Rights Advocates Ad Manager

Privacy Policy

Effective 11 September 2026

This policy explains how Rights Advocates Ad Manager ("the application") handles data, including data obtained through Google APIs. The application is internal software operated by Rights Advocates. It is not offered to the public, not sold, and not licensed to third parties.

1. Who this covers

The application is used only by authorised staff of Rights Advocates. There are no public accounts and no sign-up. It acts only on Google Ads accounts that our own team has explicitly authorised it to access.

2. What we access from Google

When a member of our team authorises the application, it is granted the https://www.googleapis.com/auth/adwords scope. That allows it to read and manage the Google Ads accounts that person can already reach. Specifically, the application accesses:

DataWhy it is accessed
The list of Google Ads accounts the authorising user can reach, with their account names and manager relationships So the operator can choose which account a campaign is created in
Campaigns, ad groups, ads, budgets, targeting criteria and conversion actions in those accounts To create new campaigns, and to read back what was created so the operator can verify it
Video assets uploaded through the Google Ads API To attach our own video creative to the ads we build
An OAuth refresh token for the authorising Google account So the application can act on those accounts without a person re-authorising each time

The application does not request access to Gmail, Drive, Contacts, Calendar, or any other Google service. It does not read the personal profile data of anyone other than the team member who authorises it, and it does not access data belonging to people who see our ads.

3. What we store, and where

We do not store the Google account password of any user; authentication is handled entirely by Google's OAuth flow.

4. What we do not do

Limited Use. The application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. How long we keep it

The refresh token is kept for as long as the application is in use by our team, and is revoked immediately when a team member leaves or when access is no longer required. Operational records are kept while the related campaigns are active and are removed when they are no longer needed for reporting or audit.

6. Revoking access and deleting data

Any authorising user can revoke the application's access at any time from Google Account permissions. Revoking access immediately invalidates the stored refresh token.

To have stored data deleted, write to privacy@rightsadvocates.com. We will delete the data we hold and confirm once it is done.

7. Security

All traffic to the application is served over HTTPS. Credentials are held outside the web root and are not included in any deployment package. Access to the application requires an account on our internal system, and access to the underlying server is restricted to key-based authentication.

8. Changes

If this policy changes, the effective date above will be updated. Material changes affecting how Google user data is handled will be reflected here before they take effect.

9. Contact

Rights Advocates — privacy@rightsadvocates.com