1Who we are
This Privacy Policy explains how "ONEADS" LLC (Armenian: «ՈՒԱՆԷԴՍ» ՍՊԸ) ("OneAds", "we", "us", "our") collects, uses, discloses and protects personal data in connection with the website https://oneads.pro and the OneAds platform.
| Legal name | "ONEADS" LLC («ՈՒԱՆԷԴՍ» ՍՊԸ) |
| Legal form | Limited Liability Company |
| Country of incorporation | Republic of Armenia |
| State registration number | 999.110.1592133 |
| Taxpayer identification number (TIN / ՀՎՀՀ) | 00549385 |
| Registered address | 2 Nar-Dos Street, Kentron, Yerevan 0018, Republic of Armenia |
| Contact for all enquiries, including privacy and data subject rights | support@oneads.pro |
We have not appointed a Data Protection Officer, as we are not required to do so. Privacy enquiries are handled by the contact above.
2What OneAds does, in one paragraph
OneAds is a business-to-business software-as-a-service platform that helps app developers, publishers and marketing agencies plan, run, automate and analyse Apple Ads (Apple Search Ads) campaigns for their iOS apps. The platform connects to the customer's own Apple Ads account and to the customer's own analytics providers, imports campaign and performance data, and provides keyword research, competitor analysis, custom product page testing, lifetime-value modelling, reporting, and automated rules that can adjust bids and campaign settings on the customer's behalf.
The Service is intended for use by businesses and professionals acting in the course of their trade, business or profession. It is not directed at consumers and is not intended for personal or household use.
3The two roles we play
Data protection law distinguishes between the party that decides why and how data is processed (the controller) and the party that processes data on someone else's instructions (the processor). OneAds acts in both capacities, and it matters which one applies to you.
We are a controller for personal data relating to our own relationship with you: your OneAds account, your use of our website and platform, our billing relationship, our support communications and our marketing. Sections 5, 6, 8–17 describe this processing.
We are a processor for the campaign, attribution and revenue data that our customers connect to the platform, including data relating to end users of our customers' mobile apps. Our customer is the controller of that data; we process it only on that customer's instructions. Section 7 describes this processing.
If you are an end user of an app that advertises through Apple Ads and your data has reached us through one of our customers, we are not the right party to contact. Please contact the app publisher directly. We will forward requests to the relevant customer where we can identify them.
4Definitions
Personal data — any information relating to an identified or identifiable natural person. This includes online identifiers such as IP addresses, cookie identifiers, and mobile advertising identifiers.
Customer — the legal entity or individual professional that has registered for the Service. You / your, where used in relation to controller processing, means a visitor to our website, a registered user of the platform, a person acting on behalf of a Customer, or a person who contacts us.
Customer Data — data that a Customer uploads to the platform or that we retrieve from third-party systems on the Customer's authorisation, including Apple Ads campaign data, mobile measurement partner data and subscription analytics data.
Aggregated Insights — statistics, benchmarks, models and reports derived from Customer Data that have been aggregated across multiple Customers and irreversibly de-identified. Defined and governed by Section 8.
GDPR — Regulation (EU) 2016/679, and, where applicable, the UK GDPR and the Data Protection Act 2018.
Armenian Data Protection Law — the Law of the Republic of Armenia "On Protection of Personal Data" (HO-49-N), as amended.
