Legal
Privacy Policy
Last updated 26 August 2026
This policy explains how E Labs Ventures Ltd collects, uses, stores, and shares personal data when you visit meta-ads-mcp.com, create an account, pay for Meta Ads MCP, or call the MCP server.
1. Who we are
Meta Ads MCP is a product of E Labs Ventures Ltd, a company registered in England and Wales (company number 17050248). Registered office: 128 City Road, London EC1V 2NX, United Kingdom. We trade as Meta Ads MCP.
For website accounts, billing, support, and our own marketing, E Labs Ventures Ltd is the data controller. Contact: hello@meta-ads-mcp.com.
We are VAT registered in the United Kingdom. VAT is added to invoices for UK businesses at the prevailing rate. Ask us if you need the VAT number on a tax invoice.
2. What this policy covers
This policy applies to:
- the website at https://meta-ads-mcp.com and related app pages
- accounts, API keys, billing, and onboarding
- the MCP endpoint at https://mcp.meta-ads-mcp.com/mcp
- emails we send (setup guide, token expiry, billing, support)
- live chat on the site (Crisp)
- enterprise enquiry and mailing-list forms
It does not apply to:
- Meta Platforms Ireland Ltd or Meta Platforms, Inc. (Ads Manager, Graph API, your Facebook app)
- OpenAI, Anthropic, Cursor, or any other client you connect to the MCP
- Google, if you paste a Drive link (Google's terms apply to that file)
- any website, pixel, or CRM you run on your own ad accounts
You connect your own Facebook app. Meta is a separate controller for data in your Business Manager, ad accounts, Pages, and pixels. Read Meta's privacy policy and terms as well.
3. Controller and processor
When we are the controller
We decide how to process data about you as a customer or website visitor: name and email on the account, one-time login codes (sent by our auth provider), plan and payment status, API key metadata, support messages, mailing-list signups, and enterprise leads.
When we are the processor
When you use the MCP to read or write Meta advertising objects, you are the controller of that advertising data (and of any personal data inside audiences, lead forms, custom conversions, or customer lists). We process it only on your instructions, to run the tools you call. We do not sell it, train models on it, or use it to market our own products.
That processor activity includes, for example:
- listing ad accounts, Pages, pixels, and campaigns you can already access with your token
- creating or updating campaigns, ad sets, ads, creatives, budgets, and rules
- uploading hashed customer lists or media you point us at
- reading insights you request
- writing an audit log of the tool name, status, ad account id, and duration
You must have a lawful basis to process any personal data you send through the MCP (including customer file audiences and lead data). You must not send special category data or children's data unless you have a valid UK GDPR condition and Meta's policies allow it.
4. Information we collect
You give us
- email address when you sign up or log in (we email a one-time code; there is no account password)
- name, company, and message on the enterprise form
- billing name, address, and payment method (collected by Stripe; we store the Stripe customer id and subscription status, not full card numbers)
- Facebook App ID and App Secret (the secret is encrypted at rest)
- a Meta user access token or System User token (encrypted at rest)
- Meta ad account ids and optional labels you attach to your plan
- API key names (the raw key is hashed; we show the prefix only after creation)
- Google Drive folder or file ids you pass into tools (we do not store Drive OAuth for customers; public-link fetches use a server API key)
- messages you send in live chat, plus any name or email you type in the widget
We collect automatically
- server logs: IP address, user agent, URL, status code, timestamp
- auth cookies needed to keep you logged in
- MCP audit logs: user id, email, tool name, ad account id, success/denied/error, duration, truncated error text
- usage rollups (call counts per day)
- optional analytics and advertising cookies, only if you accept them (see the Cookie Policy)
- Crisp widget data: a session id, device and browser info, pages you viewed while chatting, and the chat transcript
We do not collect from the MCP by default
- the full contents of every Graph API response (tools return data to your client; we log metadata, not creative copy or audience member lists)
- your LLM prompts (those stay in ChatGPT, Claude, or Cursor unless you paste them to us in support)
- card PAN or CVC
If a tool errors, a short error message may be stored so we can debug denials and Meta API failures. We strip obvious secrets (tokens, passwords, authorization headers) before logging.
5. How we use it
- create and secure your account
- take payment, issue invoices, and recover failed charges
- enforce plan quotas, ad account slots, and swap rules
- run the MCP: decrypt your token, call Meta, allowlist accounts, rate limit keys
- refresh or remind you about 60-day user tokens
- send transactional email (welcome, API key created, payment failed, reconnect Meta)
- send the setup guide if you ask for it
- reply to live chat and other support messages
- reply to enterprise pricing requests
- detect abuse, debug outages, and improve reliability
- comply with law, tax, and accounting
- measure marketing performance if you accept analytics or ads cookies
We do not sell personal data.
