Your data stays in your workspace
Customer profiles and audience data live in your isolated VectAd workspace — org-scoped and protected by row-level security. We don't centralize or resell your signal.
Hashed audience export
Customer-match audiences leave as SHA-256 hashes formatted for ad platforms. Raw identifiers are hashed before export — plaintext email and phone never leave VectAd.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. Connector credentials are encrypted with a dedicated key; secrets live in a managed secret store, never in source code.
Tenant isolation & audit
Every workspace is isolated with Postgres row-level security, and privileged actions — connector syncs, audience exports, MCP tool calls — are written to an append-only audit log.
What we request when you connect
We ask only for the scopes needed to read customers (for ingest) or manage the audiences you build (for activation) — least privilege, no surprises. You authorize each connector yourself and can revoke it any time from the provider or from Connections.
| Connector | Purpose | Scopes requested |
|---|---|---|
| Shopify | Read customers (ingest) | read_customers, read_orders |
| Braze | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
| PostHog | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
| Google Ads | Audience activation | https://www.googleapis.com/auth/adwords |
| Meta Ads | Audience activation | ads_management, business_management |
| TikTok Ads | Audience activation | user.info.basic, audience.management |
| TikTok Shop | Read customers (ingest) | — |
| WooCommerce | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
| BigCommerce | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
| HubSpot | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
| Klaviyo | Read customers (ingest) | Scoped API token you generate (read-only where supported) |
What's live vs. in development
We'd rather be transparent than oversell. Here's the honest state of the platform:
Live today
Customer ingest from Shopify, HubSpot, Braze, and Klaviyo. Vector scoring and audience building. Audience activation — pushing SHA-256 hashed Customer Match lists to Meta, Google, and TikTok runs against those platforms' official APIs (subject to each platform approving your ad app and granting the relevant access). Hashed CSV export works on every plan.
Simulated until you ask us to enable it
In-platform campaign management actions exposed to AI agents (reading campaign stats, changing budgets, publishing changes) currently return simulated data so you can build workflows safely. Additional connectors (more commerce, CRM, engagement, data warehouse, and ad networks) are registered on our roadmap and light up as we complete each integration and its platform review.
Sub-processors
The third parties that may process workspace data on our behalf:
| Provider | Role | Region |
|---|---|---|
| Supabase (Postgres) | Primary datastore — your customers, embeddings, and audiences. | Configurable region |
| Cloudflare | Application hosting and edge delivery for the VectAd app and MCP server. | Global edge |
| OpenAI | Embedding and chat models for audience matching and campaign planning. Not used to train shared models. | US |
Compliance & procurement
Data Processing Agreement (DPA)
Available on request for paid plans — email us via the contact page; we typically respond within one business day.
SOC 2
Not yet certified. We follow SOC 2-aligned practices (access control, encryption, logging) and a Type II audit is on our roadmap — ask us for our current posture.
Data residency & deletion
Your data lives in your Supabase project's region. You can export or request deletion of workspace data at any time.
Legal entity & references
VectAd is operated by the team behind vectad.com. Contact us for our registered entity name, address, customer references, and security questionnaire.
Reporting a vulnerability
If you believe you've found a security issue, we want to hear from you. Reach out through the contact page with details and we'll respond quickly. We appreciate responsible disclosure.
Contact security