5Personal data we process as a controller
| Purpose | Categories of data | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Creating and operating your account; authenticating you; managing roles and permissions within a Customer workspace | Email address, name (if provided), hashed password, role level, workspace membership, registration date, last login, account status | Performance of a contract (Art. 6(1)(b)); for individuals acting on behalf of a corporate Customer, legitimate interests (Art. 6(1)(f)) in operating the Service | Duration of the account, then 36 months after closure |
| Providing the Service: displaying dashboards, running rules, generating reports | Actions performed in the platform, settings, rule configurations, activity and audit log entries (who changed what, when, and whether the change was manual or automated) | Performance of a contract (Art. 6(1)(b)) | Duration of the account, then 36 months (audit records may be retained longer where required for dispute resolution) |
| Providing a free trial or free tier | Email address, registration date, trial start and end | Steps taken at your request prior to entering into a contract (Art. 6(1)(b)) | 24 months from trial end where no paid subscription follows |
| Billing, invoicing, tax and accounting | Advertising spend totals retrieved from your connected Apple Ads accounts, used to calculate the Usage Fee and to determine whether the Starter Plan free threshold has been reached; and transaction records received from Paddle: transaction identifier, subscription identifier, plan, amount, currency, country of purchase, tax treatment, payment status, billing email, business name and tax identification number where supplied, and truncated payment-method details (card brand and last four digits). We never receive or store full payment card numbers. | Performance of a contract (Art. 6(1)(b)); compliance with legal obligations in accounting and tax law (Art. 6(1)(c)) | As required by Armenian accounting and tax legislation, and in any event not less than 5 years from the end of the relevant reporting period |
| Customer support and communication about the Service | Email address, message content, attachments, ticket metadata, and any information you volunteer | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in responding to enquiries | 36 months from the last message |
| Service messages: outage notices, security notices, changes to terms, billing notices, alerts you have configured | Email address, alert settings | Performance of a contract (Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)) | Duration of the account |
| Security, fraud prevention, abuse detection, rate limiting, and investigating incidents | IP address, user agent, device and browser information, request timestamps, authentication events, failed login attempts, error traces | Legitimate interests (Art. 6(1)(f)) in protecting the Service, our customers and ourselves | 12 months, unless retained longer for an ongoing investigation |
| Product analytics: understanding which features are used, diagnosing usability problems, prioritising development | Pseudonymous usage events, page and screen views, feature interactions, session identifiers, device and browser type, approximate location derived from IP at country level | Consent (Art. 6(1)(a)) where required by cookie rules; otherwise legitimate interests (Art. 6(1)(f)) | 24 months |
| Error and performance monitoring | Error traces and stack traces, which may incidentally contain an account identifier, IP address or request parameters | Legitimate interests (Art. 6(1)(f)) in keeping the Service reliable | 90 days |
| Direct marketing about OneAds features, releases and offers | Email address, name, marketing preferences, engagement metrics (opens, clicks) | Consent (Art. 6(1)(a)); or legitimate interests (Art. 6(1)(f)) where we market our own similar services to an existing customer, subject to an opt-out in every message | Until you withdraw consent or object, or 24 months of inactivity, whichever is earlier |
| Establishing, exercising or defending legal claims; responding to lawful requests from authorities | Any of the above, limited to what is necessary | Legitimate interests (Art. 6(1)(f)); compliance with legal obligations (Art. 6(1)(c)) | Duration of the limitation period applicable to the claim |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your rights and freedoms. You can ask us for a summary of that assessment at any time.
6Where controller data comes from
Most of it comes directly from you: when you register, configure the platform, contact support, subscribe to our newsletter, or simply browse the website. Some of it is generated automatically by your use of the Service. Billing data reaches us from Paddle, which acts as the merchant of record for all purchases (Section 15). We do not buy personal data from data brokers and we do not enrich your profile with data purchased from third parties.
7Customer Data we process as a processor
When a Customer connects a data source to the platform, we retrieve and store data on that Customer's behalf and under that Customer's instructions. The Customer is the controller. This is governed by our Terms of Service and by the Data Processing Addendum, which is set out as Annex A to those Terms.
7.1 What we receive
From the Apple Ads Campaign Management API and Apple Ads Reporting API, on the authorisation of the Customer's Apple Ads account administrator: organisation identifiers, campaign, ad group, keyword, creative set and custom product page structures, bids and budgets, and performance metrics (impressions, taps, installs, spend, conversion counts). Where custom product pages are used, page identifiers are received alongside performance metrics. We also store the API credentials the Customer authorises us to use, encrypted at rest.
From mobile measurement partners (for example Adjust), where the Customer connects them: device-level attribution and event records. These typically include a device advertising identifier or MMP device identifier, install and event timestamps, event names, revenue amounts and currency, country, app version, and the campaign, ad group, keyword and creative attributed to the device.
From subscription analytics providers (for example Adapty), where the Customer connects them: subscription and purchase events, product identifiers, prices, trial and renewal states, refunds, and revenue, linked to a device or user identifier supplied by the Customer's own systems.
