hecigo

    Privacy Policy

    This page describes what the website hecigo.com collects, who receives it, and how to have it removed. It also covers the hosted Ads Insights service, in its own section below. Data processed inside a client's own systems during an integration engagement is governed by the contract for that engagement, not by this page.

    Data controller: HECIGO TECHNOLOGY CO., LTD, registered in Vietnam as CÔNG TY TNHH CÔNG NGHỆ HECIGO, tax code 0317653537, CirCO Dien Bien Phu, 222 Dien Bien Phu street, Xuan Hoa ward, Ho Chi Minh City, Vietnam. Contact for any privacy question or request: hi@hecigo.com.

    Legal basis. This policy is written to Vietnam's Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, both in force since 1 January 2026. The decree replaced Decree 13/2023. Where you send us an enquiry, the basis for processing is your consent, given by ticking the box on the form.

    Last updated: 11 October 2026. Version: pdp-2026-10-11d.

    What we collect

    Information you send us deliberately

    The enquiry form on this site collects exactly four fields: your name, your email address, the role you select from the dropdown, and your message. Nothing else is read from your browser and attached to it. The form cannot be sent without ticking the consent box, and we record the moment you ticked it together with the wording you agreed to and the version of this policy that was live then.

    Submitting the form sends those four fields to our intake workflow at workflow.thenexova.com, operated by THE NEXOVA on our behalf. That workflow then does three things: it emails the enquiry to our own mailbox, it sends you an automatic acknowledgement, and it posts a notification to a private Telegram chat that only we can read. Our mailboxes run on Lark, so a copy of your enquiry rests there. All four recipients are listed under Who else sees it.

    If you email or call us directly, we hold whatever you chose to put in that message for the same purpose and for the same period.

    We use this information for one thing: replying to you and, if it becomes a project, running that project. We do not sell it, rent it, or add it to a marketing list you did not ask to join.

    Information collected automatically

    • Google Analytics 4 (measurement ID G-DFZBPG12H8) records page views, approximate location derived from IP address, referrer, device type, and browser. Google processes this as our processor. IP addresses are truncated by Google before storage.
    • Meta Pixel (ID 1642547450913779) records page views and passes them to Meta so we can measure whether our posts bring anyone here. Meta acts as an independent controller for that data under its own terms.
    • Hosting and CDN logs. The site runs on Cloudflare Workers, which keeps short-lived request logs containing IP address, user agent, and requested path, for delivery and abuse prevention. We do not query these logs to identify visitors.
    • Short-link clicks. Some links we publish elsewhere, such as in a package README, in a repository, or in a channel profile, point at addresses on this site beginning /go/, which forward you to the real page. Each forward is counted. What is written down is the short code itself, the page it led to, and the country Cloudflare derived at its own edge. Your IP address is not stored, and neither is your user agent or the page you came from. The counter exists to tell us which of our links anyone follows, and it cannot tell us who you are. It is kept by Cloudflare for three months and then disappears.

    Fonts are compiled into the site at build time and served from our own domain, so loading a page does not send a request to Google Fonts. There is no chat widget, no session recorder, and no A/B testing tool on this site.

    Cookies

    Google Analytics and the Meta Pixel set cookies in your browser. They are the only cookies this site causes. Nothing on hecigo.com requires a cookie to function. Blocking them in your browser, or using any tracker-blocking extension, leaves the entire site working normally, including the enquiry form. The Ads Insights pages at ads.hecigo.com set further cookies, described under Measuring hecigo's own advertising.

    We would rather state the current position than describe it vaguely. Both scripts load when the page opens, before the site asks your opinion. There is no banner offering you the choice yet. We are working on one, and this page will be updated when it is live. Until then the ways to refuse are the ones listed under Your rights, none of which needs you to contact us.

    Automated clients and AI agents

    This site publishes machine-readable representations of its own public pages: /llms.txt, /sitemap.xml, Markdown variants of each page, and /blog-index.json. Requesting any of those is an ordinary anonymous page request and is logged the same way as a browser visit. No additional data is collected from automated clients, and none of these files contain personal data about visitors.

