Last updated July 11, 2026
Privacy Policy
How Relative Companies Inc. handles account, provider, advertising, and operational data when delivering Runes.
Who we are and what this policy covers
Runes is advertising infrastructure owned and operated by Relative Companies Inc. (“Relative,” “Runes,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our websites, create a Runes account, use our dashboard or developer tools, connect an advertising or creator account, contact us, or otherwise interact with Runes.
This policy covers the Runes website, hosted Connect experiences, dashboard, APIs, webhooks, MCP and command-line tools, documentation, support, test environment, and related services. It does not govern Meta, TikTok, Stripe, a Customer’s own product, or another third party, each of which has its own privacy practices.
Our privacy roles
Relative Companies Inc. is generally the controller of personal data used to operate Runes accounts, organizations, billing, security, support, service analytics, abuse prevention, and our business relationship with Customers.
When a SaaS Customer uses Runes to process advertising data for its own users, the Customer generally determines the purpose and means of that processing. In that context, the Customer is the controller or business, and Relative generally acts as its processor or service provider. We process that data under the Customer’s instructions, our agreement, and applicable law. End users should also review the Customer’s privacy notice and direct requests to that Customer when appropriate.
A specific order form or data-processing agreement may describe these roles in more detail and controls if it conflicts with this general explanation.
Personal data we collect
Depending on how Runes is used, we may process the following categories:
- Account and organization data: name, email address, authentication data, organization, role, invitations, account preferences, and verification status.
- Developer and project data: project names, environments, API-key metadata, scopes, redirect URLs, webhook configuration, and developer-supplied external user identifiers.
- Provider connection data: provider identity and account metadata, selected advertising accounts, permissions, connection health, credential expiry, and encrypted access or refresh credentials.
- Advertising data: campaigns, ad groups, ads, objectives, budgets, schedules, targeting, destinations, identities, creative metadata, status, provider identifiers, reporting, attribution, and operation history.
- Creative and creator data: uploaded files, checksums, processing status, safety decisions, consented creator identities and content, authorization state, and creator metrics.
- Conversion data: event data and data-minimized matching fields. Hashable identifiers are normalized and hashed before storage; permitted transient fields may be encrypted for limited delivery purposes.
- Billing data: subscription, invoice, payment status, Stripe customer identifiers, billable connected-account usage, and related tax or reconciliation records. We do not store full payment-card numbers.
- Technical and security data: IP address, user agent, timestamps, request IDs, audit activity, device and browser information, rate-limit events, authentication events, and security risk signals.
- Support and communications: messages, attachments, call notes, feedback, and records of requests or incidents.
Where data comes from
We receive personal data from:
- you and other members of your Runes organization;
- Customers that identify an end user or initiate a hosted connection;
- Meta, TikTok, and other providers after an authorized connection;
- Stripe and other vendors that support billing, infrastructure, security, or communications;
- your browser, device, application, API client, webhook endpoint, or use of the service; and
- public or lawful business sources used for verification, fraud prevention, sanctions checks, or provider approval where permitted.
Provider credentials are obtained through authorized OAuth or equivalent provider flows. Customers and end users should never send provider passwords or raw API secrets to Runes support or place them in an external user identifier.
How we use personal data
We use personal data to:
- create and secure accounts, organizations, projects, environments, and credentials;
- run hosted Connect and creator-consent flows;
- execute authorized provider reads and writes, synchronize reporting, deliver conversions, and send webhooks;
- process creative files, enforce safety controls, prevent unauthorized spend, and protect shared provider applications;
- meter usage, process subscriptions and invoices, and administer customer accounts;
- provide support, debug failures, reconcile provider state, and communicate service or security notices;
- detect, investigate, and prevent fraud, abuse, credential compromise, policy violations, and incidents;
- maintain audit trails, backups, reliability, and business records;
- improve Runes using product and operational telemetry separated from Customer advertising data; and
- comply with law, provider obligations, contractual requirements, and valid legal process.
Legal bases
Where a law requires a legal basis, we rely on one or more of the following: performance of a contract; our legitimate interests in operating, securing, supporting, and improving Runes; compliance with legal obligations; protection of vital or legal interests; and consent where required. We balance legitimate interests against the rights and reasonable expectations of affected people.
When we act as a processor or service provider, the Customer is responsible for selecting the legal basis for its processing and for giving us lawful instructions. A person may withdraw consent where consent is the basis, but withdrawal does not affect earlier lawful processing and may prevent continued use of a connected feature.
Provider data commitments
We use provider data only to provide, secure, support, and comply with the requested Runes integration. We do not sell provider data, use it for unrelated advertising profiles, or train general-purpose machine-learning models on it. We do not expose provider access or refresh tokens to Customers, end-user browsers, analytics tools, or webhook payloads.
