Privacy Policy
Last updated: October 5, 2026
1. Overview
AdVantage ("we", "our", "the extension") is a Chrome extension that enhances the Facebook Ads Library experience. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your data.
2. Data We Collect
| Data Type | What Specifically | Where Stored | Purpose |
|---|---|---|---|
| Google Account | Email address, display name, Google user ID | Firebase Authentication (cloud) + browser memory | Sign-in and scan limit enforcement |
| Marketing Email Consent | Whether you ticked the optional "I'd like to receive product updates and promotions by email" box on the consent screen (yes/no), together with the date you accepted the Terms and this Policy. The box is optional and unticked by default; the extension works exactly the same either way. | Firebase Firestore (cloud), on your account record | Deciding whether we may email product news and offers to your Google account address. Never sold, never shared with third parties, never used for ad targeting. You can withdraw this consent at any time — see Marketing emails. |
| Guide Newsletter (landing pages) | The email address you type into the "Get new guides by email" form on our landing pages; the consent text shown next to the checkbox and when you ticked it; the page and language you subscribed from; when you pressed the link in the confirmation email. If you accepted advertising cookies on the site, also a random event ID and that consent state. This form does not require a Google account or sign-in. Your IP address is not stored; only an irreversible hash of it is used to limit abuse. The form appears only while sending is switched on. | Firebase Firestore (cloud); emails are sent through Resend (an email delivery service) | Double opt-in: after you submit the form you get one confirmation email and nothing else unless you press its link. After confirming: new guide announcements and a four-email getting-started series in the first week. Never sold. If you accepted advertising cookies on the site, the moment you confirm is reported to our advertising platforms as a conversion; your email address travels in that report only as an irreversible hash (SHA-256). One-click unsubscribe link in every email; to have your record deleted, write to advantagescope@gmail.com. |
| Scan Count | Number of scans started per limit window (6 hours, all plans) | Firebase Firestore (cloud) + chrome.storage.local | Plan scan-limit tracking (all plans) |
| Filter Count | Number of times you press "Filter" to apply a pending filter change, counted in the same 6-hour window as the scan count above | Firebase Firestore (cloud) | Plan filter-limit tracking (all plans) |
| Saved Ads | Every field read from the ad card — ad ID, brand name, domain, CTA, landing URL, days running, headline, description, ad text, media links, creative count and the other card attributes. The content stays on your device and is never uploaded to our servers. Saving does send one thing: a save counter on the ad's public ID, linked to your account (see the row below). Removing a save decrements that same counter. | chrome.storage.local (your device only) | Your personal ad collection/export |
| Preferences | Language, theme, filter settings, font sizes | chrome.storage.local (your device only) | Remembering your settings |
| Seen Ads | Ad IDs you have viewed (for "New ads only" filter) | chrome.storage.local (your device only) | Filtering previously seen ads |
| Ad Popularity Counters | Public Facebook Ad Library ID of the ads listed in front of you + aggregate counters linked to your account: how many times an ad was listed, how many times it was saved, and the approximate time the mouse pointer rested on its media area (image or video). No ad content (no brand name, no text, no URLs) is transmitted — only the public ID. The ads you save stay on your device and their content is never uploaded; what reaches us is a single save counter on the ad's public ID, linked to your account. Removing a save decrements the same counter. | Firebase Firestore (cloud) — shared counters across all users | Measuring service quality, detecting popular ads/trends, abuse (fraud/bot) detection |
| Interaction Records | Which account was shown which public ad IDs, and how many interaction events that batch contained. Neither the type of each interaction nor any per-ad duration is stored in this record. | Firebase Firestore (cloud) | Abuse detection and usage analytics — ad content is never stored, only the public ID is referenced |
| Search History | The search terms you enter in the extension, the filters applied with them (country, media type), and the public ad IDs surfaced by that search — linked to your account | Firebase Firestore (cloud) | Product development (understanding which searches surface which ads), quota enforcement and abuse detection. Never shared with third parties, never used for advertising. Deleted when you delete your account. |
| Usage Statistics | Hourly and daily scan counters (aggregate). Daily feature-use counts (e.g. panel opens, scans started/finished and their card counts, filters applied, exports, quota limits reached, upgrade link clicks, errors) — numbers only, never ad content, URLs, search text or your email. | Firebase Firestore (cloud); four of the counters (install, panel opened, scan started, upgrade button clicked) are also forwarded by our server to Google Analytics 4 (see section 7) | Performance measurement, abnormal usage (bot/automation) detection, product improvement (which features are used) |
| Session & Security Data | At sign-in: IP address, a device identifier generated by the extension, and browser information (user agent). For the concurrent-computer limit of your plan, your account record also keeps, per recently active computer, an irreversible hash of the device identifier, a coarse name (e.g. "Chrome · Windows") and the last-active time; computers no longer active are removed at your next scan or filter, the whole list is deleted after 90 days without use, and with your account. | Firebase Firestore (cloud), retained max. 90 days | Abuse prevention and enforcement of our Terms of Use (e.g. multi-device account sharing, limit circumvention, ban evasion). Never used for advertising. Accounts banned for abuse are not eligible for refunds — see Terms of Use. |
| One-time Offer Record | When a one-time welcome bonus is claimed: an irreversible hash of the device identifier, an irreversible hash of the IP address, and your account ID. No raw device identifier or IP address is stored in this record. | Firebase Firestore (cloud), kept for as long as the offer exists | Enforcing "one bonus per device" and slowing down multi-account abuse. This record is deliberately not deleted after 90 days — if it were, the same device could claim the bonus again. Never used for advertising. |
| Feedback & Diagnostics | Only when you press "Send" on the feedback form. Your message, plus a diagnostic report shown to you in full, in a read-only box, before you send it. The report contains: extension and Chrome version, operating platform, screen resolution, device RAM, the path only of the Ad Library page you were on (query parameters — including what you searched for — are stripped), counts of ads scanned in the session, the public Ad Library IDs of the last 10 ads listed, your extension settings, and the last 200 console log lines from the extension. | Firebase Firestore (cloud), retained max. 90 days | Reproducing and fixing the problem you reported. Nothing is sent unless you press Send. Never used for advertising or shared with third parties. |
| Payment Card Identifier | Card brand and last 4 digits only (e.g. "Visa •••• 4242"), as provided by our payment processor Lemon Squeezy at checkout. We never see, collect, or store your full card number, expiry date, or CVC — payment is handled entirely by Lemon Squeezy. | Firebase Firestore (cloud), tied to your account | Prevents a card previously banned for abuse from being used to open a new account. Never used for advertising or shared with third parties beyond our payment processor. |
| Error Reports | Automatic, while you are signed in. When the extension hits an unexpected error, it records the name of the operation that failed, the error message (truncated to 500 characters), and the extension version. Capped at 10 records per session. No ad content, no search terms and no page URLs are included. | Firebase Firestore (cloud), retained max. 90 days | Finding and fixing crashes you would otherwise have to report by hand. Never used for advertising or shared with third parties. |
3. What We Do NOT Collect
- Ad creative content — no images, videos, brand names, headlines, ad text, CTAs, or landing/media URLs are ever uploaded or transmitted to our servers. Only the public Facebook Ad Library ID is referenced.
- Your Facebook account information or cookies
- Browsing history outside of facebook.com/ads/library
- Payment information (handled entirely by Lemon Squeezy, our payment processor)
4. How Data Is Used
- Google account info is used to authenticate you and track your scan limit, and is never sold. The one exception: if you chose Marketing in the cookie bar, your email address is sent to Meta only in hashed (SHA-256) form for ad measurement (see Meta Pixel and Conversions API).
- Scan count in Firestore is used to enforce each plan's scan limit (500 scans per 6-hour window on Free). It contains no ad content.
- Filter count in Firestore is used to enforce each plan's filter limit (100 filter applications per 6-hour window on Free, same window as the scan count). It contains no ad content.
- Ad popularity counters, interaction records and usage statistics are used to measure service quality and detect abuse (fake accounts, bots, excessive automation). They reference ads only by their public Facebook Ad Library ID and are never used for advertising or sold to third parties. The only exception to sharing is the four usage counters (install, panel opened, scans, upgrade clicks) that our server forwards to Google Analytics only if you agreed to share usage statistics, as described in section 7; they are never used for advertising or sold.