    The Ads Insights service

    Ads Insights is hosted software that reads a customer's own advertising data from Meta Ads, Google Ads and TikTok Ads, and, where the customer connects them, the Google Analytics and Google Search Console data of the customer's own websites, and shows it back to that same customer. It is a different processing context from this website, so it is set out separately.

    Which role we hold. For the workspace itself, the name and the email address of the person who runs it, hecigo is the controller. For the advertising and website data reached through it, hecigo is a processor: we read what a customer's own authorization allows, on that customer's instruction, and for no purpose of our own. The Terms of Service are the agreement required of a processor under Law 91/2025.

    What is stored. An encrypted platform credential, the identifiers of the ad accounts the customer authorized, the workspace name, a contact email, and the identifier of the Google account used to sign in to it. For each connected platform the service also keeps a list of the ad accounts that credential can reach: each account's identifier, name, status, currency and time zone, whether it is a test account, and the manager account it is reached through where there is one. The list is encrypted like the credential. It exists so the service knows which accounts a connection can read and can show the customer which ones are being read. Where Google Analytics or Search Console is connected, it also keeps, encrypted, the identifiers of the Google Analytics properties or the addresses of the Search Console sites that are read by default. If someone turns on the weekly report schedule described under Weekly report schedule, the service also keeps, encrypted, that the schedule is on, the language it is written in, and the Google-verified email address it goes to. Credentials are encrypted before they are written down, and no interface returns their values, to anyone, including the customer.

    What is not stored. No copy of the customer's advertising history, website analytics or search data is kept for our own use: figures are fetched from the platform when a question is asked, or when a scheduled weekly report runs, and they are not warehoused afterwards. No data about the people who saw or clicked a customer's ads ever reaches us. One customer's data is never pooled with another's.

    How the data is protected. Platform credentials, and above all the Google tokens described under Google user data, are the most sensitive thing the service holds. These are the safeguards in place, each one a mechanism rather than an intention.

    • Encrypted in transit. Every connection to ads.hecigo.com, and every call from it to Google, Meta and TikTok, uses TLS. A plain HTTP request is redirected to HTTPS, and browsers are instructed to use HTTPS only for this host (HSTS).
    • Encrypted at rest. Refresh tokens, access tokens and every other platform credential are encrypted with AES-256-GCM before they are stored. The key is held only in Cloudflare's secret store for the service, apart from the data it protects, and never appears in source code or logs. A copy of the database without that key cannot be read.
    • Nothing reusable is stored in the clear. Workspace keys, and the access and refresh tokens issued to AI assistants, are stored only as SHA-256 hashes. Assistants sign in through OAuth 2.1 with PKCE, their access tokens expire after one hour, and the portal's session cookie is encrypted and marked HttpOnly, Secure and SameSite.
    • Least access. No screen, API or response returns a stored credential, to anyone, including the customer and hecigo's own administrators. Each request opens only the credentials of the one workspace it belongs to, so no workspace can reach another's data. The service has no operation that changes anything on an advertising platform. Access to the systems that run it is limited to hecigo's administrators, through accounts protected by two-step verification.
    • Logs without secrets. Service logs record which tool ran, for which workspace, how long it took and whether it failed. They never contain credentials, tokens or report figures, and query strings are removed from the addresses they record.
    • Deleted when no longer needed. Disconnecting a platform deletes its encrypted credentials, any cached access token and its list of ad accounts; deleting a workspace deletes everything in it, as set out under How long.
    • Incidents. If we learn that this data has been exposed, we notify the affected customers without undue delay, and the competent authority within 72 hours as Law 91/2025 requires.

    Monitoring. To find a broken connection before the customer does, the service checks each connected platform about once a day by listing the ad accounts its credential can open, and keeps whether that worked and the platform's error message if it did not. About once a day it also lists every ad account each connection can reach and replaces the stored list of ad accounts described under What is stored with the new one; if the listing fails, the previous list stays until a listing succeeds. For each question an assistant asks, it records the tool used, the name of the assistant, how long the answer took and whether it failed, with the workspace identifier and no report figures. These usage records are kept for three months. For each AI assistant connected to a workspace it also keeps when that connection was made and when it was last used, so the portal can list every connection and flag the ones nobody uses; those two dates go when the connection ends.

