Hollow is a first-party ad tracking and attribution platform operated by Zion Hollow Creative. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. It also describes, specifically, how Hollow accesses and handles data from connected advertising platforms such as Meta, so that both our customers and platform reviewers can see exactly what the application does.
Zion Hollow Creative (“Hollow,” “we,” “us,” or “our”) operates the Hollow platform at adhollow.com. Zion Hollow Creative is based in Greeneville, TN, United States, and is the data controller responsible for the information described in this policy. For any privacy question or request, contact us at privacy@adhollow.com.
This policy applies to three groups:
When you create an account we collect your name, email address, workspace name, and role. If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment details. We do not store full card numbers on our systems; we retain only limited billing metadata such as the last four digits, card brand, and subscription status returned by Stripe.
When you connect a third-party account, you authorize Hollow to read data from it on your behalf, solely to provide the analytics you have asked for. Depending on the platforms you connect, this may include:
On websites where our customer has installed the Hollow pixel, we collect first-party analytics events on the customer's behalf: page views and clicks, referring URLs and marketing parameters (including advertising click identifiers such as fbclid), a first-party visitor and session identifier stored in the customer's own domain, IP address, user agent, and conversion or lead events. Where a person identifies themselves on the customer's funnel (for example by submitting an email or phone number, or completing a purchase), that identifier is associated with their prior activity so the customer can attribute the sale. We process this data only to provide attribution to the customer who collected it.
This section describes how Hollow handles data obtained through the Meta Marketing API and Facebook Login for Business, and applies in addition to the rest of this policy.
When you click Connect with Meta, you are taken to Meta to sign in and choose which ad accounts to authorize. Hollow never sees your Facebook password. Meta returns an access token that we exchange for a long-lived token and store in encrypted secret storage. We request only the permissions needed to provide the service:
To read the ad accounts, campaigns, ad sets, ads, and performance insights (spend, impressions, clicks) and creatives that power your reports and dashboards. This is a read-only permission.
To identify and reach the ad accounts and assets owned within your Meta Business Manager, so we can connect the specific accounts you select.
Used only where you explicitly enable conversion feedback, to send your own conversion events back to your own Meta pixel or dataset (the Conversions API) so your campaigns can optimize. We do not create, edit, pause, or otherwise manage your ad campaigns.
Our use of Meta Platform data is limited to providing and improving the Hollow features you request. Specifically, we do not sell Meta Platform data, we do not use it for advertising of our own, we do not transfer it to data brokers or use it to build profiles for unrelated purposes, and we handle it in accordance with the Meta Platform Terms and Developer Policies. Access tokens are stored encrypted, are never exposed to your browser, and are used only for server-to-server calls to Meta on your behalf.
We use the information we collect to:
We do not sell your personal information or your connected-platform data, and we do not use data from your connected accounts for any purpose other than providing the service to you.
We share information only as needed to run the service:
We retain account information for as long as your account is active. Data synchronized from a connected platform is retained while that connection is active and while your account remains open, so that historical reporting stays intact. When you disconnect a platform, the stored access credential for that connection is deleted immediately. When you close your account or ask us to delete your data, we delete or de-identify your personal and connected-platform data within 30 days, except where we must retain limited records to meet legal, tax, or accounting obligations. Residual copies may persist in encrypted backups for a limited period before being overwritten.
We protect data with encryption in transit (HTTPS) and at rest. Sensitive credentials such as platform access tokens are held in a dedicated encrypted secret store and are never sent to the browser. Access to production data is restricted and authenticated, every workspace's data is isolated, and application access is role-gated. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard safeguards.
You can exercise the following at any time:
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to or restrict certain processing and the right not to be discriminated against for exercising your rights. We do not sell personal information. To make any of these requests, contact privacy@adhollow.com. If we process data as a processor on a customer's behalf (data collected through their pixel), please direct your request to that business; we will assist them in responding.
Our own website uses only the cookies necessary to operate it, including a session cookie to keep you signed in. On our customers' websites, the Hollow pixel sets a first-party visitor and session identifier in the customer's own domain to measure attribution for that customer. These are first-party identifiers used for analytics on behalf of the site owner; they are not used to build cross-site advertising profiles by Hollow. Site owners are responsible for providing notice and obtaining any consent required in their jurisdiction for analytics on their sites.
Zion Hollow Creative is based in the United States, and the information we process is stored and processed in the United States. If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
Hollow is a business tool and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of Hollow after an update means you accept the revised policy.