Privacy Policy

Last updated: July 22, 2026

1. Introduction

OneAds Inc. ("OneAds," "we," "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our advertising analytics platform.

1a. Google Ads Data — Limited Use Disclosure

OneAds' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect a Google Ads manager account (MCC), we read the list of ad accounts you grant access to, and for each of them: campaigns, ad groups, keywords, search terms — the queries people typed that matched your ads, daily performance metrics (including a breakdown by device), and Google’s own optimisation recommendations. We store an encrypted refresh token (AES-256-GCM at rest) so we can keep that data fresh while your account is linked. We do not sell, transfer, or use this data for advertising or any purpose unrelated to providing the OneAds product. Mutations (campaign pause, budget update, bid update) only ever execute after an explicit click in the OneAds UI; OneAds does not autonomously edit your Google Ads account.

You can disconnect a Google Ads link at any time from/dashboard/integrations/google-ads. Disconnecting destroys the stored token, asks Google to revoke the authorisation itself, and stops all further syncing. The data already collected is kept by default so that reconnecting the same account does not cost you your history — the same dialog offers a tick-box to delete it instead, and tells you how many rows that is before you confirm. For full data deletion, email [email protected] and we will purge campaign / metrics data and the encrypted refresh token within 30 days.

2. Information We Collect

2.1 Information You Provide

  • Account registration: Name, email address, password
  • Workspace information: Workspace and client names you create, and the email addresses of team members you invite
  • Connection authorization: The credential you grant when linking an advertising or affiliate account, stored encrypted

We do not collect government-issued identity documents, dates of birth, bank account details, or payment card numbers. We do not perform identity verification.

2.2 Data Read From Your Connected Accounts

  • Advertising platforms: Account, campaign, ad group and keyword records; daily spend, impressions, clicks and conversions; change history and platform recommendations
  • Affiliate networks: Programs, conversion events, commission amounts, currency and approval status, and the tracking identifiers attached to them

This is business performance data about your campaigns. We do not receive the personal data of the individuals who clicked your ads or converted; where a network returns an opaque tracking identifier, we use it only to match a conversion back to the campaign that produced it.

2.3 Information Collected Automatically

  • Device data: IP address, browser type, operating system
  • Usage data: Pages visited, features used, timestamps
  • Security data: Login attempts, passkey usage, session information

3. How We Use Your Information

  • Read, store and normalize data from the accounts you connect
  • Join advertising spend to affiliate commission and compute return on investment
  • Keep that data current on a synchronization schedule while your account is linked
  • Authenticate you and enforce workspace roles and permissions
  • Detect, prevent, and investigate fraud and unauthorized access
  • Communicate service updates, security alerts, and account notifications
  • Improve our platform, features, and user experience
  • Comply with legal obligations and respond to lawful requests

We never use it for anything else. Specifically, and in the words the Google API Services User Data Policy uses, we do not: serve or target advertising with it; sell or transfer it to data brokers, information resellers, or any other party for those purposes; use it to determine creditworthiness or for lending decisions; or use it to develop, train, or improve generalised artificial-intelligence or machine-learning models. Human beings do not read it either, except where you ask us to for support, where it is needed to investigate abuse or a security incident, or where the law requires it.

4. Data Sharing

We share your information only with:

4.1 Service Providers

Infrastructure providers that host the Service and its database, and providers that deliver our transactional email. They process data only on our instructions and only as needed to run the Service. A current list is available on request from [email protected].

4.2 Platforms You Connect

We exchange data with the advertising platforms and affiliate networks you authorize, for the purpose of reading your data from them. Those platforms handle your data under their own privacy policies.

4.3 Legal Requirements

We may disclose your information when required by law, including responding to subpoenas, court orders, or lawful regulatory requests.

4.4 No Sale of Data

We do not sell, rent, or trade your personal information or your campaign data to third parties, for marketing or for any other purpose.

5. Data Security

  • Encryption: TLS 1.2+ in transit, database-level encryption at rest
  • Connected credentials: Platform tokens encrypted with AES-256-GCM at rest and never exposed to the browser
  • Authentication: Passkey/WebAuthn support, session management via Better Auth
  • Password storage: Scrypt hashing (not reversible)
  • Tenant isolation: Every record is scoped to a workspace, enforced at the data-access layer
  • Access control: Role-based access within a workspace
  • Audit logging: Append-only audit trail of account and administrative actions
  • Security headers: CSP, HSTS, X-Frame-Options, CSRF protection

6. Data Retention

We retain your data according to the following schedule:

Data TypeRetention
Connected-platform credentialsUntil you disconnect, then deleted
Campaign, search-term, spend and commission dataKept while your account is active, including across a disconnect unless you ask for it to be deleted at that point; purged within 30 days of a deletion request
Activity / audit logs180 days
Session data90 days
Account data (after closure)Deleted within 30 days of request, otherwise 12 months, then anonymized

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data and of the campaign data synchronized from your connected accounts
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain processing of your data

To exercise these rights, contact [email protected].

8. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Session cookies expire when you close your browser or after inactivity.

9. Children's Privacy

Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately.

10. International Transfers

Your data is processed and stored on servers located in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your jurisdiction.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.

12. Contact Us

For privacy-related inquiries:
Email: [email protected]
Address: OneAds Inc., San Francisco, CA