Privacy Policy

Last updated: June 5, 2026

This Privacy Policy describes how Individual entrepreneur Vadym Fertsman (FOP Vadym Fertsman) (“NettoCore”, “we”, “us” or “our”), registered in Ukraine, collects, uses, stores, transfers and protects information when you use the NettoCore website and web application available at https://nettocore.com (the “Service”).

NettoCore is an advertising analytics dashboard that helps businesses connect Facebook Ads and TikTok Ads accounts, review campaign statistics and calculate net profit (unit economics). By creating an account or using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Who we are (data controller)

The controller responsible for processing your data is:

  • Entity: Individual entrepreneur Vadym Fertsman (FOP Vadym Fertsman)
  • Jurisdiction: Ukraine
  • Privacy contact: privacy@nettocore.com

2. What data we collect

2.1 Data you provide directly

  • Account data: email address, password (stored only as a salted bcrypt hash — we never store passwords in plain text), display name, team/workspace name.
  • Business data you enter manually: daily sales, sales amounts, cost items, return rate, unit-economics settings, product prices, notes and KPI thresholds.
  • Support requests: information you provide when contacting support.

2.2 Data from connected ad platforms

When you connect a Facebook (Meta) or TikTok ad account via the secure OAuth 2.0 protocol, we receive and store on your behalf:

  • Facebook / Meta (Graph API v21.0): ad account IDs and names, account currency, business name, your Facebook user ID, the read-only (ads_read) permission you granted, campaign IDs, names, statuses and objectives, and daily statistics (impressions, reach, spend, clicks, results/leads). We request read-only access and never create, modify, pause or delete your campaigns, budgets or ad settings.
  • TikTok (Business API v1.3): ad account IDs and names, campaign IDs, names and statuses, daily reporting metrics (impressions, spend, clicks, results). Access is used only to read reporting.
  • Access and refresh tokens issued by these platforms to synchronize your campaign data.

We request the minimum necessary permissions and access only the accounts you explicitly chose to connect.

2.3 Authentication and security data

  • Two-factor authentication (2FA) secrets, if you enable it (stored encrypted).
  • Session tokens (JWT access and refresh tokens).

2.4 Data collected automatically

  • Technical data / logs: IP address, request method and path, response status and timestamps — used for security (rate limiting, abuse protection) and diagnostics. Server logs are kept for a limited time (about 30 days).
  • Browser local storage: we store authentication tokens and interface settings (for example, the theme) so you stay signed in and your preferences are kept.

3. How we use data

We use the data listed above to:

  • provide, maintain and operate the Service;
  • authenticate you and keep your account secure (including 2FA);
  • synchronize and display ad statistics from connected Facebook and TikTok accounts;
  • calculate analytics, unit economics and net profit based on platform data and the values you enter;
  • generate optional AI insights (see section 5);
  • send service emails (email confirmation, password reset, team invitations, token-expiry notices);
  • detect and prevent fraud, abuse, security incidents and technical problems;
  • comply with our legal obligations and the terms of Meta and TikTok.

We do not use your advertising data to serve ads, for profiling unrelated to the Service, or for resale.

4. Legal bases for processing (GDPR)

Where the EU/EEA or UK General Data Protection Regulation (GDPR) applies, we process personal data on the following bases:

  • Performance of a contract — to provide the Service you signed up for.
  • Consent — to connect your Facebook/TikTok accounts and for optional AI analysis. You can withdraw consent at any time by disconnecting accounts or deleting your account.
  • Legitimate interests — for security, fraud prevention and improving the Service.
  • Legal obligation — where we are required to store or disclose data by law.

5. Sharing with third parties and service providers

We do not sell your personal data. We share data only with the following categories of providers and solely to operate the Service:

  • Meta Platforms, Inc. (Facebook) and TikTok / ByteDance — we receive ad data from these platforms via their official APIs within the permissions you granted.
  • Google LLC (Google Gemini AI): if you use the optional “AI analysis” feature, aggregated campaign-results data (for example, campaign names, spend, results and calculated metrics) is sent to the Google Gemini API to generate insights. This data is processed by Google under Google’s terms. The feature is optional and runs only when you start the analysis yourself.
  • Email delivery provider (SMTP): service emails are sent through our email provider (Zoho Mail).
  • Hosting and database: the Service and database are hosted with the provider Ukraine.com.ua, located in Ukraine.

We may also disclose information where required by law, regulation, a legal request, or to protect the rights, property or safety of NettoCore, our users or third parties.

6. Platform-specific terms

6.1 Facebook / Meta platform data

We request read-only (ads_read) access to your advertising data and do not request or use any write/manage permissions. We never change your campaigns or ad account settings. Our use and transfer of data received through the Meta API complies with the Meta Platform Terms and developer policies. Access tokens are stored encrypted and are not shared with unauthorized third parties.

6.2 TikTok platform data

Our use of data received through the TikTok API complies with the TikTok Developer Terms of Service and applicable policies. TikTok data is used solely to provide reporting and analytics to the owner of the connected account, and only in read mode.

7. Data storage and security

We apply technical and organizational safeguards in line with industry standards, including:

  • Encryption of sensitive credentials: Facebook and TikTok access/refresh tokens, as well as 2FA secrets, are encrypted at rest with AES-256-GCM.
  • Password protection: passwords are hashed with bcrypt and are never stored or transmitted in plain text.
  • Transport protection: traffic between your browser and our servers is protected with HTTPS/TLS.
  • Access control: a role model (admin/manager/user), rate limiting on authentication endpoints and optional two-factor authentication.

No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.

8. Data retention

  • Account data and business data are kept while your account is active.
  • Ad data synced from Facebook and TikTok is kept while the relevant account is connected and your account is active.
  • Server logs are kept for about 30 days.
  • When you delete your account or disconnect an ad account, the related data and stored tokens are deleted as described in section 9.

9. Your rights and data deletion

Depending on your jurisdiction (including under GDPR), you may have the right to access, correct, export, restrict or delete your personal data, as well as the right to object to certain processing. To exercise these rights, email us at privacy@nettocore.com.

9.1 Disconnecting ad accounts

You can disconnect any Facebook or TikTok account at any time on the “Connections” page in the Service. Disconnecting deletes the stored access tokens for that account.

9.2 Revoking access on the platform side

You can also revoke NettoCore’s access directly:

  • Facebook: Settings → Business Integrations / Apps and Websites → remove NettoCore.
  • TikTok: TikTok for Business → Manage authorizations → revoke NettoCore’s access.

9.3 Account and data deletion

To delete your account and all related data, email privacy@nettocore.com or use the in-app account deletion feature (where available). We provide a data-deletion endpoint compatible with Meta’s Data Deletion Callback. Upon a verified request, we delete your personal data and stored platform tokens within 30 days, except where retention is required by law.

10. Cookies and local storage

NettoCore uses browser local storage, not third-party advertising cookies, to maintain your login session and store interface settings. We do not use cookies for cross-site advertising or tracking.

11. International data transfers

The Service and database are hosted in Ukraine. Some of our service providers (such as Google, Meta and TikTok) may process data in other countries. Where necessary, we rely on appropriate legal safeguards for such transfers.

12. Children’s privacy

The Service is intended for businesses and users aged 18 and over. We do not knowingly collect children’s personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest revision. We will notify you of material changes through the Service or by email where appropriate.

14. Contact

For any questions about this Privacy Policy or your data, contact us:

15. Governing law

This Privacy Policy is governed by the laws of Ukraine, without prejudice to mandatory data-protection rights you may have under the laws of your country of residence.