Privacy Policy · Effective July 24, 2026

How Vario Ads handles personal information.

ARCHEA DYNAMICS LIMITED, trading as Vario Ads, is the controller for account, billing, security, support, and Vario Ads measurement information described in this policy (2026-07-24-privacy-v5). It applies to public-site visitors, account users, and people who contact us.

Scope and sources

We collect information from you, your browser, and the services you use with Vario Ads.

We process information to provide, secure, bill for, and support the service and—where permitted by your regional settings and choices—to measure it. If you submit information about another person, your business must have authority to do so and give them any required notice.

Directly from you

Account, support, and campaign inputs

This includes information entered in forms, product-page URLs, uploaded images, briefs, instructions, scripts, claims, chats, creator and scene choices, support messages, and privacy or marketing preferences.

From providers

Authentication, billing, and generation status

Clerk provides account identifiers and email; Stripe provides customer, subscription, payment-status, invoice, and billing-period data; generation providers return task identifiers, status, usage, and outputs. We do not receive full payment-card numbers.

From devices and pages

Technical, security, and attribution data

This may include browser and device information, requested path, timestamps, security signals, privacy-permission state, and—only where the applicable regional rule and your choices permit it—random visitor, UTM, campaign, and advertising click identifiers.

Customer-directed content

Controller and processor roles can differ

Your business is normally controller for personal data it chooses to place in campaign content, and Vario Ads acts as processor when handling that data only on the customer's instructions. Vario Ads remains controller for its own account, billing, security, support, and measurement records.

Information we hold

Account records and campaign work follow the workspace and systems used.

The exact information depends on the features you use.

Account and billing

Identity, workspace, subscription, and credit records

We hold Clerk user identifiers, email, workspace identifiers and role, Stripe customer and subscription identifiers, plan and payment status, billing periods, consent records, and the render-credit ledger needed to operate paid access.

Campaign workspace

Creative source material and history

We may hold product URLs and profiles, uploaded product images, briefs, ideas, ranking context, scripts, chat history, selected creators and scenes, transcripts, render requests, generated images and video, provider task IDs, and export records.

Operations

Support, security, and measurement records

We may hold support correspondence, error and provider-status records, limited security and rate-limit data, public-site events, purchase attribution, subscription renewal, payment-failure, cancellation and refund events, consent evidence, and records required to investigate misuse, disputes, or incidents.

Purposes and lawful bases

Each use has a defined reason.

UK data-protection law requires a lawful basis. Different bases apply to different processing.

Contract

Provide the account and paid service

Where the user is personally party to the contract, including a sole trader, we use necessary account, campaign, generation, subscription, and support information to take requested pre-contract steps and provide the contracted service.

Legitimate interests

Secure, operate, and improve Vario Ads

We use proportionate account and representative data to provide the service to business customers, and technical, usage, support, and transaction information to prevent fraud and abuse, protect accounts, diagnose faults, understand performance, improve workflows, enforce terms, and establish or defend legal claims.

Legal obligation

Accounting, compliance, and lawful requests

We process and retain information where a specific duty requires it, including tax, accounting and company records, regulatory obligations, and valid legal or regulatory requests.

Permission

Optional measurement and marketing

We rely on consent where prior consent is required. For US visitors to this 18+ business service, applicable advertising measurement may operate on an opt-out basis unless Global Privacy Control or a site choice disables it. We do not apply that default where we know a stricter rule for a minor or sensitive data applies, and a regional default never overrides a browser or site-specific opt-out.

No significant automated decisions

AI ranks creative work, not people

Vario Ads uses automated systems to generate and rank advertising ideas and outputs. It does not use that ranking to make a solely automated decision about a person that has legal or similarly significant effects.

Required information

Some data is necessary for the contract

Account identity, workspace, billing status, campaign instructions, and necessary technical records are required to provide the relevant service. If they are not provided, the account, payment, or requested generation may not work.

Service providers and disclosure

Information relevant to a selected task is sent to the provider performing it.

