Privacy Policy
Last updated: 2026-09-12
This Privacy Policy explains how 8020 Holdings LLC, doing business as Adsu (“Adsu,” “we,” or “us”) handles personal data in connection with the Adsu platform (the “Service”). It should be read together with our Terms of Service.
1. Our role: controller vs. processor
For the member and lead data that flows through the Service, our gym-business customer is the controller and Adsu is the processoracting on the customer’s instructions. If you are a member or lead of a gym that uses Adsu, that gym — not Adsu — is the business that decides how your data is used; contact them to exercise your rights, and we will assist them.
Adsu is a business-to-business service. Our direct customers are gym businesses. When we process personal data about their leads, members, and contacts to produce attribution reporting, we do so as a processor on the customer’s documented instructions. Separately, Adsu is the controller for the limited personal data of the customer’s own users who administer the account (for example, an account owner’s name, email, and phone used to sign in).
2. Data we process
Depending on which integrations a customer connects, the Service processes the following categories, drawn from systems the customer authorizes:
- Advertising and click data — campaign, ad, spend, and click identifiers from Google Ads and Meta, and click and page-view events captured by the first-party tracking snippet (which may be served from a tracking subdomain the customer owns and delegates to Adsu by CNAME). This can include online identifiers such as click IDs, device and browser attributes, and IP address.
- Ad management data — authorized ad accounts and Pages, campaign settings, creative, audience definitions, tracking parameters, pixels, publishing receipts, and delivery results. When a customer uses customer-list audiences, we process the email addresses and phone numbers they submit for that operation.
- Meta lead-form data — answers and submission identifiers from the Pages and forms the customer connects, including name, email, phone, and other form answers. The customer chooses how supported contact fields map to their Adsu location.
- CRM contact data — lead and contact records from GoHighLevel, which may include name, email, phone, and lead source and status.
- Payment data (read-only) — payment, customer, and subscription records read from Stripe via Stripe Connect, used to identify paying members and revenue. Adsu reads this data and does not store full card numbers or process payments.
- Fitness software data — membership and payment records read from Mindbody (subject to the retention rules in Section 6).
- Account and usage data— information about the customer’s administrative users (sign-in identifiers, role, tenant) and technical logs generated as the Service runs.
3. Why we process it
We process personal data only to provide and support the Service on the customer’s behalf, namely to:
- create and manage campaigns, budgets, audiences, ad creative, and tracking parameters at the customer’s direction; show advertising performance; and retrieve selected Meta form submissions into the customer’s Adsu contact directory and form inbox;
- match an ad click to a lead and to an in-person payment (identity resolution) and assign a confidence band to that match;
- attribute paying members to the campaign and location that produced them and compute the per-location ROAS scorecard and its coverage statement;
- authenticate administrative users, secure the Service, prevent abuse, and provide support; and
- maintain audit logs and diagnose and fix operational problems.
Where required, the legal basis for processing as a processor rests with the customer as controller; for the limited data for which Adsu is the controller, we rely on our legitimate interest in operating and securing the Service and on performing our contract with the customer.
4. Customer-directed sharing
Adsu does not use one customer’s contact lists to create advertising audiences for another customer. When a customer directs Adsu to use Meta audience features, Adsu normalizes and hashes the submitted email addresses or phone numbers and sends those identifiers to Meta for matching and audience management. Hashing does not make identifiers anonymous. Adsu does not retain the uploaded customer CSV or individual hashes after the request. Customers are responsible for their instructions and applicable permissions to use their lists.
For mobile numbers collected for Adsu sign-in, we will not share or sell your mobile information with third parties for promotional or marketing purposes. These sign-in numbers are used only to deliver the sign-in codes you request, and are shared with our messaging carrier solely to send those messages. They are not used to populate advertising audiences. Customer-supplied audience phone numbers are a separate, explicitly selected advertising workflow.
5. SMS sign-in messages
Adsu offers sign-in by text message. When you enter your mobile number and request a code, you consent to receive transactional SMS sign-in codes from Adsu at that number. These are account-security messages only — we do not send marketing texts.
