Privacy Policy
Last updated: August 12, 2026
1. Two roles, one product
Intelligence/Ads plays two different roles under data-protection law, and this policy is organized around that distinction because it determines who to contact and what rights apply.
- For your account and billing data (when you sign up, manage a workspace, or pay for a plan), Industrial Discipline is the data controller: we decide why and how that data is processed. Section 3 covers this.
- For data about the visitors of a website where you install the Intelligence/Ads Tracker, you (our customer, the site owner) are the data controller, and Intelligence/Ads is your data processor, acting only on your instructions. Section 4 covers exactly what is collected in that role. If you are a visitor of one of our customers' websites, your rights request should generally go to that website first; we will assist them as their processor.
Throughout this policy, "the Service" means Intelligence/Ads (the dashboard, the collection endpoint, and the Tracker), and "Visitor" means a person browsing a website on which our customer has installed the Tracker.
2. Who we are
Intelligence/Ads is operated by Industrial Discipline, a SAS (société par actions simplifiée) registered in France, SIREN 903 307 387, 6 rue de Sauvage, 78125 Émancé, France. Full identification details are in our Terms of Service.
3. Data we process as controller — your account
This is the data tied to you as a person signing in and to the workspace(s) you manage:
- Identity & credentials — name (optional), email address, a hash of your password (never the password itself), and, if you enable it, a TOTP secret for two-factor authentication.
- Session data — short-lived authentication tokens held in HttpOnly cookies (an access token, ~14 minutes, and a refresh token, up to 30 days). Refresh tokens are stored server-side only as a salted hash, never in the clear. See our Cookie Policy for the exact cookies set.
- Workspace & billing data — the workspace(s) you own or belong to, your role, your current plan, and — for paid plans — a Stripe customer id and subscription id that link your workspace to your Stripe subscription. We do not store card numbers, invoices, or VAT information ourselves; Stripe holds and processes all of that as the payment processor (see Section 7).
- Support requests — if you contact support from within the product, the message, its topic, and the workspace it concerns, sent by email through our transactional email provider (Section 7).
This account data is used to operate your account, secure it (2FA, session rotation, hashed credentials), bill you where applicable, and respond to support requests.
4. Data we process as processor — your Visitors
This section describes, precisely, what the Intelligence/Ads Tracker collects when a customer installs it on their website, and what we add to it server-side. The product's design principle is observed signals, never inferred identity: everything below is either sent directly by the browser or derived from the network request itself — we do not build cross-site profiles, and we do not try to determine who a Visitor is.
4.1 Collected by the Tracker, in the browser
The Tracker sends events to our collection endpoint using the browser's navigator.sendBeacon API (falling back to a keep-alive fetch request). The Tracker does not set any cookies. It writes three small values to the browser's own storage — see our Cookie Policy for the full, itemized breakdown of keys and lifetimes. In summary:
- A randomly generated visitor identifier, persisted in localStorage until the Visitor clears their browser storage — it is not set to expire automatically, and it never leaves the Visitor's browser (no cross-device, cross-browser, or cross-site linking).
- A randomly generated session identifier and the session's initial referrer, held in sessionStorage for the duration of the browsing session.
Each event also carries:
- The page URL, path, domain, referrer, and — for single-page-app navigation — the previous in-app path.
- Acquisition parameters read from the page URL's query string: Google/Meta/TikTok/Microsoft click identifiers (gclid/fbclid/ttclid/msclkid) and UTM parameters, when present.
- Device and browser metadata: screen and viewport dimensions, pixel ratio, navigator.language, the browser's timezone offset, and navigator.userAgent.
- The page title.
- Optionally, outbound link clicks (destination and link text) and scroll-depth milestones (25/50/75/100%) — collected for a future engagement view, not currently surfaced in the product.
- Optionally, a conversion event our customer chooses to send (a type, an optional declared monetary value and currency, and an optional order/dedupe reference) — this is meant to carry business data, not personal data.
- Optionally, a consent_update event recording the choice a Visitor made on our customer's own cookie/consent banner. This is recorded as an observed fact about the session; it is not consent to us, and it does not gate whether the Tracker writes to browser storage or sends events — the legal basis for that collection is established and owned by the customer who installed the Tracker on their site.
