Privacy Policy
Effective date: August 25, 2026
StormFunnel (“StormFunnel,” “we,” “us,” or “our”) is a service operated by exegov LLC, a Delaware limited liability company (“exegov”). StormFunnel monitors National Weather Service (NWS) alerts and creates geo-targeted Google Ads campaigns in our customers’ own Google Ads accounts. This Privacy Policy explains what information we collect, how we use and protect it, who we share it with, and the choices you have.
StormFunnel is a business-to-business service intended for use by companies and their authorized representatives in the United States. It is not directed at children, and we do not knowingly collect information from anyone under 18.
1. Information we collect
Account information
When you create an account we collect your name, email address, company name, and password credentials (stored only in hashed form) or sign-in identifiers provided by your authentication provider.
Google Ads data (via Google OAuth)
If you connect your Google Ads account, you grant StormFunnel access through Google OAuth. In connection with that grant we receive and store:
- OAuth tokens (access and refresh tokens) that allow StormFunnel to act on your Google Ads account with the permissions you approved. Refresh tokens are encrypted at rest.
- Account and campaign data accessed through the Google Ads API: your Google Ads customer ID, account settings relevant to campaign creation, and the campaigns, ad groups, ads, keywords, and budgets that StormFunnel creates or manages for you.
- Performance data for those campaigns (impressions, clicks, cost, conversions), used to show you reporting and spend tracking inside StormFunnel.
Our handling of all data received from Google APIs is further restricted by the Limited Use disclosure in Section 4.
Service-area and weather-alert data
We collect the service areas you configure (such as ZIP codes, radii, towns, or counties) and we process public severe-weather alert data published by the National Weather Service to match alerts to your service area. Weather alerts are public data and are not personal information; your service-area configuration is treated as your business data.
Billing information
Payments are processed by Stripe, Inc. Your card number and full payment details are collected directly by Stripe and never touch StormFunnel’s servers. We receive from Stripe only limited billing metadata such as subscription status, invoice history, the last four digits of your card, and card brand and expiration, so we can display billing information to you and operate your subscription.
Notification settings and your mobile number
We store the email addresses you choose to receive notifications at, which events each should receive, and — only if you switch text messages on — the mobile number you enter for that purpose, together with the date you agreed and the exact wording you agreed to. We keep that record so we can show, if a carrier ever asks, what you consented to and when.
We do not text the company phone number from your business profile. Your own number reaches our notification texts only by being entered in Settings → Notifications with the consent shown on that screen.
Separately, if a business using our missed-call rescue feature misses a call on its dedicated tracked number, we store the caller’s phone number, the time of the call, and the text conversation that follows — so we can send that caller one missed-call text back on the business’s behalf, show the business the exchange, and honor the caller’s opt-out. These numbers belong to the business’s callers, are used for nothing else, and are never added to any marketing list. A caller who replies STOP is recorded as opted out immediately and is never texted from that number again.
Usage and technical data
We collect usage analytics about how you interact with StormFunnel (pages viewed, features used, actions taken), device and browser information, IP address, and application logs and error reports. We use this to operate, secure, debug, and improve the service.
Separately, our public marketing pages carry an advertising pixel that sends your IP address and the page you viewed to Meta. It runs only on those public pages, never behind a log-in. Section 2 explains what it is for and how to opt out.
If you arrive by clicking one of our ads on Google or YouTube, the web address you land on carries a click identifier that Google added to it, and we store that identifier: in a cookie our own server sets on your browser, for up to 180 days, and — if you go on to create an account — on that account’s record, for as long as we keep the account. The same cookie holds the campaign tags an ad or email link carries (such as utm_source), and it is set on whichever page of ours the link sends you to. Section 2 explains what the identifier is for, and what you can and cannot switch off.
2. How we use your information
- To provide the service: monitoring weather alerts for your service area, creating and managing Google Ads campaigns you have configured, enforcing your budget guardrails, and showing you campaign and spend reporting.
- To send you service emails, such as storm-alert notifications, campaign approval requests, campaign status updates, spend notifications, and billing and account messages.
- To generate campaign and budget recommendations, including AI-assisted recommendations (see Section 6 regarding our subprocessor Anthropic).
- If you are on the Autopilot plan and you switch on automatic improvement, to apply those recommendations to your own campaign settings without asking you to approve each change — limited to keywords and negative keywords, and taking effect on your next campaign. Your bid, budget, and campaign length are never changed this way, and a campaign that is already running is never modified. The switch is off unless you turn it on, every change is recorded in your account, and you can edit any of it back.
- To process payments and manage subscriptions through Stripe.
- To secure the service, prevent abuse, debug problems, and improve features.
- To comply with legal obligations.
We never use your StormFunnel account data — your campaigns, your budgets, your service areas, or anything you do inside the app — for advertising, and we do not sell it to anyone.
