Last updated: September 16, 2026

This policy covers adwave.com, the Adwave advertising service at waverunner.adwave.com, and data Adwave processes for advertisers. It explains what we collect, how we use and share it, and how to make a privacy request. Some website forms and analytics still use our legacy systems at app.adwave.com.

The earlier website and legacy app policy remains available as an archive. Separate products, including Wavemaker, publish their own policies. For account closure and platform connection requests, see Data deletion.

Who we are

Adwave is operated by Adwave Digital Inc ("Adwave", "we", "us"). We decide how information is used for our website, account administration, marketing, and support. For data collected on an advertiser's website or supplied for its campaigns, the advertiser is the controller and we process that data on its behalf. An agency may administer that relationship for its clients.

Our service is intended for businesses and their representatives who are 18 or older in the United States. Business use does not remove privacy rights that apply under law. Do not use the service if you are under 18.

Privacy requests: privacy@adwave.com. Account or deletion assistance: support@adwave.com.

Visitors to adwave.com and our public app pages

When you contact us, book a conversation, submit a website, or use our public pages, we may collect your name, business email, company, job title, website address, message, and other information you provide. We use these details to respond, analyze a submitted website, provide the service, and communicate with you, including marketing messages you can opt out of. We may receive business contact information from partners or public sources. Contact and support information is not limited to hashed identifiers.

Website analytics can record page URLs, referring pages, campaign parameters, browser and device information, approximate location, and interactions. We use Ahoy analytics connected to our legacy application and Google Tag Manager to manage measurement integrations. Snitcher helps identify companies visiting the website using network and activity information. We may measure email opens and link clicks.

Intercom provides support chat. On adwave.com it starts without an Adwave account identity. In the signed-in advertising app it can receive your user ID, email, and name to continue support conversations. Intercom does not load on agency partner hosts. Google reCAPTCHA helps protect website forms from spam. Sentry receives error and performance information.

Where a coverage map appears, GeoJS supplies approximate location from your network address, OpenFreeMap supplies map tiles, and a CDN supplies the map library. These services receive the connection information needed to answer the browser's requests.

On the app's sign-in and website-analysis start pages, Adwave also uses its own tracking snippet to measure visits and campaign attribution. The product tracking controls described below apply to that snippet. Other website integrations have their own settings and data handling; those controls do not automatically disable every third-party website service.

Website cookies and browser storage

Cookies and browser storage support visits, referral attribution, preferences, analytics, and customer support. The website and advertising app use different systems:

  • Website referral and campaign details: aw_referral_code lasts up to 30 days. Campaign parameters, referral parameters, and Awin click IDs can be kept in session storage for the browser session. Ahoy uses visit and visitor identifiers to connect website activity to our legacy application.
  • Website preferences: adwave_vertical remembers the industry example shown for up to 30 days. aw_exit_shown remembers that a signup prompt was shown for up to three days.
  • Analytics and support: Google measurement tools, Snitcher, and Intercom may use their own cookies or browser storage. Snitcher's company-identification cookie is described in its privacy policy.
  • App referral and setup: _wr_aff attributes a signup to a referral partner for up to 90 days. _wr_acq records a referring hostname and landing path for up to 30 days. _wr_agency_intent records an agency signup choice for up to 30 days. These cookies support attribution or account setup rather than ad targeting.
  • Account sessions: the advertising app uses HttpOnly session cookies on the hostname where you sign in.

You can remove or block cookies and clear browser storage through your browser settings. This can sign you out or affect features. You can also contact privacy@adwave.com about your choices. Ad blockers and provider opt-out tools may limit additional measurement, but no single tool necessarily covers every service.

Global Privacy Control and the consent command described below stop ad-platform sharing through Adwave's tracking system while first-party measurement continues. These product controls apply to Adwave’s tracking system. Other integrations on adwave.com use separate controls.

Account holders

When you create and use an Adwave account, we store:

  • Your email address: used for passwordless sign-in codes and transactional notifications (campaign status, billing events, the weekly digest).
  • Organization data: your businesses, buyer profiles, generated creatives, campaigns, and wallet ledger.
  • Billing records: wallet transactions and their Stripe references. Payments are processed by Stripe; your card number never touches Adwave’s servers. If you enable auto-refill, Stripe stores the payment method and we store only its reference.
  • Content from your website: pages we read to build your business profile and generate ads.

