market4.me
  • Sign in
  • Get started
Sign inGet started

Privacy Policy

Last updated: 2026-08-16

This Privacy Policy explains how market4.me (the "Service"), operated by Bleart Emini, a sole proprietor ("we," "us," "our"), collects, uses, and protects information when you use the Service. It should be read alongside our Terms of Service.

1. Information We Collect

  • Account information: business name, contact email, phone number, service area, business category, website URL, and a short description of what makes your business different — provided by you at signup and in Account Settings.
  • Campaign content: chat messages, ad copy drafts, targeting notes, any inspiration images/ video you upload, ad creative images/videos generated through the Service, and — for a video-format ad on Pro plans — any AI voiceover script and audio, and any background-music prompt/track (curated or generated), attached to that ad.
  • Service-area location data: your business's service area is geocoded to approximate coordinates to power ad-radius suggestions, and, if you use weather-triggered Live Ad Management, to check for active weather alerts in your area.
  • Spokesperson/AI-presenter ad data (Pro and Commercial plans, if you use this feature): a video ad can feature a presenter who talks to camera. By default this is a synthetic AI character generated for your account (a "character sheet" of reference images). You may instead upload a real person's photo or video — yourself, an employee, or hired talent — to use as the presenter instead. If you do, this is personal data about someone who may not be you or your customer, and we also store the written-consent confirmation you give us (a timestamped record of who attested, and their stated relationship to the person depicted) alongside the uploaded photos/video. See Section 4 for what this means for you.
  • Team member accounts (Commercial plan): if you're on the Commercial tier, each team member you invite has their own login (email, hashed password, and, if they enable it, their own two-factor authentication) and an assigned role that controls their access, including access scoped to specific business locations. We also store the email address of anyone you invite who hasn't yet accepted.
  • Sales inquiries (Commercial plan): if you contact us about the Commercial tier through our sales inquiry form, we store the business name, contact email/phone, and message you submit — this may be collected before you have an account with us.
  • Your customers' data: if you use the Leads or Inventory & Sales features, the names, contact info, and notes about your own customers/leads — either entered directly by you, or, if you've connected a Meta advertising account and enabled Business Autopilot, automatically pulled in from Meta Lead Ads/Messenger on your behalf. On Pro plans with Business Autopilot enabled, an AI model may also automatically classify a lead's status (e.g. new/contacted/won) from ingested chat content. This is your data about your customers, not ours — see Section 4.
  • Account verification/security codes: a hashed (not plain-text) 6-digit code and its expiry, generated for signup email verification, optional login two-factor authentication, and password reset — deleted automatically after expiry. If you enable two-factor authentication, we also store a "trusted device" token in your browser (so you're not asked for a code on every login from that device) with no additional personal information in it.
  • Billing information: handled directly by Stripe, our payment processor. We store your Stripe customer/subscription IDs and billing status, not your card number.
  • Website analytics (if you use the Website Building product): if you install our tracking snippet on your own site, we collect page paths, referrers, and a randomly generated browser-local visitor ID (not tied to your visitors' real identity) to show you pageview/visitor counts.
  • Public portfolio embed (if you turn this on): if you enable the public portfolio embed and add its snippet to your own site, your site's visitors' browsers fetch your completed portfolio items directly from us to render the embed. We process visitor IP addresses transiently, only to rate-limit this public endpoint against abuse — we don't log or store them.
  • Account security: a hashed password (we never store your password in plain text) and a session cookie that keeps you logged in.
  • Meta ad performance data (if you connect your own Meta advertising account): we sync that account's ad performance data (spend, clicks, impressions, reach, click-through rate) from Meta daily to power your Analytics dashboard, whether or not Live Ad Management is enabled.
  • Live Ad Management activity (if you use this optional feature): if you additionally opt in to Live Ad Management for a campaign, we also keep a log of every automated and manual budget/targeting change (what changed, when, and the AI's stated reasoning) so you can review what happened after the fact.

2. How We Use It

We use this information to operate the Service: generating ad copy and creative tailored to your business, running the ad-policy guardrail check, showing you your campaigns/leads/inventory/ analytics, processing billing through Stripe, and communicating with you about your account. If you opt in to Live Ad Management, we also use your campaign's real Meta performance data to decide whether and how to adjust its budget/targeting, within the limits you've set — see the Terms of Service for how that feature works. We do not use your business or campaign data to train AI models beyond what's necessary to generate your own drafts, and we do not sell your data to third parties.

