Privacy Policy
AdsLedger is a read-only Google Ads reporting workspace operated for internal advertising reporting. This policy explains what information AdsLedger processes when a user connects Google Ads through OAuth.
Information we collect
When an authorized user connects Google Ads, AdsLedger may process:
- Google Ads customer account identifiers, names, status, currency, and timezone metadata.
- Campaign reporting metrics such as impressions, clicks, cost, conversions, campaign status, and channel type.
- Monthly spend and performance metrics.
- Creative asset reporting data, including asset names, asset IDs, image preview URLs, text assets, performance labels, and related metrics.
- OAuth tokens required to refresh read-only reporting data.
How we use information
We use Google Ads data only to display reporting dashboards, compare customer accounts, review campaign performance, inspect creative assets, and refresh reporting rows requested by authorized users.
What AdsLedger does not do
- AdsLedger does not create, edit, pause, remove, or otherwise modify Google Ads campaigns, ads, bids, budgets, billing settings, or account settings.
- AdsLedger does not sell Google user data.
- AdsLedger does not use Google user data for targeted advertising, personalized advertising, retargeted advertising, interest-based advertising, profiling, data broker services, credit-worthiness decisions, lending, or unrelated analytics.
Sharing and storage
Google Ads reporting data is available only to authorized internal users of AdsLedger. OAuth refresh tokens are stored encrypted. We do not share Google Ads data with third parties except service providers needed to operate the application infrastructure. We do not transfer or disclose Google Ads data to third parties for targeted advertising, user advertising, personalized advertising, retargeted advertising, interest-based advertising, sale to data brokers, information resellers, credit-worthiness decisions, lending, or any purpose unrelated to operating and improving AdsLedger's user-facing reporting features.
Data protection and security
AdsLedger uses administrative, technical, and application-level controls to protect Google Ads user data:
- AdsLedger is served over HTTPS/TLS so Google OAuth authorization, application sessions, and dashboard traffic are encrypted in transit.
- OAuth refresh tokens are encrypted at rest using the application encryption key before being stored in the production database.
- Dashboard access requires authenticated user sessions, and Google Ads connectors are protected with role-based access checks so buyers can access only their own connectors while admins can manage approved internal accounts.
- OAuth state validation, CSRF protections, secure session cookies, and same-site cookie settings are used to reduce unauthorized request and session risks.
- Sync errors and logs are redacted before storage so OAuth tokens, access tokens, client secrets, and similar credentials are not written into application logs.
- Production database access, application secrets, OAuth client credentials, and server access are restricted to authorized operators who need them to run and maintain the service.
Data retention and deletion
Reporting data is retained for as long as the connector remains active. We retain Google Ads reporting data only while the connector remains active and the data is needed for reporting. Admins can delete Google Ads connectors. Deleting a connector removes the encrypted OAuth grant and cascades deletion of related loaded Google Ads account, campaign, monthly, billing, creative asset, sync request, and sync log rows. After a verified deletion request, active connector data is deleted within 30 days unless a longer period is required for legal, security, or abuse-prevention reasons. Limited backup copies and security logs may be retained for up to 90 days before rotation, and are not used for reporting after the deletion request is completed.
User rights and choices
Access, correction, export, and deletion requests for Google Ads connector data may be sent to google-ads-api@adsledger.pro. Authorized users can also remove a connector in AdsLedger to revoke the stored OAuth grant and trigger deletion of related reporting rows.
AI/ML model training
AdsLedger does not use Google Ads data to train, improve, or fine-tune generalized AI/ML models.
Google API Services User Data Policy
AdsLedger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Policy changes
We will notify users of material changes to this policy by updating the effective date above. If AdsLedger changes how it accesses, uses, stores, shares, retains, or deletes Google user data, we will update the effective date of this policy and notify affected users through the application or by email when appropriate.
Contact
For privacy or OAuth questions, contact google-ads-api@adsledger.pro.