Privacy Policy
This Privacy Policy explains how Analytics Platform (“Analytics Platform”, “we”, “us”) processes information when account owners use our advertising reporting and first-party analytics service.
1. Scope and roles
This policy applies to the Analytics Platform website, API, tracking components and integrations with services such as Google Ads, Google Analytics and Meta Ads. For client-provided data, the client generally determines the purposes of processing and Analytics Platform acts as its service provider or processor. For account, security and operational data, we may act as the controller or equivalent responsible party.
2. Information we process
Advertising platform information
- Authorized account identifiers, account names, currency, time zone and account status.
- Campaign, ad group/ad set and ad identifiers, names and statuses.
- Reporting metrics such as dates, spend, impressions, reach, clicks, conversions and conversion value.
- OAuth authorization details, granted scopes, access or refresh tokens and token expiration metadata.
First-party website and commerce events
- Page and event information, URLs, referrers, timestamps and event identifiers.
- Advertising click identifiers such as GCLID, GBRAID, WBRAID and FBCLID, and attribution parameters such as UTM values.
- Order identifiers, currency, purchase value and commerce event details.
- Technical context such as IP address, browser user agent and analytics client identifiers.
- Email addresses or phone numbers supplied for measurement. Where used for advertising measurement, these values may be normalized and SHA-256 hashed before transmission to a destination platform.
Service and security information
We process connection timestamps, synchronization status, API errors, audit information and server logs needed to operate, secure and troubleshoot the service.
3. How we use information
- Authenticate authorized users and maintain requested integrations.
- Import, normalize and display advertising performance reports.
- Attribute first-party events and purchases to marketing activity.
- Transmit measurement events to Google or Meta when configured by the client.
- Detect duplicate events, investigate failures and protect the service.
- Comply with legal obligations and enforce our Terms of Service.
Where applicable, processing is based on performance of a service agreement, the account owner’s authorization, legitimate interests in providing and securing analytics, consent where required, and compliance with law.
4. Google API Services User Data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Ads authorization is used for advertising reporting requested by the account owner. We do not use Google user data for advertising unrelated to the requested service, sell it, use it to determine creditworthiness, or permit humans to read it except when necessary for security, legal compliance, support requested by the user, or internal operations with appropriate safeguards.
5. How information is shared
We may share information only as necessary with:
- Google, Meta and other destinations explicitly configured by the client.
- Hosting, database, security and infrastructure providers acting on our instructions.
- Professional advisers or authorities where required by law.
- A successor in connection with a merger, reorganization or transfer of the service, subject to appropriate safeguards.
We do not sell or rent connected advertising account information or first-party event data.
6. Security
We use technical and organizational safeguards designed to protect information, including HTTPS in transit, access controls, token encryption at rest, least-privilege permissions, logging and database controls. No system is completely secure, and users should promptly report suspected unauthorized access.
7. Retention and deletion
OAuth credentials are retained while an integration remains connected and are removed or disabled after disconnection or a valid deletion request. Reporting and event data is retained only for as long as needed to provide the service, meet agreed reporting requirements, resolve disputes and satisfy legal obligations.
An account owner may request access, correction, export, disconnection or deletion by emailing support@alphardaudio.us. Please identify the connected advertising account and the requested action. We may verify authority before acting. Valid deletion requests are processed from active systems within 30 days where reasonably possible; residual encrypted backups expire through the normal backup lifecycle, generally within 90 days unless longer retention is legally required.
Users may also revoke Google access from their Google Account permissions page and Meta access from their Facebook Business Integrations settings.
8. International processing
Information may be processed in countries other than the user’s country. Where required, we use contractual or other lawful safeguards for international transfers.
9. Individual rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, request portability, withdraw consent, and complain to a supervisory authority. Requests may be sent to the contact below. Some requests must be handled by the client that controls the relevant first-party data.
10. Children
The service is intended for businesses and authorized advertising professionals, not children. We do not knowingly solicit personal information from children.
11. Changes
We may update this policy when the service or legal requirements change. The current version and effective date will remain available at this URL.
12. Contact
Privacy and data deletion requests: support@alphardaudio.us