Privacy Policy
Updated: 1 Jul 2026
Google API Services Usage Disclosure
AlgoTerra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only access to your Google Ads data (OAuth scope: adwords) and your Google account email address (userinfo.email) solely to analyze campaign performance, calculate ROAS, and generate automated marketing audit reports. We do not use Google user data to train AI or machine learning models.
Sharing, Transfer, and Disclosure of Google User Data
Google user data (Google account email, Google Ads customer account IDs and names, and campaign performance metrics) is not sold, rented, or licensed to third parties. We do not share, transfer, or disclose Google user data to advertisers, data brokers, or for third-party marketing unrelated to providing the AlgoTerra Audit service.
- AlgoTerra Oy (data controller) — processes data to deliver the audit service and provide customer support.
- Cloudflare, Inc. — infrastructure and application hosting processor; OAuth sessions and API requests are processed on Cloudflare Workers.
- Resend, Inc. — email delivery processor; audit report summaries and the recipient email address are transmitted over encrypted connections (TLS) to deliver the report to you and to AlgoTerra's internal lead inbox (info@algoterra.io).
- Google LLC — data is obtained only with your explicit OAuth authorization via the Google Ads API and Google OAuth endpoints; we do not disclose Google user data back to Google except as required to make authorized API calls.
Data Protection and Security Measures
Google user data and OAuth credentials are protected using the following mechanisms:
- TLS encryption (HTTPS) for all data in transit between your browser, our servers, Google APIs, and Resend.
- OAuth access tokens are stored only in HttpOnly, Secure (production), and SameSite=Lax session cookies with a 15-minute expiry; tokens are not stored in databases or browser localStorage.
- Google Ads API calls are made server-side only; access tokens are never exposed to client-side JavaScript.
- Raw Google Ads API responses are not persisted to disk or databases after the audit — data is processed temporarily in server memory and discarded when the session ends.
- Access to Google user data is limited to authorized AlgoTerra Oy personnel (e.g. lead notifications to info@algoterra.io).
- You can revoke the app's access at any time from your Google Account permissions (myaccount.google.com/permissions).
- We comply with the Google API Services User Data Policy, including Limited Use requirements.
Data controller
AlgoTerra Oy, Helsinki, Finland. Contact: info@algoterra.io
What data we collect
We collect information when you submit a contact form or reach out to us:
- Name and contact details (email, phone)
- Company name and industry
- Ad budget and service needs
- Google Ads and Meta Ads campaign metrics (read-only), when you authorize access
- Website usage data via cookies (anonymized analytics)
How we use your data
Personal data is used to respond to inquiries, provide services, manage contracts, and fulfill legal obligations. We do not sell your data to third parties.
Data retention
We retain contact details for as long as the client relationship is active or until you request deletion. Billing records are kept as required by accounting law.
Your rights
You have the right to access, correct, and delete your data and to object to processing. Contact: info@algoterra.io