Privacy Policy for TRG Ad Studio

Effective Date: July 29, 2026

TRG Research L.L.C. (“TRG,” “we,” “us,” or “our”) operates TRG Ad Studio, an internal business application used to create, publish, manage, analyze, and monitor advertising campaigns on third-party advertising platforms, including Google Ads and Meta.

This Privacy Policy explains how TRG Ad Studio accesses, collects, processes, stores, discloses, and deletes information.

1. Internal-Only Application

TRG Ad Studio is an internal business tool. It is not offered for general public use, and public account registration is not available.

Access is restricted to authorized TRG employees, contractors, administrators, and other individuals specifically approved by TRG.

Authorized users may only connect, access, or manage advertising accounts for which they have valid authorization.

2. Information We Process

TRG Ad Studio may process information provided directly by authorized users, information obtained from connected advertising platforms, and limited technical information generated through use of the application.

2.1 Account and User Information

We may process:

  • Name

  • Business email address

  • Internal user identifier

  • Job role or access level

  • Login and authentication information

  • Connected advertising-account identifiers

  • Communications, support requests, and feedback

2.2 Advertising Information

TRG Ad Studio may process:

  • Advertising-account names and identifiers

  • Business-account names and identifiers

  • Campaigns

  • Ad groups or ad sets

  • Advertisements

  • Advertising copy

  • Images, videos, and other creative assets

  • Landing-page URLs

  • Keywords

  • Audiences and targeting settings

  • Placements

  • Geographic targeting

  • Campaign schedules

  • Budgets

  • Bids

  • Campaign objectives

  • Campaign, ad set, and advertisement statuses

  • Conversion-event names and configuration information

  • Reporting attribution settings

  • Advertising performance and delivery data

Advertising performance information may include:

  • Impressions

  • Reach

  • Frequency

  • Clicks

  • Click-through rates

  • Conversions

  • Conversion values

  • Purchases

  • Leads

  • Advertising spend

  • Cost-per-click

  • Cost-per-acquisition

  • Return on advertising spend

  • Other reporting and performance metrics supplied by the connected platform

TRG Ad Studio primarily processes business advertising-account information and aggregated advertising performance data. It is not designed to collect or maintain individual Facebook, Instagram, or Google consumer profiles.

2.3 Authentication Information

When an advertising account is connected, we may process:

  • OAuth access tokens

  • Refresh tokens

  • Token expiration information

  • Granted permissions and scopes

  • Platform authorization records

  • Account connection status

We do not ask authorized users to provide their Google, Facebook, or Instagram passwords directly to TRG Ad Studio.

2.4 Technical and Security Information

We may automatically process:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • Date and time of access

  • Login attempts

  • Authentication events

  • Application activity

  • Audit logs

  • Error reports

  • Security events

  • Features used within the application

This information is used to operate, secure, maintain, and troubleshoot TRG Ad Studio.

3. Information Obtained From Meta

When an authorized user connects a Meta account, TRG Ad Studio may receive information through Meta’s APIs and business tools.

Depending on the permissions granted and features used, this information may include:

  • Meta user identifier associated with the authorized app user

  • Meta Business Portfolio identifiers and names

  • Meta advertising-account identifiers and names

  • Facebook Page identifiers and names

  • Connected Instagram professional-account identifiers and names

  • Campaigns

  • Ad sets

  • Advertisements

  • Creative assets

  • Advertising copy

  • Targeting and placement configurations

  • Audience names, identifiers, configuration information, and estimated sizes

  • Campaign budgets and bidding information

  • Campaign schedules

  • Campaign, ad set, and advertisement status

  • Conversion-event configuration information

  • Aggregated advertising performance and reporting data

  • Access tokens

  • Granted permissions

  • Other information necessary to perform a feature requested by an authorized user

TRG Ad Studio only requests Meta permissions that are reasonably necessary to provide its advertising-management, publishing, reporting, and monitoring functions.

TRG Ad Studio does not use Meta Platform Data to build unrelated consumer profiles, determine eligibility for credit, employment, housing, insurance, or similar purposes, or conduct surveillance.