- Saved ads and preferences are stored locally on your device (chrome.storage.local). Their content never leaves your browser unless you explicitly export it to Google Sheets — the only thing saving sends us is the save counter on the ad's public ID, linked to your account, described in the table above.
5. Google Sheets Export
If you use the Google Sheets export feature, the extension:
- Requests a Google OAuth token via
chrome.identity.getAuthTokenwith thedrive.filescope — access is limited to the single spreadsheet you pick, not your whole Drive - Writes your saved ad data directly from your browser to the Google Sheet you specify
- Does not route this data through our servers — the request goes browser → Google Sheets API directly
6. Google API Services & Chrome Web Store Compliance
AdVantage's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
The use of information received from this extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Data from the extension (installation, sign-in and use of the side panel) is never used for advertising and is never sent to advertising platforms such as Meta, TikTok or Google Ads. Advertising measurement runs only on this website, only with your Marketing consent.
AdVantage is developed and maintained in accordance with the Chrome Web Store Developer Program Policies, including the prominent-disclosure standards described in the User Data FAQ.
7. Data Sharing
We do not sell, trade, rent, or share your personal data with any third parties, advertisers, or data brokers.
Third-party services involved in the extension are:
- Google Firebase — our backend (Firebase Authentication, Cloud Firestore and Cloud Functions). It handles sign-in and stores the cloud data listed in section 2: your account record (plan, scan and filter limits, marketing-email consent, payment card identifier), ad popularity counters linked to your account and interaction records, search history, usage statistics (including daily feature-use counts), session and security data (a hash of your IP address, a device identifier and browser information), the one-time offer record, feedback you send, error reports, and payment event records from our payment processor. Section 8 explains what is deleted, anonymised or kept when you delete your account. (Firebase Privacy Policy)
- Google Sheets API — only when you explicitly trigger an export
- Extension usage statistics (optional). The extension itself contains no analytics script. The "Share usage statistics" switch is off by default: no counters are sent until you turn them on yourself. You can turn them on in the extension (Settings > Privacy) or on your web profile; the choice is synced to your account (stored as a consent record on your account document) and can be withdrawn at any time. Only if you turn them on, the extension counts seven groups of panel events on our own server: install, panel opened, scans, ad card views (including card conversions), filters, exports and upgrade-button clicks. On our server they are kept against your account (quota and abuse protection need that link). Search terms, ad content and personal data are never sent. Of these, only install, panel opened, scans and upgrade clicks are forwarded to Google Analytics 4, under a pseudonymous identifier derived from your account ID by one-way hashing (not your email, name or account ID; the website uses the same one-way identifier and never your raw account ID), marked non-personalized with Google's ad_user_data and ad_personalization signals set to denied. They are never used for advertising, profiling or sold. If usage statistics are off, none of them is sent and pending ones are deleted. A purchase made from the extension is reported to Google Analytics 4 only with this consent, and never to Meta. The counters are never used for advertising.
Service counters are separate: "quota reached" (quota_hit) and "error count" (error). The service needs them to enforce plan limits and spot faults, so they go to our own server whatever you chose, are never forwarded to Google Analytics and are not used for advertising.
On the website only (advantagescope.io) — and only with your choice in the cookie bar (Analytics or Marketing, as noted for each tool below). The browser extension itself loads none of these; they are website scripts and never ship inside the extension package:
- Google Analytics 4 — page views and traffic sources (before you choose, only a cookieless signal is sent, see below). Google Analytics 4 does not log or store IP addresses
- Meta Pixel and Conversions API (only if you choose Marketing in the cookie bar) — we measure which ads lead to sign-ups and purchases. The browser pixel sends the event; our server sends the same event to Meta as well (Conversions API), so that measurement survives ad blockers. The server event can carry a hashed (SHA-256) email address, a hashed account ID, your IP address, browser user agent, your country, Meta's click/browser identifiers, plus order value and currency. With Marketing we also set a random visitor ID in a first-party cookie (
_fba_vid, not derived from your account); the pixel and our server send it to Meta, the server only as a SHA-256 hash, and it is deleted as soon as you withdraw Marketing. If you buy, the same ID is also written to the order's custom data at Lemon Squeezy and stays in that order record after you withdraw. If you allow ad cookies and are signed in, the cookie identifiers (_fbp/_fbc) and your country are also kept on your account for up to 90 days so purchases can be matched to the ad that brought you; they are removed when you withdraw consent or delete your account. We never send your name, phone number, or the searches you run and the ads you review in the extension. Nothing is sent to Meta without the Marketing choice. Choosing only Analytics never loads the Meta Pixel and sends no server events. You can change or withdraw your choice at any time via the Cookie settings link at the bottom of every page. - Microsoft Clarity — anonymized heatmaps and session replay of the website. Text you type into form fields is masked
- Yandex Metrika (only if you choose Analytics in the cookie bar) — website traffic statistics and click maps, without session replay. It sets the cookies
_ym_uidand_ym_d(1 year) and_ym_isad(2 days). Yandex processes this data on our behalf as a processor. Yandex's Metrica terms do not state where the data is stored, so it may be processed outside your country; for visitors in the EEA, UK and Switzerland, Yandex's Data Processing Agreement applies - TikTok Pixel, X (Twitter) Pixel, Reddit Pixel, OpenAI Ads (oaiq) — ad performance measurement, conversion events only; none of these receive your identity, email or extension activity. Not active today: each needs an account ID that is not configured yet; with no ID, none of these four load or make any network request
Every tool and cookie in one table. This is the complete list of what the website loads, in the same three groups as the Cookie settings panel. Necessary tools run without a choice; Analytics and Marketing tools load only after you choose them. A tool appears here only while it is actually switched on.
| Tool | Category | Purpose | Cookies and lifetime | Country and transfer | Privacy policy |
|---|---|---|---|---|---|
| Lemon Squeezy | Necessary | Checkout and payment on the pricing page; needed to buy a plan | Our pages set no cookie for it; the Lemon Squeezy checkout sets its own cookies on its own domain | Lemon Squeezy (USA), our payment provider and merchant of record; data goes to the USA | Privacy policy |
| Firebase Authentication (Google) | Necessary | Keeps you signed in on the website; needed for your account | firebaseLocalStorageDb (until you sign out); Kept in your browser's IndexedDB, not as a cookie |
Google (USA); data may be processed in the USA and other countries where Google operates | Privacy policy |
| Google Analytics 4 | Analytics | Counts page views and traffic sources | _ga (2 years), _ga_S5VQY71Z6N (2 years) |
Google Ireland Limited (EEA) and Google LLC (USA); data may be transferred to the USA | Privacy policy |
| Microsoft Clarity | Analytics | Anonymized heatmaps and session replay of the website; typed text is masked | _clck (1 year), _clsk (1 day) |
Microsoft (USA; Microsoft Ireland for the EEA); data may be transferred to the USA | Privacy policy |
| Yandex Metrika | Analytics | Website traffic statistics and click maps, no session replay | _ym_uid (1 year), _ym_d (1 year), _ym_isad (2 days) |
Yandex (Russia); data may be processed outside your country; for visitors in the EEA, UK and Switzerland, Yandex's data processing agreement applies | Privacy policy |
| Meta Pixel and Conversions API | Marketing | Measures which ads lead to sign-ups and purchases; our server sends the same event to Meta | _fbp (90 days), _fbc (90 days), _fba_vid (90 days) |
Meta Platforms Ireland Limited (EEA); data may be transferred to the USA | Privacy policy |
Signed-in visitors — analytics identity. If you are signed in on the website
and you chose Analytics in the cookie bar, your Firebase user ID — the random
string that identifies your account, not your e-mail address — is sent to Google
Analytics as its user_id value, and to Microsoft Clarity as its identify
value whenever Clarity is enabled. Your name, your e-mail address, your Google profile picture and
anything you searched for or scanned are never sent to these tools. Purpose: when
the same person uses the website and the extension, we see one journey instead of two, and we can
measure how many visitors complete sign-in.
