How we use the Google Ads API and your account data
Written for clients who are about to grant us access, and for anyone reviewing how we handle it. No boilerplate — this is what the software does.
On this page
What our software is
We operate our own internal software, built on the Google Ads API, which our team uses to manage the client accounts we have been authorised to work in. It exists so that routine account work and reporting happen consistently and on schedule, instead of being retyped by hand into a spreadsheet once a month.
The software is for internal use only. It has no public interface and no sign-in for clients or any other third party. It is used solely by our own staff to deliver the services our clients have contracted us for. If we ever build a client-facing portal, that changes how this tool is classified, and this page will be updated before it launches.
The access we request
We request a single OAuth scope:
https://www.googleapis.com/auth/adwords
Google describes this scope to you, on the consent screen, as “See, edit, create, and delete your Google Ads accounts and data”. We request no other Google scope. We do not request access to your Gmail, Drive, Calendar, Contacts, YouTube account or any other Google service.
How access is granted
Access is always initiated by you, the account owner, in one of two ways:
- you link your Google Ads account to our Google Ads manager account and accept the invitation from inside your own account; or
- you complete an OAuth consent flow, which issues us a token scoped to your account.
Your Google Ads account remains owned by you throughout. We never ask for your Google password, and we never sign in as you.
What the software reads and writes
We are explicit about this because the scope permits both, and understating it would be misleading.
It reads
- account, campaign, ad group, ad, keyword and budget structure;
- performance metrics — impressions, clicks, cost, conversions, conversion value and the related segments — pulled on a schedule to build your reporting;
- search-term and audience reports used for negative-keyword and targeting work;
- keyword and forecast data from the keyword planning services, for research on your account.
It writes
- creates, edits, pauses and removes campaigns, ad groups, ads, keywords, negative keywords, negative keyword lists, audiences and ad extensions;
- sets and adjusts budgets and bid strategy settings as part of the pacing work described in our services;
- configures and verifies conversion tracking for the account;
- applies structural changes agreed in the account plan.
Every write the software makes is a change one of our specialists would otherwise make by hand in the Google Ads interface, on the same account, for the same client, under the same engagement.
Where data is stored and who can see it
- Data retrieved from the Google Ads API is stored on infrastructure we control, and is kept for the duration of the engagement plus 90 days.
- All data is transmitted over encrypted connections meeting the Google Ads API requirement of at least 128-bit encryption in transit.
- OAuth refresh tokens and client secrets are encrypted at rest and stored separately from application data.
- Access is least-privilege: the members of our team assigned to your account can see your account's data, and that access is logged. Nobody outside that team has routine access.
Limited Use
Big Sky Investments' use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
What we never do with your data
- We do not sell your Google Ads data.
- We do not transfer it to advertising platforms, data brokers or information resellers.
- We do not use it to serve, target or retarget advertising, of ours or of anyone else's.
- We do not use it to determine credit-worthiness or for any lending purpose.
- We do not use one client's data for another client's campaigns.
- We do not build audience databases from it.
- We do not use it to train generalised artificial-intelligence or machine-learning models.
- We do not allow humans to read your data except the assigned team delivering your service, where you have given consent, where security or abuse investigation requires it, or where the law compels it.
Reporting freshness and separation
Google Ads performance data in our reports is refreshed at least once every 24 hours. Where any figure is delayed beyond 24 hours, that delay is stated prominently on the report itself. Google Ads data is presented separately from, and clearly distinguished from, data originating on other advertising platforms.
Revoking our access
You may revoke Big Sky Investments’ access to your Google Ads account at any time, either by removing our application at myaccount.google.com/permissions, or by removing our manager account under Admin > Access and security in your Google Ads account.
On revocation we destroy the associated OAuth refresh tokens within 7 days, and we delete or anonymise the associated Google user data in line with the retention periods set out in our Privacy Policy. Where you ask us in writing to disassociate entirely, we remove our access and return exclusive control of the account to you within three business days.
Questions
Write to info@bigskyfinancials.trade and we will answer within one business day during business hours. The related documents are our Privacy Policy, our Terms of Service and our third-party advertising policy.