From public App Store sources: app metadata, titles, subtitles, descriptions, ratings, review counts, search results and search autocomplete suggestions. This is publicly available business information about apps, not personal data about individuals, and we use it for keyword research and competitor analysis.
7.2 Device advertising identifiers are personal data
We want to be explicit about this rather than bury it. A mobile advertising identifier such as the IDFA, or an equivalent identifier assigned by a measurement partner, is an online identifier and constitutes personal data under the GDPR even though it does not include a name. We process these identifiers because they are what makes it possible to attribute a subscription or a purchase back to the campaign and keyword that produced it — which is the core of what the platform does.
We use them only for that purpose: attribution, cohort construction, lifetime-value modelling, and the counting of paying users within a campaign. We do not use them to build advertising profiles, we do not use them for targeting, we do not combine them with data from other Customers in identifiable form, and we do not disclose them to any other Customer or to any third party except the sub-processors listed in Section 10.
7.3 Our instructions and our limits
We process Customer Data only to provide, secure and support the Service, and to comply with law. We do not process Customer Data for our own independent purposes, with a single exception: the creation of Aggregated Insights, which is described in the next section and which is expressly authorised by each Customer in the Terms of Service and the Data Processing Addendum.
7.4 Retention of Customer Data
Device-level event records are retained for a rolling window of 24 months, which is what our lifetime-value models require in order to compute long-horizon coefficients. Aggregated cohort tables are retained for the duration of the Customer's subscription. On termination, Customer Data is deleted or returned in accordance with Section 12 and with the Data Processing Addendum.
8Aggregated Insights: what we do with de-identified data
This section describes something we consider important enough to state plainly rather than hide in a definitions clause.
We create and use aggregated, de-identified market data. We combine data from many Customers to produce statistics, benchmarks, indices, models and reports — for example, typical cost per install or cost per acquisition ranges by country and app category, keyword competitiveness indices, seasonality patterns, conversion and trial-to-paid benchmarks, and lifetime-value multipliers by subscription type and market.
We use those Aggregated Insights for any lawful purpose, including improving and training the models that power the Service, publishing market research and reports, providing benchmark features to other Customers, and licensing or selling market reports commercially.
We never disclose the sources. Aggregated Insights never identify, and are never accompanied by any information that would identify, the Customer, the Customer's apps, the Customer's campaigns or any individual whose data contributed to them. We do not disclose which Customers, which apps or which campaigns any figure is derived from.
How de-identification works. Before data enters an aggregation pipeline, all direct identifiers are stripped: Customer and workspace identifiers, account emails, app names, bundle identifiers, App Store identifiers, campaign, ad group and creative names, and device and user identifiers. What remains are numerical measurements associated with neutral dimensions such as country, storefront, app category, subscription type and time period.
Minimum aggregation thresholds. We do not publish or make available any Aggregated Insight unless the underlying sample contains data from at least 10 distinct Customer organisations and at least 25 distinct apps, and no single Customer contributes more than 25% of the observations behind any published figure. Where a cell of a benchmark would fall below these thresholds, that cell is suppressed rather than published. These thresholds exist so that no published figure can be traced back to the party that contributed to it.
Legal status. Once data has been irreversibly aggregated and de-identified in this way, it no longer relates to an identified or identifiable person and is no longer personal data within the meaning of Recital 26 GDPR. It is our data, we may retain it indefinitely, and it survives the termination of any Customer relationship. Deleting a Customer's account does not require us to unwind statistics that were computed from it, because those statistics contain no personal data and no attribution to that Customer.
Enterprise opt-out. Customers on an Enterprise Plan may withdraw their authorisation for this use by written notice to support@oneads.pro. The withdrawal takes effect within 30 days and applies to data we receive after that date. It is not retrospective: statistics already computed are not unwound, because they contain no personal data and no attribution to any source. Section 8.4(f) of the Terms of Service sets this out in full.
What is not covered by this. Device advertising identifiers, event-level records, campaign names, keyword lists as configured by a specific Customer, bids, budgets and spend attributable to an identifiable advertiser are Customer Confidential Information. They are never published, never licensed, never shown to another Customer, and never sold.
9We do not sell personal data
To state our commitment without ambiguity:
- We do not sell, rent, licence or trade personal data, Customer Data or any identifiable advertising data to any third party.