4. How We Use Meta Platform Data

We use information received from Meta to:

  • Authenticate authorized users

  • Connect authorized Meta business and advertising accounts

  • Identify available advertising accounts, Pages, and Instagram professional accounts

  • Retrieve existing campaign information

  • Create and edit campaigns

  • Create and edit ad sets

  • Create and edit advertisements

  • Upload or associate approved advertising creative

  • Set campaign objectives, budgets, bids, schedules, placements, and targeting

  • Publish advertisements

  • Pause, enable, archive, or otherwise manage advertisements

  • Retrieve campaign-delivery information

  • Monitor advertising performance

  • Display advertising reports and dashboards

  • Compare campaign and creative performance

  • Calculate internal advertising metrics

  • Troubleshoot publishing and reporting errors

  • Maintain security and audit records

  • Perform automated actions configured by an authorized user

TRG Ad Studio only takes action within a Meta advertising account when directed by an authorized user or through an automation configured or approved by an authorized user.

Meta Platform Data is not used for purposes materially different from those described in this Privacy Policy without providing appropriate notice and obtaining any required authorization.

5. Information Obtained From Google

When an authorized user connects a Google account or Google Ads account, TRG Ad Studio may receive:

  • Google user identifier associated with the authorized app user

  • Google Ads customer identifiers

  • Google Ads account names

  • Manager-account information

  • Campaigns

  • Ad groups

  • Advertisements

  • Keywords

  • Advertising assets

  • Audience and targeting settings

  • Budgets

  • Bids

  • Campaign schedules

  • Conversion-action information

  • Campaign and advertisement status

  • Aggregated advertising performance information

  • Access tokens

  • Refresh tokens

  • Granted permissions

  • Other information necessary to perform a requested advertising-management or reporting function

6. How We Use Google Data

We use information obtained from Google to:

  • Authenticate authorized users

  • Connect authorized Google Ads accounts

  • Retrieve advertising-account information

  • Create and edit campaigns

  • Create and edit ad groups and advertisements

  • Upload or associate approved advertising assets

  • Manage keywords, budgets, bids, targeting, and schedules

  • Publish advertisements

  • Pause, enable, or manage campaigns

  • Retrieve and display campaign performance

  • Produce internal advertising reports

  • Troubleshoot application or publishing errors

  • Maintain security and audit records

  • Perform actions configured by authorized users

TRG Ad Studio’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

7. Purposes for Processing Information

We process information to:

  • Operate TRG Ad Studio

  • Provide advertising creation and publishing functions

  • Provide campaign-management functions

  • Monitor advertising performance

  • Generate internal reports and dashboards

  • Analyze campaign and creative performance

  • Authenticate authorized users

  • Maintain advertising-platform connections

  • Protect connected accounts

  • Prevent unauthorized use

  • Detect fraud or security incidents

  • Troubleshoot errors

  • Maintain system reliability

  • Comply with applicable laws

  • Comply with Google, Meta, and other applicable platform requirements

  • Enforce our internal policies and agreements

We limit the use of connected-platform information to the purposes described in this Privacy Policy.

8. How We Disclose Information

TRG does not sell, rent, license, or trade Meta Platform Data, Google API data, or other connected advertising-account information.

We may disclose information in the limited circumstances described below.

8.1 Connected Advertising Platforms

Information may be transmitted to Google, Meta, or another connected advertising platform to perform an action requested or configured by an authorized user.

For example, TRG Ad Studio may transmit:

  • Advertising copy

  • Creative assets

  • Landing-page URLs

  • Campaign budgets

  • Bidding instructions

  • Targeting selections

  • Campaign schedules

  • Campaign-management instructions

8.2 Service Providers

We may use service providers that assist with:

  • Cloud hosting

  • Database hosting

  • Application infrastructure

  • Authentication

  • Logging

  • Monitoring

  • Error reporting

  • Data security

  • Data backup

  • Internal analytics

Service providers may process information only as necessary to provide services to TRG. They may not use connected-platform data for their own independent purposes.

Where appropriate, service providers are subject to contractual confidentiality, security, and data-protection obligations.

