Skip to content
Ads Audit
Legal

Privacy Policy

Last updated: 2026-09-05

1. Who we are

Ads Audit is operated by PPCWAY. PPCWAY is the data controller for the information described in this policy and is the company responsible for the Ads Audit service at ads-audit.app.

PPCWAY

NIP 6792791002 · Poland

[email protected] · +48 577 042 668

This policy describes how we handle information when you create an account, sign in, connect a Google Ads account, or otherwise use the Ads Audit application.

2. Information we collect

Account information. Name, email address, organization name, and a securely hashed password when you register directly (rather than through an invitation).

Authentication data. Session identifiers stored in an HTTP-only cookie, and, if you connect Google, an OAuth token issued by Google that Ads Audit uses to call the Google Ads API on your behalf. We do not receive or store your Google account password.

Google Ads data. After you authorize a connection, we read account structure, campaigns, ad groups, keywords, search terms, ads and assets, budgets, and conversion data through the Google Ads API. Google Ads exposes a single OAuth scope covering both read and write access — Ads Audit’s own code contains no function that creates, updates, deletes or otherwise modifies anything in your Google Ads account. Every request Ads Audit makes to the Google Ads API is a read request. Section 3 describes this in detail.

Usage and log data. Basic technical logs (timestamps, request outcomes, error information) needed to operate and secure the service. Log entries are structured to avoid storing tokens, passwords, or full page content.

3. Google user data — Google Ads API, scopes and Limited Use

Why Ads Audit needs access. Ads Audit is an audit tool for Google Ads accounts. It cannot evaluate an account it cannot read, so the only way it can produce a Health Score, findings and evidence is by reading the account’s own configuration and performance data from the Google Ads API. Access is used for that user-facing feature and for nothing else.

The scope we request. When you connect a Google Ads account, Ads Audit requests exactly three OAuth scopes: openid and email, which identify the Google account you connected with, and the Google Ads scope:

https://www.googleapis.com/auth/adwords

Google Ads publishes a single scope that covers both reading and writing, so there is no narrower read-only alternative to request. What we can state — and what you can hold us to — is that Ads Audit’s code contains no call that creates, updates or deletes anything in your account: every request it sends to the Google Ads API is a read query.

You authorize the access. The connection is only ever established by you, through Google’s own consent screen. Ads Audit never asks for your Google password, never accesses an account you have not connected, and cannot connect an account on your behalf.

What we read. Through the Google Ads API we read: the account’s identity and settings (name, customer ID, currency, time zone), campaigns and their budgets and settings, ad groups, keywords and negative keywords, search terms, ads and assets, Performance Max asset groups, conversion actions and performance metrics (impressions, clicks, cost, conversions and derived values) for the period being audited. We do not read Gmail, Drive, Contacts, Calendar or any other Google service — the scopes above do not grant access to them.

How we use it. Google user data is used solely to run the audits you request: the data is evaluated against the audit rules, turned into findings, evidence, a prioritized queue and a Health Score, and shown back to you and the members of your organization. We do not use Google user data for advertising, we do not use it to build profiles, we do not sell it, and we do not use it to train generalized artificial intelligence or machine learning models.

How we store it. The Google refresh token is encrypted (AES-256-GCM) before it is written to our database; access tokens are held only in a short-lived cache until they expire and are never written to the database. Neither is ever written to application logs. The Google Ads data we read is stored as per-audit snapshots in our database, isolated per organization at the database level, so that a past audit remains reproducible and comparable with later ones.

Who it is shared with. Google user data is visible to the members of your own organization in Ads Audit, and to the infrastructure providers that host the service on our behalf (see section 10). We do not transfer it to any other application, advertiser, data broker or third party, and we do not sell it. It is disclosed beyond that only if we are legally required to do so.

How to revoke access. You can disconnect a Google connection from within the application at any time. Disconnecting deletes the stored refresh token, clears the cached access token and asks Google to revoke the grant, after which Ads Audit can no longer call the Google Ads API for that connection. You can also revoke access yourself at any time from your Google Account’s security settings, at myaccount.google.com/permissions.

How to request deletion. Revoking access stops further reads but does not by itself erase the audit history already stored. To have the Google Ads data we hold for your account deleted, write to [email protected] and we will delete it, together with your account information if you ask us to.

Ads Audit’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use other information

Account and authentication data is used to operate login, sessions, and product communication such as verification, password-reset and team-invitation emails. We do not sell personal information.

5. Security

Data is isolated per organization at the database level. Sessions use HTTP-only, same-site cookies. Sensitive values (password hashes, OAuth tokens) are never written to application logs in plain form. Traffic to the application is served over HTTPS.

6. Data retention

We retain account information for as long as your account is active. Audit history and the Google Ads snapshots behind it are retained so you can compare results over time; you can request deletion at any point (see §9). Disconnecting a Google connection deletes the stored refresh token immediately.

7. Disconnecting Google

You can disconnect a Google Ads connection from within the application at any time. Once disconnected, Ads Audit stops making requests to the Google Ads API using that connection’s credentials. You can also revoke Ads Audit’s access directly from your Google Account’s security settings.

8. Cookies and sessions

Ads Audit uses a single essential, HTTP-only session cookie to keep you signed in. We do not use third-party advertising or tracking cookies on the application itself.

9. Your rights and contact

You can request access to, correction of, or deletion of your account information and of the Google Ads data we hold, at any time, by contacting us. Depending on your location, additional rights may apply under local data protection law.

Contact: [email protected] · +48 577 042 668

10. Third-party infrastructure

Ads Audit runs on infrastructure operated by third parties, including our hosting provider and, for transactional email (account verification, password reset, team invitations), an email delivery provider. These providers process data solely to deliver the service on our behalf and do not use it for their own purposes.

11. Changes to this policy

We may update this policy as the product changes. Material changes will be reflected by updating the “Last updated” date above.