Privacy Policy
Effective 11 September 2026
This policy explains how Rights Advocates Ad Manager ("the application") handles data, including data obtained through Google APIs. The application is internal software operated by Rights Advocates. It is not offered to the public, not sold, and not licensed to third parties.
1. Who this covers
The application is used only by authorised staff of Rights Advocates. There are no public accounts and no sign-up. It acts only on Google Ads accounts that our own team has explicitly authorised it to access.
2. What we access from Google
When a member of our team authorises the application, it is granted the
https://www.googleapis.com/auth/adwords scope. That allows it to read and manage
the Google Ads accounts that person can already reach. Specifically, the application accesses:
| Data | Why it is accessed |
|---|---|
| The list of Google Ads accounts the authorising user can reach, with their account names and manager relationships | So the operator can choose which account a campaign is created in |
| Campaigns, ad groups, ads, budgets, targeting criteria and conversion actions in those accounts | To create new campaigns, and to read back what was created so the operator can verify it |
| Video assets uploaded through the Google Ads API | To attach our own video creative to the ads we build |
| An OAuth refresh token for the authorising Google account | So the application can act on those accounts without a person re-authorising each time |
The application does not request access to Gmail, Drive, Contacts, Calendar, or any other Google service. It does not read the personal profile data of anyone other than the team member who authorises it, and it does not access data belonging to people who see our ads.
3. What we store, and where
- The OAuth refresh token and client credentials. Stored on our own server, outside any web-accessible directory, readable only by the application's system account.
- Operational records. Account identifiers, campaign names and identifiers, and references to video assets we created. These exist so a launch can be repeated or audited and so the same creative is not uploaded twice.
We do not store the Google account password of any user; authentication is handled entirely by Google's OAuth flow.
4. What we do not do
- We do not sell data obtained through Google APIs, and we never have.
- We do not transfer it to third parties, other than as strictly necessary to provide and maintain the application, to comply with applicable law, or as part of a merger or acquisition.
- We do not use it for advertising, including retargeting, personalised advertising, or interest-based advertising.
- We do not allow humans to read the data, except where we have the user's explicit consent for specific messages, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised for internal operations.
5. How long we keep it
The refresh token is kept for as long as the application is in use by our team, and is revoked immediately when a team member leaves or when access is no longer required. Operational records are kept while the related campaigns are active and are removed when they are no longer needed for reporting or audit.
6. Revoking access and deleting data
Any authorising user can revoke the application's access at any time from Google Account permissions. Revoking access immediately invalidates the stored refresh token.
To have stored data deleted, write to privacy@rightsadvocates.com. We will delete the data we hold and confirm once it is done.
7. Security
All traffic to the application is served over HTTPS. Credentials are held outside the web root and are not included in any deployment package. Access to the application requires an account on our internal system, and access to the underlying server is restricted to key-based authentication.
8. Changes
If this policy changes, the effective date above will be updated. Material changes affecting how Google user data is handled will be reflected here before they take effect.
9. Contact
Rights Advocates — privacy@rightsadvocates.com