Conditions and control. Nothing is sent before you accept: if you decline — or
simply make no choice — the ID is never transmitted; it stays in the page's memory and is discarded
when you close the tab. When you sign out, the identifier is released (user_id is set
to null), so later page views are no longer attributed to you. To withdraw it
afterwards, open Cookie settings at the bottom of any page and turn Analytics off. After you delete your account the ID is never sent again; measurements already
collected by Google stay in their system for the retention period set on the property.
Two independent choices. Without Marketing, the Meta Pixel and the other ad pixels above are never loaded and no server event is sent to Meta. Without Analytics, Microsoft Clarity is never loaded. If you decline both, or make no choice, none of them is loaded — not blocked after loading, simply never requested. The Google tag does load, but in Google Consent Mode v2 denied state: it writes no cookies, sends no identifiers, and cannot be used for advertising or remarketing. It transmits only a cookieless signal that Google uses for aggregate, statistical modelling — you are never identified or followed. The website works exactly the same. Your choice is stored in your own browser and you can change it by clearing site data.
8. Data Retention & Deletion
- Local data: Automatically deleted when you uninstall the extension. You can also clear it via Chrome → Settings → Privacy → Site Data.
- Firestore usage counters: the hourly and daily usage records are retained for 90 days, then automatically purged. The running scan and filter counters stored on your account record are kept until you delete your account. You can request immediate deletion by emailing us.
- Google account info: Stored in Firebase Auth. Deleted upon account deletion request.
To request deletion of your data: advantagescope@gmail.com
Marketing emails — giving and withdrawing consent
- Marketing consent is opt-in: the box on the consent screen is unticked by default, and leaving it unticked changes nothing about the product or your plan.
- Withdrawing is as easy as giving it (GDPR Art. 7(3)): send one line to advantagescope@gmail.com and we set the flag back to "no". Every marketing email we send also carries a one-click unsubscribe link.
- Withdrawing does not affect emails you must receive as a customer — payment receipts, subscription and security notices — and it does not affect the lawfulness of messages sent before the withdrawal.
- The flag lives on your account record and is deleted together with the account.
Free Pro trial and upsell counters
Pro trial. When the 3-day Pro trial is offered, we store three things to give it once per person and to prevent abuse: a one-way hash of your email address (Gmail dots, plus-tags and googlemail.com are treated as the same address), a one-way hash of your device ID, and a one-way hash of your IP address next to the email record. Hashes cannot be turned back into the original value. No payment details are asked or stored for the trial. The IP hash is used only for abuse prevention: if three or more trial accounts come from one IP hash within 30 days, further trials from it are refused. These claim records hold no account ID, are not removed when you delete your account, and are kept until we decide to delete them; the account record also notes that you used a trial.
Upsell counters. If you chose to share usage statistics, the panel counts how often each upgrade prompt (an upsell point) was shown and clicked, and adds the name of that upsell point to the pricing page link. When the pricing page is opened with such a link, our servers count a checkout when you press a buy button and a purchase when the order completes; this checkout and purchase count needs no separate consent on the website, because it carries only the day and the upsell point name. All upsell counters are aggregated per day and per upsell point only: no user ID, no email address and no IP address is stored with them, so they cannot be traced to you. If you did not consent to usage statistics, the panel sends no such counters and adds no upsell point to the link.
Abuse prevention (App Check). To prevent abuse, server calls made with your account use Google reCAPTCHA Enterprise (Firebase App Check), which processes device and browser signals. The Google Privacy Policy (https://policies.google.com/privacy) and Terms of Service (https://policies.google.com/terms) apply.
What deleting your account removes — and what it does not
When you delete your account, we remove it immediately and completely:
- Deleted: your account record, Google sign-in identity, saved-ad interaction records, usage statistics, error reports, sign-in session records, and any feedback you sent us (including its diagnostic report).
- Anonymised, not deleted: payment event logs. These are financial records — which payment was received, for which plan, on what date — and we are required to keep them for accounting, refund and dispute purposes. Your email address and the raw payment-provider payload are erased from them; only the plan, amount and date remain, with no link to you.
- Anonymised, not deleted: refund requests and our internal admin action log entries about your account. These are audit records — which action was taken, by which staff member, when, and for what amount. Your account ID is replaced with an irreversible hash, and your email address, free-text notes and the raw payment-provider response are erased; the action, amount, method, status and date remain.
- Anonymised, then deleted after one year: retention-offer records (why a subscriber considered cancelling and whether they accepted an offer). Your account ID is replaced with an irreversible hash and any free-text note is erased; the reason and outcome remain for statistics and are deleted automatically after one year.
- Also when we delete an account: if an account is removed by us rather than from your profile page, the same clean-up runs automatically. If that account still has an active subscription, the account record is kept only until we cancel the subscription.
- Kept: if your account was banned for abuse, the ban record remains (legitimate interest). Without this, deleting an account would reset a ban and make enforcement meaningless. A ban record contains only the identifiers needed to enforce it.
- Kept, but not identifying: the one-time welcome-bonus record. It contains only irreversible hashes — no account ID, no email, no raw device identifier or IP.
Welcome and goodbye pages, uninstall survey
- /welcome (shown after installation) and /goodbye (shown after uninstalling) load no advertising pixel and no session-replay tool, whatever you chose in the cookie bar. Only Google Analytics page views run there, and only if you allowed Analytics.
- Uninstall survey: /goodbye asks one optional question. Your answer is stored as four fields only: the reason you picked, an optional note of up to 300 characters, the page language and the day. It asks for no name or email address, and we ask you not to write personal data in the note; a note that looks like an email address or phone number is discarded. No IP address, device information or account ID is stored with it, so the answer cannot be linked to you.
- Survey answers are deleted automatically after 90 days.
Team contact form (pricing page)
- What we collect: the "Contact us" form on the Team card asks for your name, company and work email address; your phone number, website, team size, intended use and a message are optional. The page language and the date are stored with them.
- Why: only to answer your sales request (seats, quota and pricing for your team). It does not subscribe you to any email list.
- Legal basis: steps taken at your request before a contract (GDPR Art. 6(1)(b), KVKK Art. 5(2)(c)) and the consent you tick on the form.
- Not stored: no IP address, browser or device information and no account ID is stored with the request.
- Team notification: a copy of your request is emailed to our team inbox through Resend (an email delivery service), so we can reply to you directly.
- Measurement: if you chose Marketing in the cookie bar, the submission is counted as a "Lead" at the moment you submit the form and reported to Meta (your email address only as a SHA-256 hash, see Meta Pixel and Conversions API); with Analytics only, Google Analytics counts it without your details. Without either choice nothing is reported.
- Retention: requests are deleted automatically 12 months after they arrive. To have yours deleted earlier, write to advantagescope@gmail.com.
9. Security
- Firebase data is protected by Google's security infrastructure with Firestore security rules.
- All network communication uses HTTPS/TLS.
- The extension does not execute remote code in its own pages. One exception, fully disclosed:
the optional Google Picker (used only when you click "Choose spreadsheet")
runs in a sandboxed extension page and loads Google's official loader
https://apis.google.com/js/api.js. This is the mechanism Google documents for the Picker API. The sandboxed page has no access to your data: it cannot callchrome.*APIs, cannot read your saved ads, and receives the OAuth token only for the duration of the picker dialog. The allowed source is declared in our manifest's sandbox CSP. No other remote code is loaded anywhere in the extension. - The Google OAuth access token used for Sheets export is never stored — it is requested per
operation and used in memory only. To keep you signed in between sessions, your Firebase session
tokens (ID token and refresh token) are saved in
chrome.storage.localon your own device; they never leave your device except to Google's own token endpoint, and they are erased when you sign out.
10. GDPR / KVKK Compliance
If you are in the European Union or Turkey, you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure ("right to be forgotten")
- Portability of your data
- Object to processing
- Withdraw consent you have given (e.g. marketing emails) at any time, as easily as you gave it
To exercise any of these rights, contact: advantagescope@gmail.com
11. Children's Privacy
AdVantage is not intended for use by anyone under 16 years of age. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via the Chrome Web Store listing or in-extension notifications. Continued use of the extension after changes constitutes acceptance.
