Privacy policy
Privacy Policy
This Privacy Policy explains how StoreAdOps collects, uses, discloses, retains, and protects information when you use StoreAdOps, Advantage MCP, our websites, hosted MCP endpoints, APIs, and related services. It also explains choices and rights available to users. StoreAdOps is designed for merchants, agencies, and other business users.
1. Our role
StoreAdOps acts as a controller of account, authentication, service-usage, security, and support information it uses to operate the Service. When StoreAdOps processes advertising or commerce data at a merchant’s or agency’s direction, StoreAdOps may act as a processor or service provider for that customer, depending on applicable law and the activity. Merchants and agencies remain responsible for their own notices, instructions, lawful bases, and customer requests.
2. Information we collect
Information you provide
- Account information: email address and, when Google Sign-In is used, the verified Google subject, name, profile image URL, and hosted-domain value returned by Google.
- Business inputs: objectives, guardrails, business profile information, margins, targets, instructions, and other settings you choose to provide.
- Support information: messages and materials you send when asking for help, reporting a security concern, or making a privacy request.
Information from connected providers
- Google Ads: authorized account identity and metadata, campaign structure, performance, budgets, bidding, search terms, assets, targeting, conversion configuration, recommendations, and results of requested changes.
- Meta Ads: authorized business, ad-account, and managed-Page metadata; campaign, ad-set, ad, performance, audience, creative, pixel, and delivery information; and recent Page-authored published posts used for ad planning.
- Microsoft Advertising: authorized account and customer metadata, campaigns, ad groups, asset groups, ads, keywords, budgets, performance reports, linked Merchant Center stores, and results of confirmed changes.
- TikTok Ads: authorized advertiser metadata, campaigns, ad groups, ads, creative and advertising identities, pixels, lead-form configuration, performance reports, and results of confirmed changes. Lead-form discovery does not retrieve submitted leads or contact details.
- Shopify: shop and installing-user metadata returned during OAuth; product, collection, inventory, order totals, line-item product/SKU/quantity data, and derived commerce signals. StoreAdOps does not request Shopify customer name, street address, email, or phone fields.
Authentication, use, and technical information
- Encrypted OAuth tokens; selected connection and account metadata; OAuth state and permission information; hashed API keys, session tokens, and sign-in codes.
- Tool names, provider and account references, accepted-call counters, rate-limit state, idempotency records, write and approval audit records, parameter hashes, outcome and controlled error text, and timestamps.
- Terms acceptance receipts, including the policy type and version, document digest, acceptance disclosure, acceptance method, and timestamp.
- IP address, request URL and method, response status, approximate request time, user agent, and similar server and security-log information generated by hosting and network infrastructure. OAuth callback query strings are excluded from the normal retained request-log sink.
3. OAuth permissions
Google Ads. StoreAdOps requests
https://www.googleapis.com/auth/adwords to read Google Ads data and perform
user-confirmed Google Ads management actions.
Meta Ads. StoreAdOps requests ads_read,
ads_management, business_management,
pages_show_list, and pages_read_engagement. These permissions
support advertising reporting and management, discovery within the business authorized
during consent, managed-Page discovery, and review of recent Page-authored posts for ad
planning. StoreAdOps does not request Page publishing, moderation, messaging,
follower-identity, or Commerce catalog permissions.
Microsoft Advertising. StoreAdOps requests
https://ads.microsoft.com/msads.manage and offline_access
to discover authorized advertising accounts, read advertising data, and perform
confirmed management actions, including refreshing authorization.
TikTok Ads. TikTok API for Business authorization grants access to the advertisers and advertising, reporting, creative, identity, pixel, and lead-form management permissions approved for the application and authorized by the user. StoreAdOps uses these permissions only for supported, user-requested workflows.
Shopify. StoreAdOps requests read_products,
read_orders, read_all_orders, read_inventory, and
read_reports.
Order access provides exact 7-, 30-, and 90-day counts and non-identifying product-revenue
fields; reporting does not request customer names, email addresses, phone numbers, or postal
addresses. The reports scope supports existing analytics and planning workflows; Account
Overview uses the exact Orders implementation. Shopify access is read-only;
StoreAdOps requests no Shopify write scope.
4. Sources of information
We collect information directly from you; from the identity provider you select; from Google, Meta, Microsoft Advertising, TikTok, and Shopify after OAuth authorization; from AI or MCP clients you authorize; and automatically from our application, hosting, email, security, and network systems. We do not purchase personal information from data brokers.
5. How we use information
- Authenticate users, maintain sessions, issue and revoke keys, connect requested providers, and select the correct tenant and account.
- Retrieve data, calculate metrics, generate requested analysis and recommendations, display connection state, and perform user-authorized actions.
- Meter usage, apply quotas and rate limits, prevent duplicate writes, maintain approval and audit history, diagnose failures, provide support, and improve reliability.
- Protect accounts and the Service, investigate abuse and incidents, enforce our Terms, comply with platform requirements, and meet legal obligations.
- Communicate service, security, policy, and support messages. We do not use connected provider data for unrelated marketing.
6. Disclosures and service providers
We disclose information only as needed for the purposes above:
- Connected providers: Google Ads, Meta, Microsoft Advertising, TikTok, and Shopify receive API requests and authorized changes for their own services.
- User-selected AI clients: an MCP-compatible client you select and direct receives the data returned for your request. Its privacy practices are governed by your relationship with that client.
