Consent preference
- Location
- Browser cookie
- Purpose
- Remember essential-only or accept-all selection
- Retention
- Up to 12 months or until cleared
Data governance
A practical map of where information is processed, why it is needed, how long it remains, and the controls available to users.
Effective date: July 22, 2026
01
02
03
Google Sign-In may authenticate application users, but Google Ads account authorization and Google Ads API access are not enabled in the current public build. Before they are enabled, the production system must enforce account authorization, tenant separation, least-privilege access, credential encryption, audit logging, and documented incident response.
A production release may process, only for the connected customer:
Tokens must remain server-side, encrypted where stored, scoped to the approved purpose, and inaccessible to other customers.
04
05
We verify that a requester controls the relevant email address or connected account. Once verified, applicable records are deleted or irreversibly anonymized from active systems within 30 days, subject to documented legal, fraud-prevention, or security requirements.
Residual backup data is isolated from ordinary use and expires within 90 days. A legal or security hold may delay deletion only for the scope and period required; the data remains restricted during that time.
06
Hosting, email, security, and optional AI providers may process limited information on our behalf. Access must be restricted to service delivery, confidentiality, security, and the disclosed purpose. Cross-border processing uses appropriate safeguards where required.
07
Controls include HTTPS, server-side secret handling, input validation, least-privilege administration, tenant separation for production tenant data, logging, backups, and incident-response procedures appropriate to the service.
Report a suspected data or credential incident immediately to earn@touchstoneads.com. Do not send passwords, developer tokens, OAuth secrets, or refresh tokens by email.