Privacy Policy — Ads Direction

Effective: 12 May 2026 Last updated: 7 September 2026 Operated by: Omar Rashid (sole proprietor; entity registration in progress)

Drafted to comply with India's DPDP Act 2023 and the EU GDPR, and with the Google API Services User Data Policy.

What changed on 7 September 2026: added section 5 (Google user data and Limited Use), and made the cross-customer learning described in section 3 explicitly opt-in rather than automatic. If you signed up before this date, that learning is off for you until you turn it on in Settings — a change in the direction of less data use, not more, so there is nothing you need to do.


1. Who we are

Ads Direction is a weekly performance-marketing audit subscription for Indian D2C founders. We connect to your Google Ads, Shopify, Merchant Center, and Meta Ads via OAuth, analyze your paid-acquisition performance daily, and deliver a fresh audit every Monday morning.

Contact: privacy@adsdirection.com | Founder: Omar Rashid

2. What data we collect

When you sign up and connect your accounts, we receive:

Account metadata

Connected platform data (read-only OAuth scopes)

Brand-asset uploads (optional onboarding step) If you provide them during onboarding or via Settings → Brand Assets, we store:

All assets are stored in Cloudflare R2 (India edge). The brand guidelines PDF is sent to the Anthropic Vision LLM once for parsing; the extracted structured fields are stored, the PDF stays in R2 for re-parsing if you update it.

Daily metric snapshots Once subscribed, we pull a small daily snapshot from your connected platforms (campaign-level spend, conversions, CPA, ROAS, key Shopify metrics). This is what powers the day-of-week anomaly detection and the "what shifted this week" surface in the Monday audit. Snapshots are retained 24 months.

Operational data

What we do NOT collect

3. Why we collect it

Primary purpose: to deliver YOUR weekly audit. We pull your data, run analyzers, generate your weekly to-do list, and deliver it Monday morning.

Secondary purpose (the data layer — opt-in, and fully disclosed): to improve Ads Direction by aggregating anonymized, cohort-level signals across customers. Specifically:

This is opt-in, and it is off until you turn it on. We ask once during onboarding, with the box unticked. You can grant or withdraw it at any time from Settings → Cross-customer learning, and withdrawal takes effect on the next refresh — we do not need to be asked twice, and there is nothing to chase.

Two commitments that make the opt-in real rather than decorative:

Google data specifically. Google Ads, Merchant Center, GA4 and Search Console data enters the aggregate only under this same explicit consent — that is what the Google API Services User Data Policy requires, and section 5 sets it out in full. Without your opt-in, your Google data is used for one thing only: producing your own audit.

What we will never do:

This stance is a hard architectural rule, not a marketing claim. We treat it as binding policy across the product.

4. How we share data

We use the following sub-processors, each governed by their own privacy policies:

VendorPurposeData shared
Supabase (Singapore region)Database + authenticationAll structured data
Cloudflare R2 (India edge)File storageBrand-asset uploads, generated audit Word docs, raw API extracts
AnthropicLLM inference for audit synthesis + Vision LLM for brand-guideline PDF parsingAnonymized + structured account data within prompts; PDF bytes for the Vision pass. Per Anthropic's API terms, this data is not used to train Anthropic's models.
ResendTransactional emailEmail address + audit-ready notification
Razorpay (Subscriptions API)Recurring paymentsEmail + payment metadata (no card details touch our servers)
VercelWeb hostingWeb traffic + server logs
RailwayAudit-engine hostingSame data as Supabase, transient during audit runs
InngestBackground job queueJob IDs + event payloads (audit metadata, not raw account data)
SentryError trackingNon-PII error stack traces

We do not sell or rent your data to advertisers.

5. Google user data and Limited Use

This section covers data we receive from Google APIs specifically. It sits alongside the rest of this policy, and where it is stricter, it governs.

Ads Direction's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google user data we access, and why each scope is needed

ScopeWhat it gives usWhy we need it
https://www.googleapis.com/auth/adwordsGoogle Ads campaigns, ad groups, search terms, auction insights, conversion dataThe audit is largely an analysis of your Google Ads account. Without it there is no product.
https://www.googleapis.com/auth/contentMerchant Center product feed health, disapprovals, product metadataFeed disapprovals are one of the most common and most expensive silent failures for a D2C brand.
https://www.googleapis.com/auth/analytics.readonlyGA4 traffic, conversions, channel attributionTo reconcile what Google Ads claims against what actually landed on your site.
https://www.googleapis.com/auth/webmasters.readonlySearch Console impressions, queries, click-throughTo tell you when you are paying for clicks you already earn organically.