13. Contact
For any privacy-related questions:
📧 advantagescope@gmail.com
Gizlilik Politikası
Son güncelleme: 5 Ekim 2026
1. Genel Bakış
AdVantage, Facebook Reklam Kütüphanesi deneyimini geliştiren bir Chrome eklentisidir. Bu Gizlilik Politikası, hangi verileri topladığımızı, nasıl kullandığımızı ve haklarınızı açıklar.
2. Topladığımız Veriler
| Veri Türü | Ne Toplarız | Nerede Saklanır | Amaç |
|---|---|---|---|
| Google Hesabı | E-posta adresi, görünen ad, Google kullanıcı kimliği | Firebase Authentication (bulut) + tarayıcı belleği | Giriş yapma ve tarama limiti takibi |
| Pazarlama E-postası Onayı | Onay ekranındaki isteğe bağlı "Ürün güncellemelerini ve kampanyaları e-posta ile almak istiyorum" kutusunu işaretleyip işaretlemediğiniz (evet/hayır) ve Kullanım Şartları ile bu Politikayı kabul ettiğiniz tarih. Kutu isteğe bağlıdır ve varsayılan olarak işaretsizdir; işaretlemeseniz de uzantı birebir aynı çalışır. | Firebase Firestore (bulut), hesap kaydınızda | Google hesabınızın e-posta adresine ürün haberi ve kampanya gönderip gönderemeyeceğimizi belirlemek. Satılmaz, üçüncü taraflarla paylaşılmaz, reklam hedefleme için kullanılmaz. Bu onayı istediğiniz zaman geri çekebilirsiniz — bkz. Pazarlama e-postaları. |
| Rehber Bülteni (landing sayfaları) | Landing sayfalarımızdaki "Yeni rehberleri e-postayla al" formuna yazdığınız e-posta adresi; onay kutusunun yanında gördüğünüz metin ve işaretleme zamanı; hangi sayfadan ve hangi dilde abone olduğunuz; onay e-postasındaki bağlantıya bastığınız zaman. Sitede reklam çerezlerini kabul ettiyseniz ayrıca rastgele bir olay kimliği ve bu izin durumu. Bu form Google hesabı ya da giriş gerektirmez. IP adresiniz saklanmaz; kötüye kullanımı sınırlamak için yalnız geri çevrilemez özeti kullanılır. Form yalnız gönderim açıkken görünür. | Firebase Firestore (bulut); e-postalar Resend (e-posta gönderim hizmeti) üzerinden gönderilir | Çift onay: formu gönderince yalnız bir onay e-postası gelir; bağlantısına basmazsanız başka e-posta gelmez. Onaydan sonra yeni rehber duyuruları ve ilk hafta dört e-postalık başlangıç serisi. Satılmaz. Sitede reklam çerezlerini kabul ettiyseniz, aboneliği onayladığınız an reklam platformlarımıza dönüşüm olarak bildirilir; e-posta adresiniz bu bildirimde yalnız geri çevrilemez özet (SHA-256) olarak gider. Her e-postada tek tıkla abonelikten çıkma bağlantısı; kaydınızın silinmesi için advantagescope@gmail.com adresine yazabilirsiniz. |
| Tarama Sayısı | Limit penceresinde (tüm planlarda 6 saat) başlatılan tarama sayısı | Firebase Firestore (bulut) + chrome.storage.local | Plan tarama limiti takibi (tüm planlar) |
| Filtreleme Sayısı | Bekleyen bir filtre değişikliğini uygulamak için "Filtrele" düğmesine bastığınız sayı; tarama sayacıyla aynı 6 saatlik pencerede sayılır | Firebase Firestore (bulut) | Plan filtreleme limiti takibi (tüm planlar) |
| Kayıtlı Reklamlar | Reklam kartından okunan tüm alanlar — reklam kimliği, marka adı, alan adı, CTA, hedef URL, yayın süresi, başlık, açıklama, reklam metni, medya bağlantıları, kreatif sayısı ve kartın diğer öznitelikleri. İçerik cihazınızda kalır ve sunucularımıza hiç yüklenmez. Kaydetme işleminin gönderdiği tek şey, reklamın herkese açık ID'sindeki hesabınıza bağlı kaydetme sayacıdır (aşağıdaki satıra bakın). Kaydı kaldırmak aynı sayacı düşürür. | chrome.storage.local (yalnızca cihazınızda) | Kişisel reklam koleksiyonunuz/dışa aktarma |
| Tercihler | Dil, tema, filtre ayarları, yazı tipi boyutları | chrome.storage.local (yalnızca cihazınızda) | Ayarlarınızı hatırlamak |
| Görülen Reklamlar | Görüntülediğiniz reklam kimlikleri ("Yeni" filtresi için) | chrome.storage.local (yalnızca cihazınızda) | Daha önce görülen reklamları filtrelemek |
| Reklam Popülerlik Sayaçları | Önünüze listelenen reklamların herkese açık Facebook Reklam Kütüphanesi kimliği (ID) + hesabınıza bağlı toplam sayaçlar: reklamın kaç kez listelendiği, kaç kez kaydedildiği ve imlecin reklamın medya alanında (görsel veya video) ne kadar süre beklediği (yaklaşık). Reklam içeriği gönderilmez — marka adı, metin, bağlantı vb. hiçbir içerik alanı sunucuya iletilmez, yalnızca herkese açık ID referans verilir. Kaydettiğiniz reklamlar cihazınızda kalır ve içerikleri sunucuya hiç yüklenmez; bize ulaşan tek şey reklamın herkese açık ID'sindeki hesabınıza bağlı kaydetme sayacıdır. Kaydı kaldırmak aynı sayacı düşürür. | Firebase Firestore (bulut) — sayaçlar tüm kullanıcılar arasında paylaşılır | Hizmet kalitesini ölçmek, popüler reklamları/eğilimleri tespit etmek, kötüye kullanım (dolandırıcılık/bot) tespiti |
| Etkileşim Kaydı | Hangi hesaba hangi herkese açık reklam kimliklerinin listelendiği ve o partide kaç etkileşim olayı olduğu. Bu kayıtta ne etkileşimin türü ne de reklam başına süre saklanır. | Firebase Firestore (bulut) | Kötüye kullanım tespiti, kullanım analitiği — reklamın kendi içeriği bu kayıtta tekrar saklanmaz, yalnızca kimliği referans verilir |
| Arama Geçmişi | Uzantıda yaptığınız arama terimleri, o aramayla birlikte uyguladığınız filtreler (ülke, medya türü) ve o aramanın getirdiği herkese açık reklam kimlikleri — hesabınıza bağlı olarak | Firebase Firestore (bulut) | Ürün geliştirme (hangi aramaların hangi reklamlara ulaştığını anlamak), kota denetimi ve kötüye kullanım tespiti. Üçüncü taraflarla paylaşılmaz, reklam amacıyla kullanılmaz. Hesabınızı sildiğinizde silinir. |
| Kullanım İstatistikleri | Saatlik ve günlük tarama sayacı (toplu, kimliksizleştirilmiş). Günlük özellik kullanım sayıları (ör. panel açılışı, başlayan/biten tarama ve kart sayısı, uygulanan filtre, dışa aktarma, kota sınırına ulaşma, yükseltme bağlantısı tıklaması, hata) — yalnız sayı; reklam içeriği, URL, arama metni ya da e-posta asla yazılmaz. | Firebase Firestore (bulut); sayaçlardan dördü (kurulum, panelin açılması, taramanın başlatılması, yükseltme düğmesine tıklama) sunucumuz tarafından ayrıca Google Analytics 4'e iletilir (bkz. 7. bölüm) | Performans ölçümü, anormal kullanım (bot/otomasyon) tespiti, ürün geliştirme (hangi özelliklerin kullanıldığı) |