Provider data remains subject to provider permissions and policies. When a connection is revoked, Runes blocks new use, removes usable encrypted credentials, and attempts provider revocation. Historical resources, reporting, lineage, and minimum audit records may remain as described below and in the Data Deletion Policy.
How we disclose data
We may disclose personal data to:
- Customers and authorized organization members according to tenant, project, environment, and role permissions;
- advertising providers when needed to perform an authorized connection, advertising operation, reporting request, conversion delivery, or revocation;
- service providers and subprocessors supporting infrastructure, storage, billing, email, security, support, and—when enabled and disclosed—content-safety processing;
- professional advisers such as lawyers, auditors, insurers, and accountants under appropriate duties;
- authorities or affected parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid process; and
- a successor in a merger, financing, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate protections.
We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law. If our practices change, we will update this policy and provide any legally required choice before the change applies.
Retention
We keep personal data only for as long as reasonably necessary for the purpose collected, the Customer relationship, provider obligations, security, auditability, billing, dispute resolution, and law. Current operational defaults include:
- transient conversion IP address, user agent, and provider click identifiers are encrypted and deleted after all provider deliveries are terminal or within 24 hours, whichever comes first;
- incomplete upload intents expire after 7 days;
- blocked, unappealed quarantine bytes expire after 30 days;
- raw provider API payloads are retained for no more than 30 days by default after required normalization and safe lineage extraction;
- bounded safety and provider-history evidence is retained for 90 days by default; and
- normalized reporting, resource history, customer-requested files, audit events, metering, and billing records follow the Customer relationship, applicable order form, provider requirements, and legal retention needs.
Data may remain longer when subject to a legal hold, active dispute, security investigation, backup cycle, tax or accounting rule, or another lawful exception. When retention ends, we delete, anonymize, aggregate, or securely isolate the data.
Security
We use safeguards designed for the sensitivity and risk of the data we process. These include tenant- and environment-scoped authorization, encryption of provider credentials, hashing of API and Link tokens, private object storage, signed webhook delivery, field redaction, least-privilege access, audit events, rate and quota controls, safety checks, and separation of human sessions from machine and provider credentials.
Decrypted provider tokens exist only for the minimum time needed to make an authorized call. Secrets, authorization headers, cookies, raw user matching fields, and unbounded provider payloads are prohibited from diagnostic logs. No security program can eliminate every risk; contact will@relativecompanies.comif you believe data or credentials have been compromised.
International data transfers
Runes and its service providers may process data in the United States and other countries where we or they operate. Those countries may have laws different from the place where the data originated.
Where required, we use contractual, organizational, and technical safeguards for international transfers, such as approved standard contractual clauses and supplementary measures. A Customer data-processing agreement may provide additional transfer terms. We do not claim participation in a certification framework unless that certification is expressly stated in current Runes documentation.
Privacy rights and choices
Depending on your location and our role, you may have rights to know or access personal data, correct inaccurate data, request deletion, receive a portable copy, restrict or object to processing, withdraw consent, opt out of certain sale or sharing, limit certain sensitive-data uses, and appeal a denied request. You may also have the right to complain to a data-protection or consumer-protection authority. We will not discriminate against you for exercising a legal privacy right.
Submit a request to will@relativecompanies.com. Include enough information to identify the relevant account, organization, Customer, or connection, but do not send passwords, API keys, provider tokens, or unnecessary sensitive information. We may verify identity and authority before acting. If Runes processes the data only for a Customer, we may direct the request to that Customer or assist it in responding.
Automated processing and safety
Runes may automatically validate advertising operations, detect abuse, classify content, apply quotas, and decide whether a write should proceed, pause, queue, or require review. These controls protect Customers, end users, providers, and the shared provider applications. Ambiguous high-risk content may be routed to human review, and safety decisions can be appealed through available support channels.
Runes does not use Customer advertising data to make solely automated decisions that produce legal or similarly significant effects about an individual. If that changes, we will provide the notices, explanation, and rights required by applicable law.
Children
Runes is a business service and is not directed to children under 13 or the higher minimum age required by local law. We do not knowingly collect personal data directly from children for their own use of Runes. Contact us if you believe a child has provided data without appropriate authorization.
Changes and contact
We may update this policy as Runes, provider requirements, vendors, and law change. The effective date above shows the latest revision. We will provide additional notice where a change materially affects privacy rights or where law requires it.
Questions, privacy requests, and complaints may be sent to Relative Companies Inc. at will@relativecompanies.com. If you are an end user of a Customer’s product, contacting that Customer first may be the fastest way to identify and act on your data.