Privacy Policy

Effective 25 September 2026

VADS is operated by Apdak Pty Ltd (ACN 644 414 620) ("VADS", "we", "us", "our"). This policy describes how we handle personal information for three kinds of people: advertisers and publishers who hold VADS accounts, the individual members of their organizations, and the end users of MCP tools that carry VADS ads. We're a small, early-stage Australian company; this policy describes our actual practices rather than asserting any certification.

1. Information we collect

We collect this information directly from account holders and their organizations:

CategoryWhat it includes
Account detailsLegal name, email address, and role for every member of an advertiser or publisher organization.
Authentication dataA salted password hash; if you enable multi-factor authentication, a TOTP secret or the public key of a registered security key (WebAuthn) — never a private key or the plain TOTP seed for anyone but you.
Session dataAn httpOnly session cookie and short-lived CSRF token for the advertiser/publisher portal.
Technical logsIP addresses and request metadata captured in server logs for operating and securing the Service.
Dispute evidenceFiles a publisher or advertiser uploads to support a billing dispute (PDF, PNG, JPEG or plain text, up to 2 MiB each) — we keep the sniffed file type, size and a hash, not the original filename.
Payment informationHandled by Stripe, not stored by us directly — see "Who we share information with" below.

2. Information about end users of MCP tools

We aren't a party to the conversation between an end user and an MCP tool, and the SDK is built not to see it. Here's exactly what touches our systems when someone uses a tool that carries a VADS ad:

  • Ad requests. The publisher's server sends VADS a small, allowlisted set of fields to select an ad — an environment flag, a category and some keywords describing the tool call. It never sends the tool's actual input or output.
  • Clicking a sponsored link. A sponsored result's link points at our redirect service (r.vads.au), which looks up the advertiser's real destination and forwards the browser there. Handling that redirect does not set a cookie or place a tracking pixel.
  • Fraud-prevention fingerprint. When a redirect is followed, we derive a coarse, pseudonymous fingerprint from the request — the IP address masked down to its /24 (IPv4) or /48 (IPv6) range, and the User-Agent reduced to a broad browser family (e.g. "chrome", "bot") — never the full IP address or User-Agent string. This is used only to detect abuse patterns like duplicate or automated clicks, and is governed by the retention limits below.

3. Cookies

The only cookie the Service sets is the advertiser/publisher portal's own session cookie, plus a short-lived CSRF token used to protect state-changing requests — both are functional, httpOnly where applicable, and exist only for people who are signed in to an account. We don't run any analytics, advertising, or tracking cookies, on the portal or anywhere an end user encounters a VADS ad. This marketing site (vads.au) sets no cookies at all.

4. How we use information

  • To create and operate advertiser and publisher accounts, including authentication and account security.
  • To run the ad marketplace: selecting, serving, billing and paying for sponsored results.
  • To review ads, destinations and publisher sites before they go live, and to investigate disputes.
  • To detect and prevent fraud and invalid traffic.
  • To meet our legal, accounting and tax obligations.
  • To communicate with you about your account, and to respond to support requests.

5. Retention and deletion

We keep information for as long as we need it for the purpose it was collected, then delete or de-identify it. Specific retention periods built into the Service today:

  • Fraud-prevention evidence tied to a specific engagement (including the coarse fingerprint described above) is retained for 180 days from receipt, after which a scheduled job purges it automatically.
  • Dispute evidence is retained for as long as it may be relevant to a billing dispute or a chargeback, and consistent with our accounting and tax record-keeping obligations.
  • Closing your account doesn't immediately erase records we're required to keep for accounting, tax, fraud-prevention or legal reasons; those follow the retention periods above and applicable law, not your account's lifecycle.

6. Who we share information with

We share information with the following categories of service providers, only as needed to run the Service:

ProviderWhat for
Amazon Web Services (us-east-1, N. Virginia)Hosting, our database, and outbound account/notification email (Amazon SES).
StripeAdvertiser card payments and wallet funding, and publisher payouts via Stripe Connect. Stripe holds your payment-method details directly — we never see or store your full card number.
Let's EncryptIssues the TLS certificates that encrypt traffic to our sites; this involves no personal information beyond the domain name itself.

We don't sell personal information, and we don't share it with advertisers or publishers beyond what's needed to run a campaign or a payout (for example, an advertiser doesn't get a publisher's identity, and vice versa, beyond what the portal itself shows for billing and disputes).

7. Security

Account passwords are never stored in plain text. Multi-factor authentication is required before financial actions, and changing a payout destination requires approval from a second, distinct member of your organization plus a cooling-off period. Every financial transaction is recorded in an append-only, double-entry ledger. No system is perfectly secure, and we can't guarantee information will never be accessed, disclosed, altered or destroyed in breach of this policy, but these controls are built into the Service, not just described here.

8. International transfers

Our infrastructure runs in AWS's us-east-1 region (the United States), and Stripe processes payments globally. This means information about Australian account holders is processed outside Australia. We choose providers with their own substantial security and compliance programs, but we don't independently certify their practices beyond what they publish.

9. Your rights

If the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to you, you have rights to access and correct the personal information we hold about you, and to complain if you think we've mishandled it. In practice:

  • You can view and correct most of your own account information directly in the portal.
  • Account owners and admins can export a copy of their organization's account records from the portal.
  • You can ask us to close your account, subject to the closure conditions in our Terms of Service.
  • You can contact us at support@vads.au for any other access, correction or deletion request, or to raise a concern — we'll respond as quickly as we reasonably can.

10. Australian Consumer Law

Nothing in this policy limits or excludes any right or remedy you have under the Australian Consumer Law that cannot lawfully be excluded.

11. Children

The Service is a business-to-business advertising marketplace and isn't directed at children. We don't knowingly collect personal information from children through the advertiser or publisher portals.

12. Changes to this policy

We may update this policy as the Service changes. We'll update the effective date above when we do, and tell active account holders about material changes.

13. Contact us

Questions, requests, or complaints about this policy or your personal information: support@vads.au.