Last updated: July 24, 2026
Plain words, no legal fog. neo (neoroas.com) is an ad tracker: our customers install it on their own sites to count which ads produce which sales. That means there are two different relationships here — yours if you have a neo account, and yours if you visited a site that uses neo. Both are covered below.
We store your email address (used for magic-link sign-in — we never see or store a password), your workspace settings, and the tracking data your sites send us. We use your email to log you in and to write to you about neo: service notices that matter (like usage warnings), and occasional product news — new features, changes, plans. You can opt out of anything that isn't essential to running your account, right from the email. We never sell your data or hand your address to anyone else.
The site owner — not us — decides to track and is the data controller. We process this data on their behalf. What the snippet collects when you visit their pages: a random visitor ID stored in a first-party cookie, the page URL and referrer, ad-click identifiers from the URL (like Meta's fbclid and UTM parameters), your IP address and browser user agent. If you type your email into one of their forms, the site owner uses neo to link it to your visit, and we also store a SHA-256 hash of it. If you buy something, their store sends us the order (amount, product, your email) so the sale can be matched to the ad click that caused it.
On the site owner's instruction, purchase and lead events are also sent to Meta's Conversions API with hashed identifiers — that's the site owner using their own Meta account, with neo as the pipe. We never combine your data across different customers' sites, and we don't build cross-site profiles of anyone.
One cookie: ft_vid, a random ID with no personal information in it, set for up to 400 days on the site you visited (browsers like Safari may cap this sooner). Its only job is recognising that the person who clicked the ad and the person who bought are the same visitor. The neo dashboard itself uses session cookies to keep you signed in. That's it — no third-party ad cookies, no fingerprinting.
Raw click data (IP, user agent, page URLs) is kept for 90 days, then automatically collapsed into daily per-campaign counts — the visitor-level detail is deleted. Clicks that are the proof behind a recorded sale are kept, because they are the attribution. The raw order payloads stores send us are wiped after 30 days. Logs of events sent to Meta are wiped after 30 days. Account data lives until you delete your account, which cascades: workspace, clicks, leads, conversions, everything.
Everything is stored with Supabase on AWS in Frankfurt (eu-central-1, European Union). The app runs on Vercel (hosting and CDN). Resend delivers our operational emails. Meta receives conversion events only as described above, only on the site owner's instruction. Nobody else. We don't sell data, we don't share it with advertisers, and there's no analytics of ours piggybacking on your visitors.
Under the GDPR you can ask for access, correction, deletion, restriction or a copy of your data. Account holders: write to hello@neoroas.com and we'll handle it. Visitors of a customer's site: your request goes to that site's owner (the controller) — but if you write to us, we'll help route it and we assist them in fulfilling it.
If this policy changes in a way that matters, account holders get notified in the app before it takes effect. The date at the top always tells you when it was last touched.