| Oturum ve Güvenlik Verileri | Girişte: IP adresi, eklentinin ürettiği bir cihaz kimliği ve tarayıcı bilgisi (user agent). Planınızın aynı anda bilgisayar sınırı için hesap kaydınızda ayrıca son aktif her bilgisayarın cihaz kimliğinin geri çevrilemez özeti (hash), kaba bir adı (örn. "Chrome · Windows") ve son etkinlik zamanı tutulur; artık aktif olmayan bilgisayarlar bir sonraki tarama ya da filtrede silinir; liste 90 gün kullanılmazsa ve hesabınız silindiğinde tamamen silinir. | Firebase Firestore (bulut), en fazla 90 gün saklanır | Kötüye kullanımın önlenmesi ve Kullanım Şartları'nın uygulanması (örn. hesabın çoklu cihazda paylaşımı, limit aşma, ban atlatma). Asla reklam amacıyla kullanılmaz. Kötüye kullanım nedeniyle banlanan hesaplara para iadesi yapılmaz — bkz. Kullanım Şartları. |
| Tek Seferlik Teklif Kaydı | Tek seferlik hoş geldin bonusu alındığında: cihaz kimliğinin geri çevrilemez özeti (hash), IP adresinin geri çevrilemez özeti ve hesap kimliğiniz. Bu kayıtta ham cihaz kimliği veya ham IP adresi saklanmaz. | Firebase Firestore (bulut), teklif var olduğu sürece saklanır | "Cihaz başına tek bonus" kuralının uygulanması ve çoklu hesap kötüye kullanımının yavaşlatılması. Bu kayıt 90 gün sonra bilerek silinmez — silinseydi aynı cihaz bonusu tekrar alabilirdi. Asla reklam amacıyla kullanılmaz. |
| Geri Bildirim ve Tanı | Yalnızca geri bildirim formunda "Gönder"e bastığınızda. Mesajınız ve göndermeden önce size salt-okunur bir kutuda tamamı gösterilen tanı raporu. Rapor şunları içerir: eklenti ve Chrome sürümü, işletim platformu, ekran çözünürlüğü, cihaz belleği, bulunduğunuz Reklam Kütüphanesi sayfasının yalnızca yolu (sorgu parametreleri — yani ne aradığınız — kesilir), oturumda taranan reklam sayıları, listedeki son 10 reklamın herkese açık Reklam Kütüphanesi kimliği, eklenti ayarlarınız ve eklentiye ait son 200 konsol log satırı. | Firebase Firestore (bulut), en fazla 90 gün saklanır | Bildirdiğiniz sorunu yeniden üretip düzeltmek. Siz Gönder'e basmadan hiçbir şey gönderilmez. Asla reklam amacıyla kullanılmaz veya üçüncü taraflarla paylaşılmaz. |
| Ödeme Kartı Kimliği | Sadece kart markası ve son 4 hane (örn. "Visa •••• 4242") — ödeme sağlayıcımız Lemon Squeezy tarafından checkout sırasında bize iletilir. Kartınızın tam numarasını, son kullanma tarihini veya CVC'sini asla görmez, toplamaz veya saklamayız — ödeme tamamen Lemon Squeezy tarafından işlenir. | Firebase Firestore (bulut), hesabınıza bağlı | Kötüye kullanım nedeniyle daha önce banlanmış bir kartın yeni bir hesap açmak için kullanılmasını önler. Asla reklam amacıyla kullanılmaz veya ödeme sağlayıcımız dışında üçüncü taraflarla paylaşılmaz. |
| Hata Raporları | Otomatik, siz giriş yapmışken. Eklenti beklenmedik bir hatayla karşılaştığında başarısız olan işlemin adını, hata mesajını (500 karakterle sınırlı) ve eklenti sürümünü kaydeder. Oturum başına en fazla 10 kayıt. Reklam içeriği, arama terimi ve sayfa adresi kaydedilmez. | Firebase Firestore (bulut), en fazla 90 gün saklanır | Sizin elle bildirmeniz gerekmeden çökmeleri bulup düzeltmek. Asla reklam amacıyla kullanılmaz veya üçüncü taraflarla paylaşılmaz. |
3. Toplamadığımız Veriler
- Reklam içeriği — resim/video dosyaları, marka adı, başlık, açıklama metni, CTA veya hedef/medya bağlantıları sunucularımıza asla iletilmez. Yalnızca reklamın herkese açık Facebook Reklam Kütüphanesi kimliği (ID) referans verilir.
- Facebook hesap bilgileriniz veya çerezleriniz
- facebook.com/ads/library dışındaki tarama geçmişiniz
- Ödeme bilgileri (tamamen ödeme sağlayıcımız Lemon Squeezy tarafından işlenir)
4. Verilerin Kullanımı
- Google hesap bilgileri kimlik doğrulama ve tarama limiti takibi için kullanılır ve asla satılmaz. Tek istisna: çerez çubuğunda Pazarlama'yı seçtiyseniz e-posta adresiniz yalnızca hash'lenmiş (SHA-256) olarak reklam ölçümü için Meta'ya iletilir (bkz. Meta Pikseli ve Conversions API).
- Tarama sayısı (kaç reklam analiz edildiği) Firestore'da tutulur ve tek başına bir sayıdır, reklam içeriği içermez.
- Reklam popülerlik sayaçları ve etkileşim kayıtları yukarıdaki tabloda açıklandığı şekilde Firestore'da tutulur — reklamlar yalnızca herkese açık ID'leriyle referans verilir, içerik saklanmaz. Amaç hizmet kalitesini ölçmek ve kötüye kullanımı (sahte hesap, bot, aşırı otomasyon) tespit etmektir. Bu veriler reklam vermek veya üçüncü taraflara satmak için kullanılmaz. Paylaşımın tek istisnası, 7. bölümde anlatıldığı gibi yalnızca kullanım istatistiklerini paylaşmayı kabul ettiysen sunucumuzun Google Analytics'e ilettiği dört kullanım sayacıdır (kurulum, panelin açılması, taramalar, yükseltme tıklamaları); bunlar reklam amacıyla kullanılmaz ve satılmaz.
- Kayıtlı reklamlarınız (kişisel koleksiyonunuz) ve tercihleriniz cihazınızda yerel olarak saklanır. İçerikleri, siz açıkça Google Sheets'e aktarmadıkça tarayıcınızdan çıkmaz — kaydetme işleminin bize gönderdiği tek şey yukarıdaki tabloda anlatılan, reklamın herkese açık ID'sindeki hesabınıza bağlı kaydetme sayacıdır.
5. Google Sheets Aktarımı
Google Sheets özelliğini kullandığınızda eklenti:
chrome.identity.getAuthTokeniledrive.filekapsamında Google OAuth token alır — erişim yalnızca senin seçtiğin tek e-tabloyla sınırlıdır, tüm Drive'ınla değil- Kayıtlı reklam verilerinizi doğrudan tarayıcınızdan belirttiğiniz Google Sheet'e yazar
- Bu verileri sunucularımızdan geçirmez — istek doğrudan tarayıcınız → Google Sheets API'si arasında gerçekleşir
6. Google API Hizmetleri ve Chrome Web Mağazası Uyumluluğu
AdVantage'ın Google API'lerinden aldığı bilgileri kullanımı ve aktarımı, Sınırlı Kullanım (Limited Use) şartları dahil olmak üzere Google API Hizmetleri Kullanıcı Verisi Politikası'na uygun şekilde gerçekleştirilir.
Google API'lerinden alınan bilgilerin kullanımı, Sınırlı Kullanım şartları dahil olmak üzere Chrome Web Mağazası Kullanıcı Verisi Politikası'na uygundur.
Bu eklentiden alınan bilgilerin kullanımı, Sınırlı Kullanım şartları dahil olmak üzere Chrome Web Mağazası Kullanıcı Verisi Politikası'na uygundur.
Eklentiden gelen veriler (kurulum, oturum açma ve yan panelin kullanımı) asla reklam amacıyla kullanılmaz ve Meta, TikTok ya da Google Ads gibi reklam platformlarına gönderilmez. Reklam ölçümü yalnızca bu web sitesinde ve yalnızca Pazarlama onayınla çalışır.
AdVantage, Chrome Web Mağazası Geliştirici Program Politikaları'na ve veri toplamanın belirgin şekilde bildirilmesini gerektiren Kullanıcı Verisi SSS standartlarına uygun şekilde geliştirilmekte ve sürdürülmektedir.
7. Veri Paylaşımı
Kişisel verilerinizi herhangi bir üçüncü taraf, reklamcı veya veri komisyoncusuyla satmaz, takas etmez veya paylaşmayız.
