Last updated: July 16, 2026
DEFY™ AdSymphony ("we", "our", or "us") is an advertising performance management platform operated by DEFY. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform at bidharmony.defycommerce.co and any associated services (collectively, the "Service").
By accessing or using the Service you agree to the practices described in this policy. If you disagree, please discontinue use of the Service.
When you register, we collect your email address, hashed password, assigned role (App Admin, Admin, or Manager), and platform access preferences. We do not store plaintext passwords.
If you connect a third-party advertising account (Amazon Ads, Meta Ads, Google Ads, or Shopify), we access performance metrics — such as spend, impressions, clicks, conversions, and revenue — through each platform's official API using OAuth tokens you explicitly authorize. We store aggregated metrics in our database to power dashboards and reporting.
We may log standard server-side information including IP addresses, browser type, pages visited, and timestamps for security monitoring and debugging purposes. This data is not sold or used for advertising.
We use browser local storage to remember your active brand selection and session token. We do not use third-party tracking cookies or advertising pixels.
We do not sell, rent, or share your data with third parties for marketing or advertising purposes.
The Service integrates with the following platforms via their official APIs. Your use of these integrations is also governed by each platform's own privacy policies:
We request only the minimum API scopes required to read performance data. We do not create, modify, or delete ads on your behalf without explicit user action within the platform.
Your data is stored in a PostgreSQL database hosted on Railway. We use industry-standard security practices including:
Our application and database run on managed cloud infrastructure (Railway), which provides network-level protections, including:
No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at the address below.
We maintain a documented Incident Response Plan governing how we detect, respond to, and report security incidents affecting personal data or data accessed through connected platform APIs (including Amazon Information). The plan is summarized below.
A designated Security Lead owns the incident response process and is the primary point of contact for any suspected or confirmed incident. The Security Lead coordinates investigation, containment, and communication, and may engage engineering and infrastructure personnel as needed. Every team member is responsible for reporting a suspected incident to the Security Lead immediately upon discovery.
Suspected incidents may be identified through server and access logs, alerts from our cloud infrastructure provider, or reports from users or researchers. Any team member who becomes aware of a suspected incident must report it to the Security Lead within 24 hours of detection so that triage can begin.
For any security incident involving Amazon Information, we will notify Amazon at security@amazon.com within 24 hours of confirming the incident. We will notify affected users, and any regulators, without undue delay and within the timeframes required by applicable law.
The Incident Response Plan is reviewed and tested at least once every six months, and is updated following any material incident or significant change to our systems, so that roles, contacts, and procedures remain current.
We enforce the following access and password controls on all accounts that can reach the Service's systems, administrative functions, source control, cloud infrastructure, or data (including personal data and data accessed through connected platform APIs):
We retain your account data for as long as your account is active. Advertising metrics are retained to power historical reporting. You may request deletion of your account and associated data at any time by contacting us. Upon deletion, your data will be removed within 30 days except where retention is required by law.
Depending on your location, you may have the right to:
To exercise any of these rights, contact us at the address in Section 11.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the revised policy. For material changes we will notify account holders via email where possible.
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact:
© 2026 DEFY™ AdSymphony. All rights reserved.
Back to App →