Privacy Policy

Last updated: September 13, 2026

1. Who we are

Targics is a performance marketing management platform, registered with the Dutch Chamber of Commerce (KvK) under number 42148450. Privacy enquiries: [email protected].

2. Data we collect and why

CategoryExamplesPurposeLegal basis
AccountEmail, name, agency nameService delivery, communicationContract (Art. 6(1)(b) GDPR)
BillingBilling email, Stripe customer IDPayment processingContract + legal obligation
Ad campaign dataMetrics, budgets, ad copyService delivery (processor)Contract (DPA)
Usage logsHashed IP, system actionsSecurity, debuggingLegitimate interest (Art. 6(1)(f))
Cookies (analytics)Anonymous session metricsProduct improvementConsent (Art. 6(1)(a))

3. Sub-processors

We share data with the following sub-processors to deliver the service:

  • Supabase Inc. (USA) — database, authentication; transfer basis: SCC
  • Stripe Inc. (USA) — payment processing; transfer basis: SCC
  • Anthropic PBC (USA) — AI processing; transfer basis: SCC
  • Resend Inc. (USA) — transactional email; transfer basis: SCC
  • Sentry (Functional Software, USA) — error monitoring; transfer basis: SCC

The full sub-processor list is available on request at [email protected].

4. Google API Services and Google Ads Data

Targics integrates with the Google Ads API to help you manage advertising accounts. This section explains what Google user data we access, how we use it, how it is stored, and your rights over it.

4a. Data accessed

When you connect a Google Ads account via OAuth 2.0, Targics may access the following categories of information through the Google Ads API:

  • OAuth authorisation tokens (access token, refresh token) — required to call the API on your behalf;
  • Google account identity information (email address, display name, and Google user ID) obtained during OAuth authorisation — the email and display name are stored to identify and label the Google connection in the Targics Integrations dashboard;
  • Google Ads account identifiers and metadata: customer IDs, descriptive names, currency, time zone, account status;
  • Manager and client account relationships and the hierarchy of accounts accessible to the authorising user;
  • Campaign information: IDs, names, status, channel type, start and end dates;
  • Ad group information: IDs, names, status;
  • Ad and creative metadata;
  • Budget information: amounts and delivery methods;
  • Performance metrics retrieved via the Google Ads Query Language (GAQL): impressions, clicks, cost, and conversion-related metrics where available and returned by the API.

We access Google user data only to the extent necessary for the purposes described below.

4b. Purpose and use

Information obtained from the Google Ads API is used exclusively to:

  • Maintain the authorised Google Ads connection and authenticate API requests;
  • Discover and list accessible Google Ads accounts for selection by the authorising user;
  • Associate selected accounts with the corresponding Targics client workspace;
  • Display and synchronise advertising account data within the Targics platform;
  • Analyse performance and generate reports and recommendations;
  • Manage campaigns, budgets and settings within the permissions, operating parameters and budget guardrails configured by the Customer;
  • Support optimisation workflows within the Targics platform.

Google user data is not sold or transferred to third parties except as necessary to provide the services described in this section. It is not used for advertising purposes unrelated to managing your own campaigns. It is not used to build or augment user profiles for purposes unrelated to the Targics service.

Where you enable AI-powered recommendations, campaign performance data and advertising account information described in section 4a may be transmitted to Anthropic PBC, Targics’s AI sub-processor, to generate the analysis, insights, and recommendations displayed in your Targics workspace. This transfer is solely to provide you with user-facing Targics features and is subject to Anthropic’s data processing terms. Your Google Ads data is not used to develop, train, improve, or fine-tune any generalised or foundation AI or machine-learning model — either by Targics or by any sub-processor acting on Targics’s instructions.

4c. OAuth authorisation

Connecting Google Ads to Targics requires you to grant OAuth 2.0 authorisation for the following scopes: https://www.googleapis.com/auth/adwords (to access and manage your Google Ads data), openid, email, and profile(to identify the authorising Google account and display its name in the Integrations dashboard — only the email address and display name are read and stored; no other profile fields are accessed). Access is limited to the permissions granted during authorisation and exercised only within the operating parameters you configure in Targics. You can disconnect the integration at any time from the Integrations page, which stops Targics from making new API calls using your credentials. You can also revoke Targics’s OAuth authorisation directly at myaccount.google.com/permissions.