    Weekly report schedule. A person signed in to a workspace can turn on a schedule that emails them that workspace's advertising figures once a week. It is off until they turn it on, and it only ever goes to the Google-verified email address they are signed in with, never to an address typed in. Each Monday morning, while the schedule is on, the service reads the previous week's figures straight from the connected platforms, the same way an assistant's question reads them, for the ad accounts the workspace has chosen: spend, impressions, clicks, messages, conversions and their value, per platform and for the campaigns that spent most, against the week before. It adds them up and sends one email through our Lark mailbox. The figures are not kept once the email is sent; the next week is read afresh. A "run it now" button does the same once a day. The service records only when the schedule last ran and whether the email went out, with no figures. The schedule stops sending while no platform connection works.

    Emails we send you. Each person who signs in to a workspace with Google has that Google-verified address kept on the workspace, sealed like the credentials, with their name and the language they use. It is used for three kinds of email, sent from hi@hecigo.com through our Lark mailbox:

    • Service emails: changes to the Terms of Service or this policy, a security incident, a connection that stopped working, and anything else needed to run the workspace. They come while the workspace exists and cannot be turned off on their own; deleting the workspace ends them.
    • Product updates and feedback requests: new features, changes worth knowing, and now and then a short question asking how the service works for you. At most four a month. They start with the first sign-in, as the Terms of Service say, and every one of them carries a link that turns them off.
    • Offers: hecigo's own offers and new products, with [QC] or [AD] in the subject. At most two a month and never more than one a day. Like product updates, they start with the first sign-in, which the sign-in card states, and every one of them carries a link that turns them off.

    The link at the foot of every email opens a page where you turn either optional kind on or off without signing in, in Vietnamese and English; mail clients that offer one-click unsubscribe use the same page, and it turns both off. Writing to hi@hecigo.com works too. For each address we record whether each optional kind is on, when that last changed, how (sign-in, the link, the portal, or a request to us) and which version of this policy was in force, so that we can show what was chosen and when. We never send to an address typed in by someone else, never buy or rent addresses, and never give the address to anyone to send their own email.

    Signing up. Sign-up to ads.hecigo.com works in one of two modes, and we switch between them. While sign-up is open, the first Google sign-in creates a workspace straight away. We keep the name and email address Google shares with us, the Google account identifier, and the language the page was shown in, as that workspace's contact details. Our Lark mailbox sends the person one welcome email with a sign-in link that works once and expires after 72 hours, and sends hecigo one notice that a workspace was created. While sign-up is under review, or once the day's quota of open sign-ups is used up, signing in sends a request instead. For a request we keep the same details and when it was made, and use them for one thing: deciding the request and telling the person the outcome. Lark sends one email to hecigo to review it, one to the person to confirm it arrived, and, if it is approved, one with a sign-in link that works once and expires after 72 hours. A request nobody has decided is deleted after 90 days, and a decided one 30 days after the decision. An approved request continues as the workspace and its contact email, kept as set out under How long. The emails themselves rest in our Lark mailbox like any other correspondence.

    Measuring hecigo's own advertising. hecigo advertises Ads Insights on Meta, TikTok and Google, and measures which of those ads bring people who sign up. This concerns our own ads and the people who respond to them. It never involves a customer's advertising data.

