Privacy policy
Privacy Policy
StoreAdOps accesses Google Ads, Meta Ads, and Shopify data only after a user authorizes each service individually through that provider’s OAuth flow. Connecting one service never grants access to another, and any service can be disconnected on its own.
Connected services and OAuth scopes
Google Ads. The app requests
https://www.googleapis.com/auth/adwords to read Google Ads account data and
perform user-confirmed Google Ads management actions.
Meta Ads. The app requests ads_read,
ads_management, business_management,
pages_show_list, and pages_read_engagement to read the selected
ad account’s campaigns, ad sets, ads, and performance, discover only the
explicitly authorized business’s ad accounts and managed Pages, display recent
Page-authored published posts for Page-admin ad planning, and perform
user-confirmed advertising changes. It does not request Page publishing,
moderation, messaging, follower-identity, or Commerce catalog access.
Shopify. The app requests read_products,
read_orders, and read_inventory. Shopify access is
read-only: the app requests no Shopify write scope and cannot modify a
store, its products, or its orders.
Stored data
Stored data is limited to SaaS account and auth state, encrypted OAuth tokens, selected account metadata, API keys hashed at rest, OAuth state, idempotency records, and write audit records. This is the same for every connected provider. Campaign, product, and order records are read live for the request that needs them and are not accumulated into a warehouse.
Data sharing and model training
StoreAdOps does not sell, rent, transfer, or disclose Google user data to third parties for advertising, data brokerage, credit, or any unrelated purpose. We share Google user data only as needed to provide the user-facing features you request: with Google Ads APIs to retrieve data or make a user-confirmed change, with Google Cloud as our infrastructure processor, and with an MCP-compatible AI client that you select and direct to make a request. Those recipients may process the data only to provide the requested service. Google user data is not used to train general AI models.
The same commitments apply to Meta Ads and Shopify data. We do not sell, rent, transfer, or disclose it for advertising, data brokerage, credit, or any unrelated purpose; we share it only with the provider’s own API to serve your request, with Google Cloud as our infrastructure processor, and with the MCP-compatible AI client you select and direct. Meta and Shopify data is not used to train general AI models.
Data protection
We protect connected-provider data in transit with HTTPS and at rest with encryption for OAuth tokens. API keys are hashed at rest. Tenant-scoped authorization limits each user to their own connected accounts, and production data and secrets are restricted to authorized services and operators. We limit each disclosure to the data needed for the user-directed request. Each provider’s tokens are encrypted separately, and environments do not share an encryption secret.
Retention and deletion
Google Ads campaign and performance data is read live and is not retained as a campaign-data warehouse; the same applies to Meta Ads campaign data and to Shopify product, order, and inventory data. We retain account and authentication data for as long as needed to operate the connected service, and security and audit data only for the period needed for security, abuse prevention, support, compliance, or other lawful business purposes.
Users can revoke access at any time: Google from their Google Account permissions, Meta from Facebook Settings › Business Integrations, and Shopify by uninstalling the app from the store’s admin. Any connection can also be disconnected inside StoreAdOps. Deletion can be requested by contacting support@storeadops.ai. After a verified deletion request, StoreAdOps deletes the user account and associated active-system data, including encrypted provider tokens, connection metadata, and API-key hashes, for every connected provider. Encrypted backups and service logs may persist until their normal retention periods expire.
Shopify customer data
The app reads order records to derive aggregate commerce signals such as revenue and product performance. It does not request Shopify customer-PII scopes, and it responds to Shopify’s mandatory compliance webhooks for customer data requests, customer redaction, and shop redaction.