Privacy Policy
Last updated: July 22, 2026
1. Introduction
OneAds Inc. ("OneAds," "we," "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our advertising analytics platform.
1a. Google Ads Data — Limited Use Disclosure
OneAds' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google Ads manager account (MCC), we read the list of ad accounts you grant access to, and for each of them: campaigns, ad groups, keywords, search terms — the queries people typed that matched your ads, daily performance metrics (including a breakdown by device), and Google’s own optimisation recommendations. We store an encrypted refresh token (AES-256-GCM at rest) so we can keep that data fresh while your account is linked. We do not sell, transfer, or use this data for advertising or any purpose unrelated to providing the OneAds product. Mutations (campaign pause, budget update, bid update) only ever execute after an explicit click in the OneAds UI; OneAds does not autonomously edit your Google Ads account.
You can disconnect a Google Ads link at any time from/dashboard/integrations/google-ads. Disconnecting destroys the stored token, asks Google to revoke the authorisation itself, and stops all further syncing. The data already collected is kept by default so that reconnecting the same account does not cost you your history — the same dialog offers a tick-box to delete it instead, and tells you how many rows that is before you confirm. For full data deletion, email [email protected] and we will purge campaign / metrics data and the encrypted refresh token within 30 days.
2. Information We Collect
2.1 Information You Provide
- Account registration: Name, email address, password
- Workspace information: Workspace and client names you create, and the email addresses of team members you invite
- Connection authorization: The credential you grant when linking an advertising or affiliate account, stored encrypted
We do not collect government-issued identity documents, dates of birth, bank account details, or payment card numbers. We do not perform identity verification.
2.2 Data Read From Your Connected Accounts
- Advertising platforms: Account, campaign, ad group and keyword records; daily spend, impressions, clicks and conversions; change history and platform recommendations
- Affiliate networks: Programs, conversion events, commission amounts, currency and approval status, and the tracking identifiers attached to them
This is business performance data about your campaigns. We do not receive the personal data of the individuals who clicked your ads or converted; where a network returns an opaque tracking identifier, we use it only to match a conversion back to the campaign that produced it.
2.3 Information Collected Automatically
- Device data: IP address, browser type, operating system
- Usage data: Pages visited, features used, timestamps
- Security data: Login attempts, passkey usage, session information
3. How We Use Your Information
- Read, store and normalize data from the accounts you connect
- Join advertising spend to affiliate commission and compute return on investment
- Keep that data current on a synchronization schedule while your account is linked
- Authenticate you and enforce workspace roles and permissions
- Detect, prevent, and investigate fraud and unauthorized access
- Communicate service updates, security alerts, and account notifications
- Improve our platform, features, and user experience
- Comply with legal obligations and respond to lawful requests
We never use it for anything else. Specifically, and in the words the Google API Services User Data Policy uses, we do not: serve or target advertising with it; sell or transfer it to data brokers, information resellers, or any other party for those purposes; use it to determine creditworthiness or for lending decisions; or use it to develop, train, or improve generalised artificial-intelligence or machine-learning models. Human beings do not read it either, except where you ask us to for support, where it is needed to investigate abuse or a security incident, or where the law requires it.
4. Data Sharing
We share your information only with:
4.1 Service Providers
Infrastructure providers that host the Service and its database, and providers that deliver our transactional email. They process data only on our instructions and only as needed to run the Service. A current list is available on request from [email protected].
4.2 Platforms You Connect
We exchange data with the advertising platforms and affiliate networks you authorize, for the purpose of reading your data from them. Those platforms handle your data under their own privacy policies.
4.3 Legal Requirements
We may disclose your information when required by law, including responding to subpoenas, court orders, or lawful regulatory requests.
4.4 No Sale of Data
We do not sell, rent, or trade your personal information or your campaign data to third parties, for marketing or for any other purpose.
5. Data Security
- Encryption: TLS 1.2+ in transit, database-level encryption at rest
- Connected credentials: Platform tokens encrypted with AES-256-GCM at rest and never exposed to the browser
- Authentication: Passkey/WebAuthn support, session management via Better Auth
- Password storage: Scrypt hashing (not reversible)
- Tenant isolation: Every record is scoped to a workspace, enforced at the data-access layer
- Access control: Role-based access within a workspace
- Audit logging: Append-only audit trail of account and administrative actions
- Security headers: CSP, HSTS, X-Frame-Options, CSRF protection
6. Data Retention
We retain your data according to the following schedule:
| Data Type | Retention |
|---|---|
| Connected-platform credentials | Until you disconnect, then deleted |
| Campaign, search-term, spend and commission data | Kept while your account is active, including across a disconnect unless you ask for it to be deleted at that point; purged within 30 days of a deletion request |
| Activity / audit logs | 180 days |
| Session data | 90 days |
| Account data (after closure) | Deleted within 30 days of request, otherwise 12 months, then anonymized |
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data and of the campaign data synchronized from your connected accounts
- Portability: Request your data in a machine-readable format
- Objection: Object to certain processing of your data
To exercise these rights, contact [email protected].
8. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Session cookies expire when you close your browser or after inactivity.
9. Children's Privacy
Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately.
10. International Transfers
Your data is processed and stored on servers located in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your jurisdiction.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
12. Contact Us
For privacy-related inquiries:
Email: [email protected]
Address: OneAds Inc., San Francisco, CA