Privacy Policy
This Privacy Policy explains how YieldBI collects, uses, shares, protects, and retains personal data.
1. Who we are
YieldBI OÜ ("YieldBI", "we", "us", or "our") is an Estonian private limited company, registry code 17553269, with its registered office at Telliskivi tn 57, 10412 Tallinn, Estonia. YieldBI operates a Meta advertising SaaS platform for direct-to-consumer Shopify brands, including AI-generated creative production, campaign management, conversion tracking via Meta Conversions API (CAPI), and performance optimization.
YieldBI OÜ is the data controller for personal data described in this Policy. Our primary supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
2. What this Policy covers
This Policy applies when you visit yieldbi.com and its subdomains, register for or use the platform, connect a Meta Ads account or Shopify store, use AI creative-generation features, or communicate with us.
It does not cover end-consumer data processed on your behalf through our platform, including CAPI integrations. For that processing, we act on your instructions as processor and the DPA applies. Third-party websites have their own privacy policies.
3. Personal data we collect and why
We collect account and contact data (name, email, work role, organization, login credentials, and billing information) to create and manage accounts, authenticate access, process payments, issue invoices, and provide service communications. The legal basis is performance of contract and, for records we must retain, legal obligation.
When you connect Meta or Shopify, we access identifiers, campaign structures, ad sets, creative assets, performance metrics, audience configurations, and configured storefront events. We use this data to provide campaign management, optimization, reporting, and creative features; the legal basis is performance of contract.
We process brand assets, creative briefs, prompts, and generated images, video ads, voiceovers, and scripts when you use AI features. We process technical and usage data, such as device and browser type, IP address, approximate location, pages and features accessed, timestamps, error events, and feature usage, to maintain, debug, secure, and improve the platform. We also process communications and marketing-preference data to respond to you and provide support.
We do not knowingly collect sensitive personal data or personal data from individuals under 18. We do not collect or store end-consumer personal data beyond what passes through CAPI at your instruction.
4. AI and automated processing
We do not use Customer Data, including brand assets, creative briefs, scripts, product images, videos, or generated Outputs, to train, fine-tune, or improve our or a third party's AI models without your explicit, separately granted written consent.
Before your first use of an AI feature that sends Inputs to a model supplier, we ask for explicit consent to that transfer so we can fulfil your request. You may decline and continue using other platform features. AI-assisted reporting uses only the aggregate performance metrics, labels, and filters necessary to answer your request; we do not send identifiers, credentials, tokens, or lead/customer contact data.
Our optimization algorithm analyzes your connected campaign and performance data to generate recommendations and settings. It does not make automated decisions about you with legal or similarly significant effects; campaign changes require your authorization.
5. Sharing and sub-processors
We share personal data only with service providers necessary to deliver the platform, Meta when you use CAPI on your behalf, and authorities or corporate counterparties where legally required. We do not sell or rent personal data, share Customer Data with other customers, disclose it to advertising networks to target your customers, or use it for our own campaigns directed at your customers.
Current providers include OpenAI for image and script generation, ElevenLabs for audio generation, Seedance for video generation, Stripe for payments, and AWS for hosting. Where personal data is transferred outside the EU/EEA, we use appropriate safeguards such as EU Standard Contractual Clauses or the EU-US Data Privacy Framework where applicable.
6. Retention and deletion
We retain personal data only as necessary for the purposes in this Policy and as required by law. Account and creative-workspace data are ordinarily retained for the account lifetime plus 30 days after cancellation. Connected platform data is retained on a rolling basis according to your plan, up to 30 days (Starter), 90 days (Growth), or 12 months (Scale), and for 30 days after cancellation. Billing records are retained for 7 years, support communications for 3 years from last contact, technical logs for 90 days, and backups are overwritten within 90 days of primary-data deletion.
Account deletion requires an authenticated user to log in and use the account-deletion option in account settings. The privacy request form is limited to marketing data and marketing communications. Following a verified marketing-data request, we delete connected-platform data that was not independently created or edited in YieldBI across production systems within 30 days, subject to legal-retention obligations. Data in backups is deleted within 90 days of the corresponding primary-data deletion.
You can end your Meta integration in two ways, with different effects on data. Disconnecting directly within YieldBI promptly deletes Meta-sourced data linked to that connection that was not independently created or edited in YieldBI. A valid Meta data-deletion callback is handled the same way. Revoking YieldBI's access in Meta settings immediately stops access to the relevant Meta assets but does not itself delete previously synced data; that data remains subject to the applicable retention schedule until you disconnect within YieldBI, Meta sends a valid data-deletion callback, or the data ages out. These events do not delete assets held directly by Meta or content independently created in YieldBI. Reconnecting creates a new authorization and does not restore deleted local data.
7. Your privacy rights
If you are in the EEA, UK, or Switzerland, you may have rights to access, rectify, erase, restrict, receive, or object to processing of your personal data; withdraw consent; and complain to a supervisory authority. California residents may have rights to know, access, correct, delete, opt out of sale or sharing for cross-context behavioral advertising, and non-discrimination. Residents of other US states may have similar rights where applicable.
- Email: privacy@yieldbi.com
- Privacy request form: yieldbi.com/privacy-request
- We respond to GDPR requests within 30 days (extendable to 90 days for complex requests with notice) and CCPA requests within 45 days. We may ask you to verify your identity.
- You may complain to Andmekaitse Inspektsioon (aki.ee) or the authority where you live or where an alleged infringement occurred.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or disclosure, including encryption in transit, encryption at rest, role-based access, least-privilege permissions, multi-factor authentication for internal access, and incident-response procedures. No internet transmission or electronic storage method is completely secure.
Where a personal data breach is likely to risk individuals' rights and freedoms, we will notify the relevant authority and affected individuals as required by applicable law, and notify affected customers where necessary to support their own obligations.
9. Cookies and tracking technologies
We use cookies and similar technologies. On yieldbi.com, we obtain consent before placing non-essential cookies, and you can change preferences via Cookie Settings in the footer. Marketing and attribution cookies may constitute sharing under California law; California residents may opt out through Cookie Settings or by contacting privacy@yieldbi.com. We honor Global Privacy Control signals as an opt-out of sale or sharing for cross-context behavioral advertising.
The platform application uses strictly necessary cookies for authentication, session management, and security. Third-party embedded content may set its own cookies under its own policies.
10. Changes and contact
We may update this Policy to reflect changes in practices, technology, legal requirements, or other factors. We will notify registered customers of material changes by email at least 30 days before they take effect. The Last updated date reflects the most recent revision.
For privacy questions, rights requests, or complaints, contact privacy@yieldbi.com. For security enquiries, contact support@yieldbi.com. YieldBI OÜ's registered address is Telliskivi tn 57, 10412 Tallinn, Estonia.
Submit a request through our privacy request form.