8.3 Authorized Personnel

Information may be accessed by authorized TRG personnel who require access to:

  • Operate the application

  • Manage advertising campaigns

  • Provide technical support

  • Investigate errors

  • Respond to security incidents

  • Comply with legal or platform obligations

Human access to connected-platform data is limited to circumstances reasonably necessary to operate and secure the application.

8.4 Legal and Security Requirements

We may disclose information when reasonably necessary to:

  • Comply with applicable law

  • Respond to a subpoena, court order, or lawful governmental request

  • Protect TRG’s rights, property, or security

  • Protect the rights or security of authorized users or other persons

  • Investigate fraud

  • Investigate unauthorized access

  • Prevent abuse

  • Respond to a security incident

  • Enforce applicable agreements

  • Comply with advertising-platform requirements

8.5 Business Transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of TRG’s business or assets.

Any recipient will remain subject to applicable privacy, security, legal, and platform obligations concerning the information.

9. Sale of Information

TRG does not sell Meta Platform Data.

TRG does not sell Google API user data.

TRG does not sell information received from connected advertising accounts.

TRG does not transfer connected-platform information to data brokers, information resellers, or unrelated advertising networks.

10. Automated Advertising Actions

TRG Ad Studio may allow authorized users to configure automated advertising-management actions.

These actions may include:

  • Publishing approved advertisements

  • Pausing campaigns

  • Enabling campaigns

  • Adjusting budgets

  • Adjusting bids

  • Updating campaign schedules

  • Generating alerts

  • Producing reports

  • Applying predefined campaign rules

Automated actions are performed only under rules, settings, or instructions approved by an authorized user.

Authorized users are responsible for reviewing the accuracy and appropriateness of campaign settings and automated rules.

11. Data Retention

We retain information only for as long as reasonably necessary to:

  • Operate TRG Ad Studio

  • Provide requested advertising-management services

  • Maintain active advertising-platform connections

  • Produce authorized historical advertising reports

  • Meet legitimate internal business requirements

  • Maintain security and audit records

  • Investigate errors or security incidents

  • Comply with applicable legal, accounting, contractual, and platform requirements

  • Resolve disputes

  • Enforce applicable agreements

Connected advertising-account data may be retained while an account remains connected and for a limited period after disconnection to complete deletion, security, backup, and audit procedures.

Access tokens and refresh tokens are deleted, revoked, or rendered unusable when:

  • The connected account is removed

  • The authorization is revoked

  • The token expires and is no longer needed

  • An authorized deletion request is completed

  • TRG determines that the connection is no longer required

Information may remain temporarily in encrypted backups, disaster-recovery systems, fraud-prevention records, or security logs until those records are overwritten or deleted through their normal retention cycle.

Information retained for legal, security, fraud-prevention, or compliance reasons will be isolated from ordinary business use and retained only for the applicable purpose.

12. Data Security

TRG uses reasonable administrative, technical, and organizational safeguards designed to protect information from:

  • Unauthorized access

  • Unauthorized disclosure

  • Loss

  • Misuse

  • Alteration

  • Destruction

Safeguards may include:

  • User authentication

  • Role-based access controls

  • Restricting access to authorized personnel

  • Encryption during transmission

  • Secure credential and token storage

  • Application monitoring

  • Audit logging

  • Access reviews

  • Security updates

  • Revocation of access when no longer required

  • Backup and recovery procedures

  • Incident-response procedures

No electronic system or method of storage can be guaranteed to be completely secure.

Authorized users are responsible for maintaining the confidentiality of their credentials and promptly reporting suspected unauthorized access.

13. Disconnecting Meta

An authorized user may disconnect TRG Ad Studio from Meta by:

  1. Removing or revoking the TRG Ad Studio integration through the applicable Facebook, Instagram, Meta Business, or Business Integrations settings; or

  2. Contacting TRG using the information in the “Contact Us” section below.

Disconnecting the integration prevents TRG Ad Studio from obtaining new Meta Platform Data or performing future actions through the disconnected authorization.

Disconnecting the app may not automatically delete information that was previously stored by TRG Ad Studio. To request deletion of previously stored information, follow the instructions in Section 15.

