Privacy Policy

Last updated: August 31, 2026

This policy explains what data Waverunner collects for always-on performance advertising measured on your site: why we collect it, and what your rights are. It covers three audiences separately: visitors to this website, Waverunner account holders, and visitors to advertisers' websites where the Waverunner tracking tag is installed. For step-by-step deletion instructions (including Meta App Dashboard requirements), see Data deletion.

1. Who we are

Waverunner is an advertising platform operated by Adwave Digital Inc (“Waverunner”, “we”, “us”). For data you give us when you create an account, Adwave Digital Inc is the data controller. For data collected by the tracking tag on an advertiser's website, the advertiser is the controller and Waverunner processes that data on their behalf.

Waverunner is built for businesses. We treat account and marketing-site interactions as business-to-business. The service is intended for users 18 or older in the United States. If you are under 18, do not use the service.

Questions about this policy: support@adwave.com.

2. Visitors to this website

We measure our public pages with our own product: the same first-party tracking tag we provide to advertisers runs on the marketing site, sign-in, and the post-sign-in start handoff on waverunner.adwave.com (not inside the signed-in product app). It records visits, pages viewed, and which of our own ads brought you here, using first-party cookies set on this domain (the cookies listed in the tracking section below).

We use Intercom for customer support chat on waverunner.adwave.com (and on adwave.com). Intercom may set its own cookies and receive the page URL plus, when you are signed in, your account identity (user id, email, and name) so we can continue a conversation across visits. See Intercom's privacy documentation for details on how they process that data as our subprocessor.

We use Snitcher and RB2B on the public marketing pages (not inside the signed-in product app) so we can tell which companies visit this site. They look up the visiting network's IP against a business directory and return company-level details such as name and industry, not a named person. They may set their own cookies. See Snitcher's and RB2B's privacy documentation for details on how they process that data as our subprocessors.

If your browser sends the Global Privacy Control signal, nothing about your visit is shared with ad platforms: no Google, Meta, or Reddit tags load for you, and you are excluded from every synced audience. Snitcher and RB2B also do not load. When we advertise Waverunner itself, visitors who have not opted out may also receive ad-platform measurement tags so those platforms can measure our ads.

If you arrive through a partner referral link (/a/{code}), we set a first-party cookie _wr_aff for up to 90 days to attribute signups to that partner. It is HttpOnly and used only for commission accounting, not ad targeting.

On sign-in and the website-analysis start handoff we may also set a first-party cookie _wr_acq for up to 30 days. It stores only the referring site hostname and the landing path (plus standard campaign tags when present) so we can tell which channel brought you here. It is HttpOnly and is not used for ad targeting.

Emails and IP addresses from this website are stored only as salted one-way hashes, exactly as described for advertiser sites below. Signing in additionally sets strictly necessary, httpOnly session cookies.

3. Public URL analysis (Campaign Intelligence Brief)

On marketing pages you can submit a public website URL to generate a Campaign Intelligence Brief without creating an account. When you do, we may scrape publicly available homepage content for that URL via our subprocessors (including Firecrawl), derive a short planning summary, and cache the scraped text and brief for a short period (typically up to 24 hours) so repeat requests for the same site do not re-scrape. We rate-limit these requests.

No account is required. We do not use this analysis to build advertising profiles of site visitors, and we do not sell the scraped content.

4. Account holders

When you create and use a Waverunner account, we store:

  • Your email address: used for passwordless sign-in codes and transactional notifications (campaign status, billing events, the weekly digest).
  • Organization data: your businesses, personas, generated creatives, campaigns, and wallet ledger.
  • Billing records: wallet transactions and their Stripe references. Payments are processed by Stripe; your card number never touches Waverunner’s servers. If you enable auto-refill, Stripe stores the payment method and we store only its reference.
  • Content from your website: pages we read to build your business profile and generate ads.

We do not sell your data, and we do not use your businesses’ data to advertise anyone else’s products.

Agency operators may access campaign and lead data for a client organization they manage, for that client only. Visitor requests still go to the advertised business. Client workspaces do not share visitor pools. For personal information in a client workspace we process as a service provider of the agency. We will sign a data processing addendum on request at support@adwave.com. Client users sign in on a branded agency host or a Waverunner partner host; those hosts set first-party session cookies on that hostname. Intercom does not load on partner hosts. We do not use names or emails from an agency's client workspaces to solicit those clients onto a direct Waverunner account.

Deleting a client user's login does not delete the client organization, its campaigns, or its tracking data. The agency administers that workspace.

5. Tracking on advertiser websites

Advertisers can install the Waverunner tag on their own websites to measure their campaigns. On those sites, the tag records page views, sessions, UTM parameters, ad-click IDs, and conversions (with value, currency, and order ID when the advertiser provides them). All cookies are first-party, set on the advertiser’s own domain:

  • _wr_vid: visitor ID, 365 days.
  • _wr_sid: session ID, 30 minutes (sliding).
  • _wr_cid: ad-click ID, 30 days.
  • _wr_utm: first-touch UTM parameters, for the session.