- Optionally, arbitrary custom data our customer's own code attaches to an event. We do not inspect, filter, or strip this field — our customer is responsible for not routing personal data through it (see our Terms).
4.2 Added server-side, on ingestion
When an event reaches our collection service, we record the request headers we receive — the User-Agent and Accept-Language headers, the Host and Referer headers — and the IP address the request came from.
We enrich that IP address, through a third-party lookup (Section 7), into: country, region, city, approximate coordinates and postal code, timezone; the network's autonomous system number, name and type; and a set of infrastructure flags — whether the address is associated with a VPN, a proxy, Tor, a private relay, hosting infrastructure, an anycast network, a mobile carrier, or a satellite connection (with the carrier name and mobile network codes when applicable). These are recorded as observed, factual attributes of the network the request came from. Consistent with the product's design, none of these attributes is treated as a verdict — a VPN, hosting, or proxy flag is surfaced as a fact for you to interpret, never labeled "bad" or "fraudulent" by the product itself.
5. How long we keep data
Every event we collect is retained indefinitely, on every plan. This is a deliberate design choice, not an oversight: storage of this kind of event data is inexpensive, and what a plan limits is the history window — how far back you may query and view data in the dashboard — not what is stored. Retention is the default; erasure happens only on instruction. Deleting a workspace you own removes your access to it immediately and records an instruction to erase the event data collected under it. That erasure is carried out afterward, not necessarily instantly — very recent events briefly cannot be modified in our data warehouse, so the deletion completes on our next scheduled pass once they are eligible.
Account data (Section 3) is kept for as long as your account or workspace exists.
6. Legal bases
For account and billing data (Section 3), we process it to perform our contract with you (providing and billing the Service), to comply with legal obligations (e.g. accounting), and, for security measures like session and login safeguards, on the basis of our legitimate interest in keeping the Service secure.
For Visitor data (Section 4), the legal basis for collection is established by our customer, as the controller of their own website's visitors — see our Terms. Our own basis for processing that data is the performance of our data-processing agreement with that customer.
7. Who we share data with
We do not sell personal data. We share it only with the service providers ("subprocessors") that operate the Service on our behalf:
- Google Cloud — hosting for our database, data warehouse, and application services. Our BigQuery data warehouse, where event and analytics data is stored, runs in the europe-west9 region (Paris, France). Our other Google Cloud services (Datastore, Cloud Run, Pub/Sub) also run within the European Union.
- ipinfo.io — IP geolocation and network enrichment described in Section 4.2. ipinfo.io is a United States-based provider and receives the IP addresses we look up. This is an international transfer of personal data outside the European Union.
- Stripe — payment processing, invoicing, and tax calculation for paid plans, via Stripe Checkout and the Stripe customer portal. Stripe receives the billing information needed to process payment (Stripe, not us, is the merchant of record for card data).
- Mailjet — delivery of transactional email (sign-in codes, password resets, support replies, account notifications).
- Cloudflare — content delivery for the Tracker's script file itself (a static, non-personal JavaScript file, served from Cloudflare R2 via Cloudflare's CDN). Visitor event data is sent directly to our own collection endpoint and does not pass through Cloudflare.
We may also disclose data where required by law, or in connection with a merger, acquisition, or sale of assets, subject to the same protections described here.
8. Security
Passwords are stored as salted hashes, never in the clear. Refresh tokens are hashed server-side with a pepper before storage; the raw token exists only in your browser's HttpOnly cookie. Two-factor authentication (TOTP, with an email-code fallback) is available on every account. Access to Visitor-level identifying fields (full IP address, city, network operator, visitor id) is gated by your plan and enforced on the server before a response is built, not hidden client-side.
9. Your rights
If you are an EU resident, the GDPR gives you the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL.
For your own account or billing data, contact us directly (Section 11). If you are a Visitor of one of our customers' websites, please contact that website first — as the controller of your data, they are best placed to act on your request, and we will assist them as their processor.
10. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect account data from children.
11. Contact
General and support inquiries: support@intelligenceads.io. To exercise your data-protection rights (access, rectification, erasure, restriction, objection, or portability), contact: contact@industrialdiscipline.com
12. Changes to this policy
We may update this policy from time to time. We will update the "Last updated" date above when we do; material changes will be communicated through the Service or by email.