1. Controller and contact
Taurus Data GmbH, Leopoldstr. 2-8, 32051 Herford, Germany is the controller when it determines why and how the data described here is processed. The service is known as plus.ad.
Send privacy requests to info@taurusdata.de. Do not email passwords, recovery codes, complete card data or unnecessary identity documents.
2. Scope and roles
This notice covers visitors, contacts, advertiser and publisher users, invited team members, administrators and people whose browser or conversion event is measured through a plus.ad campaign.
For account administration, billing, platform security, fraud prevention and operation, Taurus Data GmbH acts as controller. An advertiser controls the customer and conversion data it chooses to send from its shop. Where we handle that data only on documented advertiser instructions, we act as processor. Advertisers must provide their own privacy information and lawful basis for tracking.
3. Data we process
- Account and team: name, business email, password hash, organisation, role, status, invitations and authentication records.
- Company and billing: company name, billing email, business address, country, VAT identifier, funding references, balances, ledger entries, invoices and payment status. plus.ad does not store complete card numbers or security codes.
- Shop, catalogue and campaigns: shop domain, markets, language, feed source and import records, products, URLs, campaign settings, budgets, approvals and delivery status.
- Measurement: random click and event IDs, campaign, shop and product references, country code, timestamps, CPC, publisher and ad-space IDs, conversion type, event/order reference, value, currency, product references and consent status. Advertisers must not include personal contact or special-category data.
- Security and technical: session and trusted-device IDs, hashed recovery and one-time codes, sign-in and rate-limit events, audit actions, API-key prefixes and hashes, IP-derived hashes, user agent, security events and request logs.
- Contact: business email, message, handling status, browser data and a keyed IP-derived hash for spam prevention.
We receive data from users and their organisations, advertiser shops and tracking integrations, participating publishers, and automatically when a browser or system interacts with the Service.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Typical retention |
|---|---|---|
| Accounts, workspaces, team access, shops, products, campaigns, publisher feeds, support and reporting | Contract and requested pre-contract steps | Account term, then up to 24 months, unless deletion or a longer legal period applies |
| Authentication, 2FA, trusted devices, recovery, abuse prevention and incident investigation | Contract and legitimate security interests | Sessions up to 12 hours; trusted devices up to 30 days; expired one-time records generally 30 days; security and audit records generally 24 months, longer for an active incident or claim |
| Contact requests and spam prevention | Requested pre-contract steps and legitimate protection interests | Enquiries generally 12 months after resolution; anti-abuse attempts generally 30 days |
| Deliver, validate and report clicks; attribute conversions; prevent invalid traffic; calculate charges and compensation | Contract and legitimate interests in accurate secure measurement | Event-level measurement generally up to 25 months; financial records as below |
| Funding, billing, invoices, ledger, tax and legal compliance | Contract and legal obligation | Applicable German statutory periods, generally 8 to 10 years depending on the record |
| Reliability, troubleshooting, aggregate statistics and Terms enforcement | Legitimate interests in a reliable secure service | Raw technical logs generally 30 days; relevant incident or enforcement records up to 24 months or the duration of a claim |
| Activation, invitations, security codes, password reset and service notices | Contract, security interests and legal obligation where applicable | Only as long as needed for delivery, troubleshooting and evidence of required notices |
Periods may be extended for a legal hold, fraud investigation, dispute, enforcement or statutory duty. At expiry, data is deleted or irreversibly anonymised. Non-identifying aggregate statistics may be kept.
5. Legitimate interests
Our legitimate interests are securing business accounts, preventing spam and invalid traffic, maintaining reliable measurement, protecting billing and publisher compensation, defending claims and improving the Service. We consider the context, reasonable expectations and safeguards such as hashing, access limits, retention and human review. You may object as described below.
6. Recipients
Authorised recipients may include the organisation managing your account; participating publishers receiving the campaign, product, click and compensation data needed for distribution and reporting; the service providers described below; banks, accountants and tax advisers; professional advisers, courts, regulators and authorities where lawful; and a successor in a merger, financing, reorganisation or sale under confidentiality safeguards.
We do not sell personal data or share it for third-party cross-context behavioural advertising.