Raw personal identifiers are never stored. When an advertiser identifies a visitor (for example, an email on a purchase), the email and the visitor’s IP address are hashed with a salt before storage. The advertiser is responsible for their own site’s privacy disclosures and any consent requirements that apply to them.

6. Conversion forwarding to ad platforms

To optimize delivery, attributed conversions may be forwarded to Meta (Conversions API), Google (offline conversion uploads), and Reddit (Conversions API), depending on which channels the advertiser selected. These platforms typically require a SHA-256 hash of the customer email (and sometimes phone) for matching; only hashes are sent, per each platform's specification. Forwarding exists solely to improve that advertiser's own campaign performance. We do not use one advertiser's conversion data to run ads for another advertiser or for ourselves.

7. Audience building

Audience sync is on by default for advertiser accounts so campaign reach and customer matching can work. Advertisers can turn it off anytime in Tracking. By keeping sync on, the advertiser attests that their website's privacy policy discloses audience building. When sync is on:

  • Campaign reach audiences. When an ad we serve is displayed, the ad platforms' own measurement pixels (Google, Meta, Reddit as applicable) may fire alongside ours to support Preparing and Live on those platforms. Each platform processes those signals under its own privacy policy.
  • Audience lists. SHA-256 hashes of customer emails (never raw addresses) may be sent to Google Customer Match, Meta custom audiences, and Reddit custom audiences, per each platform's specification. When someone leaves an audience, or the advertiser turns sync off, removals are propagated.
  • TV household matching. Visitor IP addresses are required by TV ad systems for household matching. They are held AES-256-GCM encrypted in a transient queue, deleted immediately after upload, and hard-purged within 24 hours regardless. Raw IP addresses are never stored anywhere else, never logged, and never included in data exports.
  • Optional platform tags. The advertiser can additionally allow the Waverunner tag to load Google (gtag) and Meta (fbevents) tags on their own website to improve audience match quality. This is off by default and gated on the same attestation.

8. Ad platform data (Meta, Google, Reddit, TV)

When you launch campaigns, we create and manage ads, audiences, and conversion events on advertising platforms (including Meta, Google, Reddit, and our TV / display DSP partners) on your behalf. Platform data we obtain for a customer (campaign structure, delivery and performance, audience membership, and conversion match signals) is used only to run and measure that customer's campaigns inside Waverunner. We keep each customer's advertising data separate from other customers' data and do not sell personal information.

Each platform also processes data under its own terms and privacy policy. You are responsible for having the rights and any required notices or consents for the businesses and customer data you advertise.

9. Subprocessors

Waverunner runs on a small set of infrastructure and service providers:

  • Stripe: payment processing
  • Fly.io: application hosting
  • Neon: Postgres database hosting
  • Cloudflare: DNS, CDN, and DDoS protection
  • S3-compatible object storage: generated ad assets
  • AI model providers: ad copy, imagery, and video generation
  • Firecrawl: website content extraction
  • Meta, Google, Reddit, and our DSP partner: ad delivery, conversion matching, and audience building (when audience sync is on)
  • Google Analytics 4: server-side advertising measurement when audience sync is on
  • Resend: transactional email
  • Sentry: error monitoring
  • Intercom: customer support messaging
  • Snitcher: company identification on the public marketing site
  • RB2B: company identification on the public marketing site

10. Data retention

Account and organization data is retained while your account is active. Wallet ledger entries are retained as financial records. Tracking events are retained to power attribution and reporting for the advertiser that collected them. When an account is deleted, associated personal data is removed except where retention is legally required (for example, transaction records). Individual workspace owners can close from Settings → Security. Other requests go through Data deletion.

11. Your rights

  • Export: the API includes a full-organization export endpoint (GET /api/v1/export) that returns your businesses, campaigns, ledger, and tracking data as one JSON document.
  • Deletion and correction: follow the steps on Data deletion or email support@adwave.com. We will verify and act on eligible requests.
  • Marketing emails: unsubscribe using the link in the email (performance digests and campaign-update reminders). You may still receive transactional messages about your account, campaign launches/pauses, and billing.

If you are a visitor to an advertiser's website, direct requests about that site's data to the advertised business (the controller). If you cannot reach them, contact the agency that runs the ads, or email support@adwave.com; we assist the controller in fulfilling such requests.

12. US state privacy rights

If you are a resident of California or another US state with a comprehensive consumer privacy law, you may have rights to know, access, correct, or delete personal information, and to opt out of certain sharing for targeted advertising, subject to legal limits. Waverunner is a B2B advertising product; we do not sell personal information for money.

To exercise these rights, email support@adwave.com or use Data deletion. We may need to verify your identity (and an authorized agent's authority) before responding. We will not discriminate against you for exercising privacy rights.

13. Security

We use administrative, technical, and organizational measures designed to protect personal information (including encryption in transit, access controls, and salted hashing of sensitive identifiers). No method of transmission or storage is completely secure. See also our Security page.

14. Changes to this policy

We will update this page when the policy changes and revise the “Last updated” date above. Material changes affecting account holders are announced by email.