Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how Jimm Barrow, doing business as AdMonitorHQ ("we", "us") handles information in connection with AdMonitorHQ (the "Application"), an advertising operations console used by our team to monitor and manage the TikTok advertising accounts through which we run our own advertising, using the TikTok Marketing API.
1. Who is responsible for your data
The business responsible for the data described here is Jimm Barrow, doing business as AdMonitorHQ. This covers both the operation of the Application itself — team member accounts, technical logs and security — and the advertising data of the accounts connected to it.
An advertising account is connected by the member of our team who holds it, by granting the authorization in TikTok Ads Manager. That person can withdraw the authorization at any time, which ends our access to the account immediately.
For any privacy question, write to support@admonitorhq.com.
2. Information we process
2.1 Account and authentication data
- The identifier, name, currency and time zone of each connected advertising account.
- OAuth access tokens and refresh tokens issued by the platform.
- The permissions granted to the Application and the time of authorization.
2.2 Advertising data
- Campaign, ad group and ad identifiers, names, status and budget settings.
- Spend, impressions, clicks and conversion counts reported by the platform.
2.3 Operational data
- Technical logs of API requests made by the Application (endpoint, timestamp, response code).
- Errors and diagnostic messages needed to keep the Application working.
2.4 Team member accounts
- Sign-in details of our own team members (name, work email address, role).
- Session records showing when a team member signed in and what they changed in the console.
Through the platform APIs, the Application does not request or store organic post content, comments, private messages, audience or custom audience lists, creative assets, pixel or event data, lead form submissions, or the profile data of any individual. We do not collect biometric data, precise location, payment card data, government identifiers, or any other category treated as sensitive personal information under United States state privacy laws.
3. Why we process it
- To operate the connected advertising accounts — reviewing the campaign structure and pausing, resuming or deleting the campaigns, ad groups and ads in those accounts.
- To report — measuring how the connected campaigns perform and what they cost.
- To keep sessions working — refreshing tokens so the Application stays connected.
- To secure and debug the Application — detecting failures, abuse and configuration errors.
We operate from the United States, and United States federal and state privacy law governs this processing. Where the GDPR, the UK GDPR or the Swiss FADP applies to a particular individual, we rely on our legitimate interest in running our advertising accounts efficiently and keeping the Application secure, together with the authorization given by the team member who holds an account when that account is connected.
4. TikTok data and platform rules
Data obtained through the TikTok Marketing API is used only for the purposes described above and in accordance with the TikTok developer terms and policies. Specifically, we:
- request only the permissions required for the features we actually ship;
- do not sell, rent or license TikTok data;
- do not transfer TikTok data to advertising networks, data brokers or resellers;
- do not use TikTok data to build profiles of individuals or to train machine learning models;
- delete TikTok data when it is no longer needed, when an account is disconnected, or when the platform requires deletion.
5. Sharing
We share data only with:
- Infrastructure providers that host the Application and its database, acting on our instructions under a written agreement;
- Authorities, where disclosure is required by applicable law, a court order or a valid legal request.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. Retention
- Access and refresh tokens — kept while the account is connected; erased on disconnection or revocation.
- Campaign structure and advertising metrics — kept on a rolling 24-month window, then deleted.
- Technical logs — kept up to 90 days.
- Backups — overwritten within 35 days.
7. Security
- Tokens and secrets are encrypted at rest and are never written to application logs.
- All traffic between the Application and platform APIs uses TLS.
- Access to the console and to the database is limited to named, authenticated team members.
- Permissions follow the principle of least privilege and are reviewed periodically.
8. Where data is processed
We operate from the United States, and the Application and its database are hosted in the United States. If you are located elsewhere, the data described above is transferred to and processed in the United States, where privacy laws may differ from those of your own country.
Where a transfer from the European Economic Area, the United Kingdom or Switzerland is subject to the GDPR, the UK GDPR or the FADP, we rely on the standard contractual clauses adopted by the European Commission together with the corresponding United Kingdom and Swiss addenda.
9. Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you, to obtain a copy of it, to correct it, to have it deleted, and to limit how it is used. We do not discriminate against anyone for exercising any of these rights.
Residents of California, Colorado, Connecticut, Texas, Virginia and other states with a comprehensive privacy statute may exercise the rights that statute grants them, including the right to appeal a decision we make on a request. Residents of the European Economic Area, the United Kingdom and Switzerland may additionally ask us to restrict processing, object to processing, and receive their data in a portable form.
To exercise any right, write to support@admonitorhq.com. The Application operates exclusively online, and this email address is our designated method for receiving requests. We confirm that the request comes from the person concerned or from an authorized agent, and we respond within 45 days, which we may extend once by a further 45 days where a request is complex. If we decline a request you may appeal it by replying to our response. You may also complain to the attorney general of your state, to the United States Federal Trade Commission, or — if you are in the EEA, the United Kingdom or Switzerland — to your local supervisory authority.
10. Deleting your data
You can revoke the Application's access at any time in TikTok Ads Manager, and you can request full erasure of stored data at any time. The procedure is described on the Data Deletion page.
11. Children
The Application is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13, consistent with the Children's Online Privacy Protection Act, and we do not knowingly sell or share the personal information of anyone under 16. If we learn that we hold such information, we delete it.
12. Cookies
This website is a static informational site. It sets no advertising or analytics cookies and embeds no third-party trackers. The Application itself uses a single session cookie that is strictly necessary to keep a signed-in team member logged in.
13. Changes
If this policy changes materially, we will update the date at the top of this page and, where required, notify connected users before the change takes effect.
14. Contact
Jimm Barrow, doing business as AdMonitorHQ
111 E Wisconsin Ave, Suite 200, Milwaukee, WI 53202
support@admonitorhq.com