7. Key service providers and data protection roles
| Provider and service | Data and purpose | Data protection role |
|---|---|---|
| Stripe Hosted checkout and payment processing | Business and billing details, payment amount, currency, payment and fraud-prevention metadata. Complete card details are entered directly into Stripe Checkout and are not stored by plus.ad. | Stripe acts as our processor where it provides technical services on our documented instructions. It acts as an independent controller for regulated payment processing, fraud and loss prevention, compliance, interactions with banks and payment networks, and its own service administration. These role boundaries and transfer safeguards are set out in Stripe’s Data Processing Agreement. |
| Mailtrap (Railsware Products Studio LLC) Transactional email and inbound support email | Sender and recipient address, name, subject, message body, delivery metadata and support-ticket references. | Mailtrap acts as our processor when sending or receiving messages on our instructions. It acts as an independent controller for its account administration, security, abuse prevention and legal compliance. Mailtrap states that service data is hosted in the United States; its contractual terms and DPA govern the processing. |
| Shopify Optional shop, catalogue and conversion integration | Shop domain, optional product catalogue, order or event references, amounts, currency, timestamps, consent state and delivery diagnostics. plus.ad does not require shopper names, email addresses or postal addresses for this integration. | The advertiser or merchant controls the shop and customer data. Shopify generally processes merchant customer data for the merchant under the Shopify DPA, while it may act as an independent controller for specified platform, security and consumer services. plus.ad acts as the advertiser’s processor for instructed catalogue and conversion measurement, and as controller for its own app security, audit and account administration. |
| Spaceship, Inc. Virtual-server hosting and network infrastructure | Application data, databases, encrypted secrets, files, backups and technical logs required to host and protect the Service. | Spaceship acts as our processor for hosted customer data under its Data Processing Addendum. It remains an independent controller for its own customer account, billing, security and legal-compliance data. |
Where a provider acts as our processor, it may use approved subprocessors subject to contractual safeguards. A provider’s separate controller processing is governed by its own privacy information. The precise role follows the actual processing activity rather than the provider name alone.
8. International transfers
Stripe, Mailtrap, Shopify and Spaceship may process data outside the European Economic Area, including in the United States, or engage subprocessors there. Before a restricted transfer made by us, we rely on a Chapter V GDPR mechanism such as an adequacy decision (including an applicable EU-US Data Privacy Framework certification) or European Commission Standard Contractual Clauses, plus supplementary safeguards where required. Provider-specific mechanisms are documented in the agreements linked above. You may request information about the applicable safeguard; commercially sensitive details may be redacted.
9. Cookies and browser storage
plus.ad uses strictly necessary technology: a signed session cookie for login and CSRF protection; an optional trusted-device cookie for up to 30 days; and browser session storage for a click ID used to attribute a conversion during the session. Secure, HttpOnly and SameSite attributes are applied where appropriate.
We do not currently use advertising or cross-site behavioural cookies on plus.ad. Before introducing non-essential analytics or marketing technology, we will provide information and obtain consent where required. Removing necessary cookies may sign you out or prevent security features from working.
10. Automated validation
Automated rules apply campaign status, market, duplication, rate, bot, budget and attribution checks to clicks and conversions. A rule can accept or reject an event for reporting, charging or publisher compensation and pause campaigns with insufficient funds. These controls concern business advertising activity rather than shopper characteristics.
An authorised user may request human review of a result materially affecting charges or access by providing the click, event or campaign ID. We do not use this data for automated decisions producing legal or similarly significant effects on individual shoppers.
11. Your rights
Subject to GDPR conditions and exceptions, you may request access, a copy, correction, deletion, restriction or portability, and object to processing based on legitimate interests. Consent can be withdrawn at any time without affecting earlier processing.
Email info@taurusdata.de and identify the relevant account, organisation, click or interaction. We may request proportionate verification. We normally respond within one month; a permitted extension will be explained.
You may complain to the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia at ldi.nrw.de, or the authority where you live or work.
12. Security
Measures appropriate to risk include access controls, password hashing, two-factor authentication, hashed or encrypted security secrets, scoped roles, audit logging, transport encryption, security headers and restricted administration. No internet service guarantees absolute security. Users must protect credentials and promptly report suspected compromise.
13. Age restrictions
plus.ad is a business-to-business service and is not intended for use by children. User accounts may only be created by individuals who are at least 18 years old and authorised to act on behalf of a business.
14. Changes
We may update this notice when the Service, providers or law changes. The current version and effective date remain here. We will notify account Owners by email or in the Service before a material change where required.