    • Tags on two pages. The home page of ads.hecigo.com and its guide at ads.hecigo.com/guide load the tags of Google Analytics (measurement ID G-DFZBPG12H8), Google Ads, the Meta Pixel (ID 1642547450913779) and the TikTok Pixel. They record the page view, a click on the sign-in button and the submission of the sign-in code form, and they set their own cookies (_ga, Google Ads' _gcl_ cookies, _fbp and _fbc, _ttp). No page behind sign-in carries a tag: not the portal, the consent pages, the pages that connect an ad platform, or any other.
    • One cookie of our own. When you arrive from an ad, or for the first time from another site, ads.hecigo.com sets a cookie named hg_attr. It records when you arrived, the page you landed on, the click identifier the ad platform added to the link (gclid, gbraid, wbraid, fbclid or ttclid), any campaign tags in the link, and the name of the site that sent you. It is encrypted, no script can read it, and it expires after 90 days.
    • Three moments reported. When a workspace is created, when it connects its first ad platform, and when an AI assistant first uses it, the service reports that moment to Meta (Conversions API), TikTok (Events API), Google Analytics (Measurement Protocol) and Google Ads (conversion upload). Each report carries which moment it was and when; the workspace's random identifier, hashed for Meta and TikTok; the email address of the person who signed in, as a SHA-256 hash only (for Google Ads, Gmail addresses are hashed after removing dots and anything after a "+", the way Google compares them); the click identifier and campaign details from hg_attr; the cookies the tags set; the channel the person came from; and, for a connection, which platform was connected. The report of a new workspace also carries the IP address and the browser of the request that created it. The IP address is used for that report and is not stored.
    • What we keep. The workspace keeps a record of the above: the channel, the arrival details, the tag cookies, the browser, the hashed email address and the dates of the three moments, so that the later two can be reported. The customer does not see it, and it is deleted with the workspace.
    • What is never reported. The workspaces of hecigo's own people and of our test account, and every workspace created before 25 September 2026.
    • Who receives it. Meta, TikTok and Google, each under its own terms with hecigo, on infrastructure outside Vietnam.
    • Your choice. There is not yet a step on ads.hecigo.com that asks before the tags load or before a sign-up is reported. We intend to add one, and this page will say so when it is live. Until then you can refuse in any of these ways, and none of them costs you any part of the service: block the tags with a tracker blocker or your browser's settings, which also stops their cookies; delete the hg_attr cookie; or write to hi@hecigo.com, and we remove every identifier from your workspace's record and report nothing more about it. A report already sent cannot be taken back from the platforms, but each lets you limit how it is used for ads: Meta at facebook.com/adpreferences, Google at myadcenter.google.com, and TikTok under Settings and privacy, Ads, in the TikTok app.

    Basis. Performing the agreement the customer entered into, plus the authorization the customer granted on the platform's own consent screen. For service emails, product updates and feedback requests, the same agreement, which the Terms of Service describe; the optional ones stop the moment you turn them off, your right to object under Law 91/2025. For offers, the agreement to receive email from hecigo that signing in states, which you withdraw by turning them off, at any time, from any of them or the portal; we then stop within one working day. For sign-up, whether it opens a workspace or sends a request, the person's own request to use the service, made by signing in. For the weekly report schedule, the person's own request, made by turning it on. Measuring our own advertising is not yet based on a choice we ask for; see Your choice under Measuring hecigo's own advertising.

    Who else sees it. Cloudflare, which runs the service and stores the encrypted record. Lark, whose mail servers carry the sign-up and access-request emails and keep copies in our mailbox, and carry each weekly report email to the address it was turned on for, and the emails described under Emails we send you. The figures a customer asks for go to the AI assistant that customer connected, such as Claude or ChatGPT, whose provider handles them under its own terms with the customer. The advertising platforms are the source of the data rather than recipients of it, with one exception: the measurement of hecigo's own advertising reports sign-ups to Meta, TikTok and Google, as set out above. Nobody else.

    How long. Until the customer removes it. Revoking the authorization on the platform stops all reading immediately; writing to hi@hecigo.com deletes the workspace and everything in it, within 30 days, with written confirmation. A customer can also rotate or revoke their own access key at any time, and disconnect any AI assistant connection in the portal. An assistant connection that has not been used for 90 days is disconnected automatically. The weekly report schedule and its email address last until the person turns the schedule off, in the portal or through the link in any of its emails, which needs no sign-in; turning it off deletes both straight away, as does deleting the workspace. The record kept for measuring our own advertising goes with the workspace, and loses every identifier sooner if you ask; the hg_attr cookie expires after 90 days. The addresses kept for Emails we send you, and the record of the choices made for them, last as long as the workspace and go with it; turning both optional kinds off keeps the address only for service emails.

    Rights. The rights listed under Your rights below apply to the workspace and contact details we hold as controller. For the advertising data we hold as processor, the platform and the customer's own contract with it govern access and erasure, and we act on the customer's instruction.

    Google user data. Ads Insights receives data from Google in four ways, and uses it only as described here.