- We do not disclose one Customer's campaigns, keywords, bids, spend, conversion data or app performance to another Customer, to a competitor, to an agency, or to anyone else, in identifiable form.
- We do not share personal data with data brokers.
- The only data we make commercially available is Aggregated Insights as defined in Section 8, which is anonymous and carries no attribution to its sources.
- For the purposes of the California Consumer Privacy Act as amended by the CPRA, we do not "sell" personal information and we do not "share" personal information for cross-context behavioural advertising. We run no advertising pixels and no cross-context advertising of any kind.
10Who we share data with
We disclose personal data only to the categories of recipients below.
10.1 Sub-processors and service providers
| Provider | Role | Location | Data involved |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting, compute, database and backup storage | Germany / Finland (EU) | All platform data, including account data and Customer Data |
| Paddle.com Market Ltd and its affiliates | Merchant of record, payment processing, subscription billing, tax, invoicing, buyer support | United Kingdom, United States, and other jurisdictions depending on buyer location | Billing and transaction data |
| Functional Software, Inc. (Sentry) | Application error and performance monitoring | United States | Error traces, which may incidentally include an account identifier, IP address or request context |
| Google LLC (Google Cloud) | Object storage | European Union region | Customer Data delivered as scheduled exports |
| Titan (Neo / Titan Mail) | Hosted email service for our own mailboxes, and delivery of messages submitted through the forms on our website | European Union | Email address, name where provided, message content |
| Resend, Inc. | Delivery of account, security and service email sent by the platform | United States. Sending is configured to the EU region (Ireland); account data, email metadata and delivery logs are stored by Resend in the United States. Transfers are made under the Standard Contractual Clauses. | Email address, name where provided, message content, delivery metadata |
Mobile measurement partners and subscription analytics providers are not our sub-processors. Providers such as Adjust, Adapty and AppsFlyer are engaged by the Customer under the Customer's own contract, and data flows from them to us on the Customer's authorisation. We do not send Customer Data to them.
The table above is our current sub-processor list. Before a new sub-processor begins processing Customer Data, we update this Policy and Annex A to our Terms of Service and republish them with a revised "Last updated" date, at least 30 days in advance. Customers are responsible for reviewing the published versions and may object to a new sub-processor in accordance with Annex A to our Terms of Service.
10.2 Other recipients
Professional advisers — lawyers, accountants and auditors, bound by professional confidentiality, where necessary.
Authorities — courts, regulators and law enforcement, where we are legally required to disclose. We review each request, we disclose only what is legally required, and we notify the affected Customer unless we are legally prohibited from doing so.
Acquirers — in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and to the acquirer being bound by protections no less protective than this Policy. We will notify Customers before their data becomes subject to a materially different privacy policy.
11International transfers
Our production infrastructure is hosted in the European Union. Our personnel operate from the Republic of Armenia and other jurisdictions, and certain sub-processors are located outside the European Economic Area.
Armenia has not been the subject of a European Commission adequacy decision. Where personal data originating in the EEA, the United Kingdom or Switzerland is transferred to us in Armenia, or onward to a sub-processor in a third country, we rely on:
- the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), incorporated into our Data Processing Addendum, using the module appropriate to the relationship;
- the UK International Data Transfer Addendum for transfers subject to UK GDPR;
- the Swiss Federal Data Protection and Information Commissioner's recognition of the SCCs, with the amendments it requires, for transfers subject to Swiss law;
- supplementary technical and organisational measures, including encryption in transit and at rest, access control on a least-privilege basis, and logging of administrative access.
We have carried out transfer impact assessments for the destinations we rely on. A copy is available to Customers on request.
You may request a copy of the safeguards applicable to a specific transfer by writing to us at the address in Section 1.
