TheWinningLoop
Back to app

Privacy Policy

TheWinningLoop is an advertising-research tool. It reads advertising that is already public on Meta's Ad Library and on public storefronts, and it has a single operator account rather than a user base. That shape is why this document is short: there is no sign-up, no audience profiling, and no personal information collected from visitors beyond what any web server records in its logs.

Last updated 17 September 2026

01Scope

This policy covers the TheWinningLoop application and its API — the software you are using right now. It does not cover Meta, Google, Shopify or any other third-party service, each of which has its own privacy policy and its own relationship with you.

Two different roles matter here, and they get different answers:

  • You, the operator. The person signing in. We hold almost nothing about you — see sections 04 and 05.
  • Advertisers. Businesses whose public advertising appears in the data set. The material we store about them is business information they published for the express purpose of being seen, and is described in section 03.

02The short version

  • No sign-up, no newsletter, no analytics or advertising trackers, no third-party pixels of our own.
  • One cookie, used only to keep you signed in. No consent banner is needed because nothing optional is set.
  • Ad data comes from Meta's public Ad Library; the content belongs to the advertisers, not to us.
  • No customer, order, payment or end-shopper data is collected, at any point, from anyone.

03What we store

Advertising data. For each ad captured from Meta's Ad Library we store the ad's public identifier and detail URL, the advertiser's page name and numeric page identifier, the ad copy and link-card text, the creative image or video URL, the landing page URL and domain, the date the ad started running, its status, and a count of how many other ads reuse the same creative. This is what the product does; without it there is no product.

Store research data. When you look up a store, we fetch that store's own public surfaces — its product listing, its theme name, the marketing pixels its pages load, and any contact address it publishes on its site — and store the result against the store's domain. The marketing pixels we record are named only (for example, meta or klaviyo); we never load them, and no tracking identifier belonging to anyone is captured.

Search trend data. Aggregate interest figures for a search term, as published by Google Trends. These are normalised, audience-level numbers and contain no individual.

Your search terms and saved boards. The keyword and country of each sweep you run, and the ads you save, so the interface can show you your own history and reuse cached results instead of re-fetching them.

Server logs. Like any web server, the host records request metadata including IP address, user agent, path and timestamp. This is standard operational and security logging, not analytics, and it is not used to build a profile of you.

04What we do not collect

There is no account registration, so we hold no name, no email address, and no phone number for you. We do not process payments, so we never see card or bank details. We do not store your password: the single operator credential lives in the server's environment configuration, and a sign-in attempt is compared against it in memory and then discarded. We run no analytics product, no session recording, no advertising network and no social plugin of our own.

We also do not collect consumer data from the stores we research — no shoppers, customers, orders or addresses. Where a store publishes a business contact address on its own website, that address may be recorded as part of the store profile; it is business contact information that the store chose to publish.

05Cookies and local storage

Exactly one cookie is set by this application:

  • thewinningloop_session — a signed, HttpOnly token that records that you are signed in and when the session expires. It is set with SameSite=Lax and is marked Secure over HTTPS. It contains a username and two timestamps; it is not a tracking identifier and is not shared with anyone. It lasts up to seven days or until you sign out.

Separately, your light/dark theme choice is saved in your browser's localStorage under the key thewinningloop-theme. That value never leaves your device and is not sent to the server.

Because the only cookie is strictly necessary for the service you asked for, there is no analytics or marketing cookie to consent to, and so no consent banner is shown.

06Third-party services

Operating TheWinningLoop necessarily involves other companies' services, and each receives only what the relevant feature needs:

  • Meta Platforms — the source of the advertising data, via the public Ad Library.
  • Google — Trends for the demand figures, and Google Fonts for the typefaces. Requesting a web font discloses your IP address to Google.
  • Shopify — when the product-import feature is used, the chosen product is written into your own store as a draft.
  • The hosting and database providers running this deployment, which store the data described in section 03 on our behalf.

We do not sell, rent, or trade any of this information, and we do not disclose it to anyone else except where the law compels us to — in which case we will disclose no more than we are required to.

07Why we use it

  • To provide the research features you are using — search, filtering, saving, exporting.
  • To keep you signed in between visits, and to keep unauthorised visitors out.
  • To keep the service running: debugging failures and detecting abuse.
  • To avoid repeating a fetch we have already done, which is what the cache and the sweep log are for.

We do not use any of it to train machine-learning models, to build advertising audiences, or for any purpose unrelated to running this tool.

08Legal bases (UK and EEA)

Where the UK GDPR or EU GDPR applies, we rely on legitimate interests for processing publicly available advertising and business information for market research, and on performance of a contract for the session cookie, which is necessary to provide the service you have requested. You may object to processing based on legitimate interests at any time using the contact details in section 12.

09How long we keep it

Ad and store research records are kept long term, because tracking whether an advertiser is scaling a creative only works if the history stays. Trend snapshots are kept per term and region. Sweep logs are kept so a later run does not refetch data we already have. Server logs are kept for a short operational window set by the host. Your session cookie expires automatically after seven days, or immediately when you sign out.

Because the research data is a historical record, it may remain in place even if an advertiser later deactivates an ad. It reflects what was publicly visible on a given date.

10Security

Credentials are compared server-side, the session cookie is signed and HttpOnly so page scripts cannot read it, and the entire application and its API sit behind that session check so an unauthenticated request never reaches the data. Traffic is served over HTTPS. No system is perfect; if you believe you have found a vulnerability, please report it using the contact details below rather than testing it against data that is not yours.

11Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, and to receive it in a portable form. Because we hold so little, most requests will resolve to "we do not hold personal data about you" — but ask, and we will confirm that in writing and explain what, if anything, does exist.

If you are an advertiser and want your public advertising removed from this data set, write to the address below with the ad library identifier or the landing domain. We will action verifiable requests. Note that removing a record here does not remove it from Meta's Ad Library, which is the original public source — that requires a request to Meta.

If you are in the UK or EEA and are unhappy with our response, you have the right to complain to your national data protection authority.

12Contact

Privacy questions, data requests and removal requests: support@thewinningloop.com. We aim to respond within 30 days.

13Children

This is a business research tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided information to us, contact us and we will delete it.

14Where your data is processed

This deployment is operated from, and its database hosted in, the region configured by the operator. The third-party services listed in section 06 may process data in other countries, including the United States. Where personal data is transferred out of the UK or EEA, we rely on the appropriate safeguards those providers put in place, such as the UK Addendum or the EU Standard Contractual Clauses.

15Changes to this policy

If this policy changes in a way that affects what we collect or why, the date at the top of this page will be updated and the change noted in the repository history. Continuing to use TheWinningLoop after a revision means you accept the revised policy. This document was last updated on 17 September 2026.

TheWinningLoop · support@thewinningloop.com·Privacy Policy·Terms & Conditions