The short version
- We collect only what you hand us — mostly a name, an email, and some context about your Amazon account.
- We don't run analytics, advertising pixels, or tracking cookies on this site.
- We don't sell your data. Ever. There's no scenario where that happens.
- If you're a client, your Amazon advertising data is used to do your work and nothing else.
- Email info@adscreek.com to see, correct, or delete anything we hold.
Who we are
Adscreek is a founder-led Amazon PPC and advertising consultancy operating from Burnie, Tasmania, Australia, and run by Malik Bilal. In this policy, "we", "us", and "our" mean Adscreek. "You" means anyone visiting adscreek.com or engaging us for services.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we serve clients or visitors in the United Kingdom or the European Economic Area, we also apply the standards of the UK GDPR and EU GDPR to that information.
This policy covers this website and our client engagements. It does not cover third-party sites we link to, or the Amazon platforms themselves, which have their own privacy terms.
What we collect
Information you give us directly
When you book a diagnostic through this site, we ask for:
- Your full name and email address
- Your Amazon storefront URL
- Your approximate monthly ad spend, as a range
- A short description of the PPC problem you're facing
If you subscribe to our newsletter, we collect your email address and nothing else. If you email us directly, we hold whatever you choose to put in that email.
Information collected automatically
Our host records standard server logs when a page is served — IP address, browser and device type, the page requested, and a timestamp. These are used to keep the site running, diagnose faults, and detect abuse. We do not use them to build a profile of you.
What we deliberately don't collect
We do not ask for, and have no use for, sensitive information as defined by the Privacy Act — health, biometric, racial or ethnic origin, political or religious views, sexual orientation, or criminal record. Please don't send it to us.
We never ask for your Amazon password. Account access is granted through Amazon's own permission systems, described in section 6.
How we use it
We use personal information to:
- Prepare for and run your diagnostic call, and follow up afterwards
- Quote for, deliver, and support the services you've engaged us for
- Send the newsletter, if you asked for it
- Reply to enquiries
- Meet our tax, accounting, and other legal obligations
- Keep the website secure and working
For visitors covered by the GDPR, our legal bases are: performance of a contract (delivering services you've engaged), consent (the newsletter — withdrawable at any time), legitimate interests (replying to enquiries, securing the site), and legal obligation (record-keeping).
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.
Third parties
We keep the number of third parties deliberately small. Right now, three touch this website:
- Calendly — powers the booking widget on our Diagnostic page. When that widget loads or you book a time, Calendly receives your booking details and sets its own cookies. Calendly is a US company and acts as its own data controller for that information. See Calendly's privacy notice.
- Google Fonts — we load the DM Sans typeface from Google's font servers, which means Google receives your IP address and user-agent when a page loads. No cookies are set by this.
- Vercel — hosts and serves this website, and generates the server logs described above.
For client work we also use Amazon Ads and Amazon Seller Central, and standard business tools for email, invoicing, and file storage. We choose providers that offer appropriate security and contractual protections.
We are a member of the Amazon Ads Partner Network. Amazon is an independent company with its own privacy terms — nothing in this policy binds Amazon or changes how it handles your data.
Client account data
Client engagements are different from casual browsing, so they deserve their own section.
To manage advertising, we typically need delegated access to your Amazon Ads and, where relevant, Amazon Seller Central accounts. That access is always granted by you through Amazon's own user-permission systems, at the permission level required for the work, and it can be revoked by you at any time without our involvement.
Through that access we see campaign structures, keyword and search-term data, bids, spend, sales and conversion figures, and related advertising reporting. We use this only to plan, run, optimise, and report on your advertising.
We treat your account data as confidential. Specifically, we will not:
- Use your data to benefit a competitor
- Sell, licence, or share it with data brokers
- Publish it, or identify you in a case study, without your written permission
Where we reference results publicly, figures are aggregated or anonymised unless you have specifically agreed to be named.
When an engagement ends, ask us to step back from your accounts — or revoke access yourself — and we'll confirm it's done.
Overseas transfers
We're based in Australia, but some of our providers are not. Calendly and Vercel operate primarily from the United States, and Google's font infrastructure is global. Amazon processes data in the regions where you sell.
This means your information may be stored or processed outside Australia. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, and where the GDPR applies we rely on appropriate safeguards such as standard contractual clauses.
Security
We take practical, proportionate measures to protect personal information: encrypted connections (HTTPS) across the site, multi-factor authentication on business-critical accounts, least-privilege access to client platforms, and a deliberately small number of systems holding data.
No method of transmission or storage is completely secure, and we can't guarantee absolute security. If we ever become aware of a data breach likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
How long we keep it
We keep personal information only as long as we have a reason to:
- Enquiries and diagnostic submissions that don't become engagements — up to 24 months, then deleted
- Client records — for the engagement, then as long as required for tax and legal purposes (generally seven years under Australian law)
- Newsletter subscriptions — until you unsubscribe
- Server logs — a short rolling window set by our host
When information is no longer needed, we delete it or de-identify it.
Your rights
You can ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate or out of date
- Delete it, where we don't have a legal reason to keep it
- Stop using it for a particular purpose, including marketing
- Unsubscribe from the newsletter — every email has a one-click link
If the GDPR applies to you, you also have the right to data portability, the right to restrict processing, the right to object to processing based on legitimate interests, and the right to withdraw consent at any time without affecting processing already carried out.
Email info@adscreek.com and we'll respond within 30 days. There's no charge. We may need to verify your identity first, which protects you as much as us.
Complaints
If you think we've mishandled your personal information, tell us first — email info@adscreek.com with the details. We'll investigate and respond within 30 days. Most issues are a misunderstanding and get resolved quickly.
If you're not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au. If you're in the UK or EEA, you may instead complain to your local supervisory authority.
Children
Our services are built for businesses, and this site isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we'll delete it.
Changes to this policy
We'll update this policy when our practices change — for example, if we add analytics or a new tool. The "last updated" date at the top always reflects the current version.
If a change materially affects how we handle your information, we'll take reasonable steps to tell you directly rather than relying on you to re-read this page.
Contact us
Questions about this policy, or about anything we hold on you:
Adscreek
Attn: Privacy — Malik Bilal
Burnie, Tasmania, Australia
info@adscreek.com