6. Legal bases (UK GDPR)
We only process personal data when a UK GDPR basis applies:
- Contract (Art. 6(1)(b)): account, MCP, billing, token refresh, support for paying customers.
- Legitimate interests (Art. 6(1)(f)): securing the service, audit logs, abuse prevention, limited product analytics of logged-in use, B2B sales replies. You can object. We balance this against your rights.
- Consent (Art. 6(1)(a) and PECR): optional mailing list; non-essential cookies and pixels. You can withdraw at any time.
- Legal obligation (Art. 6(1)(c)): tax records, responding to lawful requests.
Where we act as processor, your instructions and your own legal bases cover Meta advertising data. Our contract with you (the Terms of Service plus this policy) is the documented instruction to process that data to operate the tools you call.
8. International transfers
The core database is in the United Kingdom (Supabase eu-west-2). Crisp stores chat in the EU (France). Some processors store or access data in the United States or other countries (Stripe, Resend, Vercel, Cloudflare, Meta, Google).
Where UK GDPR requires a transfer tool, we rely on the UK Extension to the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or an adequacy regulation, plus the processor's supplementary measures. Ask hello@meta-ads-mcp.com for a current processor list.
9. How long we keep it
- Account profile and subscription: for the life of the account, then up to 7 years for invoices and tax.
- Encrypted Meta tokens and app secrets: until you disconnect, the token expires, or you delete the account.
- API key hashes: until you revoke the key or delete the account.
- MCP audit logs and daily usage: 24 months, unless we must keep a subset for a dispute or security incident.
- Temp media in storage (mcp-temp): short-lived, typically hours, for Graph uploads only.
- Mailing-list emails: until you ask us to delete them, or 24 months after the last send if the list is unused.
- Enterprise leads: 24 months after the last contact, unless we enter a contract (then as account data).
- Live chat: 24 months after last contact, unless we must keep a thread longer for a dispute. Crisp holds the transcript on its infrastructure.
- Server logs: typically 30 to 90 days.
- Stripe records: according to Stripe's retention and our 7-year finance need.
You can ask us to delete your account. We will remove or anonymise what we no longer need to keep by law.
10. Security
We use measures appropriate to a paid ads API product:
- one-time login codes via email (Supabase Auth). Codes expire. We do not store an account password.
- App secrets and Meta tokens encrypted at rest (AES-256-GCM)
- API keys stored as SHA-256 hashes; the raw key is shown once
- TLS in transit
- row-level security so customers cannot read each other's rows
- allowlisting so tools refuse Meta ad accounts that are not on your plan
- rate limits on MCP keys
- admin-only access to aggregate logs
No method is perfect. You must protect your Facebook app, Business Manager roles, API keys, and LLM workspace. Revoke a key if it leaks. Rotate a token if a laptop is lost.
11. Your rights
Under UK GDPR you can ask to:
- access your personal data
- correct it
- erase it (in some cases)
- restrict or object to processing (in some cases)
- receive a portable copy of data you provided
- withdraw consent where we rely on consent
- not be subject to a solely automated decision with legal or similarly significant effects (we do not make those decisions)
Email hello@meta-ads-mcp.com. We may need to verify it is you. We will respond within one month, or tell you if we need more time.
If you are in the EEA or Switzerland, you have equivalent rights under the GDPR or FADP. If you are a California resident, you can ask for the categories and pieces of personal information we collected about you as a customer, and to delete it, subject to exceptions. We do not sell or share personal information as those terms are used in the CPRA for cross-context behavioural advertising, unless you accept advertising cookies. You can opt out by rejecting those cookies.
12. Email and marketing
Transactional mail (login, billing, token expiry, API key notices) is part of the service. We send it under contract or legitimate interests. You cannot opt out of essential service mail while you have an account.
The homepage setup-guide form is optional. We send that pack only if you submit the form. We will not add you to an unrelated newsletter without a clear ask. You can email us to be removed from that list.
14. Children
Meta Ads MCP is a business tool. It is not directed at anyone under 18. We do not knowingly collect data from children. If you believe we have, email us and we will delete it.
15. Changes
We will update this page when the product or the law changes. The date at the top is the latest version. If a change is material, we will email the account address or show a notice in the dashboard.
16. Complaints
Please contact us first at hello@meta-ads-mcp.com. You can also complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, 0303 123 1113.
If you are in the EEA you may complain to your local supervisory authority. This does not affect any other remedy you have.
Related: Terms of Service and Cookie Policy.