Legal

Privacy Policy

This policy explains what personal information Nead, LLC, doing business as ROI.me, collects, why, and the choices and rights you have. It applies to our website at roi.me, the ROI.me application, our API and MCP server, and our sales and support conversations.

Last updated September 28, 2026

1. Who we are

ROI.me is an advertising platform operated by Nead, LLC ("ROI.me", "we", "us" or "our"). Businesses use ROI.me to understand visitors to their websites, build audiences, create advertising, and run and measure campaigns across advertising networks.

Questions about this policy or your personal information can be sent to [email protected].

2. Our two roles

We handle personal information in two different capacities, and this policy treats them separately:

  • As a controller, for information about the people who visit roi.me, sign up for or use ROI.me, contact us, or buy from us. We decide how that information is used, and this policy describes it.
  • As a processor (or service provider), for information our customers send to ROI.me about their own website visitors, leads and customers ("Customer Data"). Our customer decides what is collected and why; we process it only on their instructions, under our Data Processing Addendum at roi.me/dpa. If you visited a website that uses ROI.me, that website's owner is responsible for the processing, and their privacy notice applies. We will help them respond to your requests.

3. Information we collect as a controller

Information you give us

  • Account information: your name, work email address and organization, and your role within it. We receive this when you sign up or sign in, including through the erp.io single sign-on service.
  • Billing information: billing contact, company details and tax information. Payment card details are collected and stored by our payment processor, Stripe; we receive only limited details such as the card brand, last four digits and expiry date.
  • Communications: what you send us through our contact form, email, chat or support channels, such as your name, email, company, advertising budget range and message.
  • Content you add to the service: brand information, product details, uploaded images, video and audio, prompts, campaign settings and similar material.

Information collected automatically

  • Usage information: pages and features used in the application, actions taken (for example, approvals and campaign changes, which we keep in an audit log), and API and MCP requests made with your keys.
  • Device and connection information: browser type, operating system and approximate location derived from your connection. We use IP addresses transiently for security and rate limiting.
  • Cookies and similar technologies: see Cookies below.

Information from others

  • Single sign-on: when you sign in through erp.io, it tells us your name, email, whether your email is verified, your organization and your role.
  • Connected services: when you connect an advertising network, CRM or commerce platform, we receive account identifiers, names and the data you authorize us to access, on your behalf.
  • Business contact sources: information from publicly available sources and partners, to understand prospective customers' businesses.

4. How we use information

  • To provide, maintain and secure the service, including authenticating users and enforcing roles, approvals and spending limits.
  • To process payments, manage subscriptions and usage, and prevent fraud and abuse.
  • To provide support and respond to your requests.
  • To send service messages, such as approvals awaiting you, security notices and billing notices.
  • To send marketing communications about our products, where permitted. You can opt out at any time.
  • To analyze and improve the service, including aggregated and de-identified statistics about how features perform.
  • To comply with law, enforce our terms, and protect the rights and safety of our users and others.

Legal bases (EEA, UK and Switzerland)

Where the GDPR or a similar law applies, we rely on these legal bases: performance of our contract with you (to provide the service); our legitimate interests (to secure, support, improve and market the service, balanced against your rights); your consent (for non-essential cookies and certain marketing, which you can withdraw at any time); and legal obligation (for tax, accounting and compliance).

5. Artificial intelligence

ROI.me uses AI models from third-party providers to analyze brands, generate creative, score content and answer questions through ROI Agent. When you use these features, the relevant content (such as brand information, prompts, and data the agent needs to answer) is sent to the provider to produce the result.

  • We use AI providers under their business and API terms, not consumer terms, and they are listed as sub-processors at roi.me/subprocessors.
  • We do not use Customer Data to train AI models, and we do not permit our AI providers to use it to train theirs.
  • AI output can be inaccurate. ROI.me shows how the agent reached an answer, and launches and spend changes always go through the approvals you configure.

6. Data we process for our customers

When a business uses ROI.me, we process Customer Data on its behalf, for example:

  • Website activity collected by the ROI Pixel on the customer's website: pages viewed, events such as form submissions, referrer and campaign parameters, device type, browser, operating system and approximate country. The pixel does not collect the contents of form fields or passwords, and it removes values that look like card numbers or government identifiers.
  • Identifiers: a random visitor identifier, and, where a visitor identifies themselves to the customer (for example by submitting a form), a one-way hash of their email address or phone number. We do not store IP addresses with website activity.
  • CRM and commerce records the customer connects, such as contacts, deals and orders, used to measure results.
  • Advertising data: campaigns, audiences and performance from the customer's advertising accounts.

