Privacy Policy

Last updated: September 4, 2026

This policy explains what data Waverunner collects for always-on performance advertising measured on your site: why we collect it, and what your rights are. It covers three audiences separately: visitors to this website, Waverunner account holders, and visitors to advertisers' websites where the Waverunner tracking tag is installed. For step-by-step deletion instructions (including Meta App Dashboard requirements), see Data deletion.

1. Who we are

Waverunner is an advertising platform operated by Adwave Digital Inc (“Waverunner”, “we”, “us”). For data you give us when you create an account, Adwave Digital Inc is the data controller. For data collected by the tracking tag on an advertiser's website, the advertiser is the controller and Waverunner processes that data on their behalf.

Waverunner is built for businesses. We treat account and marketing-site interactions as business-to-business. The service is intended for users 18 or older in the United States. If you are under 18, do not use the service.

Questions about this policy: support@adwave.com.

2. Visitors to this website

We measure our public pages with our own product: the same first-party tracking tag we provide to advertisers runs on the marketing site, sign-in, and the post-sign-in start handoff on waverunner.adwave.com (not inside the signed-in product app). It records visits, pages viewed, and which of our own ads brought you here, using first-party cookies set on this domain (the cookies listed in the tracking section below).

We use Intercom for customer support chat on waverunner.adwave.com (and on adwave.com). Intercom may set its own cookies and receive the page URL plus, when you are signed in, your account identity (user id, email, and name) so we can continue a conversation across visits. See Intercom's privacy documentation for details on how they process that data as our subprocessor.

We use Snitcher and RB2B on the public marketing pages (not inside the signed-in product app) so we can tell which companies visit this site. They look up the visiting network's IP against a business directory and return company-level details such as name and industry, not a named person. They may set their own cookies. See Snitcher's and RB2B's privacy documentation for details on how they process that data as our subprocessors.

If your browser sends the Global Privacy Control signal, nothing about your visit is shared with ad platforms: no Google, Meta, or Reddit tags load for you, and you are excluded from every synced audience. Snitcher and RB2B also do not load. When we advertise Waverunner itself, visitors who have not opted out may also receive ad-platform measurement tags so those platforms can measure our ads.

If you arrive through a partner referral link (/a/{code}), we set a first-party cookie _wr_aff for up to 90 days to attribute signups to that partner. It is HttpOnly and used only for commission accounting, not ad targeting.

On sign-in and the website-analysis start handoff we may also set a first-party cookie _wr_acq for up to 30 days. It stores only the referring site hostname and the landing path (plus standard campaign tags when present) so we can tell which channel brought you here. It is HttpOnly and is not used for ad targeting. If you start the agency sign-up flow we set _wr_agency_intent (a single flag, 30 days) so the workspace you create is set up as an agency.

Emails and IP addresses from this website are stored only as salted one-way hashes, exactly as described for advertiser sites below. Signing in additionally sets strictly necessary, httpOnly session cookies.

3. Public URL analysis (Campaign Intelligence Brief)

On marketing pages you can submit a public website URL to generate a Campaign Intelligence Brief without creating an account. When you do, we may scrape publicly available homepage content for that URL via our subprocessors (including Firecrawl), derive a short planning summary, and cache the scraped text and brief for a short period (typically up to 24 hours) so repeat requests for the same site do not re-scrape. We rate-limit these requests.

No account is required. We do not use this analysis to build advertising profiles of site visitors, and we do not sell the scraped content.

4. Account holders

When you create and use a Waverunner account, we store:

  • Your email address: used for passwordless sign-in codes and transactional notifications (campaign status, billing events, the weekly digest).
  • Organization data: your businesses, buyer profiles, generated creatives, campaigns, and wallet ledger.
  • Billing records: wallet transactions and their Stripe references. Payments are processed by Stripe; your card number never touches Waverunner’s servers. If you enable auto-refill, Stripe stores the payment method and we store only its reference.
  • Content from your website: pages we read to build your business profile and generate ads.

We do not sell your data, and we do not use your businesses’ data to advertise anyone else’s products.

Agency operators may access campaign and lead data for a client organization they manage, for that client only. Visitor requests still go to the advertised business. Client workspaces do not share visitor pools. For personal information in a client workspace we process as a service provider of the agency. We will sign a data processing addendum on request at support@adwave.com. Client users sign in on a branded agency host or a Waverunner partner host; those hosts set first-party session cookies on that hostname. Intercom does not load on partner hosts. We do not use names or emails from an agency's client workspaces to solicit those clients onto a direct Waverunner account.