    • Sign in with Google (scopes openid, email, profile). Google shares the account identifier, name, email address and profile picture. We keep the identifier, the name and the email address as the workspace's contact details, as set out under Signing up. A one-way hash of the email address also takes part in the measurement set out under Measuring hecigo's own advertising. The profile picture is not stored.
    • Connecting Google Ads (scopes https://www.googleapis.com/auth/adwords and openid). The customer grants access on Google's own consent screen. We store the refresh token Google issues, encrypted with AES-GCM, and the identifiers of the Google Ads accounts it can open, with the manager account used to reach them where there is one. We also keep, encrypted, the name, status, currency, time zone and test-account flag of each Google Ads account the token can reach, as the list of ad accounts described under What is stored. From openid we read only the Google account identifier, and keep only a one-way hash of it, sealed with the token. It has one use: when a workspace disconnects, telling whether the same Google account still connects another hecigo Ads Insights workspace, so that revoking the grant does not cut that workspace off. With it we list the accounts the customer can access and run reporting queries on them: performance, configuration, ad content and delivery diagnostics.
    • Connecting Google Analytics (scopes https://www.googleapis.com/auth/analytics.readonly and openid) and connecting Search Console (scopes https://www.googleapis.com/auth/webmasters.readonly and openid). Each is its own grant, made on Google's own consent screen, separate from Google Ads and from each other; both scopes are read-only. For each we store the refresh token Google issues, encrypted with AES-GCM, the identifiers of the Google Analytics properties or the addresses of the verified Search Console sites read by default, and, from openid, a one-way hash of the Google account identifier, used as it is for Google Ads. With them we list the Google Analytics properties (Admin API account summaries) or the Search Console sites the customer can access, and, when the customer asks, run reports on them: Google Analytics reports of sessions, users, events, key events and revenue by channel, source, campaign, page, device, place or date (Data API), and Search Console reports of clicks, impressions, click-through rate and position by search query, page, country, device or date (Search Analytics). Google Analytics reports reach us already aggregated; Search Console withholds rare queries before they reach us.

    How it is used. Only to answer the questions the customer asks through their own AI assistant, to send the weekly report email a customer turned on to that customer's own Google address, as set out under Weekly report schedule, to show the customer the state of the connection in the portal, and to check about once a day that the connection still works and which accounts it reaches, as set out under Monitoring. Google offers a single scope for the Google Ads API and it also permits editing, but Ads Insights has no operation that creates, changes or deletes anything in Google Ads. The Google Analytics and Search Console scopes permit reading only.

    What is never done with it. Nothing received through the Google Ads, Google Analytics or Search Console connections is sold, used for advertising, retargeting or profiling, or used to decide credit-worthiness or lending. The only Google user data that takes part in advertising at all is the sign-in email address, as a one-way hash, in measuring hecigo's own ads as described above, and it is never sold. The sign-in address is also the one hecigo writes to, as set out under Emails we send you: service emails, product updates and feedback requests, and offers, each of the optional ones until the person turns it off. It is not used to develop, improve or train any artificial intelligence or machine learning model, ours or anyone else's. Nobody at hecigo reads it, except with the customer's permission to resolve a support request, where it is needed to investigate security or abuse, or where the law requires it.

    Who receives it. The figures go to the AI assistant the customer connected, because that is where the customer asked for them, or, when the customer turned on the weekly report schedule, to that customer's own email address through Lark's mail servers. Cloudflare stores the encrypted token and runs the service. The hash of the sign-in email address goes to Meta, TikTok and Google as set out under Measuring hecigo's own advertising. Nothing else is transferred to anyone.

    How it is protected. As set out under How the data is protected: encrypted with AES-256-GCM at rest and TLS in transit, never returned by any interface, never written to logs, and opened only to answer the customer's own requests.

    How long it is kept. The token, the account identifiers and the list of ad accounts stay until the customer disconnects Google Ads in the portal or deletes the workspace. The Google Analytics token and property identifiers, and the Search Console token and site addresses, each stay until the customer disconnects that connection in the portal or deletes the workspace. Disconnecting deletes them and revokes the grant at Google straight away, except when the same Google account still holds another hecigo Ads Insights connection, in another workspace or as another of the same workspace's Google connections, or hecigo cannot confirm that it does not. Google withdraws a grant from every workspace that account connected at once, so in that case the grant stays until the account's last workspace disconnects, and the portal says so. A customer can also remove access at any time at myaccount.google.com/permissions. Report figures are not kept after the answer is returned or the weekly report email is sent.

