Privacy Policy
Last updated: September 4, 2025
1) Who we are
Adstera (“we”, “us”, “our”) provides a platform to link and manage Google Ads accounts and campaigns. This policy explains what data we collect, how we use and share it, and how we protect it.
Contact: anastasia@blackrock-traffic.com
2) Scope & Google API Services (Limited Use)
We use Google OAuth and the Google Ads API with the scope https://www.googleapis.com/auth/adwords to provide user-requested features (e.g., linking accounts, creating/updating campaigns, retrieving metrics). Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We access Google user data only to provide the features you request inside Adstera.
- We do not sell Google user data or use it for advertising outside those features.
- Human access to Google user data is disabled by default and allowed only for support/security/legal obligations, with least privilege and logging.
3) Data we collect
- Account data: name, email, organization, role, login events.
- Google user data (Google Ads): customer IDs (CID/MCC), account hierarchy, campaign/ad group/asset metadata, and performance metrics necessary to operate features you request.
- Operational/billing data: balances, transactions, refunds, invoices (no payment card PAN stored on our servers).
- Technical data: IP address, device/browser info, and logs required for security and troubleshooting.
We collect data from you, from your Google account when you authorize access, and from your use of the service.
4) Purposes of use
- Authenticate users (OAuth) and link Google Ads accounts at your request.
- Display account structure and metrics; create/update campaigns and related entities you initiate.
- Operate the service, provide support, ensure security, prevent fraud/abuse, comply with legal obligations.
- Billing and communications related to the service.
5) Data sharing & disclosures (with whom, why, what)
We do not sell personal data. We share data only with the service providers below acting on our behalf under data processing terms, or when required by law or with your explicit consent.
| Provider | Purpose | Data types | Region |
| Render (hosting & managed PostgreSQL) |
Application hosting, databases, encrypted backups, logs |
Account data; operational/billing data; Google Ads metadata & metrics processed by the service; audit logs |
EU/US (depending on selected region) |
| Cloudflare (CDN/WAF/DDoS protection) |
Traffic delivery, caching of static assets, web application firewall |
IP addresses and request headers/metadata (no Google Ads content is cached) |
Global |
| Email service provider |
Transactional email and support communications |
Name, email address, message content |
EU/US |
Google user data sharing: We do not share Google user data with third parties except the processors above acting on our behalf, or as required by law or with your explicit consent.
International transfers: Where data is transferred outside your region, we rely on appropriate safeguards (e.g., Standard Contractual Clauses).
6) Data protection & security measures
- Encryption: TLS 1.2+ for all connections; database/storage encryption provided by Render where available; encrypted backups.
- Access control: role-based access (RBAC) with least privilege; admin access protected with MFA; secrets kept in secure environment storage.
- Network security: Cloudflare CDN/WAF, DDoS protection, rate limiting; firewalls; no public database exposure.
- Application security: input validation, dependency monitoring and patching, audit/event logs.
- Data minimization: we store only what is needed to operate the service; optional raw data is not persisted.
- Human access to Google user data: disabled by default; allowed only to resolve a user request, security incident, or legal obligation, with logging and approval.
- Backups & continuity: automated encrypted backups; restore procedures tested periodically.
7) Retention & deletion
We retain account and operational data while your account is active and as required for legal, tax, or security purposes. Google user data is kept only as long as needed to provide the requested features. You may request deletion at any time by contacting us; upon account deletion we revoke Google tokens and remove associated data (subject to lawful retention obligations).
8) Your choices & rights
- Access, correction, deletion, objection, and portability (where applicable).
- Revoke Google Ads access at any time via your Google Account security settings and inside Adstera.
- Opt out of non-essential communications by contacting support.
9) Children
Our service is not directed to children under 16 and we do not knowingly collect their data.
10) Changes
We may update this policy from time to time. Material changes will be posted on this page with a new “Last updated” date.