12Security
We implement technical and organisational measures appropriate to the risk, including:
- encryption of all data in transit using TLS 1.2 or higher;
- encryption at rest for databases, backups and stored third-party API credentials;
- passwords stored only as salted bcrypt hashes; we never store passwords in a recoverable form;
- token-based authentication with short-lived access tokens and revocable refresh tokens;
- role-based access control within each Customer workspace, with distinct owner, administrator, writer, analyst and viewer privilege levels;
- an immutable activity log recording every material change made in the platform, including whether it was made by a person or by an automated rule;
- least-privilege administrative access for our personnel, granted individually, logged, and reviewed periodically;
- confidentiality undertakings binding on all personnel and contractors;
- segregation of production and non-production environments; production data is not used in development or testing;
- automated backups with defined retention, and restoration testing;
- continuous error and availability monitoring;
- a documented incident response procedure.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and we will notify affected individuals and Customers without undue delay where the law requires it. Where we act as a processor, we notify the relevant Customer without undue delay so that the Customer can meet its own obligations.
13Your rights under the GDPR
If the GDPR applies to the processing of your personal data, you have the following rights. They are not absolute and each is subject to conditions and exceptions in the legislation.
Access — to obtain confirmation of whether we process personal data about you, a copy of that data, and information about the purposes, categories, recipients, retention period, the source of the data if not collected from you, and the existence of your other rights.
Rectification — to have inaccurate personal data corrected and incomplete data completed.
Erasure — to have personal data deleted where it is no longer necessary, where you withdraw consent and there is no other basis, where you object and there is no overriding legitimate ground, or where the data has been processed unlawfully. This right does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims. It does not extend to Aggregated Insights, which contain no personal data.
Restriction — to have processing limited to storage only, while the accuracy of the data is verified, where processing is unlawful but you prefer restriction to erasure, where we no longer need the data but you need it for a legal claim, or pending the outcome of an objection.
Portability — to receive personal data you provided to us, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible. This applies where processing is based on consent or contract and is carried out by automated means.
Objection — to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims. You may object to direct marketing at any time, without giving reasons, and we will stop immediately.
Withdrawal of consent — to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal. Unsubscribe links appear in every marketing email. Cookie consent can be changed through the cookie settings control on our website.
Complaint — to lodge a complaint with a supervisory authority, in particular in the EU or EEA member state of your habitual residence, place of work, or the place of the alleged infringement. A list of authorities is published by the European Data Protection Board at https://edpb.europa.eu/about-edpb/board/members_en. In the United Kingdom, the authority is the Information Commissioner's Office (https://ico.org.uk).
How to exercise these rights. Write to us at the privacy contact in Section 1. We respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month. Exercising your rights is free of charge; where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee reflecting our administrative costs, or refuse to act, and we will explain why.
Identity verification. We may ask for information reasonably necessary to confirm your identity before acting on a request. We ask for the minimum needed. If you do not provide it and we cannot identify you, we will not be able to act on the request.
14United States privacy rights
This section applies to residents of California, and, where equivalent rights exist, to residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy statutes.
14.1 Categories of personal information
In the twelve months preceding the effective date of this Policy, we have collected the following categories, as defined by the CCPA: identifiers (name, email address, account identifier, IP address, device identifiers); commercial information (subscription plan, transaction records); internet or other electronic network activity (usage of the platform and website, interactions, error traces); geolocation data at country level, derived from IP address; and inferences drawn from the above, limited to product usage patterns. We do not collect sensitive personal information as that term is defined by the CPRA, and we do not use or disclose personal information for purposes that would require us to offer a right to limit its use.
We collect these categories for the business purposes described in Section 5 and disclose them to the categories of recipients described in Section 10.
14.2 Sale and sharing
We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We have never done so. We have not sold or shared the personal information of minors under 16, and we do not knowingly collect personal information from anyone under 18.
For the avoidance of doubt: the Aggregated Insights described in Section 8 are deidentified information. We maintain them in deidentified form, we do not attempt to reidentify them, and we contractually obligate recipients to do the same, as required by California Civil Code § 1798.140(m).
14.3 Your rights
You have the right to know what personal information we collect, use and disclose; the right to delete personal information, subject to statutory exceptions; the right to correct inaccurate personal information; the right to opt out of sale or sharing; and the right not to be discriminated against for exercising any of these rights. We do not offer financial incentives in exchange for personal information.
To exercise these rights, contact us at the privacy contact in Section 1. We will verify your identity by matching the information you provide against the information we hold. An authorised agent may submit a request on your behalf with written authorisation and proof of identity. We respond within 45 days, extendable once by a further 45 days with notice.