Deleting a client user's login does not delete the client organization, its campaigns, or its tracking data. The agency administers that workspace.

5. Tracking on advertiser websites

Advertisers can install the Waverunner tag on their own websites to measure their campaigns. On those sites, the tag records page views, sessions, UTM parameters, ad-click IDs, and conversions (with value, currency, and order ID when the advertiser provides them). All cookies are first-party, set on the advertiser’s own domain:

  • _wr_vid: visitor ID, 365 days.
  • _wr_sid: session ID, 30 minutes (sliding).
  • _wr_utm: last-touch campaign (UTM) parameters (the most recent campaign-tagged landing wins), 30 minutes (sliding with the session).
  • _wr_cid: Waverunner's own click ID from the ad that brought the visitor (platform click ids such as gclid or fbclid are kept in local storage, below), 30 days.
  • _wr_aid: the id of the ad that brought the visitor, 30 days.
  • _wr_li: the id of the audience line the ad click came from, 30 days.
  • _wr_camp: the id of the campaign that brought the visitor, 30 days.
  • wr_consent: set only when the advertiser calls the tag's consent API; records whether the visitor declined ad-platform sharing, 365 days.

The tag also keeps browser local storage copies of the visitor, click, ad, and campaign ids (so a blocked cookie does not double-count a visitor), a small cache of the platform click ids it saw (_wr_ads), and a retry queue of events that could not be sent yet (_wr_rq). Those entries expire on the same schedules as the cookies above.

Landing pages we host for an advertiser set one extra first-party cookie, _wr_lpv (30 days), that remembers which page variant a visitor saw so they keep seeing the same one. The ad platforms' own cookies (for example Meta's _fbp and _fbc or Google's _gcl_au) are read by the tag for conversion matching when the advertiser has enabled sharing, but are never set by us.

Raw personal identifiers are never stored. When an advertiser identifies a visitor (for example, an email on a purchase), the email and the visitor’s IP address are hashed with a salt before storage. The advertiser is responsible for their own site’s privacy disclosures and any consent requirements that apply to them.

6. Conversion forwarding to ad platforms

To optimize delivery, attributed conversions may be forwarded to Meta (Conversions API), Google (offline conversion uploads), and Reddit (Conversions API), depending on which channels the advertiser selected. These platforms typically require a SHA-256 hash of the customer email (and sometimes phone) for matching; only hashes are sent, per each platform's specification. Forwarding exists solely to improve that advertiser's own campaign performance. We do not use one advertiser's conversion data to run ads for another advertiser or for ourselves.

7. Audience building

Audience sync is on by default for advertiser accounts so campaign reach and customer matching can work. Advertisers can turn it off anytime in Tracking. By keeping sync on, the advertiser attests that their website's privacy policy discloses audience building. When sync is on:

  • Campaign reach audiences. When an ad we serve is displayed, the ad platforms' own measurement pixels (Google, Meta, Reddit as applicable) may fire alongside ours to support Preparing and Live on those platforms. Each platform processes those signals under its own privacy policy.
  • Audience lists. SHA-256 hashes of customer emails (never raw addresses) may be sent to Google Customer Match, Meta custom audiences, and Reddit custom audiences, per each platform's specification. When someone leaves an audience, or the advertiser turns sync off, removals are propagated.
  • TV household matching. Visitor IP addresses are required by TV ad systems for household matching. They are held AES-256-GCM encrypted in a transient queue, deleted immediately after upload, and hard-purged within 24 hours regardless. Raw IP addresses are never stored anywhere else, never logged, and never included in data exports.
  • Optional platform tags. The advertiser can additionally allow the Waverunner tag to load Google (gtag) and Meta (fbevents) tags on their own website to improve audience match quality. This is off by default and gated on the same attestation.

8. Ad platform data (Meta, Google, Reddit, TV)

When you launch campaigns, we create and manage ads, audiences, and conversion events on advertising platforms (including Meta, Google, Reddit, and our TV / display DSP partners) on your behalf. Platform data we obtain for a customer (campaign structure, delivery and performance, audience membership, and conversion match signals) is used only to run and measure that customer's campaigns inside Waverunner. We keep each customer's advertising data separate from other customers' data and do not sell personal information.

Each platform also processes data under its own terms and privacy policy. You are responsible for having the rights and any required notices or consents for the businesses and customer data you advertise.