14. Disconnecting Google

An authorized user may revoke TRG Ad Studio’s access through the security or third-party access settings associated with the relevant Google account.

Authorized users may also contact TRG and request that a Google Ads connection be removed.

Revoking or removing access may prevent TRG Ad Studio from retrieving advertising information, publishing advertisements, monitoring campaigns, or providing connected features.

15. Meta User Data Deletion Instructions

A user may request deletion of information obtained from Meta by sending an email to:

[PRIVACY EMAIL]

Use the subject line:

Meta User Data Deletion Request

The request should include, when available:

  • The requester’s full name

  • The requester’s business email address

  • The name of the connected Meta Business Portfolio

  • The relevant Meta advertising-account ID

  • The relevant Facebook Page or Instagram account

  • A description of the information the requester wants deleted

A requester is not required to maintain access to TRG Ad Studio to submit a deletion request.

We may request information reasonably necessary to verify:

  • The requester’s identity

  • The requester’s relationship to the connected account

  • The requester’s authority to request deletion

After verifying a valid request, TRG will promptly:

  • Disconnect the applicable Meta authorization

  • Revoke or delete applicable Meta access tokens under our control

  • Delete or de-identify stored Meta Platform Data associated with the requester or connected account

  • Stop processing the deleted information for ordinary business purposes

  • Provide confirmation that the request has been completed or explain any information that must be retained

We may retain limited information when required for:

  • Legal compliance

  • Security

  • Fraud prevention

  • Abuse prevention

  • Recordkeeping

  • Establishing, exercising, or defending legal claims

  • Demonstrating compliance with Meta’s requirements

Information remaining in backups will be deleted or overwritten through the ordinary backup-retention process and will not be restored for ordinary business use.

16. Google Data Deletion Requests

A user may request deletion of information obtained from Google by emailing:

[PRIVACY EMAIL]

Use the subject line:

Google Data Deletion Request

The request should include, when available:

  • The requester’s name

  • The requester’s business email address

  • The applicable Google Ads customer ID

  • A description of the information to be deleted

After verifying the request, TRG will revoke or delete applicable authorization tokens and delete or de-identify associated Google data under its control, except where retention is required for legal, security, fraud-prevention, or compliance purposes.

17. Other Access, Correction, and Deletion Requests

Authorized users may request access to, correction of, or deletion of other personal information associated with TRG Ad Studio by emailing:

[PRIVACY EMAIL]

We may verify the requester’s identity and authority before completing the request.

We will respond within a reasonable period and in accordance with applicable legal and platform requirements.

18. Children’s Privacy

TRG Ad Studio is an internal business application and is not directed to children.

We do not knowingly allow children under 13 to use TRG Ad Studio or knowingly collect personal information from children through the application.

19. International Data Processing

Information may be processed or stored in the United States and in other locations where TRG or its service providers operate.

Where required by applicable law, TRG will use appropriate safeguards for international transfers of personal information.

20. Third-Party Platforms

Google, Meta, Facebook, Instagram, and other connected platforms operate under their own privacy policies, terms, and data practices.

This Privacy Policy describes TRG’s handling of information through TRG Ad Studio. It does not control the independent privacy practices of Google, Meta, advertisers, advertiser websites, or other third parties.

TRG Ad Studio is not endorsed by or affiliated with Google or Meta except through authorized use of their applicable APIs, developer tools, and advertising services.

21. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • TRG Ad Studio

  • Our information practices

  • Applicable law

  • Security requirements

  • Google requirements

  • Meta requirements

  • Other connected-platform requirements

The updated policy will be posted at the same publicly accessible URL and will include a revised effective date.

If a change materially affects how connected-platform data is accessed, used, stored, disclosed, or deleted, we will provide any additional notice or obtain any authorization required by applicable law or platform policy.

22. Contact Us

Questions, privacy requests, and data-deletion requests may be sent to:

TRG Research L.L.C.
Operator of TRG Ad Studio
Email: [PRIVACY EMAIL]

For Meta deletion requests, use the subject line:

Meta User Data Deletion Request

For Google deletion requests, use the subject line:

Google Data Deletion Request