then deleted with Account DataBilling verification and dispute resolution. These record the account, the number of Credits used, and a short description of the action; they do not contain your prompts or generated content

7.2 Deletion on Termination

When your account terminates, we delete your Account Data and User Content records from active production systems within thirty (30) days. For thirty (30) days following termination you may request an export of your data under Terms of Service Section 11.5.

Uploaded files are rendered inaccessible rather than erased. Creative files you upload are held in private storage and are never publicly addressable. On deletion we remove the records that reference them and no access URL is issued again, which makes them permanently unreachable. We do not state that the underlying file is erased, because our hosting platform does not currently expose a file deletion interface to us. We describe this accurately rather than claim an erasure we cannot perform, and we will delete the files themselves if and when that capability becomes available.

7.3 What Deletion Does Not Reach

Deleting your account does not require us to delete, and we do not delete:

  • Aggregated Data, and models or algorithms trained using Service Data, which are our property under Terms of Service Sections 4.4 and 4.5 and are not personal data;
  • copies persisting in encrypted backups until the applicable backup cycle expires, or in caches until they expire, which cannot be selectively reached;
  • uploaded creative files, which are rendered permanently inaccessible as described in Section 7.2 but are not erased from underlying storage;
  • records we are required or permitted to retain by law, for tax purposes, or for the establishment or defense of legal claims; and
  • records necessary to prevent fraud, enforce our Terms of Service, or maintain security.

We state this plainly because a deletion right that quietly excludes categories is worse than one that names them.

08Your Rights and Choices

8.1 Account Controls

You can review and update your account information at any time in your account settings.

8.2 Rights Available to You

Depending on the state in which you reside, you may have the right to know what personal data we hold about you, to access a copy of it, to correct inaccuracies, to request deletion, to obtain a portable copy, to opt out of sale, sharing, or targeted advertising, to limit the use of sensitive personal information, and to appeal a denial of any of these requests.

8.3 How to Submit a Request

Submit requests to privacy@passiv.app. We will acknowledge your request within ten (10) business days and respond substantively within forty-five (45) days. Where a request is complex we may extend this by a further forty-five (45) days and will tell you why before doing so. There is no charge for a request unless it is manifestly unfounded or excessive, in which case we will tell you before proceeding.

8.4 Verifying Your Identity

We will ask you to verify your identity before acting on a request, using information already associated with your account. We ask only for what is necessary to match you to your record, and we do not retain verification information beyond the purpose of verification. If we cannot verify you, we will tell you and explain why.

8.5 Authorized Agents

You may use an authorized agent to submit a request on your behalf. We will require written proof of the agent's authorization and may also require you to verify your own identity directly with us.

8.6 Appeals

If we decline your request in whole or in part, you may appeal by replying to our response or writing to privacy@passiv.app with the word "Appeal" in the subject line. We will review the appeal and respond in writing within forty-five (45) days, explaining the reasons for our decision. If the appeal is denied, we will provide a method by which you may contact your state Attorney General to submit a complaint. This appeal right is available to all users regardless of state of residence.

8.7 No Discrimination

We will not deny you service, charge you a different price, provide a different level of service, or retaliate against you for exercising any privacy right.

8.8 Requests From End Users of Our Customers' Websites

If you are a visitor to a website operated by one of our business customers and you wish to exercise rights over data collected there, contact that business, not us. For Gateway Data we act as a processor on our customer's behalf and we do not have the standing to action your request directly. If you contact us, we will forward your request to the relevant customer where we can identify them, and tell you that we have done so. We will assist our customers in responding to such requests as required by our contract with them.

8.9 Marketing Opt-Out

Every marketing message contains an unsubscribe link. Transactional messages about billing, security, and service availability cannot be opted out of while your account remains open, because they are necessary to provide the Service.

09Security Incident Notification

If we confirm an unauthorized acquisition of personal data affecting the pixel gateway, customer account data, or stored credentials, we will notify affected account holders by email without undue delay after becoming aware of it, and will provide the information then reasonably available to us to assist you in meeting your own obligations. You remain responsible for determining whether an incident triggers a notification obligation under any law applicable to you, including the Illinois Personal Information Protection Act, and for making any notification that law requires. Nothing in this Section extends, shortens, or substitutes for any deadline imposed on you by law.

This mirrors Terms of Service Section 5.7. The prior version of this Policy committed to notification within seventy-two (72) hours; that commitment has been removed because it presupposes detection capability that a company of our size cannot presently guarantee, and a deadline we cannot meet is worse than an honest one.

10Children's Privacy

The Service is a business tool offered only to individuals aged eighteen (18) and over. We do not knowingly collect personal data directly from anyone under eighteen, and if we learn that we have, we will delete it.

A separate limitation applies to the pixel gateway. The gateway receives data about visitors to our customers' websites, and we have no means of determining the age of those visitors. We rely on our customers not to deploy the gateway on properties directed to children. Customers must not transmit data of any individual known or reasonably believed to be under thirteen (13) years of age, as required by Terms of Service Section 5.3 and Section 5 of this Policy. Deployment of the gateway on a child-directed property is a breach of our Terms of Service.

If you believe we have received data concerning a child, contact privacy@passiv.app and we will investigate and delete it from active production systems, subject to the limits described in Section 7.3.

11Geographic Scope

The Service is offered in the United States and is operated from the United States. All data is processed and stored in the United States.

The Service is not offered to, and must not be used to collect, process, or transmit personal data of individuals located in the European Economic Area, the United Kingdom, or Switzerland. We have not appointed an EU or UK representative. If your properties receive traffic from those regions, you must implement geographic controls preventing the pixel gateway from firing for those visitors, as required by Terms of Service Section 5.8.

12Changes to This Policy

We may revise this Policy. We will give at least thirty (30) days' advance notice of material changes by email to your registered address and by in-app notice, and the change will take effect on the stated effective date. You may cancel your subscription before that date if you do not accept the change. Non-material changes may take effect on posting. Prior versions are archived and available on request. This mirrors Terms of Service Section 2.2.

13Contact

Passiv Solutions LLC — Privacy

Email: privacy@passiv.app

3115 Tall Grass Drive

Naperville, Illinois 60564, United States

Passiv Solutions LLC · privacy@passiv.app · legal@passiv.app

Passiv logoPassiv

AI-powered advertising for small businesses. Create, manage, and optimize your ads — automatically.

$99.99/mo · Cancel anytime

Product

  • Features
  • How It Works
  • Contact
  • Get Started

Company

  • About
  • Contact

Legal

  • Terms
  • Privacy
  • Cookie Settings
© 2026 Passiv Solutions LLC. All rights reserved. Made for small businesses