1. Purpose and Scope
This document describes how Duneside accesses, uses, stores, and protects data from Google Ads accounts you choose to connect. Duneside is a read-only analytics and reporting platform for marketing agencies. We access Google Ads data solely to produce performance reports and consolidated cross-channel insights.
This policy supplements our Privacy Policy and Terms of Service.
2. User Authority and Account Ownership
You retain full ownership and authorityover your Google Ads accounts at all times. Connecting an account to Duneside is entirely voluntary. By connecting, you confirm that you have lawful permission to grant read access to the account's performance data.
Duneside does not take ownership of, transfer, sublicense, or resell your Google Ads accounts. You may revoke access at any time using the procedure in Section 9 of this document.
3. Google Ads API Access — Data We Retrieve
Our application uses the Google Ads API to retrieve read-only performance and analytics data. Specifically, we access:
- Campaign-level performance metrics
- Account-level statistics
- Metrics including cost, clicks, impressions, conversions, CTR, CPC, and ROAS
- Historical performance data for user-selected reporting periods
We request only the minimum API scopes necessary to deliver the reporting features described above.
4. How We Use Google Ads Data
Data retrieved from your Google Ads account is used exclusively to:
- Generate advertising performance reports for your agency and clients
- Provide consolidated reporting across multiple marketing channels within Duneside
- Display analytics dashboards and exportable summaries you configure
We do not use Google Ads data for advertising placement, bid optimization, campaign automation, or any purpose unrelated to analytics and reporting.
5. Read-Only Commitment
Duneside is a read-only platform. Through the Google Ads API, we do not perform:
- Ad or campaign creation, editing, or deletion
- Bid management or automated bidding changes
- Budget modifications or spend cap adjustments
- Keyword additions, removals, or status changes
- Any other campaign management or operational actions
All campaign management remains your responsibility and must be performed directly in Google Ads or through tools you separately authorize for that purpose.
6. Prohibited Business Activities
Duneside does not engage in, and does not permit use of our Platform for:
- Selling advertising inventory or media placements
- Generating clicks or artificial traffic
- Creating or distributing invalid traffic
- Reselling, brokering, or transferring Google Ads accounts
- Operating click arbitrage, traffic arbitrage, or similar business models
Our business model is limited to SaaS analytics and reporting services for agencies.
7. Authentication and Data Security
Access to Google Ads is established through Google's official OAuth 2.0 authorization flow. Duneside does not collect or store your Google account password. API tokens are stored securely and used only to retrieve authorized reporting data.
Data is transmitted over encrypted connections (TLS). We apply access controls and industry-standard security practices to protect stored performance data.
8. Data Retention and Deletion
Google Ads performance data is retained only while your Google Ads integration remains connected and as needed to provide reporting for your selected date ranges. When you disconnect in Duneside, or when Google authorization is revoked and our systems are notified, we delete the associated integration and stored Google Ads performance data within a reasonable timeframe, subject to any legal retention obligations.
9. Account Removal Procedure
You may disconnect your Google Ads account from Duneside at any time. Complete the steps below to stop future data access and remove data stored by Duneside.
- Disconnect in Duneside: Sign in to Duneside. Open Clients and select the client whose Google Ads account you connected. In the Integrations section, find Google Ads and click Disconnect. When you disconnect, Duneside immediately stops retrieving new Google Ads data for that connection, removes the stored integration connection from our systems, and deletes synced Google Ads campaign performance data associated with that integration. If you manage multiple clients, repeat this for each client where Google Ads is connected.
- Revoke Google authorization: After disconnecting in Duneside, the Google user who originally authorized the connection must revoke Duneside's access at myaccount.google.com/connections or via Google Account → Security → Your connections to third-party apps and services. Select Duneside and choose Remove access. If your agency connected via a Google Ads Manager (MCC) account, this step must be completed by the same Google user who completed the OAuth sign-in.
- If you cannot sign in to Duneside: You may complete Step 2 in your Google Account. Revoking access is sufficient to immediately stop Duneside from retrieving new Google Ads data. If you also need confirmation that stored data has been removed from Duneside, email support@useduneside.com with your agency or company name, the email address on your Duneside account (if known), and the Google Ads customer ID(s) you disconnected. We will confirm removal and assist with any remaining data deletion requests within a reasonable timeframe.
- Automated removal via Google: If you remove Duneside from your Google Account connections, Google may notify us through their platform removal processes. When that happens, Duneside will delete the associated integration and stored Google Ads performance data linked to that authorization.
10. Contact
For questions about Google Ads data handling, API access scope, or account removal, contact support@useduneside.com.