Privacy Policy
Last updated 26 August 2026 · Effective 26 August 2026
Commnd is a marketing operations platform operated by Vallejo Labs ("Vallejo Labs", "we", "us"). This policy explains what data Commnd handles, why, where it lives, how long we keep it, and how to make us delete it.
Commnd is a business-to-business tool. Our users are the businesses and agencies that sign in to it. Commnd is not intended for consumers and is not directed at children under 16.
1. The short version
- We store aggregated marketing performance figures from the accounts you connect — spend, impressions, clicks, conversions, rankings, opens and similar.
- We do not store personal information about your customers or your ad audiences. Not names, not email addresses, not phone numbers, not advertising identifiers, not lists.
- We never sell data and we never use your data to train artificial intelligence models.
- You can disconnect any platform, and delete your organization and everything in it, at any time. See Data Deletion.
2. Who is responsible
For the account data of people who sign in to Commnd, Vallejo Labs is the data controller — we decide what is collected and why.
For the marketing data we read from the platforms you connect, you are the controller and Vallejo Labs acts as your data processor: we handle that data on your instructions, to provide Commnd to you, and for nothing else.
3. What we collect
3.1 Account and identity data
Handled by our identity provider, Clerk. We receive your name, email address, profile image if you set one, the organization you belong to and your role in it. We never see or store your password.
3.2 Data from the platforms you connect
Connecting a platform is always a deliberate act: you click through that platform's own authorization screen and grant the access you choose. Commnd can then read the following from the accounts you granted, and nothing outside them.
| Kind of platform | What Commnd reads |
|---|---|
| Advertising — Meta Ads, Google Ads, TikTok Ads, LinkedIn Ads, Microsoft Ads, Amazon Ads | Ad account, campaign, ad set and ad names and identifiers; spend, budget, impressions, reach, clicks, conversions, cost per result, and similar aggregated performance figures; creative text, headlines and image or video references; account and campaign status. |
| Analytics — Google Analytics 4, Google Search Console, Google Tag Manager, Hotjar | Aggregated traffic, session, conversion and funnel reports; search queries, impressions, positions and click-through rates at the property level. |
| Social and content — Instagram, Facebook Pages, LinkedIn Pages, YouTube | Page and profile identifiers you own; post-level and account-level engagement counts such as reach, impressions, likes, comments and shares; published post content and scheduling metadata. |
| Commerce and CRM — Shopify, HubSpot | Aggregated order, revenue and pipeline totals. We do not import customer records. |
| Email — Klaviyo, Mailchimp, ActiveCampaign | Campaign-level and flow-level counts: sends, opens, clicks, unsubscribes, revenue attributed. Not subscriber lists or individual recipient addresses. |
| SEO tooling — Ahrefs, Semrush | Keyword, ranking and backlink data for the domains you configure. |
3.3 What we deliberately throw away
Some platform endpoints return personal information whether we want it or not. Commnd is built to discard it: if a data pull contains email addresses, names, phone numbers, postal addresses, device or advertising identifiers, or any other identifier belonging to an individual end user, it is dropped before anything is written to our database. We do not retain it, and it does not reach our AI agents.
3.4 Credentials
Access tokens issued by the platforms you connect are stored encrypted at rest in a dedicated secret store and are only ever decrypted on our servers, at the moment a request is made. They are never included in a page sent to your browser, never written to an application log, and never exposed to another customer.
3.5 Operational data
To keep the service running we record technical logs and error reports: timestamps, the organization and job involved, request and response status, performance timings, and diagnostic stack traces. We also record AI usage — which model ran, for which organization, and how many tokens it consumed — for billing and cost control.
4. Meta Platform data
Where you connect a Meta product — Meta Ads, Facebook Pages or Instagram — the following applies specifically, in addition to everything above.
- Commnd requests only the permissions needed to read the performance of, and to propose changes to, the ad accounts and pages you yourself administer.
- Meta Platform data is used only to generate reporting and recommendations inside your own Commnd organization. It is not used for any other purpose.
- We do not transfer Meta Platform data to any data broker, ad network, monetization service, or any other third party for their own use.