- Frequency. Message frequency may vary: one message each time you request a sign-in code.
- Cost. Standard message and data rates may apply, depending on your carrier and plan.
- Opting out. Reply STOP to any message to opt out; reply HELPfor help. Opting out stops the texts — you can still sign in by email link, and you can reply UNSTOP at any time to start receiving codes again.
- Sharing. Sign-in mobile numbers are never shared or sold to third parties for promotional or marketing purposes.
6. Retention
We keep personal data only as long as needed to provide the Service to the customer, then delete or de-identify it, subject to any legal obligation to retain it. The following rules apply:
- Meta lead-form answers.Answers are encrypted and retained for 30 days from the lead’s creation. Authorized users can erase answers from the Adsu form inbox sooner. A minimal receipt prevents a deleted submission from being reimported. Contact records already created in the directory and the original lead stored by Meta are managed separately. A deletion request should identify any associated contact records and connected forms so the applicable route can be stopped and those records addressed as well.
- Mindbody data. Under our retention addendum, Mindbody data and derived attribution are retained for the period needed to provide and support reporting for the customer. Pausing or disconnecting Mindbody stops new updates; previously imported history remains available, with sync freshness shown in the Service. Customer deletion and subscription wind-down rules continue to apply.
- Click, lead, and Stripe datais retained for the period needed to produce and support attribution reporting for the customer, and is deleted or de-identified after the customer’s subscription ends, subject to the wind-down described in our Terms of Service.
7. Subprocessors
We use a small set of vetted service providers (“subprocessors”) to run the Service. They process personal data only on our instructions and under contractual confidentiality and security obligations. As of the date above, they include:
- Vercel— application hosting and content delivery;
- Neon— managed PostgreSQL database;
- Inngest— background job and event processing;
- Resend— transactional email delivery (for example, sign-in and account emails);
- Telnyx— delivery of the SMS sign-in codes described in Section 5. Telnyx receives the mobile number and the code text solely to deliver that message.
- Stripe— the payment data source we read via Stripe Connect, and our own subscription billing.
- Adobe(Typekit / Adobe Fonts) — serves the typeface the Service is set in. Because the font is fetched by your browser when a page loads, Adobe receives your IP address, user agent, and the time of the request. We send them no account, member, or payment data.
The advertising, CRM, and fitness platforms a customer connects (Google Ads, Meta, GoHighLevel, Mindbody) are the customer’s own sources, not Adsu subprocessors; data flows between them and the Service under the customer’s authorization, including the advertising actions described above. We may update this list as our providers change and will reflect changes here.
8. Security
We take reasonable and appropriate technical and organizational measures to protect personal data, including encryption of data in transit, access controls that scope each customer’s data to that customer’s tenant, least-privilege access to credentials and OAuth tokens, and audit logging of system actions. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. This policy makes no claim to any specific security certification.
9. International transfers
Adsu and its subprocessors may process personal data in the United States and other countries. Where personal data is transferred across borders, we and our customers rely on appropriate safeguards required by applicable law, such as standard contractual clauses, as implemented in the relevant data processing arrangements.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal data, to data portability, and to object to certain processing, under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).
Because Adsu processes member and lead data as a processor on the gym’s behalf, if you are a member or lead, please direct your request to the gym you interacted with — they are the controller. If you send a request to us, we will forward it to the relevant customer and support their response. For the limited data for which Adsu is the controller (administrative account users), you can reach us directly at will@willocho.com. We do not use personal data to make decisions producing legal or similarly significant effects without human involvement.
11. Children
The Service is a business tool and is not directed to children. We do not knowingly process the personal data of children through the Service outside of records a customer maintains about its own members in its own systems, for which the customer is the controller.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after a change takes effect is your acknowledgment of the updated policy.
13. Contact
Questions about this policy or our data practices can be sent to will@willocho.com, or by mail to 8020 Holdings LLC, 6131 Gypsy Bell, San Antonio, TX 78215.