If you connect Google or Facebook to your Adwave sign-in, we use the provider’s account identifier, name, and email address when the provider supplies one to identify you. Google may also supply a profile picture. These sign-in connections request only basic identity information, without access to your advertising accounts, posts, or contacts. Provider tokens are used to complete sign-in and are not kept for later access. A matching email address does not automatically connect accounts. We keep the sign-in connection until you disconnect it or it is removed through a verified deletion request, subject to the retention exceptions below. You can disconnect a sign-in provider in the Adwave app under Settings → Security and use email codes to sign in.

We do not sell personal information for money or use one advertiser’s customer data to advertise another advertiser’s products. Campaign delivery and measurement can involve disclosures to ad platforms as described below.

Agency operators may access campaign and lead data for a client organization they manage, for that client only. Visitor requests still go to the advertised business. Client workspaces do not share visitor pools. For personal information in a client workspace we process as a service provider of the agency. We will sign a data processing addendum on request at support@adwave.com. Client users sign in on a branded agency host or an Adwave partner host; those hosts set first-party session cookies on that hostname. Intercom does not load on partner hosts. We do not use names or emails from an agency's client workspaces to solicit those clients onto a direct Adwave account.

Deleting a client user's login does not delete the client organization, its campaigns, or its tracking data. The agency administers that workspace.

Tracking on advertiser websites

Advertisers can install the Adwave tag on their own websites to measure their campaigns. On those sites, the tag records page views, sessions, UTM parameters, ad-click IDs, and conversions (with value, currency, and order ID when the advertiser provides them). All cookies are first-party, set on the advertiser’s own domain:

  • _wr_vid: visitor ID, 365 days.
  • _wr_sid: session ID, 30 minutes (sliding).
  • _wr_utm: last-touch campaign (UTM) parameters (the most recent campaign-tagged landing wins), 30 minutes (sliding with the session).
  • _wr_cid: Adwave's own click ID from the ad that brought the visitor (platform click ids such as gclid or fbclid are kept in local storage, below), 30 days.
  • _wr_aid: the id of the ad that brought the visitor, 30 days.
  • _wr_li: the id of the audience line the ad click came from, 30 days.
  • _wr_camp: the id of the campaign that brought the visitor, 30 days.
  • wr_consent: set only when the advertiser calls the tag's consent API; records whether the visitor declined ad-platform sharing, 365 days.

The tag also keeps browser local storage copies of the visitor, click, ad, and campaign ids (so a blocked cookie does not double-count a visitor), a small cache of the platform click ids it saw (_wr_ads), and a retry queue of events that could not be sent yet (_wr_rq). The visitor and Adwave click-ID copies follow their corresponding cookie lifetimes. Platform click-ID storage uses separate limits: Facebook click IDs expire after seven days; Google, Microsoft, Reddit, and TikTok click IDs expire after 90 days. Pending retry events expire after 24 hours.

Landing pages we host for an advertiser set one extra first-party cookie, _wr_lpv (30 days), that remembers which page variant a visitor saw so they keep seeing the same one. The ad platforms' own cookies (for example Meta's _fbp and _fbc or Google's _gcl_au) are read by the tag for conversion matching when the advertiser has enabled sharing, but are never set by us.

Tracking identifiers are protected according to their use. Persistent matching records use salted hashes of email addresses and IP addresses. Short-lived connection data needed for conversion forwarding or TV household matching can include encrypted IP addresses. Lead forms, customer imports, account records, and support conversations can contain contact information, as described elsewhere in this policy. The advertiser is responsible for their own site’s privacy disclosures and any consent requirements that apply to them.

Conversion forwarding to ad platforms

To optimize delivery, attributed conversions may be forwarded to Meta (Conversions API), Google (offline conversion uploads), and Reddit (Conversions API), depending on which channels the advertiser selected. Email, phone, and name values used for matching are sent as SHA-256 hashes according to each platform's specification. Forwarded events can also include conversion details, platform click IDs, source URLs, and short-lived connection details such as the visitor's IP address and browser user agent. Forwarding exists solely to improve that advertiser's own campaign performance. We do not use one advertiser's conversion data to run ads for another advertiser or for ourselves.

