VectAd
Security & Trust

Privacy by construction.

Good targeting and good privacy aren't a trade-off. VectAd is designed so your signal stays yours, raw PII never leaves your control, and you can verify exactly what we access before you connect anything.

Your data stays in your workspace

Customer profiles and audience data live in your isolated VectAd workspace — org-scoped and protected by row-level security. We don't centralize or resell your signal.

Hashed audience export

Customer-match audiences leave as SHA-256 hashes formatted for ad platforms. Raw identifiers are hashed before export — plaintext email and phone never leave VectAd.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Connector credentials are encrypted with a dedicated key; secrets live in a managed secret store, never in source code.

Tenant isolation & audit

Every workspace is isolated with Postgres row-level security, and privileged actions — connector syncs, audience exports, MCP tool calls — are written to an append-only audit log.

What we request when you connect

We ask only for the scopes needed to read customers (for ingest) or manage the audiences you build (for activation) — least privilege, no surprises. You authorize each connector yourself and can revoke it any time from the provider or from Connections.

ConnectorPurposeScopes requested
ShopifyRead customers (ingest)read_customers, read_orders
BrazeRead customers (ingest)Scoped API token you generate (read-only where supported)
PostHogRead customers (ingest)Scoped API token you generate (read-only where supported)
Google AdsAudience activationhttps://www.googleapis.com/auth/adwords
Meta AdsAudience activationads_management, business_management
TikTok AdsAudience activationuser.info.basic, audience.management
TikTok ShopRead customers (ingest)
WooCommerceRead customers (ingest)Scoped API token you generate (read-only where supported)
BigCommerceRead customers (ingest)Scoped API token you generate (read-only where supported)
HubSpotRead customers (ingest)Scoped API token you generate (read-only where supported)
KlaviyoRead customers (ingest)Scoped API token you generate (read-only where supported)

What's live vs. in development

We'd rather be transparent than oversell. Here's the honest state of the platform:

Live today

Customer ingest from Shopify, HubSpot, Braze, and Klaviyo. Vector scoring and audience building. Audience activation — pushing SHA-256 hashed Customer Match lists to Meta, Google, and TikTok runs against those platforms' official APIs (subject to each platform approving your ad app and granting the relevant access). Hashed CSV export works on every plan.

Simulated until you ask us to enable it

In-platform campaign management actions exposed to AI agents (reading campaign stats, changing budgets, publishing changes) currently return simulated data so you can build workflows safely. Additional connectors (more commerce, CRM, engagement, data warehouse, and ad networks) are registered on our roadmap and light up as we complete each integration and its platform review.

Sub-processors

The third parties that may process workspace data on our behalf:

ProviderRoleRegion
Supabase (Postgres)Primary datastore — your customers, embeddings, and audiences.Configurable region
CloudflareApplication hosting and edge delivery for the VectAd app and MCP server.Global edge
OpenAIEmbedding and chat models for audience matching and campaign planning. Not used to train shared models.US

Compliance & procurement

Data Processing Agreement (DPA)

Available on request for paid plans — email us via the contact page; we typically respond within one business day.

SOC 2

Not yet certified. We follow SOC 2-aligned practices (access control, encryption, logging) and a Type II audit is on our roadmap — ask us for our current posture.

Data residency & deletion

Your data lives in your Supabase project's region. You can export or request deletion of workspace data at any time.

Legal entity & references

VectAd is operated by the team behind vectad.com. Contact us for our registered entity name, address, customer references, and security questionnaire.

Reporting a vulnerability

If you believe you've found a security issue, we want to hear from you. Reach out through the contact page with details and we'll respond quickly. We appreciate responsible disclosure.

Contact security