3. Third-Party Service Providers

Delivering the Service involves the following subprocessors, each of which processes a subset of your data under their own privacy terms: Anthropic (ad copy/targeting generation, ad-policy and media-quality guardrail checks on generated copy and images, Meta ad-spec conversion, website-scan/brand analysis, spokesperson-ad script generation and claim checks, and, if enabled, Business Autopilot lead classification, Live Ad Management budget/targeting decisions, Supercharged trend research, and AI inventory-capture item classification — receives your business context, chat messages, and, for the relevant features, generated images, an uploaded real presenter's photo (for automated framing/quality feedback), campaign performance data, and cropped regions of stock photos you take with inventory capture), fal.ai (image, video — including spokesperson/ talking-head video — AI voiceover, and background-music generation, plus speech-to-text transcription of your ad's narration audio as part of our automated media-quality check and object detection on AI inventory-capture photos — receives prompts, any inspiration images/video you upload, an uploaded real presenter's photo/video and voiceover audio (to animate that likeness, if you use that option), the shelf/stock photos you take for inventory capture, and, for narration, your voiceover script text and the raw narration audio itself), Meta (if you connect your own Meta advertising account — receives your business/ad account info, targeting, ad creative, and, if you enable Live Ad Management, ongoing budget/targeting changes; if you enable conversion tracking, also receives a one-way cryptographic hash of a lead's email/phone number plus the sale amount, via Meta's Conversions API, for ad-performance measurement; if you enable Business Autopilot, also sends lead/contact data from your Meta Lead Ads/Messenger back to us; if you connect Instagram for organic posting, receives each post you approve — caption, hashtags, and media, which Instagram's servers fetch from us via short-lived signed links), Resend (transactional email — receives your account's contact email address, and, for Commercial-tier team invites, an invited team member's email address, to deliver signup verification, two-factor, and password-reset codes, along with other transactional mail: the welcome email, trial reminders, team invites, and — unless you turn it off — a monthly digest whose body includes your business's campaign, lead, and revenue summary), Stripe (billing — receives your payment details directly, not through us), OpenCage (geocoding — receives your business's service-area text to convert it to approximate coordinates), the U.S. National Weather Service (if you use weather-triggered Live Ad Management — receives your business's approximate service-area coordinates to check for active weather alerts; a U.S. government API, no account or API key involved), MongoDB Atlas (database hosting — stores everything listed in Section 1), Upstash (rate limiting), Fly.io and Cloudflare (application hosting), and Sentry (error monitoring — may capture technical error details, not intentionally your business content). Keep this list in sync with the Terms of Service and the Infra & Integrations table in CLAUDE.md if the stack changes.

4. Your Customers' and Other Third Parties' Data

If you use the Leads or Inventory & Sales features to track your own customers, you are the one collecting and controlling that data — we're processing it on your behalf, as a tool you use, not as an independent party with our own relationship to your customers. You're responsible for having a lawful basis to collect and store your customers' information and for your own privacy disclosures to them.

If you use the spokesperson ad feature with your own uploaded photo or video of a real person, that person may be neither you nor your customer — for example, an employee or hired talent. As with your customers' data, we're processing this on your behalf as a tool you use, not independently reaching out to that person ourselves. You're responsible for obtaining that person's written consent before uploading their likeness, and for your own disclosures to them about how it will be used. We store your confirmation that you've done so (see Section 1) but do not independently verify the underlying release.

5. Cookies and Tracking

We use up to four first-party cookies, all functional (no third-party advertising or tracking cookies on the Service itself): a session cookie that keeps you logged in; if you enable two-factor authentication, a short-lived cookie that tracks a pending 2FA verification during login (expires with the verification code, typically minutes); if you choose "remember this device," a trusted-device cookie (expires after 30 days) so you're not asked for a 2FA code on every login from that browser; and, if you're accepting a Commercial-tier team invite, a similar short-lived cookie that tracks a pending team-invite verification during that signup. If you install the optional website tracking snippet (Website Building product) on your own site, it sets a `localStorage` entry (not a cookie) on your visitors' browsers to generate an anonymous, randomly-assigned visitor ID for pageview counting.

6. Data Retention

If you cancel your subscription, your account data is retained for 90 days (to allow easy reactivation) and then permanently deleted, except where we're required to retain records by law. This applies to everything described in Section 1, including uploaded spokesperson photos/video and their consent records, and Commercial-tier team member and location data. This matches the retention policy stated in our Terms of Service.

7. Your Rights

Depending on where you're located, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To request deletion of your data, see our Data Deletion Instructions page. For any other request — access, correction, or objection — contact us (below); there is currently no self-serve way to export or manage this data from within the Service, so we handle these requests manually.

8. Children's Privacy

The Service is intended for business use and is not directed at children. You must be at least 18 years old to create an account, per our Terms of Service.

9. Security

We take reasonable technical measures to protect your information, including password hashing (argon2id), httpOnly session cookies, and encrypted connections. Every account must verify its email address, and you can additionally enable optional two-factor authentication (an emailed one-time code at login) in Settings for extra protection. If you connect your own Meta advertising account, the access token we store for it is additionally encrypted at rest (AES-256-GCM) — a stronger protection than the rest of your account data receives, because unlike most of what we store, a live token is directly usable against a third-party API if exposed. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

A small number of our own operators can access account data (including data listed in Section 1) through an internal tool, to provide customer support, resolve billing issues, or set up an account on your behalf when you ask us to. This access is not available to the public and is separate from any account-level login.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you by email at least 30 days before material changes take effect, matching our Terms of Service.

11. Contact

Questions about this Privacy Policy, or requests to access/correct/delete your data: art@market4.me.