Providers handle that information under the terms and settings applicable to the service we use. The provider can vary with the feature and current configuration.

Core infrastructure

Clerk, Stripe, and Cloudflare

Clerk provides identity and authentication. Stripe receives customer and workspace identifiers, plan and subscription details, the accepted Terms version, and—when supplied—consent and attribution metadata for Checkout, payment, invoices, subscriptions, and the billing portal. Cloudflare provides application delivery, security, database, object storage, queues, and related infrastructure. Their published processing terms are available from Clerk, Stripe, and Cloudflare; product coverage and the contracting entity still depend on the active account terms.

AI and media

OpenAI, Google Gemini, and Kling

Depending on the feature, OpenAI processes campaign prompts and structured creative context; Google Gemini processes product or image context; and Kling processes images, transcripts, and video instructions to generate native-audio video. Published processor terms are available from OpenAI and Google. Google requires a paid Gemini API configuration for a UK-facing API client; its Gemini terms then apply the processor addendum. Kling's published API terms describe it as a processor and state that prompts and responses are logged for 30 days; its privacy policy says data is stored on servers in Singapore.

Optional measurement

Google, Meta, and TikTok, when configured and permitted

Where the applicable regional rule and your choices permit it, Vario Ads records limited first-party funnel and attribution events. Configured Google, Meta, or TikTok tags may also load on public pages and receive page views, content views, funnel actions, browser identifiers, and campaign attribution. Marketing tags stay off dashboard and admin pages; permitted dashboard funnel events may instead be sent server-side to Meta. Signed Stripe webhooks create operational purchase and subscription-lifecycle records and may send purchase conversions to Google Analytics 4 or Meta. Meta may receive a one-way hash of the random visitor ID, advertising identifiers, and—for a completed purchase—a one-way hash of the billing email. Campaign creative is not sent to these measurement providers.

Other disclosures

Advisers, authorities, and corporate transactions

We may disclose information to professional advisers, insurers, auditors, regulators, courts, law enforcement, or a buyer or successor where reasonably necessary and lawful. We do not sell personal information for money.

International processing

Some providers may process information outside the United Kingdom.

UK data-protection law requires a valid transfer route before Vario Ads makes a restricted transfer. Depending on the provider and destination, that route may be UK adequacy regulations or approved contractual safeguards with any required assessment.

Safeguards

Protection follows the transfer

A provider's contracting entity, processing location, and transfer route can vary with the feature and account configuration. Contact us for the current information available under our provider terms, including the destination and whether the applicable route is UK adequacy, the UK-US Data Bridge where available, an approved UK addendum or international data-transfer agreement, or another lawful safeguard. You may request a copy of the relevant safeguard, subject to necessary commercial or security redactions. If we cannot identify a lawful route, we will not intentionally make the restricted transfer.

Account-specific record

Published terms are only the starting point

The provider links above show public standard terms, not proof of the contracting entity, account region, product coverage, or transfer route active for a particular Vario Ads account. We must keep that account-specific provider and transfer record separately. Kling's published API terms do not themselves identify an Article 28 DPA or UK transfer safeguard, so any applicable separate arrangement and destination must be confirmed in that record before a restricted transfer of Customer Personal Data. Unless that confirmation is given, use Kling-backed generation only with synthetic or product material that does not identify a real person.

Customer choices

Minimise personal data in campaign material

Product and advertising work normally does not need personal or sensitive information. Remove unnecessary personal details before submitting a page, image, brief, script, prompt, or support attachment to a generation service.

Model use

No Vario Ads training programme

Vario Ads does not use customer campaign content to train its own general-purpose AI model. External providers handle submitted material under the API, account, retention, and model-improvement settings applicable to the service we use.

Cookies and browser storage

Essential storage works automatically; optional measurement follows regional permissions.

Cookies and similar browser storage support authentication, security, billing redirects, privacy choices, and—only where the applicable regional rule and your choices permit it—measurement and attribution.

