Privacy Policy
Last updated: 2 June 2026
1. Who We Are
AdsMCP (“AdsMCP”, “we”, “us”) is a service operated by Marketing Panda Pty Ltd, an Australian-registered business. This Privacy Policy explains what personal information we collect, how we use it, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It also explains, in Sections 4 and 5, exactly how we handle data we access from Google APIs.
By creating an account or using AdsMCP, you agree to this Privacy Policy. If you do not agree, do not use the service.
2. What We Collect
We collect only what we need to operate the service:
- Account information: your name, email address (verified via Google OAuth).
- Business qualification details: mobile number, business name, website, industry, monthly advertising spend bracket, agency/in-house status. You provide these voluntarily during onboarding.
- Authentication tokens: when you connect your Google Ads, GA4, or GTM accounts, we receive OAuth refresh tokens from Google. These are encrypted at rest using AES-256-GCM. We never view, share, or store them in plain text.
- API keys: when you generate an AdsMCP API key, we store only an SHA-256 hash. We can never recover the raw key - if you lose it, you must generate a new one.
- Usage events: for each tool call (e.g. “list campaigns”), we log the user ID, tool name, success/failure status, duration, and timestamp. We do not log the actual data returned by Google.
- Billing information: handled entirely by Stripe. We store only a Stripe customer ID and subscription status. We never see or store your card details.
- Communications: if you contact us, we retain those messages for support and record-keeping.
3. How We Use Your Information
- To provide, maintain, and improve AdsMCP.
- To authenticate you and authorize access to your Google Ads, GA4, and GTM data.
- To bill your subscription via Stripe.
- To send transactional emails (welcome, payment receipt, account notifications, trial reminders). You cannot opt out of these while you have an active account.
- To detect, prevent, and respond to fraud, abuse, or technical issues.
- To comply with Australian legal obligations (tax records, AML, court orders).
- With your explicit consent, to refer you to Marketing Panda Pty Ltd’s consulting services if your business qualification details indicate a fit.
- In aggregated, anonymised form for analytics, product research, and benchmarking. Aggregated data never includes the content of your Google Ads, GA4, or GTM accounts.
4. Google User Data We Access
When you choose to connect a Google account, AdsMCP requests your consent to the following OAuth scopes. We request only the minimum scopes needed to operate the service, and the data-access scopes below are read-only:
openid,email,profile- your Google account’s email address and basic profile, used to identify you and to attribute each connected advertising account to the Google login that authorized it.https://www.googleapis.com/auth/adwords- to read your Google Ads accounts, campaigns, ad groups, ads, keywords, assets, and performance metrics so your AI client can report on and analyse them.https://www.googleapis.com/auth/analytics.readonly- to read your Google Analytics 4 properties, reports, and metrics (read-only).https://www.googleapis.com/auth/tagmanager.readonly- to read your Google Tag Manager containers, tags, and configuration (read-only).
What we do with it: Google user data is fetched on demand to fulfil a request you (or an AI client you control) make, returned to your authorised AI client, and used to provide the features described above. The OAuth refresh token that enables this access is encrypted at rest (AES-256-GCM) and is the only persistent Google credential we store. We do not copy your Google Ads, GA4, or GTM account contents into our own long-term storage; our usage logs record only metadata (which tool ran, when, success/failure), never the returned data.
5. Limited Use of Google User Data
AdsMCP’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the user-facing features that are prominent in AdsMCP’s interface - connecting accounts and answering your queries about your Google Ads, GA4, and GTM data.
- We do not transfer or sell Google user data to third parties, advertising platforms, data brokers, or for any purpose unrelated to operating AdsMCP.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless: (a) you give us explicit consent (for example, to debug a specific issue you raise with support); (b) it is necessary for security purposes such as investigating abuse; or (c) we are required to by applicable law.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or machine-learning models. Your data is only ever exposed to the AI client you connect and control.
6. Who We Share With
We share your data only with third-party processors essential to operating the service:
- Supabase - database and authentication hosting (United States).
- Vercel - web application hosting (United States).
- Railway - MCP server hosting (Singapore).
- Stripe - payment processing (United States, PCI-DSS compliant).
- Resend - transactional email delivery (United States).
- Twilio - SMS verification (United States), if mobile OTP is used.
- Google - only via OAuth scopes you explicitly grant; we never give Google any other data about you.
- Marketing Panda Pty Ltd (our parent company) and its affiliates / sibling companies - AdsMCP is a product of Marketing Panda. We may share your account and billing information with Marketing Panda and its related companies to operate, support and improve the service, and (with your consent) to offer you related services. They act as service providers under this policy. Your Google Ads, GA4, Tag Manager and Search Console data stays subject to Google's Limited Use requirements and is never shared with affiliates for their own purposes.
We do not sell your personal information. We do not share your data with advertisers or data brokers. We do not share the contents of your Google Ads, GA4, or GTM accounts with anyone other than the AI client you connect. The processors above act on our instructions and only receive the data needed to perform their function; none receive your Google user data except Google itself.
7. International Data Transfers
Several of our processors are located outside Australia (primarily the United States and Singapore). By using AdsMCP, you consent to your data being transferred and processed in those jurisdictions. All processors are bound by industry-standard data protection agreements.
8. Data Security
- OAuth refresh tokens encrypted with AES-256-GCM at rest.
- API keys stored as SHA-256 hashes only.
- All data transmitted over TLS 1.2 or higher.
- Row-Level Security on all database tables - you can only access your own records.
- Service role keys never exposed to client-side code.
No system is perfectly secure. While we use industry-standard practices, we cannot guarantee absolute security. You are responsible for protecting your own credentials (Google login, AdsMCP API keys, Claude Desktop config files). You must notify us immediately at hello@adsmcp.io if you suspect unauthorised access.
9. Data Retention and Deletion
We retain your data for as long as your account is active. After cancellation, we retain billing records and basic account information for up to seven (7) years to comply with Australian tax and legal record-keeping requirements.
You can revoke AdsMCP’s access to any connected Google account at any time, either by disconnecting it from your AdsMCP dashboard or directly via your Google Account permissions page. When you disconnect an account, or within 30 days of cancelling your AdsMCP account, we delete the associated encrypted Google OAuth refresh token. To request deletion of all remaining personal data we hold about you, email us at hello@adsmcp.io and we will action it within 30 days, subject to the legal retention requirements above.
10. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your data (subject to legal retention requirements above).
- Withdraw consent for optional processing (e.g. consulting referrals).
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached our obligations.
To exercise any of these rights, email us at hello@adsmcp.io. We aim to respond within 30 days.
11. Cookies
We use only essential cookies necessary for authentication and session management. We do not use third-party advertising cookies or cross-site tracking.
12. Children
AdsMCP is intended for businesses and is not directed at individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal information, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to your account address at least 30 days before they take effect. Continued use of AdsMCP after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For privacy questions, data access requests, or complaints, email hello@adsmcp.io.