Advertising cookies, and the ad clicks we record
Our public marketing pages — the StormFunnel home page and the Storm Replay page — use the Meta pixel, a cookie and similar storage technology provided by Meta Platforms, Inc. It tells us how many people who clicked one of our ads actually reached the page and what they did there, and it lets Meta show StormFunnel ads to people who have visited us. This is cross-context behavioral advertising: Meta receives your IP address and the page you viewed, and may combine that with information it already holds about you.
The pixel does not run anywhere behind a log-in. If you create an account after arriving from one of our ads, our server tells Meta that a signup happened, using the same information the pixel already collects — your IP address, your browser and Meta’s own cookie identifiers — together with a reference number for the account just created, so that the same signup cannot be counted twice. Nothing else: never your name, your email or your company. What happens inside your account — your campaigns, your budgets, your spend — is never sent to Meta.
The same is true of Google. When you click one of our ads on Google or YouTube, Google adds a click identifier to the web address you land on, and our own server records it. This part is not a third-party script and it is not limited to our marketing pages: it happens on whichever page of ours the ad points at, including pages behind the log-in, and the identifier is kept in a cookie for up to 180 days as Section 1 describes. Our server sends Google Ads two messages after that, and only these two. The first goes when you open our sign-up page: the click identifier, the time, and a short code worked out from that same identifier so one advert click cannot be counted twice — no account exists at that moment and none is named. If you then create an account, our server tells Google Ads that that click became a signup, sending the click identifier, the time, and a reference number for the account just created so that the same signup cannot be counted twice. Neither message carries anything else: never your name, your email or your company, and never anything from inside your account. If you did not arrive from a Google ad, there is no identifier and nothing is sent.
What that one does and does not switch off. Turning off ad personalisation at My Ad Center changes the ads Google shows you, and we recommend it if that is what you want — but it does not stop the message described above, and neither does blocking third-party advertising cookies: the identifier arrives inside the web address you clicked, and both the cookie and the message are our own. What does stop it is opening our site from an address that carries no click identifier, or clearing your cookies for stormfunnel.com before you create an account. We keep no other way of connecting a signup to an ad click, so there is nothing else for us to switch off on your behalf.
How to opt out of the advertising cookies. You can turn off ad personalisation in your Meta ad preferences, opt out of interest-based advertising across participating companies at optout.aboutads.info, or block advertising cookies in your browser settings. Blocking them does not affect your use of StormFunnel. These three reach the advertising cookies; the Google click identifier is covered by the paragraph above it, which says what they do not reach.
We receive no money for any of this. Some state privacy laws nonetheless define a “sale” of personal information broadly enough to cover an advertising cookie like this one, so rather than rely on the label we have described exactly what happens and given you the way out above.
3. Legal bases and marketing
We process your information to perform our contract with you, to pursue the legitimate interests described above, with your consent where required, and to meet legal obligations. We may send you product news about StormFunnel itself; you can opt out of non-essential emails at any time using the unsubscribe link, and service-critical notifications (such as spend alerts you configured) can be managed in your notification settings.
4. Google API Services — Limited Use disclosure
StormFunnel’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We only use data received from Google APIs to provide and improve the user-facing features of StormFunnel that you see and interact with: creating and managing the Google Ads campaigns you configure, and showing you reporting, spend tracking, and recommendations for your own account.
- We do not use data received from Google APIs to serve advertisements, including retargeting, personalized, or interest-based advertising. (StormFunnel creates campaigns in your own Google Ads account at your direction; it does not use your Google data to target ads at you or anyone else.)
- We do not sell data received from Google APIs.
- We do not transfer data received from Google APIs to third parties except as necessary to provide or improve user-facing features (via the subprocessors listed in Section 6, acting on our instructions), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not allow humans to read data received from Google APIs, except (a) with your explicit consent, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
- We do not use data received from Google APIs to develop, improve, or train generalized artificial-intelligence or machine-learning models.
5. Storage, security, and encryption
- Data is stored with our hosting and database providers (Vercel and Neon) in the United States, encrypted in transit (TLS) and at rest.
- Google OAuth refresh tokens are additionally encrypted at rest at the application level before storage; decryption keys are managed separately from the database.
- Passwords, where used, are stored only as salted hashes.
- Access to production systems is restricted to authorized personnel on a need-to-know basis and is logged.
No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your information with industry-standard measures.
6. Sharing and subprocessors
We do not rent your personal information, and nothing in your StormFunnel account is ever sold. We share data with service providers (subprocessors) that help us operate StormFunnel, under contracts that restrict their use of it to providing services to us — with two exceptions, noted in the list below and described in Section 2: the advertising measurement we do with Meta and with Google, which each of them also uses for its own purposes:
- Vercel — application hosting, content delivery, and website analytics (page views and the site that referred you). This analytics does not use cookies, does not follow you across other websites, and does not build an advertising profile.