Audience building

Audience sync is on by default for advertiser accounts so campaign reach and customer matching can work. Advertisers can turn it off anytime in Tracking. By keeping sync on, the advertiser attests that their website's privacy policy discloses audience building. When sync is on:

  • Campaign reach audiences. When an ad we serve is displayed, the ad platforms' own measurement pixels (Google, Meta, Reddit as applicable) may fire alongside ours to support Preparing and Live on those platforms. Each platform processes those signals under its own privacy policy.
  • Audience lists. SHA-256 hashes of customer emails (never raw addresses) may be sent to Google Customer Match and Meta custom audiences, per each platform's specification. We do not upload customer match lists to Reddit or TikTok. When someone leaves a Google or Meta customer audience, or the advertiser turns sync off, removals are propagated subject to the platform’s processing times.
  • TV household matching. Visitor IP addresses are required by TV ad systems for household matching. They are held AES-256-GCM encrypted in a transient queue, deleted immediately after upload, and hard-purged in 24 hours regardless. These household-matching IPs are separate from the short-lived encrypted connection data used for conversion forwarding. They are excluded from customer data exports.
  • Optional platform tags. The advertiser can also allow the Adwave tag to load Google (gtag) and Meta (fbevents) tags on their own website to improve audience match quality. This is off by default and gated on the same attestation.

Ad platform data (Meta, Google, Reddit, TV)

When you launch campaigns, we create and manage ads, audiences, and conversion events on advertising platforms (including Meta, Google, Reddit, and our TV / display DSP partners) on your behalf. Platform data we obtain for a customer (campaign structure, delivery and performance, audience membership, and conversion match signals) is used only to run and measure that customer's campaigns inside Adwave. We keep each customer's advertising data separate from other customers' data and do not sell personal information for money.

Each platform also processes data under its own terms and privacy policy. You are responsible for having the rights and any required notices or consents for the businesses and customer data you advertise.

Service providers, ad platforms, and connected systems

We use the following providers and categories of providers to operate the advertising service. Ad platforms and customer-authorized systems also process information under their own terms:

  • Stripe: payment processing and partner payouts
  • Fly.io: application hosting
  • Neon: Postgres database hosting; AWS: independent backup storage
  • Cloudflare: DNS, CDN, DDoS protection, and hosting for the landing-page domains you connect
  • Cloudflare R2 and S3-compatible object storage: uploaded creative files, generated ad assets, and backups
  • AI model providers: ad copy, imagery, and video generation
  • Firecrawl: website content extraction
  • Meta, Google, Reddit, TikTok, Pinterest, and our DSP partner: ad delivery, conversion matching, and audience building (when audience sync is on)
  • Google Analytics 4: server-side advertising measurement when audience sync is on
  • Twilio: call tracking numbers and call forwarding when an advertiser turns on call tracking (caller numbers are stored encrypted)
  • A print and mail fulfillment provider and a mailing-list data provider: printing, addressing, and delivering Neighborhood mail pieces to the households an advertiser selects
  • US Census Bureau geocoder: turning a business address into map coordinates for local targeting
  • Resend: transactional email
  • Sentry: error monitoring
  • Intercom: customer support messaging
  • Attio: our own customer relationship records for account holders (name, email, workspace, plan)
  • Slack: internal operations alerts to our team (workspace and campaign identifiers, never customer contact details)
  • Awin: affiliate network conversion reporting

The website additionally uses the analytics, company-identification, mapping, spam-prevention, and support providers described in Visitors to adwave.com. Google Tag Manager manages tags; the presence of that container does not mean every ad-platform tag runs on every visit.

Connectors you authorize. When you connect a customer system to a business (QuickBooks, Stripe, Shopify, Square, Clover, HubSpot, GoHighLevel, or Google Business Profile), that provider processes data for you under your own agreement with them. We hold the access token encrypted, read the data needed for the enabled connection, such as orders, catalog items, location information, and permitted customer details, and send leads to the CRMs you choose. Access depends on the provider permissions and your configuration. For example, Shopify customer-contact access depends on the permissions approved for that connection. When you disconnect a connector or close your workspace, we delete the token; where the provider offers it (HubSpot, Shopify, Google) we also revoke the grant on their side.