9. Subprocessors

Waverunner runs on a small set of infrastructure and service providers:

  • Stripe: payment processing and partner payouts
  • Fly.io: application hosting
  • Neon: Postgres database hosting
  • Cloudflare: DNS, CDN, DDoS protection, and hosting for the landing-page domains you connect
  • S3-compatible object storage: uploaded creative files and generated ad assets
  • AI model providers: ad copy, imagery, and video generation
  • Firecrawl: website content extraction
  • Meta, Google, Reddit, TikTok, Pinterest, and our DSP partner: ad delivery, conversion matching, and audience building (when audience sync is on)
  • Google Analytics 4: server-side advertising measurement when audience sync is on
  • Twilio: call tracking numbers and call forwarding when an advertiser turns on call tracking (caller numbers are stored encrypted)
  • A print and mail fulfillment provider and a mailing-list data provider: printing, addressing, and delivering Neighborhood mail pieces to the households an advertiser selects
  • US Census Bureau geocoder: turning a business address into map coordinates for local targeting
  • Resend: transactional email
  • Sentry: error monitoring
  • Intercom: customer support messaging
  • Attio: our own customer relationship records for account holders (name, email, workspace, plan)
  • Slack: internal operations alerts to our team (workspace and campaign identifiers, never customer contact details)
  • Awin: affiliate network conversion reporting
  • Snitcher: company identification on the public marketing site
  • RB2B: company identification on the public marketing site

Connectors you authorize. When you connect a customer system to a business (QuickBooks, Stripe, Shopify, Square, Clover, HubSpot, GoHighLevel, or Google Business Profile), that provider processes data for you under your own agreement with them. We hold the access token encrypted, read customer contact details only to build audiences and match leads, and push leads back to the CRMs you choose. When you disconnect a connector or close your workspace, we delete the token; where the provider offers it (HubSpot, Shopify, Google) we also revoke the grant on their side.

10. Data retention

Account and organization data is retained while your account is active. Wallet ledger entries are retained as financial records. Tracking events are retained to power attribution and reporting for the advertiser that collected them, within these windows:

  • Page views and identify events: 180 days.
  • Clicks and on-page interactions: 90 days.
  • Ad impressions and video playback events: 90 days (daily totals without identifiers are kept).
  • Conversions: kept while the account is active, because lifetime return on ad spend is reported from them. The platform click ids attached to a conversion for forwarding are cleared 7 days after the forward and no later than 90 days after the event.
  • Visitor IP addresses for TV household matching: deleted after upload and no later than 24 hours. Connection details held for conversion forwarding are deleted once forwarded and no later than 24 hours.
  • Lead contact details (name, email, phone, message) and imported customer emails: stored encrypted and kept while the account is active.
  • Uploaded creative files, generated ads, mail artwork, and listing photos: kept while the account is active and deleted from object storage when the workspace closes.
  • Public URL analysis (Campaign Intelligence Brief): scraped text and the brief are cached for up to 24 hours.

When an account is closed, associated personal data is removed except where retention is legally required (for example, transaction records). Individual workspace owners can close from Settings → Security. Other requests go through Data deletion.

11. Your rights

  • Export: the API includes a full-organization export endpoint (GET /api/v1/export) that returns your businesses, campaigns, ledger, and tracking data as one JSON document.
  • Deletion and correction: follow the steps on Data deletion or email support@adwave.com. We will verify and act on eligible requests.
  • Marketing emails: unsubscribe using the link in the email (performance digests and campaign-update reminders). You may still receive transactional messages about your account, campaign launches/pauses, and billing.

If you are a visitor to an advertiser's website, direct requests about that site's data to the advertised business (the controller). If you cannot reach them, contact the agency that runs the ads, or email support@adwave.com; we assist the controller in fulfilling such requests.

12. US state privacy rights

If you are a resident of California or another US state with a comprehensive consumer privacy law, you may have rights to know, access, correct, or delete personal information, and to opt out of certain sharing for targeted advertising, subject to legal limits. Waverunner is a B2B advertising product; we do not sell personal information for money.

To exercise these rights, email support@adwave.com or use Data deletion. We may need to verify your identity (and an authorized agent's authority) before responding. We will not discriminate against you for exercising privacy rights.

13. Security

We use administrative, technical, and organizational measures designed to protect personal information (including encryption in transit, access controls, and salted hashing of sensitive identifiers). No method of transmission or storage is completely secure. See also our Security page.

14. Changes to this policy

We will update this page when the policy changes and revise the “Last updated” date above. Material changes affecting account holders are announced by email.