Legal and privacy

Privacy Policy

A clear account of the information this service handles today and the controls required before any production Google Ads connection is enabled.

Effective date: July 24, 2026

01

Scope and operator

This policy explains how Touch Stone Ads Technology Limited (触石互动广告(深圳)有限公司, “we”, “us”, or “our”) handles information in connection with AI Ads Editor, its website, and related support services.

We operate independently. Google and Google Ads are referenced only to describe compatibility; Google does not sponsor, certify, or endorse this service.

02

Current product status

The current public build supports Google Sign-In for user authentication when configured. It uses mock Google Ads accounts and does not request Google Ads account authorization, read a live Google Ads account, or create or modify live Google Ads resources.

Strategy projects and campaign drafts are stored in your browser using local storage. They are not written to the Audience Guard database. When Shopify Audience Guard is enabled, its PostgreSQL database stores agency organization, membership, and client records under server-enforced tenant authorization. Website analysis can retrieve limited public pages from a URL you submit. If the optional OpenAI analysis mode is configured and you request it, extracted public website content and the related analysis input are sent to OpenAI to generate the requested result.

03

Information we handle

Depending on the feature you choose, the service may handle:

  • website URLs and limited text retrieved from publicly accessible pages;
  • business descriptions, target markets, budgets, keywords, and campaign drafts;
  • CSV data you import for local campaign analysis;
  • a consent cookie recording “essential only” or “accept all” for up to 12 months;
  • Google Analytics 4 measurements such as page views, approximate device and browser information, and interaction events when you choose “accept all”;
  • if you choose Google Sign-In, your Google account identifier, verified email address, name, profile image, and an application session cookie used only for authentication;
  • messages and contact details you voluntarily submit through our contact form or send to our support email; and
  • if you use Shopify Audience Guard, agency organization names, membership roles, client names, and optional client website URLs;
  • basic security and diagnostic records produced by hosting infrastructure.

We do not intentionally request payment-card data, account passwords, OAuth client secrets, developer tokens, or Google refresh tokens through ordinary page forms.

04

Google Sign-In and Google Ads authorization

Google Sign-In currently requests only the standard OpenID, email, and profile information needed to authenticate you. It does not grant access to a Google Ads account. If a future production release enables a separate Google Ads authorization flow, it will require your explicit approval and remain limited by your existing Google Ads permissions. You may connect only accounts that you own, manage, or are authorized to access.

For customer-requested creation, deployment, and reporting, that release may process:

  • customer account identifiers, names, status, and configuration summaries;
  • campaign, budget, ad group, keyword, match type, bid, and status settings; and
  • impressions, clicks, cost, conversions, conversion value, and date segments.

Google user data will be used only to provide the feature you request, maintain security, respond to support needs, and satisfy applicable legal obligations. We will not sell or rent it, use one customer’s data to benefit another customer, or disclose it for an independent advertising or profiling purpose.

05

Use, sharing, and service providers

We use information to operate requested workflows, validate inputs, generate customer- directed analysis, provide support, protect the service, prevent abuse, and comply with law. We do not perform hidden campaign deployments or unrelated account changes.

Infrastructure, email, security, and AI service providers may process only the data needed to perform services for us. Their access is limited by confidentiality, security, and purpose restrictions. We may also disclose information when legally required or when necessary to protect users, the public, or the service from fraud or abuse.

We use Google Analytics 4 to understand aggregate website use. The Google tag starts with analytics storage denied. Analytics storage is granted only after you choose “accept all” in the cookie control. Advertising storage, advertising user data, and advertising personalization remain denied. You can replace your choice at any time through the cookie-settings control.

06

Storage and retention

  • Browser projects, drafts, and imported CSV-derived data remain on that device until you delete them in the product or clear the site’s browser storage.
  • The consent cookie expires after 12 months unless you replace or delete it sooner.
  • The Google Sign-In application session expires after no more than 30 days. Signing out or clearing the site's cookies ends the local session sooner.
  • Contact and support records are generally retained for up to 24 months after the last interaction, unless a longer period is required for security or legal reasons.
  • Audience Guard organization and client records remain until an authorized deletion request is completed, subject to backup expiry and documented legal or security holds.
  • If production Google Ads storage is introduced, verified deletion requests will be completed or irreversibly anonymized in active systems within 30 days. Protected backup copies will expire within 90 days unless law, fraud prevention, or security requires a documented exception.

07

Your controls, revocation, and deletion

You can clear local projects and drafts through the product or your browser settings. You can reopen the cookie control at any time, sign out of the application, and revoke Google Sign-In access through your Google Account. If separate Google Ads authorization is enabled later, you will also be able to disconnect that account and revoke the applicable Google Ads permission; revocation prevents new API access using that grant.

To request access, correction, deletion, or restriction, email earn@touchstoneads.com. We may verify that you control the relevant email address or account before acting.

08

Security and account isolation

We use secure transport, least-privilege access, credential separation, input validation, access logging, and incident-response procedures appropriate to the service. OAuth client secrets, developer tokens, refresh tokens, and access tokens must remain server-side and must not appear in customer reports or browser storage.

Any production multi-customer Google Ads integration must logically separate customer records and verify account ownership or authorization before access. No security measure is perfect, so please contact us promptly if you suspect unauthorized use.

09

International processing and children

Service providers may process information in countries other than your own. Where required, we use appropriate contractual or legal safeguards for those transfers.

The service is intended for businesses and authorized account managers, not children. We do not knowingly collect personal information from children through this service.

10

Changes and contact

We will update this policy before materially expanding Google Ads API functions or data use. The effective date above identifies the current version. Material changes may also be presented in the product where consent or notice is required.

Questions or privacy requests: Touch Stone Ads Technology Limited, earn@touchstoneads.com.