Essential

Authentication, security, and service state

Clerk and the application use necessary cookies or storage to keep users signed in, prevent abuse, and maintain requested service state. Stripe may use necessary storage on its hosted Checkout and billing pages. These functions cannot be switched off in Vario Ads privacy choices.

Preferences

Privacy permission and campaign fallback

A choice you make remains in first-party local storage until you clear it or its permission-record version is replaced; the matching cookie lasts up to 12 months. An unconfirmed US regional default is held only for the browser session and is re-evaluated on a later session. Temporary campaign fallback data also uses browser session storage. Clearing browser data removes these local copies.

First-party inventory

The storage names, purposes, and lifetimes

vario_privacy_consent stores a choice and permission-record version in local storage and a cookie; the cookie lasts up to 12 months. vario_privacy_regional_permission stores an unconfirmed US regional default in session storage only. vario_marketing_visitor and vario_marketing_attribution store a random visitor ID and permitted campaign or click attribution in local storage only while an optional category is allowed. Registration and paywall deduplication flags are used only with optional measurement; the registration flag remains in local storage and the paywall flag lasts for the browser session. Campaign fallback uses scoped session storage and ends with that browser session. These first-party measurement copies are removed when both optional categories are disabled, when the applicable permission-record version replaces them, or when you clear browser data.

Optional

Permitted browser and server-side measurement

Where the applicable regional rule and your choices allow the relevant category, we may store a random visitor ID and campaign or click identifiers and record limited funnel events. Configured marketing tags may load on public pages; dashboard and admin pages remain tag-free. Permitted events may also be sent server-side to Meta, while completed purchases may be sent to configured Google Analytics 4 and Meta services. Shared browser and server event IDs are used to help providers deduplicate the same action. Local visitor and attribution copies are removed when both optional categories are disabled or browser data is cleared. Campaign creative is not sent to these providers.

Provider credentials

Optional OpenAI key is encrypted

If an authorised user supplies an OpenAI API key in Settings, Vario Ads encrypts it in an HTTP-only, same-site cookie and uses it for requests from that browser session. The user can clear it from Settings; do not place provider keys in campaign text.

Your privacy choices

Accept, reject, opt out, or change optional measurement at any time.

Use the privacy choices link in a public-page footer, or Privacy & data in dashboard Settings, to change your choice at any time. Disabling optional measurement does not prevent account, billing, security, or campaign features.

Advertising

US opt-out; prior consent elsewhere

For US visitors to this 18+ business service, advertising measurement may be enabled for the browser session unless you opt out. In locations requiring prior permission, whenever location cannot be verified, or where we know a stricter minor or sensitive-data rule applies, it remains off until the required permission is obtained. Some US state laws may call advertising disclosures a sale, sharing, or targeted advertising even where no money is paid for the data; choosing the advertising-off control opts out of all three for this browser.

GPC

Global Privacy Control is honoured

If the browser sends Sec-GPC: 1 or exposes the corresponding Global Privacy Control browser property, Vario Ads locks advertising measurement and Meta server conversion delivery off for that browser. We also publish our support at /.well-known/gpc.json. You do not need an account to make or change a browser privacy choice.

Email

An email request is not active consent

Selecting a marketing-email option records an opt-in request only. Vario Ads does not treat it as active marketing consent or send promotional email until the address and choice are verified through a separate process. That request is separate from accepting the Business Terms and from site measurement. After activation, permission can be withdrawn using an unsubscribe method or the contact below; essential account, billing, security, and service messages may still be sent.

Retention and security

Retention depends on the record and why it is needed.

We do not keep every category for the same period. We restrict access and use technical and organisational measures designed to protect information, but no online service can promise absolute security.

Account and campaigns

While needed for the workspace and closure process

Account, workspace, campaign, render, and asset records are kept while needed to provide the account and resolve support, security, or billing issues. To close an account and request deletion, use the contact below. Legal duties and third-party rights may require limited retention.

