Privacy Policy
Effective date: July 16, 2026
AdsCove connects AI agents to ecommerce and advertising platforms. This policy explains what data AdsCove collects, why it is needed, and how users can disconnect or delete data.
Information we collect
- Account information: email address, login provider, user ID, and basic profile information provided by your authentication provider.
- Connected platform information: Shopify shop domains, Meta ad account IDs, Google Ads customer IDs, account names, currency, time zone, connection status, granted scopes, and encrypted access or refresh tokens.
- Operational data: tool requests, tool responses, approval decisions, execution status, usage counts, billing records, and diagnostic logs needed to operate AdsCove.
- Marketing measurement data: with your consent, page visits, account registrations, checkout starts, purchases, campaign parameters, and browser identifiers may be sent to Google Analytics, Google Ads, Meta, and TikTok for attribution and advertising measurement.
Cookies and advertising measurement
- AdsCove does not load Google, Meta, or TikTok advertising measurement tags until you choose Accept analytics in the cookie notice.
- You can reopen Cookie settings from the site footer and withdraw consent. Necessary authentication and security storage remain active because the service cannot operate without them.
- Measurement providers process data under their own privacy terms. AdsCove does not send passwords, OAuth tokens, connected-account credentials, Google Ads customer IDs, Google Ads report contents, or Google Ads-derived tool results through advertising events.
Google Ads data use
- AdsCove requests the Google Ads OAuth scope https://www.googleapis.com/auth/adwords so users can connect their own Google Ads accounts to AI-agent workflows.
- We use Google Ads data only to provide requested AdsCove features: listing accessible Google Ads customers, reading campaign/ad group/search term/performance data, preparing optimization recommendations, and creating or updating paused or approval-gated advertising changes requested by the user.
- AdsCove does not use raw, aggregated, or derived Google user data for unrelated advertising, data brokerage, credit or lending decisions, or training generalized AI or machine-learning models.
Google user data sharing, transfer, and disclosure
- AdsCove shares, transfers, or discloses Google user data only in the limited circumstances listed below and only when necessary to provide, secure, or support user-requested AdsCove functionality.
- Google: AdsCove sends user-authorized requests to the Google Ads API and receives the Google Ads account and performance data required to complete those requests.
- User-selected AI clients and agents, such as Codex, Claude, Cursor, or Windsurf: when a user invokes an AdsCove tool, AdsCove returns only the Google Ads data and derived results needed for that user-requested operation. AdsCove never discloses Google OAuth access or refresh tokens to those clients or agents.
- Infrastructure service providers acting on AdsCove's behalf: Vercel hosts the application and processes web requests, and Supabase provides authentication, database, and secure storage services. These providers receive only the Google user data necessary to perform those services for AdsCove.
- Legal and safety recipients: AdsCove may disclose Google user data to courts, regulators, law enforcement, or professional advisers only when required by law or reasonably necessary to protect users, prevent fraud or abuse, or enforce legal rights.
- AdsCove does not sell Google user data or disclose it to advertising networks, data brokers, information resellers, or unrelated third parties. Google user data is not shared for targeted or personalized advertising.
Tokens and security
- OAuth access tokens, refresh tokens, and API keys are never stored in plaintext. They are encrypted or hashed before storage.
- Write operations are approval-gated by default. High-risk operations require explicit user approval before AdsCove sends changes to Shopify, Meta, or Google Ads.
- Users can disconnect platform accounts from the Connections page. Disconnecting removes the stored platform token from AdsCove.
Retention and deletion
- We retain platform connection records, tool invocation logs, and billing records for as long as needed to provide the service, meet security audit needs, and comply with legal obligations.
- Users can request account deletion, platform token deletion, or data export by following the Data Deletion instructions linked below.
- When a platform connection is disconnected, AdsCove removes the stored access and refresh tokens for that connection.
Contact
- For privacy, data deletion, or OAuth verification questions, contact hz9lucky@gmail.com.
Data deletion
See the public data deletion instructions at https://adscove.com/data-deletion.