Eklentide kullanılan üçüncü taraf hizmetler:
- Google Firebase — arka uç hizmetimiz (Firebase Authentication, Cloud Firestore ve Cloud Functions). Oturum açmayı yürütür ve 2. bölümde bulutta saklandığı yazan verileri tutar: hesap kaydınız (plan, tarama ve filtreleme sınırları, pazarlama e-postası onayı, ödeme kartı kimliği), hesabınıza bağlı reklam popülerlik sayaçları ve etkileşim kayıtları, arama geçmişi, kullanım istatistikleri (günlük özellik kullanım sayıları dahil), oturum ve güvenlik verileri (IP adresinizin geri çevrilemez özeti, cihaz kimliği ve tarayıcı bilgisi), tek seferlik teklif kaydı, gönderdiğiniz geri bildirimler, hata raporları ve ödeme sağlayıcımızdan gelen ödeme olay kayıtları. Hesabınızı sildiğinizde neyin silindiğini, kimliksizleştirildiğini ya da tutulduğunu 8. bölüm anlatır. (Firebase Gizlilik Politikası)
- Google Sheets API — yalnızca siz dışa aktarma tetiklendiğinde
- Eklenti kullanım istatistikleri (isteğe bağlı). Eklentinin kendisinde analiz betiği yoktur. "Kullanım istatistiklerini paylaş" anahtarı varsayılan olarak kapalıdır: sen kendin açmadıkça hiçbir sayaç gönderilmez. Eklentide (Ayarlar > Gizlilik) ya da web profilinde açabilirsin; seçim hesabına senkronlanır (hesap belgende bir onay kaydı olarak saklanır) ve istediğin zaman geri çekilebilir. Yalnızca açarsan eklenti, yedi grup panel olayını kendi sunucumuzda sayar: kurulum, panelin açılması, taramalar, reklam kartı görüntüleme (kart dönüştürme dahil), filtreler, dışa aktarmalar ve yükseltme düğmesine tıklamalar. Sunucumuzda bunlar hesabına bağlı tutulur (kota ve kötüye kullanım koruması bu bağı gerektirir). Arama terimi, reklam içeriği ve kişisel veri asla gönderilmez. Bunlardan yalnızca kurulum, panelin açılması, taramalar ve yükseltme tıklamaları Google Analytics 4'e iletilir; hesap kimliğinden tek yönlü özetle türetilmiş takma adlı bir tanımlayıcıyla (e-postan, adın ya da hesap kimliğin değil; web sitesi de aynı tek yönlü tanımlayıcıyı kullanır, ham hesap kimliğini asla) gider, kişiselleştirilmemiş olarak işaretlenir ve Google'ın ad_user_data ile ad_personalization sinyalleri reddedildi (denied) olarak ayarlanır. Reklam, profil çıkarma amacıyla kullanılmaz, satılmaz. Kullanım istatistikleri kapalıysa hiçbiri gönderilmez ve bekleyenler silinir. Eklentiden yapılan bir satın alma yalnızca bu onayla Google Analytics 4'e bildirilir, Meta'ya asla. Sayaçlar hiçbir zaman reklam amacıyla kullanılmaz.
Hizmet sayaçları ayrıdır: "kota doldu" (quota_hit) ve "hata sayısı" (error). Hizmet, plan sınırlarını uygulamak ve arızaları görmek için bunlara ihtiyaç duyar; bu yüzden seçimin ne olursa olsun yalnızca kendi sunucumuza gider, Google Analytics'e hiç iletilmez ve reklam için kullanılmaz.
Yalnızca web sitesinde (advantagescope.io) — ve yalnızca çerez çubuğundaki seçiminizle (her araçta aşağıda belirtildiği gibi Analitik ya da Pazarlama). Tarayıcı eklentisi bunların hiçbirini yüklemez; bunlar web sitesi betikleridir ve eklenti paketinin içine asla girmez:
- Google Analytics 4 — sayfa görüntüleme ve trafik kaynağı (siz seçmeden önce yalnızca çerezsiz bir sinyal gider, aşağıya bakın). Google Analytics 4 IP adreslerini kaydetmez ve saklamaz
- Meta Pikseli ve Conversions API (yalnızca çerez çubuğunda Pazarlama'yı seçerseniz) — hangi reklamın kayıt ve satın almaya yol açtığını ölçeriz. Tarayıcı pikseli olayı gönderir; sunucumuz aynı olayı Meta'ya ayrıca iletir (Conversions API), böylece ölçüm reklam engelleyicilerde de kaybolmaz. Sunucu olayı hash'lenmiş (SHA-256) e-posta adresi, hash'lenmiş hesap kimliği, IP adresiniz, tarayıcı bilgisi (user agent), ülkeniz, Meta'nın tıklama/tarayıcı tanımlayıcıları, ayrıca sipariş tutarı ve para birimini içerebilir. Pazarlama seçiliyken birinci taraf bir çerezde (
_fba_vid, hesabınızdan türetilmez) rastgele bir ziyaretçi kimliği de tutarız; piksel ve sunucumuz bunu Meta'ya gönderir, sunucu yalnız SHA-256 özeti olarak; Pazarlama'yı geri aldığınız an silinir. Satın alırsanız aynı kimlik Lemon Squeezy'deki siparişin özel verisine de yazılır ve geri almadan sonra o sipariş kaydında kalır. Reklam çerezlerine izin verdiyseniz ve oturum açıksa, çerez tanımlayıcıları (_fbp/_fbc) ve ülkeniz, satın alımların sizi getiren reklamla eşleştirilebilmesi için en fazla 90 gün hesabınızda tutulur; izninizi geri aldığınızda veya hesabınızı sildiğinizde kaldırılır. Adınız, telefonunuz ya da eklentide yaptığınız aramalar ve incelediğiniz reklamlar hiçbir zaman gönderilmez. Pazarlama seçimi olmadan Meta'ya hiçbir şey gönderilmez. Yalnız Analitik'i seçmek Meta Pikselini yüklemez ve sunucu olayı göndermez. Seçiminizi istediğiniz an her sayfanın altındaki Çerez ayarları bağlantısından değiştirebilir ya da geri alabilirsiniz. - Microsoft Clarity — web sitesinin anonim ısı haritası ve oturum tekrarı. Form alanlarına yazdığınız metin maskelenir
- Yandex Metrika (yalnızca çerez çubuğunda Analitik'i seçerseniz) — web sitesi trafik istatistikleri ve tıklama haritası, oturum kaydı olmadan.
_ym_uidve_ym_d(1 yıl) ile_ym_isad(2 gün) çerezlerini yazar. Yandex bu veriyi bizim adımıza veri işleyen olarak işler. Yandex'in Metrica şartları verinin nerede saklandığını belirtmez; bu yüzden veri ülkeniz dışında işlenebilir. AEA, Birleşik Krallık ve İsviçre'deki ziyaretçiler için Yandex'in Veri İşleme Sözleşmesi (DPA) geçerlidir - TikTok Pixel, X (Twitter) Pixel, Reddit Pixel, OpenAI Ads (oaiq) — reklam performans ölçümü, yalnızca dönüşüm olayı; kimliğiniz, e-postanız veya eklenti kullanımınız bunlara gönderilmez. Bugün aktif değil: dördü de henüz kurulmamış bir hesap kimliği ister; kimlik yokken hiçbiri yüklenmez, hiçbir ağ isteği göndermez
Tüm araçlar ve çerezler tek tabloda. Web sitesinin yüklediği her şeyin tam listesi; Çerez ayarları penceresindeki üç grupla aynıdır. Zorunlu araçlar seçim gerektirmeden çalışır; Analitik ve Pazarlama araçları yalnızca siz seçtikten sonra yüklenir. Bir araç burada yalnızca gerçekten açıkken görünür.