We do not identify anonymous visitors from device data or by combining data across different customers, and we do not sell Customer Data. Each customer's data is kept separate from every other customer's. Requests about Customer Data should go to the business whose website you visited; if you contact us instead, we will refer you to them and help them respond.

7. How we share information

We share personal information only as follows:

  • Service providers (sub-processors) that host, secure, bill, email and provide AI for the service, under contracts that limit their use of the data. The current list is at roi.me/subprocessors.
  • Services you connect. When you direct us to, we send data to advertising networks, CRMs and other services you connect, for example to create a campaign or sync an audience. Their use of that data is governed by their own terms and privacy policies.
  • Within your organization. Other members of your organization can see content and activity in your shared workspace, according to their roles.
  • Legal and safety. When required by law or legal process, or to protect the rights, property or safety of our users, the public or us.
  • Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this policy.

We do not sell personal information, and we do not share it for cross-context behavioral advertising of our own.

8. Cookies and similar technologies

On roi.me. We use necessary cookies to run the site and remember your cookie choices (the roi_consent cookie, kept for six months). With your consent, we use analytics and advertising cookies. Our website chat assistant is provided by Phony (erp.io). You can change your choice at any time using Cookie preferences in the site footer.

In the ROI.me application. We use a necessary session cookie (__roi_session) to keep you signed in. It lasts up to 14 days and ends after 3 days without use.

The ROI Pixel on customers' websites. The pixel sets a first-party visitor cookie (_roi_vid, up to 13 months) and a session cookie (_roi_ses, one day), and briefly stores unsent events in the browser's local storage. The customer decides whether the pixel runs only after consent, and is responsible for obtaining any consent their visitors' laws require.

Most browsers let you block or delete cookies. Blocking necessary cookies may stop parts of the service from working.

9. How long we keep information

  • Account and workspace data: for as long as your organization's account is active.
  • After an organization is deleted: access ends immediately, and its data is permanently deleted 30 days later.
  • Website activity (Customer Data): up to 25 months, unless the customer deletes it sooner or erases a person's data.
  • Billing records: as long as required for tax and accounting, typically seven years.
  • Audit and security logs: for as long as the account is active, to show who approved and changed what.
  • Backups: replaced on a rolling schedule and kept for no more than 12 months.

10. Security

We protect personal information with administrative, technical and physical safeguards, including encryption in transit, encryption of stored credentials with AES-256-GCM, hashing of API keys and session tokens, role-based access control, isolation between customers, audit logging and approvals for spend-affecting actions. More detail is at roi.me/security. No system is perfectly secure; please report suspected vulnerabilities to [email protected].

11. International transfers

We are based in the United States, and we and our service providers process information in the United States and the European Union. When we transfer personal information from the EEA, the UK or Switzerland to countries without an adequacy decision, we use Standard Contractual Clauses (and the UK Addendum where relevant) or another lawful transfer mechanism.

12. Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal information we hold about you, and receive a copy in a portable format;
  • correct inaccurate information;
  • delete your information;
  • object to or restrict certain processing, including direct marketing;
  • withdraw consent where we rely on it, without affecting earlier processing;
  • not be discriminated against for exercising your rights.

To exercise these rights, email [email protected]. We will verify your request and respond within the time the law requires (generally within 30 days, or 45 days under US state laws). An authorized agent may make a request for you with your written permission. If you are in the EEA, the UK or Switzerland, you can also complain to your local data protection authority.

California and other US states. In the last 12 months we have collected the categories of information described above (identifiers, commercial information, internet activity, approximate geolocation and professional information) for the business purposes described in this policy. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics.

13. Children

ROI.me is a business service. It is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact [email protected] and we will delete it.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new effective date and, for material changes, notify account owners by email or in the application before the change takes effect.

15. Contact us

Nead, LLC (ROI.me). Privacy questions and requests: [email protected]. Security reports: [email protected]. Everything else: [email protected].

  • Necessary: Keeps the site working and secure, and remembers this choice. Always on.
  • Analytics: Measures how the site is used so we can improve it. First-party only.
  • Advertising: Uses your visits to show you relevant ROI.me ads on other sites.