Buben Media

Privacy Policy

Last updated: 18 July 2026

Who we are

This platform is operated by BBNS s.r.o. (trading as Buben Media), a company registered in the Czech Republic, with its registered office at Na Labišti 525, 530 09 Pardubice, Czech Republic. BBNS s.r.o. is the data controller for the data described here. For any privacy question you can reach our data protection contact, Jan Buben, at buben@buben-media.cz.

What the platform does

Buben Media provides marketing agencies with a set of web tools: consolidated advertising performance reporting (Google Ads and Meta Ads), product-feed optimization for shopping channels, e-shop user-experience analysis, and related workspace features. This policy covers all of them. Access to advertising and merchant data is always granted by the account owner and is used only to provide these tools.

What data we collect

Account data

Your e-mail address, name and a securely hashed password (or, if you sign in with Google, your Google account e-mail and name). We use this to create and secure your account.

Data from Google (when you connect Google)

  • Sign-in: basic Google profile (e-mail and name) if you choose Google Login.
  • Google Ads: read-only advertising performance data (e.g. spend, impressions, clicks, conversions) for the ad accounts you authorize, to build the agency reporting dashboard.
  • Google Merchant Center (Content API): product data, account information and performance reports for the Merchant accounts you connect, to provide product-feed optimization, product reviews and shopping-program features. We store a connection token, encrypted at rest.

Data from Meta (when you connect Meta)

  • a long-lived Meta access token (stored encrypted at rest);
  • your Meta user ID and, where applicable, Business Manager ID;
  • the ad accounts you grant access to (IDs, names, currency, status);
  • aggregated advertising performance metrics for those accounts (spend, impressions, clicks, conversions and conversion value).

Data you provide or generate in the tools

  • e-shop web addresses you submit for analysis, and the screenshots and reports we generate from those public pages;
  • product feeds you upload and the optimized output produced from them;
  • files, briefs and content you create or upload in the workspace;
  • messages you send us (e.g. support or error reports).

Billing data

If your account is billed, we store company billing details (name, company ID / VAT ID, address, billing e-mail). Card payments are handled by our payment provider (Stripe) — we do not store full card numbers.

Technical data

Authentication cookies and basic security/operational logs needed to run the service.

Why we process it, and our legal basis

We process the data to provide the tools you use — advertising reporting, feed optimization, e-shop analysis and workspace features — to secure your account, to bill where applicable, and to support and improve the service. Under the GDPR our legal bases are the performance of our contract with you, our (and our clients’) legitimate interest in providing these tools, and, where relevant, your consent. Advertising data is used strictly to produce reports and outputs for you. Our Meta access is read-only — we request only the permissions needed to read ad performance (ads_read) and to list the ad accounts you authorize (business_management); we never create, edit, pause or manage ads, campaigns or budgets, and we do not request ads_management or any write permission.

Google user data — Limited Use

Buben Media’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features described above; we do not sell it, do not use it for advertising, do not transfer it except as needed to provide these features or as required by law, and do not allow humans to read it except with your consent, for security or to comply with the law.

Automated processing

Some features use automated and AI-assisted processing to analyze e-shop pages and to enrich product-feed data. This operates on the business content described above; we do not use it to make decisions producing legal effects about individuals.

How we store and protect your data (data security)

We apply technical and organizational security measures designed to protect the data we process — including sensitive data obtained from Google (Google Ads reporting and Google Merchant Center data) and from Meta — against unauthorized access, disclosure, alteration and loss. In particular:

  • Encryption in transit: all communication with the platform is protected with industry-standard TLS/HTTPS. The application is not served over unencrypted connections.
  • Encryption at rest: OAuth access and refresh tokens for Google and Meta are additionally encrypted at the application level before being stored, so they are never persisted in plain text. Data is held in a managed database with encrypted storage.
  • Access control and least privilege:using the platform requires authentication, and every request is authorized against the signed-in user’s role and organization, so each customer can access only their own data (strict tenant isolation). Access to your Google and Meta data is limited to the user-facing features the account owner has authorized.
  • Restricted internal access: access to production systems and stored credentials is limited to a small number of authorized team members on a strict need-to-know basis. We do not read your connected Google or Meta data except with your consent, for security, or to comply with the law.
  • Secure, isolated hosting: the application and database run on Render (Render Services, Inc.), our infrastructure sub-processor, in an EU data centre in Frankfurt, Germany, on isolated, access-controlled infrastructure. Secrets and API credentials are kept in a secured configuration store, separate from the source code.
  • Monitoring and minimal logging: we keep the operational and security logs needed to run and protect the service, and design them to avoid recording sensitive third-party data.
  • Incident response: if we become aware of a personal data breach, we assess it without undue delay and notify the affected users and the competent supervisory authority where required by the GDPR.

Who we share it with

We do not sell your data. We share it only with sub-processors that operate the service on our behalf, and only as needed:

  • Render (Render Services, Inc.) — cloud hosting and database.
  • Stripe — payment processing (for billed accounts).

We also use vetted sub-processors for AI-assisted content analysis and enrichment and for transactional e-mail delivery, all bound by data-processing agreements; a current list of all sub-processors is available on request at buben@buben-media.cz. Google and Meta are the sources of the advertising and merchant data you connect. We may disclose data where required by law.

International transfers

Data is hosted in the EU (Frankfurt). Some providers (e.g. Render, Stripe) are established outside the EU; where data is transferred internationally it is covered by appropriate safeguards such as the EU Standard Contractual Clauses.

How long we keep it

We keep data for as long as your account and connections remain active. When a connection is removed, the associated tokens, accounts and metrics are deleted; when an account is closed, its data is deleted after any legally required retention (e.g. tax records for invoices). See our Data Deletion page.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. Where we rely on your consent, you may withdraw it at any time, without affecting processing already carried out. To exercise any of these rights contact buben@buben-media.cz or use our Data Deletion page. You may also lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů).

Changes to this policy

We may update this policy from time to time. The current version and its date are always shown at the top of this page.