Privacy Policy
Last updated: 2026-08-20
This Privacy Policy explains how 8020 Holdings LLC (“Adsu,” “we,” or “us”) handles personal data in connection with the Adsu platform (the “Service”). It should be read together with our Terms of Service.
1. Our role: controller vs. processor
For the member and lead data that flows through the Service, our gym-business customer is the controller and Adsu is the processoracting on the customer’s instructions. If you are a member or lead of a gym that uses Adsu, that gym — not Adsu — is the business that decides how your data is used; contact them to exercise your rights, and we will assist them.
Adsu is a business-to-business service. Our direct customers are gym businesses. When we process personal data about their leads, members, and contacts to produce attribution reporting, we do so as a processor on the customer’s documented instructions. Separately, Adsu is the controller for the limited personal data of the customer’s own users who administer the account (for example, an account owner’s name, email, and phone used to sign in).
2. Data we process
Depending on which integrations a customer connects, the Service processes the following categories, drawn from systems the customer authorizes:
- Advertising and click data — campaign, ad, spend, and click identifiers from Google Ads and Meta, and click and page-view events captured by the first-party tracking snippet (which may be served from a tracking subdomain the customer owns and delegates to Adsu by CNAME). This can include online identifiers such as click IDs, device and browser attributes, and IP address.
- CRM contact data — lead and contact records from GoHighLevel, which may include name, email, phone, and lead source and status.
- Payment data (read-only) — payment, customer, and subscription records read from Stripe via Stripe Connect, used to identify paying members and revenue. Adsu reads this data and does not store full card numbers or process payments.
- Fitness software data — membership and payment records read from Mindbody (subject to the ephemerality rule in Section 6).
- Account and usage data— information about the customer’s administrative users (sign-in identifiers, role, tenant) and technical logs generated as the Service runs.
3. Why we process it
We process personal data only to provide and support the Service on the customer’s behalf, namely to:
- match an ad click to a lead and to an in-person payment (identity resolution) and assign a confidence band to that match;
- attribute paying members to the campaign and location that produced them and compute the per-location ROAS scorecard and its coverage statement;
- authenticate administrative users, secure the Service, prevent abuse, and provide support; and
- maintain audit logs and diagnose and fix operational problems.
Where required, the legal basis for processing as a processor rests with the customer as controller; for the limited data for which Adsu is the controller, we rely on our legitimate interest in operating and securing the Service and on performing our contract with the customer.
4. We do not sell personal data
Adsu does not sell personal data and does not share personal data for cross-context behavioral advertising. We do not pool one customer’s member or lead data with another customer’s for any purpose that would identify individuals across customers. Any product improvement uses only aggregated, de-identified information.
This applies specifically to mobile numbers: we will not share or sell your mobile information with third parties for promotional or marketing purposes. Mobile numbers collected for sign-in are used only to deliver the sign-in codes you request, and are shared with our messaging carrier solely to send those messages.
5. SMS sign-in messages
Adsu offers sign-in by text message. When you enter your mobile number and request a code, you consent to receive transactional SMS sign-in codes from Adsu at that number. These are account-security messages only — we do not send marketing texts.
- Frequency. Message frequency may vary: one message each time you request a sign-in code.
- Cost. Standard message and data rates may apply, depending on your carrier and plan.
- Opting out. Reply STOP to any message to opt out; reply HELPfor help. Opting out stops the texts — you can still sign in by email link, and you can reply UNSTOP at any time to start receiving codes again.
- Sharing. Mobile numbers are never shared or sold to third parties for promotional or marketing purposes.
6. Retention
We keep personal data only as long as needed to provide the Service to the customer, then delete or de-identify it, subject to any legal obligation to retain it. Two specifics matter:
- Mindbody data is ephemeral by design. Data sourced from Mindbody is held as a short, rolling mirror and is not retained beyond approximately 48 hours; each cycle re-reads current history from Mindbody and the Service re-derives its results rather than keeping an aging copy. If a Mindbody connection is paused or removed, the Mindbody-derived parts of the scorecard go blank honestly rather than showing stale figures, and repopulate when the connection is restored.
- Click, lead, and Stripe datais retained for the period needed to produce and support attribution reporting for the customer, and is deleted or de-identified after the customer’s subscription ends, subject to the wind-down described in our Terms of Service.
7. Subprocessors
We use a small set of vetted service providers (“subprocessors”) to run the Service. They process personal data only on our instructions and under contractual confidentiality and security obligations. As of the date above, they include:
- Vercel— application hosting and content delivery;
- Neon— managed PostgreSQL database;
- Inngest— background job and event processing;
- Resend— transactional email delivery (for example, sign-in and account emails);
- Telnyx— delivery of the SMS sign-in codes described in Section 5. Telnyx receives the mobile number and the code text solely to deliver that message.
- Stripe— the payment data source we read via Stripe Connect, and our own subscription billing.
- Adobe(Typekit / Adobe Fonts) — serves the typeface the Service is set in. Because the font is fetched by your browser when a page loads, Adobe receives your IP address, user agent, and the time of the request. We send them no account, member, or payment data.
The advertising, CRM, and fitness platforms a customer connects (Google Ads, Meta, GoHighLevel, Mindbody) are the customer’s own sources, not Adsu subprocessors; data flows from them into the Service under the customer’s authorization. We may update this list as our providers change and will reflect changes here.
8. Security
We take reasonable and appropriate technical and organizational measures to protect personal data, including encryption of data in transit, access controls that scope each customer’s data to that customer’s tenant, least-privilege access to credentials and OAuth tokens, and audit logging of system actions. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. This policy makes no claim to any specific security certification.
9. International transfers
Adsu and its subprocessors may process personal data in the United States and other countries. Where personal data is transferred across borders, we and our customers rely on appropriate safeguards required by applicable law, such as standard contractual clauses, as implemented in the relevant data processing arrangements.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal data, to data portability, and to object to certain processing, under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).
Because Adsu processes member and lead data as a processor on the gym’s behalf, if you are a member or lead, please direct your request to the gym you interacted with — they are the controller. If you send a request to us, we will forward it to the relevant customer and support their response. For the limited data for which Adsu is the controller (administrative account users), you can reach us directly at will@willocho.com. We do not use personal data to make decisions producing legal or similarly significant effects without human involvement.
11. Children
The Service is a business tool and is not directed to children. We do not knowingly process the personal data of children through the Service outside of records a customer maintains about its own members in its own systems, for which the customer is the controller.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after a change takes effect is your acknowledgment of the updated policy.
13. Contact
Questions about this policy or our data practices can be sent to will@willocho.com, or by mail to 8020 Holdings LLC, 6131 Gypsy Bell, San Antonio, TX 78215.