Data governance

Data Management

A practical map of where information is processed, why it is needed, how long it remains, and the controls available to users.

Effective date: July 22, 2026

01

Data management principles

  • Collect and process only what is needed for a user-requested feature.
  • Keep secrets and service credentials out of browser storage and customer reports.
  • Enforce server-side tenant membership and role checks for multi-customer records.
  • Use explicit review and authorization before any Google Ads account action.
  • Provide practical controls for access, revocation, export, correction, and deletion.

02

Current build data map

Consent preference

Location
Browser cookie
Purpose
Remember essential-only or accept-all selection
Retention
Up to 12 months or until cleared

Optional Google Analytics 4 usage measurements

Location
Google Analytics when accept-all consent is active
Purpose
Understand aggregate page use and improve the public website
Retention
Controlled by the configured Google Analytics property retention settings

Google Sign-In profile and application session

Location
Transient server authentication processing and browser session cookie
Purpose
Authenticate the user and maintain the selected session
Retention
Session up to 30 days or until sign-out or cookie removal; no application database persistence

Strategy projects and campaign drafts

Location
Browser local storage on the user’s device
Purpose
Restore the demonstration workspace
Retention
Until deleted in the product or browser settings

Imported campaign CSV data

Location
Processed in the browser for the current session/workspace
Purpose
Generate local analysis and preview recommendations
Retention
Controlled by local workspace and browser storage

Submitted website URL and public page content

Location
Transient server-side request processing
Purpose
Perform the website analysis requested by the user
Retention
No application-database persistence in the current source

Optional OpenAI product-analysis input and output

Location
Application server and OpenAI API when configured
Purpose
Generate the analysis explicitly requested by the user
Retention
No application-database persistence in the current source; provider terms may apply

Contact form, support email, and related contact details

Location
Operational email systems
Purpose
Respond to support, privacy, and business requests
Retention
Generally up to 24 months after the last interaction

Audience Guard organizations, membership roles, clients, and optional client websites

Location
PostgreSQL when the Audience Guard module is configured
Purpose
Provide a tenant-isolated agency workspace and authorize client access
Retention
Until an authorized deletion request, subject to backup and legal retention

04

User controls

  1. Delete individual local projects or clear site storage in your browser.
  2. Use the cookie-settings control to replace your consent preference.
  3. Sign out of the application or revoke Google Sign-In access through your Google Account.
  4. If separate Google Ads authorization is enabled later, disconnect that account in the product and revoke the applicable Google Ads permission.
  5. Email earn@touchstoneads.com to request access, correction, restriction, export, or deletion of information held by us.

05

Deletion workflow and timeframes

We verify that a requester controls the relevant email address or connected account. Once verified, applicable records are deleted or irreversibly anonymized from active systems within 30 days, subject to documented legal, fraud-prevention, or security requirements.

Residual backup data is isolated from ordinary use and expires within 90 days. A legal or security hold may delay deletion only for the scope and period required; the data remains restricted during that time.

06

Service providers and transfers

Hosting, email, security, and optional AI providers may process limited information on our behalf. Access must be restricted to service delivery, confidentiality, security, and the disclosed purpose. Cross-border processing uses appropriate safeguards where required.

07

Security and incident response

Controls include HTTPS, server-side secret handling, input validation, least-privilege administration, tenant separation for production tenant data, logging, backups, and incident-response procedures appropriate to the service.

Report a suspected data or credential incident immediately to earn@touchstoneads.com. Do not send passwords, developer tokens, OAuth secrets, or refresh tokens by email.