01Who you are contracting with
AdCrime is operated by Staromeda OÜ, a private limited company registered in Estonia, European Union. Staromeda OÜ is the contracting party on every plan, the data controller for your account data, and the data processor for the scan inputs you give us.
- Legal name: Staromeda OÜ
- Registry code: available on request
- Registered address: available on request
- Jurisdiction: Republic of Estonia. Our terms are governed by Estonian law.
- Contact for legal, privacy and security matters: mario@adcrime.com
AdCrime is independent. It is not affiliated with Google or with any affiliate network, and it does not take money from publishers.
02What AdCrime needs from you, and what it never touches
The service works from the outside. To monitor a brand we need three things: the brand name, its official domain, and the search terms to watch. That is the whole integration.
- Nothing is installed on your website. No tag, no script, no pixel.
- No access to your analytics, your ad accounts, or your CRM.
- No login to your affiliate network. We never hold your network credentials or API keys, and we never act inside your program on your behalf.
- No access to your customers' data. The evidence we collect is about publicly visible advertisements and the publicly reachable pages they lead to.
The output is a case file you can hand to your network's compliance desk. Filing it is your decision and your action.
03What data we hold, and where
We hold three kinds of data, and we keep them apart:
- Account data - your name, work email, and billing status. This is the only personal data the service needs.
- Scan inputs - brand names, official domains, and keywords. Business data, not personal data.
- Evidence - captured advertisements, redirect chains, tracking parameters, coupon codes, and screenshots of public pages, together with our classification and its written reason.
Application data is stored in the European Union. Where a provider processes data outside the EEA, transfers rest on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Full detail is in our privacy policy.
04Sub-processors
Every provider below is bound by a data processing agreement and may use your data only to deliver its service to us. We give customers on a signed DPA thirty days' notice by email before adding a sub-processor that will handle their personal data.
| Provider | Purpose | Personal data | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account data, scan inputs, evidence | EU data region |
| Vercel | Application hosting and content delivery | Request logs (IP address, user agent) | Global edge; SCCs / DPF |
| Stripe | Payments and subscription billing | Billing name, email, payment method (we never see card numbers) | EU / US; SCCs / DPF |
| Google Workspace | Email correspondence and report delivery | Name, email, message content | EU / US; SCCs / DPF |
| Scanning infrastructure | Running public search queries and loading public pages | None. These systems see brand keywords, never account data | Multiple regions, matching the markets scanned |
05Security measures
What follows is what we actually do. We hold no third-party certification (no SOC 2, no ISO 27001) at this stage of the company and will say so plainly rather than imply otherwise. Security questionnaires are answered in writing within five business days.
- Transport. TLS on every connection, HTTP Strict Transport Security with a one-year max-age, and no plaintext fallback.
- Browser hardening. Framing denied (X-Frame-Options and CSP frame-ancestors), MIME sniffing disabled, same-origin referrer policy, and camera, microphone and geolocation permissions switched off site-wide.
- Storage. Account data, scan inputs and evidence records are encrypted at rest and in transit on the database platform. Evidence screenshots are served from our own infrastructure under unguessable identifiers; they depict public web pages and carry no account data.
- Authentication. Managed authentication with server-side sessions. Dashboard routes are protected at the edge before any page code runs.
- Payment data. Handled entirely by Stripe. Card numbers never reach our systems.
- Access. Production access is held by the founder alone. There is no support tier with customer-data access and no third party with standing production credentials. Administrative actions on customer accounts are written to an audit log.
- Isolation between customers. Evidence is scoped to the account that commissioned the scan. Cross-brand offender intelligence shares one number across the boundary - the count of brands an operator was flagged on - and never which brands.
06Incidents and vulnerability reports
If we confirm a security incident affecting your data, we notify you by email without undue delay and no later than 48 hours after becoming aware of it, with what happened, what data was involved, and what we are doing about it. That leaves you time to meet your own 72-hour obligation to your supervisory authority.
Found a vulnerability? Email mario@adcrime.com with “Security report” in the subject. You will get a human acknowledgement within two business days. Please test only against accounts you own, and do not access other customers' data. We do not run a paid bounty program.
07Retention, export and deletion
- Evidence and scan history stay available for as long as your account is active. It is yours: export it whenever you like, on every plan, and keep it if you leave.
- Ask us to delete your account and we remove account data, scan inputs and evidence within 30 days, except billing records we are required by Estonian law to keep.
- The 30-day refund on every plan does not claw back the evidence. You keep it either way.
08Data processing agreement
Customers who need a signed Article 28 GDPR data processing agreement can use ours. The full text is published at adcrime.com/trust/dpa, with the processing details, the technical and organisational measures, and the sub-processor list as annexes.
To execute it, email mario@adcrime.com with your legal entity name and the account email. We return a countersigned copy within two business days. If your organisation requires its own paper, send it and we will review it.
09Changes to this page
This page describes the service as it is run today. When something material changes - a new sub-processor, a change in data location, a certification we obtain - the “last updated” date above moves and customers on a signed DPA are told by email.
Reviewing us for procurement? Send the questionnaire to mario@adcrime.com. - Staromeda OÜ, Estonia, EU.