plus.ad
Why plus.adWhere you appearHow it works
Log inStart advertising
LEGAL

Data Privacy Notice

Effective 11 October 2026 · Version 2026-10-11

Privacy in brief

We use data necessary to operate accounts, campaigns, billing, measurement and security. We do not require shoppers’ names, personal email addresses, postal addresses or payment-card details for conversion measurement.

1. Controller and contact

Taurus Data GmbH, Leopoldstr. 2-8, 32051 Herford, Germany is the controller when it determines why and how the data described here is processed. The service is known as plus.ad.

Send privacy requests to info@taurusdata.de. Do not email passwords, recovery codes, complete card data or unnecessary identity documents.

2. Scope and roles

This notice covers visitors, contacts, advertiser and publisher users, invited team members, administrators and people whose browser or conversion event is measured through a plus.ad campaign.

For account administration, billing, platform security, fraud prevention and operation, Taurus Data GmbH acts as controller. An advertiser controls the customer and conversion data it chooses to send from its shop. Where we handle that data only on documented advertiser instructions, we act as processor. Advertisers must provide their own privacy information and lawful basis for tracking.

3. Data we process

  • Account and team: name, business email, password hash, organisation, role, status, invitations and authentication records.
  • Company and billing: company name, billing email, business address, country, VAT identifier, funding references, balances, ledger entries, invoices and payment status. plus.ad does not store complete card numbers or security codes.
  • Shop, catalogue and campaigns: shop domain, markets, language, feed source and import records, products, URLs, campaign settings, budgets, approvals and delivery status.
  • Measurement: random click and event IDs, campaign, shop and product references, country code, timestamps, CPC, publisher and ad-space IDs, conversion type, event/order reference, value, currency, product references and consent status. Advertisers must not include personal contact or special-category data.
  • Security and technical: session and trusted-device IDs, hashed recovery and one-time codes, sign-in and rate-limit events, audit actions, API-key prefixes and hashes, IP-derived hashes, user agent, security events and request logs.
  • Contact: business email, message, handling status, browser data and a keyed IP-derived hash for spam prevention.

We receive data from users and their organisations, advertiser shops and tracking integrations, participating publishers, and automatically when a browser or system interacts with the Service.

4. Purposes, legal bases and retention

PurposeLegal basisTypical retention
Accounts, workspaces, team access, shops, products, campaigns, publisher feeds, support and reportingContract and requested pre-contract stepsAccount term, then up to 24 months, unless deletion or a longer legal period applies
Authentication, 2FA, trusted devices, recovery, abuse prevention and incident investigationContract and legitimate security interestsSessions up to 12 hours; trusted devices up to 30 days; expired one-time records generally 30 days; security and audit records generally 24 months, longer for an active incident or claim
Contact requests and spam preventionRequested pre-contract steps and legitimate protection interestsEnquiries generally 12 months after resolution; anti-abuse attempts generally 30 days
Deliver, validate and report clicks; attribute conversions; prevent invalid traffic; calculate charges and compensationContract and legitimate interests in accurate secure measurementEvent-level measurement generally up to 25 months; financial records as below
Funding, billing, invoices, ledger, tax and legal complianceContract and legal obligationApplicable German statutory periods, generally 8 to 10 years depending on the record
Reliability, troubleshooting, aggregate statistics and Terms enforcementLegitimate interests in a reliable secure serviceRaw technical logs generally 30 days; relevant incident or enforcement records up to 24 months or the duration of a claim
Activation, invitations, security codes, password reset and service noticesContract, security interests and legal obligation where applicableOnly as long as needed for delivery, troubleshooting and evidence of required notices

Periods may be extended for a legal hold, fraud investigation, dispute, enforcement or statutory duty. At expiry, data is deleted or irreversibly anonymised. Non-identifying aggregate statistics may be kept.

5. Legitimate interests

Our legitimate interests are securing business accounts, preventing spam and invalid traffic, maintaining reliable measurement, protecting billing and publisher compensation, defending claims and improving the Service. We consider the context, reasonable expectations and safeguards such as hashing, access limits, retention and human review. You may object as described below.

6. Recipients

Authorised recipients may include the organisation managing your account; participating publishers receiving the campaign, product, click and compensation data needed for distribution and reporting; the service providers described below; banks, accountants and tax advisers; professional advisers, courts, regulators and authorities where lawful; and a successor in a merger, financing, reorganisation or sale under confidentiality safeguards.

We do not sell personal data or share it for third-party cross-context behavioural advertising.