| Araç | Kategori | Amaç | Çerezler ve süre | Ülke ve aktarım | Gizlilik politikası |
|---|---|---|---|---|---|
| Lemon Squeezy | Zorunlu | Fiyat sayfasında ödeme; plan satın almak için gerekli | Sayfalarımız bunun için çerez yazmaz; Lemon Squeezy ödeme sayfası kendi alan adında kendi çerezlerini yazar | Lemon Squeezy (ABD), ödeme sağlayıcımız ve satıcı kaydı sahibi; veri ABD'ye gider | Gizlilik politikası |
| Firebase Authentication (Google) | Zorunlu | Web sitesinde oturumunuzu açık tutar; hesabınız için gerekli | firebaseLocalStorageDb (oturumu kapatana kadar); Çerez olarak değil, tarayıcınızın IndexedDB alanında tutulur |
Google (ABD); veri ABD'de ve Google'ın faaliyet gösterdiği diğer ülkelerde işlenebilir | Gizlilik politikası |
| Google Analytics 4 | Analitik | Sayfa görüntülemelerini ve trafik kaynaklarını sayar | _ga (2 yıl), _ga_S5VQY71Z6N (2 yıl) |
Google Ireland Limited (AEA) ve Google LLC (ABD); veri ABD'ye aktarılabilir | Gizlilik politikası |
| Microsoft Clarity | Analitik | Web sitesinin anonim ısı haritaları ve oturum kaydı; yazdığınız metin gizlenir | _clck (1 yıl), _clsk (1 gün) |
Microsoft (ABD; AEA için Microsoft Ireland); veri ABD'ye aktarılabilir | Gizlilik politikası |
| Yandex Metrika | Analitik | Web sitesi trafik istatistikleri ve tıklama haritaları, oturum kaydı yok | _ym_uid (1 yıl), _ym_d (1 yıl), _ym_isad (2 gün) |
Yandex (Rusya); veri ülkeniz dışında işlenebilir; AEA, Birleşik Krallık ve İsviçre'deki ziyaretçiler için Yandex'in veri işleme sözleşmesi geçerlidir | Gizlilik politikası |
| Meta Pixel and Conversions API | Pazarlama | Hangi reklamların kayıt ve satın almaya yol açtığını ölçer; sunucumuz aynı olayı Meta'ya da gönderir | _fbp (90 gün), _fbc (90 gün), _fba_vid (90 gün) |
Meta Platforms Ireland Limited (AEA); veri ABD'ye aktarılabilir | Gizlilik politikası |
Oturum açmış ziyaretçiler — analitik kimliği. Web sitesinde oturum açtıysanız
ve çerez çubuğunda Analitik'i seçtiyseniz, Firebase kullanıcı kimliğiniz —
hesabınızı temsil eden rastgele dizge, e-posta adresiniz değil — Google
Analytics'e user_id değeri olarak, Microsoft Clarity etkinse ona da
identify değeri olarak gönderilir. Adınız, e-posta adresiniz, Google profil
fotoğrafınız ve aradığınız/taradığınız hiçbir şey bu araçlara gönderilmez. Amaç:
aynı kişi hem siteyi hem eklentiyi kullandığında iki ayrı ziyaret yerine tek bir yolculuk görmek
ve kaç ziyaretçinin girişi tamamladığını ölçebilmek.
Koşul ve kontrol. Siz kabul etmeden hiçbir şey gönderilmez: reddederseniz — ya
da hiç seçim yapmazsanız — kimlik iletilmez; yalnızca sayfanın belleğinde durur ve sekmeyi
kapattığınızda silinir. Oturumu kapattığınızda kimlik bırakılır (user_id
null yapılır); sonraki sayfa görüntülemeleri artık size atfedilmez. Onayınızı
sonradan geri çekmek için herhangi bir sayfanın altındaki Çerez ayarları bağlantısını açıp Analitik'i kapatın. Hesabınızı sildikten sonra bu kimlik bir daha
gönderilmez; Google'ın daha önce topladığı ölçümler mülk için belirlenen saklama süresi
boyunca onların sisteminde kalır.
Birbirinden bağımsız iki seçim. Pazarlama'yı seçmezseniz Meta Pikseli ve yukarıdaki diğer reklam pikselleri hiç yüklenmez, Meta'ya sunucu olayı da gönderilmez. Analitik'i seçmezseniz Microsoft Clarity hiç yüklenmez. İkisini de reddederseniz ya da hiç seçim yapmazsanız hiçbiri yüklenmez — yüklendikten sonra engellenmez, hiç istenmez. Google etiketi yüklenir, ancak Google Consent Mode v2'nin reddedildi durumunda: çerez yazmaz, kimlik göndermez, reklam veya yeniden pazarlama için kullanılamaz. Yalnızca çerezsiz bir sinyal iletir; Google bunu toplu ve istatistiksel modelleme için kullanır — siz tanımlanmaz, takip edilmezsiniz. Site tamamen aynı şekilde çalışır. Tercihiniz kendi tarayıcınızda saklanır; site verilerini temizleyerek değiştirebilirsiniz.
8. Veri Saklama ve Silme
- Yerel veriler: Eklentiyi kaldırdığınızda otomatik olarak silinir.
- Firestore kullanım sayaçları: saatlik ve günlük kullanım kayıtları 90 gün sonra otomatik temizlenir. Hesap kaydınızdaki güncel tarama ve filtreleme sayaçları ise hesabınızı silene kadar durur. Anında silme için e-posta gönderin.
Veri silme talebi: advantagescope@gmail.com
Pazarlama e-postaları — onay verme ve geri çekme
- Pazarlama onayı açık rızaya bağlıdır: onay ekranındaki kutu varsayılan olarak işaretsizdir; işaretlemediğinizde üründe ya da planınızda hiçbir şey değişmez.
- Geri çekmek, vermek kadar kolaydır (GDPR m.7(3), KVKK ilgili kişi hakları): advantagescope@gmail.com adresine tek satır yazmanız yeter, kaydı "hayır" yaparız. Gönderdiğimiz her pazarlama e-postasında ayrıca tek tıkla abonelikten çıkma bağlantısı bulunur.
- Onayı geri çekmek, müşteri olarak almanız gereken e-postaları (ödeme makbuzu, abonelik ve güvenlik bildirimleri) etkilemez; geri çekmeden önce gönderilmiş iletilerin hukuka uygunluğunu da etkilemez.
- Bu kayıt hesap kaydınızda tutulur ve hesabınızla birlikte silinir.
Ücretsiz Pro denemesi ve yükseltme sayaçları
Pro denemesi. 3 günlük Pro denemesi sunulduğunda, denemeyi kişi başına bir kez vermek ve kötüye kullanımı önlemek için üç şey saklarız: e-posta adresinizin tek yönlü özeti (Gmail noktaları, artı etiketleri ve googlemail.com aynı adres sayılır), cihaz kimliğinizin tek yönlü özeti ve e-posta kaydının yanında IP adresinizin tek yönlü özeti. Özetler asıl değere geri çevrilemez. Deneme için ödeme bilgisi istenmez ve saklanmaz. IP özeti yalnızca kötüye kullanım önleme içindir: aynı IP özetinden 30 gün içinde üç veya daha fazla deneme hesabı gelirse, ondan sonraki denemeler reddedilir. Bu hak kayıtları hesap kimliği taşımaz, hesabınızı sildiğinizde silinmez ve biz silmeye karar verene kadar tutulur; hesap kaydında da denemeyi kullandığınız yazar.
Yükseltme sayaçları. Kullanım istatistiklerini paylaşmayı seçtiyseniz, panel her yükseltme önerisinin (yükseltme noktası) kaç kez gösterildiğini ve tıklandığını sayar ve fiyat sayfası bağlantısına o yükseltme noktasının adını ekler. Fiyat sayfası böyle bir bağlantıyla açıldığında, satın alma düğmesine bastığınızda ödemeye geçişi, sipariş tamamlandığında da satın almayı sunucularımız sayar; bu sayım yalnızca gün ve yükseltme noktası adını taşıdığı için sitede ayrıca onay istemez. Tüm yükseltme sayaçları yalnızca günlük ve yükseltme noktası bazında toplanır: yanlarında kullanıcı kimliği, e-posta adresi ve IP adresi saklanmaz, size kadar izlenemez. Kullanım istatistiklerine onay vermediyseniz panel bu sayaçları göndermez ve bağlantıya yükseltme noktası eklemez.