4d. Token storage and security

OAuth tokens are encrypted using AES-256-GCM at the application layer before being stored in the database. Encryption keys are stored as restricted-access environment variables on the production server (file permissions: owner-read-only) and are never stored in application code or the database. Database access is governed by row-level security (RLS) policies that enforce tenant isolation — no Targics user or organisation can access the Google Ads data of another organisation. All data is transmitted over TLS.

4e. Sharing

Google Ads data and OAuth credentials are shared only with the following named sub-processors, each acting solely on Targics’s instructions and bound by contractual data-processing safeguards:

  • Supabase Inc. (USA) — encrypted database storage and authentication. Google Ads data is stored here under tenant-isolated RLS policies.
  • Anthropic PBC (USA) — AI-powered analysis and recommendations. Campaign performance data is transmitted to generate insights displayed in your workspace. Anthropic does not use this data to train generalised AI models.
  • Sentry / Functional Software Inc. (USA) — error monitoring. Diagnostic metadata (stack traces, request context) may be included where relevant to debugging.

Google user data obtained via Google APIs is explicitly not:

  • sold or rented to any third party;
  • used for advertising or retargeting purposes unrelated to your own campaigns;
  • shared with or sold to data brokers;
  • used for credit, insurance, lending, or similar financial determinations;
  • used to develop, train, improve, or fine-tune any generalised or foundation AI or machine-learning model;
  • shared with any party other than the named sub-processors above, except where required by law.

Disclosure to law enforcement or regulatory authorities may occur where required by applicable law.

4f. Retention and deletion

Targics distinguishes three categories of Google-related data:

  • OAuth credentials. Access tokens are short-lived. Refresh tokens are retained in encrypted form for the duration of the service relationship. When you disconnect the integration from the Integrations page, Targics stops making API calls on your behalf; however, the OAuth token remains in Targics’s encrypted storage and is not automatically deleted. To permanently revoke Targics’s OAuth access at Google’s level, visit myaccount.google.com/permissions. To request deletion of the token from Targics’s systems, contact [email protected].
  • Imported Google Ads data (account records, campaign data, performance metrics). This data is retained for the duration of the service relationship under the applicable DPA. It is not automatically deleted when you disconnect the Google Ads integration. To request deletion, contact [email protected].
  • Derived reports and business records generated from Google Ads data may be retained for the duration of any applicable legal or contractual retention obligation.

4g. Google API Services User Data Policy

Targics’s use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Targics is not affiliated with or endorsed by Google LLC.

In accordance with the Limited Use requirements, Google user data obtained via Google APIs is used only to provide or improve user-facing features that are prominent in Targics’s user interface. Specifically, this data is not used to:

  • serve advertising other than in connection with your own Google Ads campaigns;
  • sell to or share with data brokers;
  • determine creditworthiness or for lending, insurance, or similar purposes;
  • develop, train, improve, or fine-tune any generalised or foundation AI or machine-learning model (by Targics or any sub-processor);
  • perform any transfer not necessary to provide the features described above.

Human access: No Targics staff member has routine access to Google user data stored in the platform. Access is restricted to authenticated agency users within their own tenant. Targics personnel may access specific data only when: (a) required for security investigation or incident response; (b) required by applicable law; or (c) expressly authorised by you for support purposes.

5. Retention

Account data is retained for the duration of the contract plus 2 years (tax obligations). Ad campaign data is governed by the DPA. Security logs are kept for 90 days. After account deletion, data is anonymised or deleted within 30 days.

6. Your rights (GDPR / AVG)

You have the right to:

  • Access your data (data export)
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”)
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time (without affecting prior processing)

To submit a request: [email protected]. We respond within 30 days. You also have the right to lodge a complaint with your supervisory authority (NL: Autoriteit Persoonsgegevens).

7. Security

All data is transmitted over TLS. Database access is restricted by RLS policies. Integration secrets are encrypted at the application layer (AES-256-GCM). Regular security audits are conducted.

8. Contact

Privacy enquiries: [email protected]. Cookie Policy · Terms of Service

Privacy Policy — Targics