    Limited Use. hecigo Ads Insights' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    How long we keep it

    Enquiries have no fixed expiry. We keep an enquiry, and the correspondence that followed it, until you ask us to delete it. If it became a signed engagement, that contract's retention terms apply instead. There is no timer running in the background. Ask and it goes; see Your rights below.

    Ads Insights access requests last 90 days, or 30 days once decided. A request nobody has decided is deleted 90 days after it was made; one that was approved or turned down, 30 days after that decision. The storage expires them on its own, so nothing depends on someone remembering to clean up. An approved request carries on as a workspace, described in The Ads Insights service.

    Short-link click counts last three months. That is Cloudflare's own schedule for the store we keep them in, and we do not copy them anywhere else before they go.

    Analytics data is not attached to you, and cannot be deleted on request. Google Analytics and the Meta Pixel record page views, not identities. Nothing this site sends them carries your name, your email, or any account of yours, so there is no "your data" for us to look up and remove. The honest answer is that we could not comply with such a request even if we wanted to. What that data does instead is expire on the platform's own schedule: 14 months for Google Analytics, and Meta's default for the Pixel. You can stop the collection at any time, without asking us, with a tracker blocker. On ads.hecigo.com a hashed email address is part of what is reported when a workspace is created; that is set out under Measuring hecigo's own advertising, and stops on request.

    Who else sees it

    Only these, and nobody else:

    • THE NEXOVA runs the intake workflow that receives the form.
    • Lark hosts our mailboxes, so the enquiry email and our reply rest there, as do the emails Ads Insights sends about sign-up and access requests, and they carry the weekly report emails a customer turns on.
    • Telegram carries the notification that an enquiry arrived, to a private chat.
    • Google (analytics) and Meta (pixel) receive page-view data, not enquiries.
    • Meta, TikTok and Google also receive the measurement of hecigo's own advertising on ads.hecigo.com, set out under Measuring hecigo's own advertising.
    • Cloudflare serves and protects the site, keeps short-lived request logs, and holds the short-link click counts described above.

    We do not share enquiry contents with anyone else, and we do not publish client names or details without written permission. Netlify served this site until 30 August 2026 and was removed on 1 September 2026; it no longer receives anything.

    Your rights

    Article 4 of Law 91/2025 gives you a set of rights over your personal data. These are the ones that bite here, covering what we hold under your name or email address: your enquiry and everything we exchanged after it. Write to hi@hecigo.com and you can:

    • ask what we hold about you and how we are using it,
    • ask for a copy of it,
    • have anything wrong corrected,
    • have it deleted,
    • withdraw the consent you gave on the form, at any time, which stops any further use and leads to deletion unless a contract or the law requires us to keep it,
    • ask us to pause processing while a dispute about it is open,
    • object to a particular use,
    • complain to the competent authority, or take the matter to court, if you think we have handled your data wrongly.

    We act on these requests within 30 days and do not charge for them. You do not need to give a reason, and you do not need to have been a client.

    They do not extend to the analytics data or the short-link click counts described above, for the reason given there: neither is linked to an identity, so there is nothing to retrieve or erase. To stop that collection, use a tracker blocker or your browser's "do not track" setting, or opt out through Google's and Meta's own controls, none of which requires contacting us.

    International transfers

    Google, Meta, TikTok, Cloudflare, Lark, and Telegram process data on infrastructure outside Vietnam. The measurement of hecigo's own advertising on ads.hecigo.com reaches Meta, TikTok and Google this way. That includes the enquiry itself, because our mailboxes run on Lark and the arrival notification goes through Telegram. The intake workflow runs on a server operated for Vietnam and Singapore. Submitting the form means accepting that the data travels this way, for the purposes named above and no others.

    Children

    This site is aimed at businesses. We do not knowingly collect information from anyone under 16. If you believe we have, write to hi@hecigo.com and we will delete it.

    Changes

    If this policy changes materially we will update the date and the version code at the top, and keep a copy of the superseded wording so that a consent record from an earlier date can still be matched to the text that was live then. The current version is always at hecigo.com/privacy, and a Markdown copy is at hecigo.com/privacy.md.