On read-only. We only ever read. We never create, edit, pause or delete anything in your Google accounts, and the product has no code that writes to a Google API. Two of the scopes above — adwords and content — are nonetheless documented by Google as read/write, because Google publishes no read-only variant of either. We request the narrowest scope Google offers for each API; for those two, the narrowest available is broader than our use.

How we use it. To produce your audit and your weekly recommendations, and — only if you opt in, see below — to contribute anonymised patterns to the benchmarks other audits are judged against.

How we share it. We do not sell, rent or transfer Google user data to anyone for advertising, marketing or any purpose unrelated to delivering your audit. It reaches only the sub-processors in section 4, each strictly to run the service.

Human access. No human reads your Google user data as a matter of course. We access it individually only where you ask us to (a support request you raise), where required by law, or to investigate a specific security incident or abuse — the exceptions the Limited Use requirements permit.

AI and machine learning. Your Google user data is sent to Anthropic's API to write your audit; per Anthropic's API terms it is not used to train Anthropic's models. We do not use Google user data to develop, improve or train generalised AI or ML models.

We do run a cross-customer learning layer, described in section 3. Google user data enters it only with your explicit, opt-in consent, requested during onboarding and changeable at any time in Settings. The box is not ticked by default. If you decline — or simply never answer — your Google data is used solely to produce your own audit, and your audit is in no way reduced.

Revoking access. You can disconnect Google at any time from Settings, or revoke it directly at myaccount.google.com/permissions. Revoking stops all future access immediately. To delete data already collected, see section 13 — deletion also removes you from every aggregate on the next refresh.

6. Data residency

Per your DPDP Act 2023 expectations:

If India-residency is a hard requirement for your compliance, contact us before subscribing — we can discuss in-country data routing for enterprise plans.

7. How long we keep it

8. Your rights (DPDP + GDPR aligned)

You have the right to:

To exercise any of these, email privacy@adsdirection.com. We respond within 7 days.

9. Cookies + tracking

The Ads Direction website uses minimal cookies:

We do not use Google Analytics, Meta Pixel, or any retargeting cookies on our own site. We are an audit tool, not an ad platform.

10. Security

If you discover a security issue, email security@adsdirection.com. Public bounty program TBD.

11. Children

Ads Direction is a B2B tool for business operators. We do not knowingly collect data from anyone under 18.

12. Changes to this policy

If we change this policy in a material way (data-use stance, vendor changes, scope expansions), we email you at least 14 days before the change takes effect. Non-material changes (typos, vendor name updates) post here without notice.

13. Data deletion

You can delete your Ads Direction account and all data we hold for you at any time.

From the app (immediate): sign in to https://adsdirection.com → Account / Settings → Delete account. This:

By email (if you cannot sign in): email privacy@adsdirection.com with subject "Account deletion request" from the email associated with your account. We confirm within 2 business days and complete the deletion within 7 business days.

Meta-specific: when you disconnect Meta Ads from /onboarding/connect (or delete your account), we delete the Meta access token we hold and purge all cached campaign, ad set, audience, insight, and Pixel data from our database, along with the corresponding files in object storage. We do not call Meta's revocation endpoint on your behalf — remove Ads Direction under Settings → Business integrations to revoke the grant on Meta's side. We retain only a deletion-confirmation record (your user_id + timestamp) for 90 days for compliance audit, then purge that too.

Google-specific and Shopify-specific: same flow — we delete the tokens we hold and purge all extracted data and stored files. Revoking the app grant on the platform's side is done by you, at https://myaccount.google.com/permissions or in your Shopify admin.

If you have questions about your deletion request or want confirmation that it completed, email privacy@adsdirection.com.

14. Contact


Reviewed against the current product mechanics on 12 May 2026. Drafted to comply with India's DPDP Act 2023 and the EU GDPR. The data-use stance in §3 is locked architecturally — we treat it as a binding rule, not a marketing claim.