If you are a business customer, note that much of the personal information we hold about your app's end users is processed in the capacity of a service provider under the CCPA. Requests from those end users should be directed to the app publisher.
15Payments
Paddle.com Market Ltd and its affiliates act as the merchant of record for all purchases of OneAds subscriptions. This means Paddle is the seller for the transaction, and Paddle handles payment processing, currency conversion, sales tax, VAT and GST calculation and remittance, invoicing, refunds and chargebacks.
Payment card details are entered directly into Paddle's checkout and are processed by Paddle as an independent controller under Paddle's own privacy notice, available at https://www.paddle.com/legal/privacy. We never receive, see or store full payment card numbers, CVV codes or bank account credentials.
Paddle provides us with the transaction data described in Section 5, which we use for account provisioning, entitlement management, accounting and tax compliance.
Buyer support for payment matters — receipts, cancellations, refunds, tax exemption, and questions about a charge — is available from us at support@oneads.pro, and from Paddle at https://paddle.net. Cancellation, refunds and payment disputes are governed by Sections 7.8 to 7.10 of our Terms of Service at https://oneads.pro/legal/terms.
16Cookies and similar technologies
Our website and platform use cookies and similar technologies. We group them as follows.
Strictly necessary — required for the Service to function: session and authentication tokens, security and anti-abuse cookies, load balancing, and storage of your cookie preferences. These cannot be disabled and do not require consent.
Functional — remember your preferences, such as interface language, selected workspace, table layouts and display settings.
Analytics — help us understand how the Service is used so we can improve it. Set only with your consent where consent is required.
We do not use advertising or remarketing cookies. We run no third-party advertising pixels on our website or in the platform, and we do not build advertising audiences from your visit.
Where consent is required, we obtain it through a consent banner before non-essential cookies are set, and you may withdraw or change it at any time through the cookie settings control available on every page. The cookie settings control lists each cookie in use, with its provider, purpose and lifetime, and lets you change your choices at any time.
Most browsers also allow you to block or delete cookies through their settings. Blocking strictly necessary cookies will prevent the platform from working.
17Automated processing and automated decision-making
The platform performs automated actions. Rules configured by a Customer can, without further human intervention, change keyword bids, adjust cost-per-acquisition goals, pause or resume keywords, ad groups and campaigns, and apply or revert custom product page assignments.
These automated actions are taken in respect of advertising campaigns, not in respect of individuals. They do not evaluate personal aspects of any natural person, and they produce no legal effects concerning any individual and no similarly significant effects on any individual. Accordingly, they do not constitute automated individual decision-making within the meaning of Article 22 GDPR.
We do not make automated decisions about you, and we do not carry out profiling of individuals, that produce legal or similarly significant effects.
18Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has provided us with personal data, contact us and we will delete it.
19Armenian data protection law
As a company established in the Republic of Armenia, we also process personal data in accordance with the Law of the Republic of Armenia "On Protection of Personal Data" (HO-49-N). Under that law you have rights of access, rectification, blocking and destruction of your personal data, and the right to complain to the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia. Where the protections of the GDPR are broader, we apply the broader standard to all individuals, regardless of where they are located.
20Changes to this Policy
We may update this Policy. When we make a material change, we will give notice that is prominent in the circumstances: a notice within the Service, an email to registered users, or both, at least 30 days before the change takes effect where the change is adverse to you. The "Last updated" date at the top always reflects the current version. Previous versions are available on request.
Continued use of the Service after a change takes effect indicates acceptance of the updated Policy, except where the change requires your consent, in which case we will ask for it.
21How to contact us
| All enquiries, including privacy and data subject rights | support@oneads.pro |
| Postal address | "ONEADS" LLC, 2 Nar-Dos Street, Kentron, Yerevan 0018, Republic of Armenia |
| Payment, billing and refund enquiries | Paddle buyer support at https://paddle.net |
22Related documents
- Terms of Service — https://oneads.pro/legal/terms
Apple, App Store, Apple Ads and Apple Search Ads are trademarks of Apple Inc. OneAds is an independent third-party platform and is not affiliated with, endorsed by, sponsored by or otherwise associated with Apple Inc.