Service providers & subprocessors
The services involved in hosting, protecting and operating Ads Lighthouse.
Last updated
About this overview
This overview describes the functional service categories involved in operating the current application. The identified contracting entities, processing locations and transfer safeguards must be supplied in the customer agreement or provider schedule; use the contact link to request the current named subprocessor list. This overview does not replace that schedule.
Application hosting
Application hosting runs the application, database and background processing. The hosted environment holds account, project and monitoring records, encrypted connector credentials and operational data.
Network delivery and traffic protection
Network delivery and traffic protection handle DNS, proxied web traffic, request metadata and security controls needed to deliver the site. This service may operate across locations; the applicable configuration and transfer safeguards are described in the identified provider schedule.
Transactional email
Transactional email services handle recipient addresses, message content and delivery metadata for account messages and alerts you request. Only configure recipients authorised to receive that project's information.
Private capture storage and encrypted backups
Private capture storage can hold validated landing-page data and fetch metadata associated with an authorised project. Encrypted backup storage holds encrypted database backup objects. Capture objects are retrieved through authenticated application requests and are not published as public files.
Managed search-data collection
A configured search-data collection service receives configured keywords, location, language and device parameters to retrieve search advertising observations. It does not need your Google account credentials to perform those checks.
Avoid placing unnecessary personal or confidential information in search queries.
Automated advertising-policy review
An AI inference service receives selected public ad copy, brand and advertiser domains, search context and, when available, relevant text from the public landing page. It returns a screening assessment against advertising-policy criteria. Requests are routed only through no-training providers, and the result is presented as decision support rather than a platform decision or legal conclusion.
Do not place confidential or unnecessary personal information in monitored keywords, ad labels or advertiser notes. Contact us for the identified provider, processing location and transfer information that applies to your agreement.
Payment processing and billing
Stripe provides hosted Checkout, subscription billing, invoices and customer billing management when paid billing is available. We send an account reference, the selected plan and either the account owner's email address or an existing Stripe customer reference to open Checkout. Stripe collects payment details, billing address and any tax ID entered on its pages, and processes information for payment security and fraud prevention. Its processor and controller roles are explained in its own privacy and data processing documents.
Google: connected services and domain icons
Google sign-in is an authentication option. If you authorise a project connection, Google Ads or Search Console supplies requested account and report data. Google controls its underlying account services under its own terms; connecting an account is not blanket authorisation to use Google data for unrelated purposes.
The panel also requests domain icons from Google's favicon service. That request includes a public hostname and the browser's network metadata. It is separate from OAuth authorisation. Our Privacy policy explains the information we store and how you can revoke a connection.
With optional tracking consent, the browser also requests Google Tag Manager to deliver the permitted container. This is separate from signing in or connecting Google reports. See Cookies & browser storage for the current tag inventory and how to change your choice.
Provider changes and questions
We update this overview when the functional operating setup changes. Where a customer data processing agreement requires notice and an opportunity to object to a new or replacement subprocessor, its agreed procedure applies. Publication here does not replace a required individual notice.
Contact us for the identified subprocessor schedule, processing locations or transfer documentation relevant to your agreement. Do not infer an audit certification, approved transfer mechanism or contractual service level from a provider's inclusion on this page.