- Meta Platforms — advertising measurement on our public marketing pages only, through the Meta pixel described in Section 2. Meta uses this data for its own advertising purposes as well as ours, which is why it is one of the two entries on this list not acting solely on our instructions. Opt-out links are in Section 2.
- Google— advertising measurement for our own marketing, as described in Section 2: if you reached us by clicking one of our ads, we tell Google Ads that the click became a signup. Google uses this for its own advertising purposes as well as ours, which makes it the second entry here not acting solely on our instructions. (Google also hosts the ad campaigns you configure in your own account — that is a different relationship, covered in Section 4.)
- Neon — managed Postgres database hosting.
- Stripe — payment processing and subscription billing.
- Resend — transactional email delivery (alerts, approvals, notifications).
- Twilio — text message (SMS) delivery, and only for accounts that have switched text messages on.
- Anthropic— AI-assisted campaign and budget recommendations. Data sent to Anthropic through its commercial API is used only to generate the recommendations displayed to you; under Anthropic’s commercial terms it is not used to train Anthropic’s models and is retained only transiently to process the request and guard against abuse.
We do not sell, rent, or share mobile numbers or text-message opt-in data with anyone for marketing purposes. A number you give us for text messages is used to send you the notifications you asked for and for nothing else. It is passed only to the messaging provider named above, acting on our instructions to deliver those messages, and it is not shared with any affiliate or third party for their own marketing.
We may also disclose information if required by law or legal process, to protect the rights, safety, or property of StormFunnel or others, or in connection with a merger, acquisition, or sale of assets (in which case this policy will continue to apply and we will notify you of any change of controller).
7. Data retention and deletion
- Account and configuration data is retained while your account is active and deleted or anonymized within 30 days after account deletion, except where longer retention is required by law (for example, billing records retained for tax purposes).
- Google OAuth tokens are deleted promptly when you disconnect your Google Ads account, when you delete your StormFunnel account, or when Google notifies us of revocation.
- Campaign and performance data imported from the Google Ads API is retained while your Google Ads connection is active and deleted within 30 days after disconnection or account deletion.
- The cookie described in Section 1 — campaign tags and, if you arrived from a Google ad, the click identifier — expires 180 days after it is set, and you can clear it from your browser at any time. If you create an account, the same values are copied onto the account record and are then covered by the first bullet above.
- Application logs and error reports are retained for up to 90 days.
You can request deletion of your account and associated data at any time by contacting us (Section 12) or using in-app account deletion where available.
8. Revoking StormFunnel’s access to Google
This section applies when you connected your own Google Ads account. If we run your campaigns in an account we manage for you, read If we manage your Google Ads account at the end of this section instead.
You can revoke StormFunnel’s access to your Google Ads account at any time:
- In StormFunnel: use the “Disconnect Google Ads” option in your account settings. This deletes our stored tokens for your account.
- In Google: visit your Google Account security settings at myaccount.google.com/permissions and remove StormFunnel’s access.
After revocation StormFunnel can no longer create or manage campaigns in your Google Ads account. Campaigns that already exist in your Google Ads account are yours and remain under your control there.
If we manage your Google Ads account
The steps above do not apply to you. There is no Google Ads access grant of your own to revoke: the account is under our Google Ads manager account, and we access it with our own credentials rather than with permission you granted.
If you sign in to StormFunnel with Google, that sign-in permission is a separate thing, and removing it does not affect your ads.
To stop us managing your campaigns, tell us. We will pause everything that is running, and you can ask us either to transfer the account into your own Google login with its history intact, or to close it. Any unspent advertising balance is refundable.
9. Your rights
Depending on where you live, you may have the right to access, correct, download, restrict, or delete your personal information, and to object to certain processing. To exercise any of these rights, contact us at the address in Section 12. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
10. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended (CCPA/CPRA) gives you specific rights:
- Right to know — request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom it is shared.
- Right to delete — request deletion of your personal information, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell personal information. We do share information for cross-context behavioral advertising, but only through the advertising pixel on our public marketing pages, and never any part of your StormFunnel account. Section 2 has the opt-out links, and you can also email us at the address in Section 12 and we will honor the request.
- Non-discrimination — we will not treat you differently for exercising these rights.
Categories of personal information we collect are described in Section 1 and map to the CCPA categories of identifiers, commercial information, internet activity, and professional information. We retain each category as described in Section 7. To exercise your California rights, email us at the address in Section 12; you may use an authorized agent as permitted by law.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes we will notify you by email or by a prominent notice in the app before the changes take effect, and we will update the effective date above. Your continued use of StormFunnel after the effective date constitutes acceptance of the updated policy.
12. Contact
Questions, requests, or complaints about privacy can be sent to: support@stormfunnel.com
Postal address:
exegov LLC
c/o Legalinc Corporate Services Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States