Overview
The WBI Advertising Operations Tool (the “Application”) is an internal advertising operations and reporting tool operated by WBI Consulting Group, a Nevada S Corporation with its principal place of business in Oviedo, Florida, USA. It is used by WBI's own authorized personnel to manage and report on the Google Ads accounts of WBI's clients under a signed services agreement.
The Application is not distributed, licensed, resold, or made available to any party outside WBI Consulting Group. There is no public sign-up. This policy explains what information the Application accesses, how it is used, and the choices available to the account owners whose data it touches.
Information we collect
Operator account information
When an authorized WBI staff member signs in with Google, the Application receives basic profile information from that Google Account — name and email address. This is used solely to identify the operator, confirm authorization, and attribute entries in the audit log.
Google API data
With the operator's explicit consent, the Application requests access to the following Google services in order to perform its core functions:
-
Google Ads API (
adwordsscope) — read access to campaign, ad group, keyword, and search-term performance metrics (spend, impressions, clicks, conversions), and write access to create or adjust campaigns, budgets, and negative keywords. Access is limited to client accounts linked to the WBI manager (MCC) account with the client's approval. - Google Analytics (read access) — session and conversion event data for the client properties WBI is engaged to measure, joined to ad performance for outcome measurement and tracking diagnostics.
-
Google Drive (
drive.filescope) and Google Docs (documentsscope) — used by WBI's internal content-planning tools, which share this Google Cloud project. Access is limited to the specific files and folders those tools create, or that a user explicitly opens through them. They cannot see or access any other files in the operator's Google Drive.
Credentials
The Application stores the OAuth tokens (access and refresh tokens) needed to maintain the operator's connection to Google, together with the Google Ads developer token. These are held locally in a restricted user directory, are not transmitted to any third party, and are not committed to source control.
How we use this information
- Authenticate the operator and confirm they are authorized to run the Application.
- Retrieve advertising and analytics performance data for the client accounts WBI is engaged to manage.
- Create and adjust campaigns, budgets, and negative keywords in those accounts, subject to human approval and configured safety limits.
- Produce advertising performance reports that are reviewed by WBI staff and delivered to the client the data belongs to.
- Maintain an audit log of every operation, including dry-runs, for accountability.
- Maintain, secure, and improve the Application.
No automated decisions are applied to a client account without human review.
Limited Use disclosure
The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google APIs is used only to provide and improve the Application's user-facing features. We do not transfer or sell this data to third parties, do not use it for advertising, do not use it to build or enrich any commercial dataset, and do not allow humans to read it except where required for security, compliance, or to provide support at the account owner's request, or as required by law.
Client segregation
Data is stored and processed per client. Performance data from one client account is never surfaced to, benchmarked against, or used to optimize another client's campaigns, and is never aggregated into any cross-client or commercial dataset.
Data sharing
We do not sell personal information. Retrieved data is shared only with the client it belongs to, in the form of the reports the Application produces, and with Google in order to perform the actions the operator requests. Where the Application relies on infrastructure providers to host reporting or supporting services — Vercel (application hosting) and Neon (database hosting) — those providers process data on our behalf under their own security and privacy commitments.
Scope minimization
The Application requests only the scopes required to perform the functions described above. It does not request access to Gmail, contacts, calendars, or any Google service outside those listed, and it does not scrape or collect competitor data.
Data retention and deletion
Reporting extracts are retained only as long as the client engagement requires. They are deleted on client request, or at the end of the engagement, along with the removal of the manager-account link.
An operator may revoke the Application's access to their Google Account at any time via their Google Account permissions page. A client may remove WBI's manager-account link from within their own Google Ads account at any time, which immediately ends the Application's access to that account. To request deletion of data held about your account, contact us at the address below.
Security
Credentials are stored in a restricted local directory with filesystem permissions limited to the operator. Application data is stored in access-controlled storage and transmitted over encrypted connections (HTTPS). Access to the Application is limited to named WBI personnel who are under contract and bound by confidentiality terms.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date above.
Contact
Questions about this policy or requests regarding your data can be sent to bbell@wbicg.com.
← Back to home