Privacy Policy
Last updated 14 September 2026
This policy covers the WelcomeAd publisher portal and the serving API your app calls. It describes what we hold, why, and for how long.
1. Who we are
WelcomeAd is operated by [Company legal name] of [registered address], the data controller for the portal. Privacy questions: [privacy@yourdomain].
For the ads delivered inside your app, you are the controller of your users’ data and we act on your behalf. Your own privacy policy has to cover the advertising SDKs your app contains.
2. Account data
For each publisher we store a name, an email address, a role, an account status, and the times the account was created and last active. We use these to authenticate you, to show your apps and earnings, and to contact you about the Service.
Passwords are stored only as an argon2id hash — never in a form that can be read back, by us or by anyone who obtained the database. Accounts carried over from an earlier system may hold a bcrypt hash until the owner next signs in, at which point it is rewritten as argon2id.
3. Sessions and cookies
Signing in sets a single strictly necessary cookie holding a random session token. We store only a SHA-256 hash of that token, so a database leak would not yield a usable session. Signing out deletes the session; an administrator password reset revokes every session for that account.
The portal sets no advertising or analytics cookies and embeds no third-party trackers.
4. App listing data
When you add an app we read its public Google Play listing for the name, icon, developer, category, rating, install count and screenshots, and cache the result so the listing is not re-fetched on every page view. This is public information about the app, not about any person.
5. Ad delivery data
When your app requests a placement and reports an impression or a click, we record: the app, the placement, which demand source filled it, the price and your share, a coarse country, timestamps, and a one-way hash of a device identifier used to cap how often the same device sees the same ad.
We do not collect names, email addresses, phone numbers, contacts, precise location, or the contents of anything a user types. We do not build advertising profiles of your users and we do not sell or share delivery data with anyone other than the demand source that served the ad.
6. Third-party ad networks
Ads are filled by the networks you attach — Google AdMob, Google Ad Manager, or others. Their SDKs run inside your app and collect data under their own privacy policies, which you accept directly with them. That processing is outside our control.
Where the law requires consent for personalised advertising — for example the GDPR and ePrivacy rules in the EEA and UK, or state privacy laws in the US — obtaining and passing that consent to the SDKs is your responsibility as the app publisher. If your app is directed at children, you must declare it and disable personalised advertising accordingly.
7. Administrative access
Administrators can see account details across the network and can reset a password or change an app’s status. Every reset is written to an audit log with who performed it, on whom, by what method, and from which IP address. The audit log never records a password or a reset token.
8. Retention
- Sessions — deleted when they expire or when you sign out.
- Password reset tokens — single-use, and expire within an hour of being issued.
- Delivery records — retained while they may be needed for reporting, payment and fraud investigation, then deleted or aggregated so no device-level row remains.
- Account and payment records — retained while the account is open and afterwards for as long as tax and accounting law requires.
- Audit log — retained as a security record.
9. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable form, object to or restrict how we use it, and complain to your data protection authority. Write to [privacy@yourdomain] and we will respond within the period the law allows.
Deleting an account removes your personal details. Aggregated delivery totals that no longer identify anyone, and records we must keep for tax or fraud purposes, may remain.
10. Where data is held
The Service runs on [hosting provider and region]. If data is transferred outside your country, we rely on the safeguards that apply to that transfer, such as the European Commission’s standard contractual clauses where the GDPR applies.
11. Changes and contact
We will post any update here with a new “last updated” date and notify you of a material change by email or in the portal. Questions, requests or complaints: [privacy@yourdomain].