7. Key service providers and data protection roles

Provider and serviceData and purposeData protection role
Stripe
Hosted checkout and payment processing
Business and billing details, payment amount, currency, payment and fraud-prevention metadata. Complete card details are entered directly into Stripe Checkout and are not stored by plus.ad.Stripe acts as our processor where it provides technical services on our documented instructions. It acts as an independent controller for regulated payment processing, fraud and loss prevention, compliance, interactions with banks and payment networks, and its own service administration. These role boundaries and transfer safeguards are set out in Stripe’s Data Processing Agreement.
Mailtrap (Railsware Products Studio LLC)
Transactional email and inbound support email
Sender and recipient address, name, subject, message body, delivery metadata and support-ticket references.Mailtrap acts as our processor when sending or receiving messages on our instructions. It acts as an independent controller for its account administration, security, abuse prevention and legal compliance. Mailtrap states that service data is hosted in the United States; its contractual terms and DPA govern the processing.
Shopify
Optional shop, catalogue and conversion integration
Shop domain, optional product catalogue, order or event references, amounts, currency, timestamps, consent state and delivery diagnostics. plus.ad does not require shopper names, email addresses or postal addresses for this integration.The advertiser or merchant controls the shop and customer data. Shopify generally processes merchant customer data for the merchant under the Shopify DPA, while it may act as an independent controller for specified platform, security and consumer services. plus.ad acts as the advertiser’s processor for instructed catalogue and conversion measurement, and as controller for its own app security, audit and account administration.
Spaceship, Inc.
Virtual-server hosting and network infrastructure
Application data, databases, encrypted secrets, files, backups and technical logs required to host and protect the Service.Spaceship acts as our processor for hosted customer data under its Data Processing Addendum. It remains an independent controller for its own customer account, billing, security and legal-compliance data.

Where a provider acts as our processor, it may use approved subprocessors subject to contractual safeguards. A provider’s separate controller processing is governed by its own privacy information. The precise role follows the actual processing activity rather than the provider name alone.

8. International transfers

Stripe, Mailtrap, Shopify and Spaceship may process data outside the European Economic Area, including in the United States, or engage subprocessors there. Before a restricted transfer made by us, we rely on a Chapter V GDPR mechanism such as an adequacy decision (including an applicable EU-US Data Privacy Framework certification) or European Commission Standard Contractual Clauses, plus supplementary safeguards where required. Provider-specific mechanisms are documented in the agreements linked above. You may request information about the applicable safeguard; commercially sensitive details may be redacted.

9. Cookies and browser storage

plus.ad uses strictly necessary technology: a signed session cookie for login and CSRF protection; an optional trusted-device cookie for up to 30 days; and browser session storage for a click ID used to attribute a conversion during the session. Secure, HttpOnly and SameSite attributes are applied where appropriate.

We do not currently use advertising or cross-site behavioural cookies on plus.ad. Before introducing non-essential analytics or marketing technology, we will provide information and obtain consent where required. Removing necessary cookies may sign you out or prevent security features from working.

10. Automated validation

Automated rules apply campaign status, market, duplication, rate, bot, budget and attribution checks to clicks and conversions. A rule can accept or reject an event for reporting, charging or publisher compensation and pause campaigns with insufficient funds. These controls concern business advertising activity rather than shopper characteristics.

An authorised user may request human review of a result materially affecting charges or access by providing the click, event or campaign ID. We do not use this data for automated decisions producing legal or similarly significant effects on individual shoppers.

11. Your rights

Subject to GDPR conditions and exceptions, you may request access, a copy, correction, deletion, restriction or portability, and object to processing based on legitimate interests. Consent can be withdrawn at any time without affecting earlier processing.

Email info@taurusdata.de and identify the relevant account, organisation, click or interaction. We may request proportionate verification. We normally respond within one month; a permitted extension will be explained.

You may complain to the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia at ldi.nrw.de, or the authority where you live or work.

12. Security

Measures appropriate to risk include access controls, password hashing, two-factor authentication, hashed or encrypted security secrets, scoped roles, audit logging, transport encryption, security headers and restricted administration. No internet service guarantees absolute security. Users must protect credentials and promptly report suspected compromise.

13. Age restrictions

plus.ad is a business-to-business service and is not intended for use by children. User accounts may only be created by individuals who are at least 18 years old and authorised to act on behalf of a business.

14. Changes

We may update this notice when the Service, providers or law changes. The current version and effective date remain here. We will notify account Owners by email or in the Service before a material change where required.

plus.ad

Self-service CPC advertising for ecommerce.

ImprintData Privacy NoticeTerms