- We do not use Meta Platform data to build or enrich profiles of individuals, to train machine learning models, or to make decisions about eligibility for employment, housing, credit, insurance or similar.
- Commnd will never write a change to your Meta ad account without a recommendation that a named person in your organization has explicitly approved.
- Meta Platform data is deleted when you disconnect Meta from Commnd, when you delete your organization, or on request — see Data Deletion.
5. How we use it
- To run the product: show you the state of each marketing area, calculate changes over time, and detect anomalies. This part is ordinary arithmetic done in code.
- To generate recommendations: aggregated figures and your own campaign copy are sent to a large language model, which writes the interpretation and the proposed action in plain language.
- To execute approved changes against a connected platform — and only after a named person has approved the specific recommendation.
- To keep the service healthy and secure: monitoring, debugging, abuse prevention, and cost accounting.
We do not use your data for advertising, we do not build profiles of individuals, and we do not make automated decisions that produce legal or similarly significant effects on any person.
6. Artificial intelligence and your data
Commnd sends aggregated marketing figures and your own marketing copy to third-party language model providers to produce recommendations. We use providers that operate under commercial terms which prohibit training on the data submitted through their business APIs.
Vallejo Labs does not train any model on your data, and does not permit our providers to do so.
7. Who we share it with
We share data only with the service providers needed to run Commnd, each bound by contract to protect it and to use it only for us.
| Provider | What it does |
|---|---|
| Vercel | Hosts and serves the application |
| Supabase | Database and encrypted credential storage |
| Clerk | Sign-in, accounts and organizations |
| Composio | Manages the authorized connections to your marketing platforms |
| Anthropic, OpenAI and other model providers via OpenRouter | Generate the written recommendations |
| LangSmith | Records agent runs so we can diagnose failures |
| Sentry | Error and crash reporting |
| Inngest | Runs scheduled and background jobs |
We may also disclose data where we are legally required to, or to establish or defend a legal claim. If Vallejo Labs is ever acquired or merged, data may transfer to the acquirer under this same policy, and we will tell you before that happens.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
8. Where your data is stored
Commnd runs on infrastructure located in the United States. If you access Commnd from the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States under the Standard Contractual Clauses adopted by the European Commission, which our providers incorporate into their terms.
9. How long we keep it
| Data | Kept for |
|---|---|
| Account and organization records | As long as the account exists, then deleted within 30 days |
| Platform metrics and generated recommendations | As long as the organization exists, then deleted within 30 days |
| Access tokens for connected platforms | Deleted immediately when you disconnect the platform |
| Audit records of changes written to your platforms | 24 months, for accountability |
| Technical logs and error reports | Up to 90 days |
Backups are overwritten on a rolling cycle and are fully cleared within 90 days.
10. Your rights
Depending on where you live, you may have the right to:
- Ask what data we hold about you and get a copy of it
- Have inaccurate data corrected
- Have your data deleted
- Object to or restrict how we process it
- Receive your data in a portable format
- Withdraw consent, at any time, by disconnecting a platform
- Complain to your local data protection authority
Write to admin@myaimatch.ai and we will respond within 30 days. Exercising these rights costs nothing and we will not treat you differently for it.
11. Security
- Everything travels over encrypted connections, and data is encrypted at rest.
- Platform credentials are held in a dedicated encrypted secret store, readable only by our servers.
- The database enforces separation between organizations on every query, so one customer's records cannot be read by another even if application code were wrong.
- Access to production systems is limited to the people who need it.
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authorities as required by law.
12. Cookies
Commnd uses only the cookies it needs to work: a session cookie that keeps you signed in and security cookies that protect the sign-in process. We do not use advertising or cross-site tracking cookies.
13. Children
Commnd is not for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
14. Changes to this policy
We will update this page when this policy changes and move the "last updated" date at the top. For changes that materially affect your rights, we will also email the administrators of each organization at least 30 days before they take effect.
15. Contact us
Vallejo Labs
1401 NE 9th St, Unit 8
Fort Lauderdale, FL 33304
United States
Privacy and general enquiries: admin@myaimatch.ai
Deletion requests: commnd.com/data-deletion