Privacy policy
What information Ads Lighthouse uses, why it is needed, and how to exercise your privacy rights.
Last updated
Who handles your information
The operator of Ads Lighthouse is responsible for personal information used to administer the website, accounts, customer enquiries and service security. For personal data processed on a business customer's instructions within its projects, the customer determines the purpose and Ads Lighthouse acts as its processor under the applicable customer agreement.
Email [email protected] or use the contact page for a privacy request. If your request concerns a project managed by your employer or client, we may need to direct it to that organisation.
Information we handle
The information depends on the features you use.
- Account information: email address, password hash when you use a password, sign-in identifiers, sessions and access role. Google sign-in can provide basic profile information and an email address.
- Project information: project and brand names, domains, keywords, markets, devices, advertiser classifications and monitoring preferences.
- Monitoring records: returned advertising and search observations, URLs, timestamps, alerts and job activity. Public source material can contain personal data, including a person's name or business contact details.
- Automated policy-review records: selected public ad copy, advertiser and brand domains, search context, relevant public landing-page text, the resulting screening assessment and its limitations.
- Connections: the selected provider, project and connection owner, authorisation scope, and encrypted access and refresh credentials when supplied by Google.
- Billing information: the selected plan, checkout attempt, Stripe customer and subscription references, subscription status, billing period and related support or audit records. Payment card details are entered on Stripe's hosted pages; Ads Lighthouse does not store full card numbers.
- Enquiries and administration: support correspondence and any records required for an agreed commercial relationship.
- Technical information: request and security metadata such as IP address, browser information, errors and service activity needed to operate and protect the application.
Purposes and legal grounds
We use account and enquiry information to provide the service, answer questions and administer our relationship. The legal basis is performance of a contract or steps you request before entering one, where you are the contracting individual. For staff acting for a business, we rely on our legitimate interest in managing that business relationship.
We use necessary technical and security information to prevent abuse, troubleshoot failures and protect the service, based on our legitimate interests in secure operation. Where accounting, tax or other law requires a record, the basis is the relevant legal obligation. A processing activity that requires consent will be presented separately; acknowledging this policy is not consent to unrelated marketing.
Where paid billing is available, we use billing information to open Checkout, confirm subscriptions, provide or restrict paid access, handle payment issues and administer the customer agreement. We retain records needed for accounting, tax and legal obligations under the applicable law.
Google sign-in and optional connections
Google sign-in authenticates your account. Connecting Google Ads or Search Console is a separate, optional authorisation for the selected project. Search Console uses a read-only scope. Google's Ads scope is broader, but the implemented connector only queries reports and account information; it does not edit campaigns.
Requested report data passes through our server to answer your query. We do not ingest those live Google report responses into a historical reporting database. Connection metadata and encrypted credentials are stored so an authorised connection can be used again. This does not apply to the separate search-ad monitoring records that you ask us to collect.
We use Google user data only to provide the connected features you request. We do not sell it, use it for advertising, or use it to train general-purpose AI models. Ads Lighthouse's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
You can revoke access in your Google Account at any time. Revocation stops future authorised API access but does not itself delete the connection metadata held by Ads Lighthouse. Contact us to request its removal. Human access to Google user data is limited to your affirmative permission for specific support, necessary security investigation, legal requirements or other cases permitted by Google's policy.
Retention and deletion
We retain information according to its purpose: operating an active account, preserving the monitoring history you request, handling an enquiry, investigating security events or meeting legal record-keeping duties. The relevant period depends on the record, your instructions and applicable law. We do not promise one deletion deadline for every category.
You can delete a project in the application and request account closure or removal of personal information through the contact page. Some operational history may remain without a project association. Deletion from the active application does not instantly remove protected backup copies or records that must be retained for legal reasons. Ask us for the retention arrangements relevant to your account before submitting data subject to a specific deletion obligation.
Security and international processing
Measures in the application include password hashing, encrypted connector credentials, server-side access checks, expiring sessions and protections for sensitive administrative actions. The deployment uses encrypted transport and encrypted database backup files. No system can guarantee absolute security.
Some providers operate internationally. Where a restricted international transfer occurs, the applicable arrangement must provide a lawful transfer mechanism, such as an adequacy decision or appropriate contractual safeguards, with additional measures where needed. A provider's presence on our list does not mean every service or region has a particular certification. Contact us for the transfer arrangements relevant to your agreement.
Your rights
Where applicable, you can request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent for processing that relies on consent without affecting earlier lawful processing. These rights have conditions and exceptions; we will explain the outcome of your request.
Send a request through the contact page. We may ask for proportionate information to verify your identity, and will respond within the period required by applicable law, normally one month under the GDPR. You may complain to your competent data protection authority, including the Spanish Data Protection Agency where relevant.
Children and policy updates
Ads Lighthouse is intended for business users, not children. Do not submit children's information or sensitive personal data to monitoring projects.
The date above identifies this version. We will update the policy when our processing changes and provide additional notice where required. New purposes requiring consent will not be authorised simply by publishing an updated policy.