Other uses and disclosures

We use information to operate and secure our services, answer requests, improve features, detect fraud, and enforce our agreements. We may share information with professional advisers, respond to lawful requests, or disclose it when needed to protect rights, safety, and property. Information may also be transferred in a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable obligations.

Links and integrations can take you to services we do not control. Review their privacy policies for their handling of information. Our payment provider publishes its Stripe Privacy Policy; Google publishes its Privacy Policy.

Data retention

Account and organization data is retained while your account is active. Wallet ledger entries are retained as financial records. Tracking events are retained to power attribution and reporting for the advertiser that collected them, in these windows:

  • Page views and identify events: 180 days.
  • Clicks and on-page interactions: 90 days.
  • Ad impressions and video playback events: 90 days (daily totals without identifiers are kept).
  • Conversions: kept while the account is active, because lifetime return on ad spend is reported from them. The platform click ids attached to a conversion for forwarding are cleared 7 days after the forward and no later than 90 days after the event.
  • Visitor IP addresses for TV household matching: deleted after upload and no later than 24 hours. Connection details held for conversion forwarding are deleted once forwarded and no later than 24 hours.
  • Lead contact details (name, email, phone, message) and imported customer emails: stored encrypted and kept while the account is active.
  • Uploaded creative files, generated ads, mail artwork, and listing photos: kept while the account is active and deleted from object storage when the workspace closes.
  • Public URL analysis (Campaign Intelligence Brief): scraped text and the brief are cached for up to 24 hours.

When a workspace is closed, associated personal data in active systems is deleted or de-identified, subject to required retention of transaction records and other legal obligations. Restricted backup copies can remain until their retention periods expire. Deletion from active systems does not mean every backup copy disappears immediately. Individual workspace owners can close from Settings → Security. Other requests go through Data deletion. These product event windows do not set a retention period for website inquiries, marketing correspondence, or legacy-system records. We retain those records as needed for their purpose, account support, and applicable legal obligations; contact us about a particular record.

Your rights

  • Export: the API includes a full-organization export endpoint (GET /api/v1/export) that returns your businesses, campaigns, ledger, and tracking data as one JSON document.
  • Deletion and correction: follow the steps on Data deletion or email support@adwave.com. We will verify and act on eligible requests.
  • Marketing emails: unsubscribe using the link in the email (performance digests and campaign-update reminders). You may still receive transactional messages about your account, campaign launches/pauses, and billing.

For website information or legacy app records, email privacy@adwave.com. Identify the website or account involved so we can locate the relevant system. Product self-service export and closure do not automatically apply to every legacy record.

If you are a visitor to an advertiser's website, direct requests about that site's data to the advertised business (the controller). If you cannot reach them, contact the agency that runs the ads, or email support@adwave.com; we assist the controller in fulfilling such requests.

US state privacy rights

If you are a resident of California or another US state that has a consumer privacy law, you may have rights to know, access, obtain a portable copy of, correct, or delete personal information; to limit certain uses of sensitive personal information; and to opt out of certain sale, sharing, or targeted advertising, subject to legal limits. We do not sell personal information for money. Depending on the applicable law, disclosures for advertising can be subject to rights concerning sale, sharing, or targeted advertising. Business context does not by itself exclude information from every privacy law.

To exercise these rights, email privacy@adwave.com or use Data deletion. We may need to verify your identity (and an authorized agent's authority) before responding. We will not discriminate against you for exercising privacy rights. If we decline a request, we will explain the decision and how to appeal where an appeal right applies. You may also contact your state’s privacy regulator. Browser cookie choices, advertising opt-outs, and unsubscribing from emails are separate choices; one does not necessarily perform the others. The California Attorney General explains these rights in its CCPA guidance.

Security

We use administrative, technical, and organizational measures designed to protect personal information (including encryption in transit, access controls, and salted hashing of sensitive identifiers). No method of transmission or storage is completely secure. See also our Security page.

Changes to this policy

We will update this page when the policy changes and revise the “Last updated” date above. Material changes affecting account holders are announced by email.