Mintro

Privacy Policy

Last updated 7 August 2026

Mintro LLC operates ARIA, a monitoring dashboard for advertising agencies. This policy explains what we collect, why, where it lives, and how to get it deleted. It is written to be read, not to be survived.

Who we are

Mintro LLC (“Mintro”, “we”) is a Massachusetts limited liability company. We provide ARIA, software that reads advertising data on behalf of agencies and tells them which client accounts need attention.

Our customers are agencies. Where an agency connects advertising accounts belonging to their own clients, the agency is the controller of that data and Mintro is a processor acting on their instructions.

What we collect

Account information. The agency name, work email address and password you provide at signup. Passwords are stored only as a salted PBKDF2 hash; we never store or transmit them in readable form.

Advertising data. When you connect a Meta advertising account, we read performance data through the Meta Marketing API: ad account names, identifiers, currency and time zone, account status, spend, impressions, clicks, conversions and lead events, and campaign, ad set and ad names.

Access credentials. The OAuth access token Meta issues when you connect. It is encrypted before it is written to our database and is only decrypted, in memory, for the duration of a request.

Technical data. Standard server logs — IP address, timestamp, requested path — retained for security and troubleshooting.

What we do not do

  • We never write to your ad accounts. ARIA only ever reads. No part of the product issues a write operation — it does not create, edit, pause or spend, and it has no feature that could.
  • We never sell your data, and we do not share it with advertisers, data brokers or ad networks.
  • We do not use your advertising data to train machine-learning models — not ours, and not a third party’s. Where a feature generates a written summary of an account, the request is sent with training disabled.
  • We do not store the personal data of your customers’ end users. ARIA keeps aggregate performance metrics — spend, counts, totals — not contact records or audience lists. Where a CRM is connected, we read opportunity records to count and total them, and retain only those counts and totals.

How we use it

  • To show you your advertising performance in the dashboard.
  • To detect problems — accounts spending without producing leads, cost per lead moving outside its normal range, delivery stopping.
  • On paid plans, to send you those findings by Slack or email, and to produce reports you have asked us to produce.
  • To operate, secure and support the service, and to bill you.

We do not use advertising data for any purpose you have not asked for. In particular, we do not aggregate it into benchmarks or market research products.

Where it lives, and how it is protected

Data is stored in a Postgres database hosted by Supabase in the United States (Oregon), and the application runs on Vercel. Every tenant’s rows are isolated at the database level by row-level security, so one agency’s data cannot be returned to another even in the event of an application bug.

OAuth tokens are encrypted with AES-256-GCM using a key held outside the database. A compromise of the database alone does not yield usable credentials. Traffic is encrypted in transit with TLS.

Who else processes it

We keep the list of sub-processors short and name them plainly:

  • Vercel — application hosting (United States).
  • Supabase — database hosting (United States).
  • Meta Platforms — source of the advertising data you connect.
  • Anthropic— where you use a feature that writes a summary of an account, the performance figures for that account are sent to Anthropic’s API to generate the summary. Sent with training disabled; no credentials and no contact data are included.
  • Stripe — payment processing, where you are on a paid plan. Mintro does not receive or store your card details.
  • Slack — only where you have asked us to deliver alerts or reports to a Slack workspace.

How long we keep it

Advertising data is retained while your account is active. If you disconnect a platform, we stop collecting from it immediately and delete the stored credential. If you close your account, we delete your data within 30 days, except where we are required to keep billing records for tax purposes.

Deleting your data

You can remove your data at any time, and you do not need to ask us first:

  • Disconnect a platform in the dashboard. The stored access token is deleted and we stop reading from that platform.
  • Remove ARIA from Meta directly— in Facebook, go to Settings & Privacy → Settings → Business Integrations, find ARIA by Mintro and remove it. This revokes our access immediately.
  • Delete your account entirely by emailing jimmybrutskiy@gmail.com from your registered address with the subject Delete my account. We action these within 30 days and confirm by email when it is done.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Email us and we will action it — we do not require a formal process, and we do not charge for it.

Cookies

ARIA sets one cookie: a signed, HTTP-only session cookie that keeps you logged in. It expires after seven days. We do not use advertising or cross-site tracking cookies in the product.

Children

ARIA is a business tool. It is not directed at anyone under 18 and we do not knowingly collect their data.

Changes

If we change this policy in a way that materially affects how we handle your data, we will email account holders before it takes effect. The date at the top always reflects the current version.

Contact

Mintro LLC
74 Old Holyoke Road, Westfield, MA 01085, United States
jimmybrutskiy@gmail.com

See also our Terms of Service.