Kötüye kullanım önleme (App Check). Kötüye kullanımı önlemek için hesabınızla yapılan sunucu çağrılarında Google reCAPTCHA Enterprise (Firebase App Check) kullanılır; bu hizmet cihaz ve tarayıcı sinyallerini işler. Google Gizlilik Politikası (https://policies.google.com/privacy) ve Hizmet Şartları (https://policies.google.com/terms) geçerlidir.
Hesabınızı sildiğinizde ne siliniyor, ne silinmiyor
Hesabınızı sildiğinizde şunlar anında ve tamamen kaldırılır:
- Silinir: hesap kaydınız, Google giriş kimliğiniz, reklam etkileşim kayıtlarınız, kullanım istatistikleriniz, hata raporlarınız, oturum kayıtlarınız ve bize gönderdiğiniz geri bildirimler (tanı raporu dahil).
- Silinmez, kimliksizleştirilir: ödeme olay kayıtları. Bunlar mali kayıttır — hangi ödeme, hangi pakete, ne zaman alındı — ve muhasebe, iade ve uyuşmazlık için saklamamız gerekir. Bu kayıtlardan e-posta adresiniz ve ödeme sağlayıcısından gelen ham veri SİLİNİR; yalnızca paket, tutar ve tarih kalır, sizinle bağı kalmaz.
- Silinmez, kimliksizleştirilir: hesabınızla ilgili iade talepleri ve iç işlem günlüğü kayıtlarımız. Bunlar denetim kaydıdır — hangi işlem, hangi ekip üyesince, ne zaman, hangi tutarla yapıldı. Hesap kimliğiniz geri çevrilemez bir özetle (hash) değiştirilir; e-posta adresiniz, serbest metin notlar ve ödeme sağlayıcısının ham yanıtı SİLİNİR; işlem, tutar, yöntem, durum ve tarih kalır.
- Kimliksizleştirilir, bir yıl sonra silinir: kalma teklifi kayıtları (bir abonenin neden iptali düşündüğü ve teklifi kabul edip etmediği). Hesap kimliğiniz geri çevrilemez bir özetle değiştirilir, serbest metin not silinir; neden ve sonuç istatistik için kalır ve bir yıl sonra otomatik silinir.
- Hesabı biz sildiğimizde de: hesap profil sayfanızdan değil de bizim tarafımızdan kaldırılırsa aynı temizlik otomatik çalışır. O hesabın hâlâ etkin bir aboneliği varsa, hesap kaydı yalnızca abonelik iptal edilene kadar tutulur.
- Kalır: hesabınız kötüye kullanım nedeniyle banlandıysa ban kaydı kalır (meşru menfaat). Aksi hâlde hesabı silmek banı sıfırlardı ve ban diye bir şey kalmazdı. Ban kaydı yalnızca uygulanması için gereken kimlikleri içerir.
- Kalır ama kimlik taşımaz: tek seferlik hoş geldin bonusu kaydı. İçinde yalnızca geri çevrilemez özetler (hash) vardır — hesap kimliği, e-posta, ham cihaz kimliği veya IP yoktur.
Karşılama ve veda sayfaları, kaldırma anketi
- /welcome (kurulumdan sonra) ve /goodbye (kaldırdıktan sonra) sayfaları, çerez şeridinde ne seçtiğinden bağımsız olarak hiçbir reklam pikseli ve oturum kaydı aracı yüklemez. Orada yalnızca Google Analytics sayfa görüntülemesi çalışır, o da Analitik'e izin verdiysen.
- Kaldırma anketi: /goodbye tek bir isteğe bağlı soru sorar. Cevabın yalnızca dört alan olarak saklanır: seçtiğin neden, en çok 300 karakterlik isteğe bağlı bir not, sayfa dili ve gün. Ad ya da e-posta istemez; nota kişisel bilgi yazmamanı rica ederiz, e-posta adresi ya da telefon numarasına benzeyen not atılır. Yanında IP adresi, cihaz bilgisi ya da hesap kimliği saklanmaz; bu yüzden cevap sana bağlanamaz.
- Anket cevapları 90 gün sonra otomatik silinir.
Team iletişim formu (fiyat sayfası)
- Ne topluyoruz: Team kartındaki "Bize yaz" formu adını, firmanı ve iş e-posta adresini ister; telefon numarası, web sitesi, ekip büyüklüğü, kullanım amacı ve mesaj isteğe bağlıdır. Yanında sayfa dili ve tarih saklanır.
- Neden: yalnızca satış talebine (ekibin için kullanıcı sayısı, kota ve fiyat) cevap vermek için. Seni hiçbir e-posta listesine eklemez.
- Hukuki dayanak: sözleşme öncesi senin talebinle atılan adımlar (KVKK md. 5/2-c, GDPR md. 6/1-b) ve formda işaretlediğin onay.
- Saklanmayanlar: talebin yanında IP adresi, tarayıcı ya da cihaz bilgisi ve hesap kimliği saklanmaz.
- Ekip bildirimi: talebinin bir kopyası, sana doğrudan cevap verebilmemiz için Resend (e-posta gönderim hizmeti) üzerinden ekip gelen kutumuza e-postayla iletilir.
- Ölçüm: çerez şeridinde Pazarlama'yı seçtiysen gönderim, formu gönderdiğin anda "Lead" olarak sayılır ve Meta'ya bildirilir (e-posta adresin yalnız SHA-256 özeti olarak; bkz. Meta Pikseli ve Conversions API); yalnız Analitik'i seçtiysen Google Analytics bilgilerin olmadan sayar. İkisi de seçili değilse hiçbir şey bildirilmez.
- Saklama: talepler geldikten 12 ay sonra otomatik silinir. Daha önce silinmesini istersen advantagescope@gmail.com adresine yaz.
9. Güvenlik
- Firebase verileri Google'ın güvenlik altyapısı ve Firestore güvenlik kurallarıyla korunur.
- Tüm ağ iletişimi HTTPS/TLS üzerinden yapılır.
- Eklenti kendi sayfalarında uzak kod çalıştırmaz. Tam olarak beyan edilen tek istisna:
isteğe bağlı Google Picker (yalnız "E-tablo seç" düğmesine bastığınızda çalışır)
sandbox (yalıtılmış) bir eklenti sayfasında koşar ve Google'ın resmî yükleyicisi
https://apis.google.com/js/api.js'i yükler. Bu, Google'ın Picker API için belgelediği mekanizmadır. Sandbox sayfasının verilerinize erişimi yoktur:chrome.*API'lerini çağıramaz, kaydettiğiniz reklamları okuyamaz; OAuth belirtecini yalnız seçim penceresi açıkken alır. İzin verilen kaynak manifest'imizin sandbox CSP'sinde açıkça beyan edilmiştir. Eklentinin başka hiçbir yerinde uzak kod yüklenmez. - Sheets aktarımı için kullanılan Google OAuth erişim belirteci hiçbir zaman saklanmaz — her işlemde
yeniden istenir ve yalnız bellekte tutulur. Oturumunuzun açık kalması için Firebase oturum
belirteçleriniz (kimlik belirteci ve yenileme belirteci) kendi cihazınızdaki
chrome.storage.localalanına kaydedilir; Google'ın kendi belirteç ucu dışında cihazınızdan hiçbir yere gitmez ve çıkış yaptığınızda silinir.
10. KVKK ve GDPR Hakları
Türkiye veya Avrupa Birliği'nde iseniz aşağıdaki haklara sahipsiniz:
- Verilerinize erişim
- Hatalı verilerin düzeltilmesi
- Verilerinizin silinmesi (unutulma hakkı)
- Veri taşınabilirliği
- İşlemeye itiraz
- Verdiğiniz onayı (örn. pazarlama e-postası) istediğiniz zaman geri çekme — vermek kadar kolay
Bu hakları kullanmak için: advantagescope@gmail.com
11. Çocukların Gizliliği
AdVantage 16 yaşından küçüklerin kullanımı için tasarlanmamıştır. Çocuklardan bilerek veri toplamayız.
12. Politikadaki Değişiklikler
Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişiklikler Chrome Web Mağazası sayfası veya uzantı içi bildirimle duyurulur. Değişikliklerden sonra uzantıyı kullanmaya devam etmek kabul anlamına gelir.
13. İletişim
Gizlilikle ilgili her türlü soru için:
📧 advantagescope@gmail.com