Privacy Policy
This policy explains what data we collect when you visit the ivmero website and use the ivmero service, why we process it, and who we share it with.
1. Controller
The controller for the ivmero service is ROADMAP Danışmanlık Anonim Şirketi, Kağıthane, Istanbul, Turkey. For data protection matters: privacy@ivmero.com
2. Data we collect
- Data you give us: name, work email, phone number, store URL, monthly ad budget range and any notes in the demo request form
- Data from your connected accounts: campaign, spend, conversion and product-level performance metrics from Google Ads, Google Merchant Center, Meta Ads, TikTok Ads and GA4
- Product data: title, brand, price, cost, stock, category and variant fields read from your XML or product feed
- Technical data: IP address, browser and device information, pages visited and session duration
3. Why we process data
- To provide the service: calculating product scores, producing the 13 segments and preparing label recommendations
- To respond to demo requests and communicate with you
- To keep the service secure, detect faults and prevent abuse
- To measure site usage — only with your consent
4. Our approach to customer data
The data you connect is processed solely to deliver the service to you. We do not sell it, we do not use it for advertising to third parties, and we do not use it to train general-purpose machine learning models.
5. Google user data we access
Through the official Google APIs we read, with your authorisation:
- Google Ads: campaign, ad group and product-level spend, conversion and revenue metrics; custom_label 0-4 fields
- Google Merchant Center: product feed status and disapproval reasons
- Google Analytics 4: product-level event and funnel data
6. Sharing and transfer of Google user data
ivmero’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features of ivmero; it is never transferred to third parties except as necessary to provide the service, for security purposes or to comply with applicable law, and it is never used for advertising or sold.
Write access is limited to product label (custom label) fields. Campaign structures, budgets and bids are not modified.
7. Meta user data
Through the Meta Marketing API we read ad set and product set metrics and, where you approve it, write product set labels. Access is granted through Meta’s own authorisation screen and can be revoked at any time.
8. Processors
We work with the following suppliers to deliver the service. Any change to this list is published on this page.
| Processor | Service | Data location |
|---|---|---|
| Amazon Web Services EMEA SARL | Server, database and backup infrastructure | European Union |
| Vercel Inc. | Website hosting | European Union |
| Sendinblue SAS (Brevo) | Delivery of the demo request form and contact list | European Union |
| Google Ireland Ltd. | Site usage statistics (Google Analytics 4) | European Union |
| Anthropic PBC | Large language model generating rule recommendations | United States |
| Functional Software, Inc. (Sentry) | Error and fault logging | European Union |
9. International transfers
Our server, database and backup infrastructure is hosted in the European Union. Transfers outside the EEA are made under the European Commission’s Standard Contractual Clauses or an applicable adequacy decision, together with the requirements of Article 9 of Turkish Law No. 6698.
10. Security
- All traffic between your browser, ivmero and third-party APIs is encrypted with TLS.
- OAuth tokens are stored encrypted at application level and are never written to logs.
- Access rights are role-based, logged, and access to production systems is restricted.
- Backups are encrypted and restore procedures are tested regularly.
11. Retention and deletion
Demo request data is kept for 24 months. Service data is kept for the term of the contract; after the contract ends or access is revoked, it is deleted within 30 days, except where a statutory retention period applies.
12. Your rights
You have the rights set out in Articles 15 to 22 GDPR — access, rectification, erasure, restriction, objection and portability — and the equivalent rights under Article 11 of Turkish Law No. 6698. Send requests to privacy@ivmero.com; we respond within one month. You may also lodge a complaint with your supervisory authority.
13. Changes and contact
Changes to this policy are published on this page with a revised date. For questions: privacy@ivmero.com · Security reports: security@ivmero.com
