Privacy policy
Last updated 6 October 2026. This policy covers Tony at meettony.app, run by Hundred Club Digital, a registered business name of 0-100 Group Pty Ltd (ABN 54 661 098 540). We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and, for people in the UK and EU, the UK GDPR and EU GDPR.
What we collect
- What you type in: first name, email, business name, and if you give them, mobile number and website.
- Your audit answers: how your ads are set up and run, your spend band and business type.
- If you give them, your last 30 days of ad numbers (spend, impressions, clicks, results, revenue, margin, frequency).
- If you give us your website address, what our scanner finds on that public page: tracking code, platform, speed and similar.
- Your country (from your connection) to show prices in your currency, and your timezone so your weekly email arrives on Monday morning your time.
- How you found us: the ad or link you clicked, including campaign tags and Meta's click identifier.
- If you subscribe: your subscription status. Card details go straight to Stripe and never touch our servers.
- What you tick off in your dashboard, and the weekly numbers you enter.
- If you connect your Meta ad account: a read-only access token; the names, on/off status, budgets and bid settings of your campaigns, ad sets and ads; their performance (spend, impressions, link clicks, purchases or leads, purchase value, frequency, video views); whether each ad is an image, video, carousel, collection, catalogue or flexible ad, and a link to Meta’s small preview picture of it (shown to you, never downloaded or stored by us); Meta's review feedback on rejected ads; and the ad account's status and spending limit. We use this only to run your audit, daily check, hourly alerts and weekly review, and we keep daily check results and alerts for 30 days.
- If you turn on phone notifications: the address your browser gives us for sending them (it doesn’t identify you or your phone number) and the device type, for example “iPhone”. Deleted when you turn notifications off or remove the device in Settings. We can’t create, change or pause ads, and we don’t read audiences, download your images or videos, or anyone’s personal data. The token is stored encrypted and deleted when you disconnect.
- If you use Ask: your questions and the answers, kept for 90 days so you can scroll back, and deleted sooner if you press “Start again”. If you send a support request: what you write, and our replies.
- If you use the setup guide: which steps you’ve ticked, and what the live check found on your Meta account (business portfolio, payment method on file shown as Meta displays it, for example “Visa *4242”, Page, Instagram account name, pixel ID and which pixel events arrived in the last 7 days, with counts only).
- If you connect a Shopify store: a read-only access token, stored encrypted; from your orders only the date, totals, tax, currency, whether it was a test or cancelled, the products and quantities, and the source of the visit that led to it; and your products’ “cost per item”. We use these for the store comparison and the daily profit tracker, with the costs you enter (fees, shipping, fixed costs). We never read or store customer names, emails or addresses. Daily profit figures are kept for the last 30 days. All of it, including the costs you entered, is deleted when you disconnect or uninstall the app.
- If you’re on a paid plan: your website’s address, and the results of checking it about once an hour (whether it loaded, how long it took, whether the cart page and Meta pixel were there). Checks are kept for 14 days and website alerts for 90.
- If you use our free tools: the Landing Page X-ray reads the public web page you enter, once, and keeps nothing. Ad Score sends the ad text you paste to Anthropic to score it; we don’t keep the text or tie it to you. Both note your IP address briefly to stop overuse.
- If you use the content planner: the details you type in and the plans written for you, kept for 12 months.
- If you watch competitor websites: the addresses you add, and what their public pages showed (product names, prices, stock and home page wording). We only read public pages, about once a day, and skip anything a site asks automated tools not to read. Changes are kept for 90 days.
- If you’re on the Agency plan: your agency name, contact line, colour and logo, and each client report you make (a snapshot of that account’s numbers). Anyone with a report link can open it until it expires after 90 days or you delete it.
- If you share your referral link: who signed up from it, and the credit applied to your Stripe account when they pay.
Why we collect it
- To score your audit, show and email you your results, and run your account if you subscribe (lawful basis: performing our contract with you).
- To send your Monday check-in email if you subscribe, and to work out your weekly results from the numbers you enter. You can stop it by cancelling.
- To send you the rest of your report over the following week, only if you ticked the box (lawful basis: consent). Every email has an unsubscribe link.
- To measure which of our ads work (lawful basis: legitimate interests). We share a scrambled (hashed) version of your email and phone with Meta when you complete the audit or start a subscription, so Meta can tell us which ads led to it. Meta's pixel also sets cookies for this. You can opt out of ad personalisation in your Meta ad preferences.
- If your audit suggests our agency could help, we may contact you about it. Tell us not to and we won't.
- To show businesses how they compare (lawful basis: legitimate interests). Your last 7 days’ totals (cost per result, return on ad spend, click-through and cost per 1,000 views) are pooled with other accounts of the same business type. Only the pooled figures are shown, never for a group of fewer than 5 accounts, and never with your name or ad account. You can leave the comparison in Settings.
We do not sell, rent or trade your information.
Who else handles it
Cloudflare (hosting and database), Stripe (payments), Resend (email delivery), Anthropic (writes ad scripts from the details you type into the script writer, writes content plans from the details you type in, scores ads pasted into Ad Score, and answers your questions in Ask, using your first name, business name and type, country, audit score and a summary of your latest daily check, alerts and setup check; it doesn’t use it to train its models), Shopify (if you connect a store), Meta (ad measurement) and Microsoft (our email). They process data on our behalf and may store it outside Australia, including in the United States.
Deleting your Meta data
Disconnect any time from your dashboard, or remove “TONY” in your Facebook settings under Apps and websites. Either way we delete the access token and stop pulling numbers. To have your whole account deleted, see our data deletion page.
How long we keep it
Audit results and contact details for people who don't subscribe are deleted after 24 months. Subscriber records are kept for seven years after you leave, to meet Australian tax and record-keeping obligations.
Your rights
You can ask what we hold about you, correct it, get a copy, object to how we use it, or have it deleted. Email grow@hundredclubdigital.com and we will respond within 30 days.
Complaints
Contact us first. If we can't resolve it, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au), or in the UK the ICO (ico.org.uk), or your local EU data protection authority.
Changes
If this policy changes we will update the date at the top of this page.