- Infrastructure and operations: Google Cloud hosts the application, database, secrets, logs, and backups; Resend delivers authentication and service email; Google Identity Services provides optional Google Sign-In; unpkg serves a browser-side icon library on sign-in and authenticated interface pages; and Descope supports MCP OAuth identity and consent using a stable opaque StoreAdOps login identifier rather than the StoreAdOps email address.
- Legal and safety: information may be disclosed when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or establish and defend legal claims.
- Business transactions: information may be transferred as permitted by law in a merger, financing, reorganization, or sale. We will provide notice and obtain consent where a provider policy or applicable law requires it.
StoreAdOps does not sell, rent, transfer, or disclose Google user data to third parties for advertising, data brokerage, credit, or other unrelated purposes. Google user data is shared only as necessary for the user-facing features you request, including with Google Cloud as our infrastructure processor, the Google Ads API, and the MCP-compatible AI client you select and direct. Google user data is not used to train general AI models.
The same commitments apply to Meta and Shopify data. Meta and Shopify data is not used to train general AI models. StoreAdOps does not sell or share personal information for cross-context behavioral advertising and does not act as a data broker.
The same data-use restrictions, including no sale of provider data or use to train general AI models, apply to Microsoft Advertising and TikTok data.
7. Retention and deletion
Advertising, product, inventory, and order information is generally retrieved live for the requested tool call and is not accumulated as a campaign, customer, or order-data warehouse. When growth-analysis features are enabled, StoreAdOps may store encrypted, size-limited snapshots of normalized advertising and commerce data with a 30-day expiration. Expired snapshots are eligible for deletion by a maintenance sweep. StoreAdOps may also store bounded outputs or controlled error text needed for auditing and support.
Account and connection records are retained while the account or connection is active. Authentication and OAuth-state records expire or are revoked according to their function. Certain derived recommendation, approval, execution, usage, idempotency, security, and audit records are retained longer than a growth snapshot for service operation, duplicate-write prevention, security, support, dispute resolution, platform compliance, and law. Write-audit and certain durable safety-history records do not currently have a fixed automatic deletion schedule. We periodically review these records and our retention practices as the Service matures.
After verified deletion, StoreAdOps deletes active-system account and connection data, including encrypted provider tokens, connection metadata, and API-key hashes, except records we must retain for security, fraud prevention, legal compliance, or legal claims. Encrypted backups and service logs may persist until their normal retention periods expire. Deleting StoreAdOps data does not itself revoke a provider OAuth grant.
8. Data protection and security
We use administrative, technical, and organizational safeguards described on our Security page, including HTTPS, encryption of OAuth tokens at rest, hashing of credentials, restricted production access, write-safety controls, logging safeguards, and incident procedures. No system can be guaranteed completely secure.
Tenant-scoped authorization limits users to their own connected accounts and selected provider resources.
9. Your choices and privacy rights
You can revoke Google access through Google Account permissions, revoke Meta access through Facebook Settings › Business Integrations, and revoke Shopify access by uninstalling the app. You can disconnect individual providers and revoke StoreAdOps API keys in the Service.
Depending on where you live and whether applicable law covers StoreAdOps, you may have the right to request access to, correction of, deletion of, or portability of personal information; learn its categories, sources, purposes, and recipients; object to or restrict certain processing; or appeal a denied request. StoreAdOps does not sell or share personal information for targeted advertising, so there is no sale or targeted-advertising opt-out needed for our current practices. We will not discriminate against you for exercising an applicable privacy right.
Submit a request to support@storeadops.ai. We will verify the request before acting and may ask an authorized agent to provide proof of authority. You may also use signed-in account controls to disconnect providers or revoke keys. If StoreAdOps processes information solely for a merchant or agency, we may direct the request to that business.
10. Cookies and similar technology
StoreAdOps uses necessary cookies for browser sessions, security, and any enabled pre-release access gate. When configured in production, we also use Google Ads cookies by default on our website to measure whether an ad leads to a successful sign-in. Google receives ad-click identifiers, a random conversion receipt, the page address, and technical connection information such as your IP address and browser information. We do not send your email, sign-in credentials, or connected advertising or commerce account data through these tags. Personalized advertising and enhanced conversions are disabled.
StoreAdOps does not load the measurement tag when your browser sends a Global Privacy Control signal, and it continues to honor a previously saved decline for up to 180 days. You can also block or clear advertising cookies through your browser without affecting sign-in or use of StoreAdOps. Google’s use of measurement data is described at Google Business Data Responsibility. Google Sign-In and other third-party login or provider pages may use their own cookies under their policies.
11. Children
The Service is for business users who are at least 18. We do not knowingly collect personal information from children. Contact us if you believe a child provided information to StoreAdOps.
12. International processing
StoreAdOps and its service providers process information in the United States. If you use the Service from another country, information may be transferred to a country with different data-protection laws. Where applicable, we will use a legally recognized transfer mechanism and provide required information about that transfer.
13. Policy changes
We may update this Policy prospectively. We will change the effective date, preserve prior versions as appropriate, and provide reasonable notice of material changes. If a change materially expands how Google user data or other connected data is used, we will provide notice and request consent before the new use where required.
14. Contact
The Service is operated by StoreAdOps. Send privacy and data requests to support@storeadops.ai.