Billing and disputes

Longer where law or evidence requires it

Accounting and transaction records are kept for the legally required period—commonly six years from the end of the relevant UK company financial year, and longer where required. Consent, complaint, and security records follow necessity, limitation, dispute, and legal-claims criteria rather than a single fixed maximum.

Measurement and rate limits

Bounded operational periods

Browser marketing events are pruned after about 400 days. Purchase, subscription-lifecycle, refund, and visitor-attribution records may be kept longer where needed for billing, consent evidence, fraud prevention, or claims. The preference cookie lasts up to 12 months. Cloudflare and our security controls may process network identifiers for rate limiting; retained application identifiers are one-way, scope-bound hashes rather than raw IP in browser marketing events.

Providers and backups

External copies follow the applicable contract and deletion cycle

Provider-side task data, generated media, logs, and protected backups may remain after active deletion for periods set by the applicable provider terms, account settings, or backup overwrite cycle. We do not intentionally return a deleted backup copy to ordinary use except where necessary for recovery, and deletion must be reapplied after a restore where applicable. Retention may continue where necessary to comply with law, investigate security, or establish, exercise, or defend legal claims. Ask us for the current known criterion for a specific provider or record type.

Your rights

UK users can ask to access, correct, delete, restrict, move, or object to processing.

Rights depend on the information, lawful basis, and legal exceptions. You can also withdraw consent at any time. We may ask for proportionate information to verify identity and authority before acting on a request.

Requests

Use the privacy contact

Tell us the account email, the right you want to exercise, and enough detail to locate the information. We normally respond to a valid UK rights request within one month, subject to extensions and exceptions allowed by law.

Objection

Direct marketing can always be stopped

You can object to direct marketing at any time. You may also object to processing based on legitimate interests; we will stop unless a lawful overriding reason or legal-claims exception applies.

Complaints

Complain to us or the ICO

You may send a data-protection complaint electronically using the privacy contact below; contacting us is not a prerequisite to contacting the regulator. We will acknowledge receipt within 30 days, make appropriate enquiries, keep you informed where the investigation continues, and tell you the outcome without undue delay. You may also complain directly to the UK Information Commissioner's Office through its complaint service.

US state rights

Additional rights may apply

Eligible US residents may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of sale, sharing, targeted advertising, or certain profiling, plus a right to appeal where applicable. The privacy choices control available from public-page footers and dashboard Settings stops browser advertising tags and updates the current pseudonymous visitor permission so later browser-attributed provider delivery, including Meta server conversion delivery, remains off; contact us for account-level requests or an authorised-agent request.

No retaliation

Rights do not reduce ordinary service

We do not unlawfully discriminate because someone exercises a privacy right. A request may affect a feature only where the information is genuinely required to provide it or where deletion closes the relevant account.

Representatives

Authorised agents may submit requests

An authorised agent may act where applicable law permits. We may request evidence of authority and may still need to verify the identity of the person whose information is involved.

People and content safeguards

Do not submit children's or unnecessary sensitive information.

Vario Ads is a business service for users aged 18 or over and is not directed to children.

Children

The service is not for anyone under 18

Do not create an account for a minor or submit a child's personal information. Contact us if you believe information about a child has been provided so we can investigate and take appropriate action.

Sensitive data

Remove what the campaign does not need

Do not upload government identifiers, payment-card data, health records, precise location, biometric templates, special-category information, or other sensitive personal data unless we have expressly agreed a lawful and necessary process in writing.

Changes

We will identify material policy updates

We may update this policy when the service, providers, or law changes. We will change the effective date and give a prominent account, email, or site notice before a material new use where required.

Controller and privacy contact

Contact for questions, requests, objections, and complaints.

Use these details for a privacy request or to ask about a provider, retention period, lawful basis, or international-transfer safeguard.

Brand
Vario Ads
Legal name
ARCHEA DYNAMICS LIMITED
Company number
15791014
Registered in
England and Wales
Contact
help@varioads.com
Registered office
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Location
United Kingdom
Privacy Policy | Vario Ads