1. Information We Collect
Depending on how you use Claditly, we may collect the following categories of information.
Account Information
When you create or manage a Claditly account, we may collect:
email address
account identifier
authentication information
account and security settings
subscription and plan information
billing-related references
account creation and activity timestamps.
Passwords are not stored in plaintext.
Authentication and Security Information
To protect accounts and the Service, we may process:
login events
IP address
device and browser information
session information
authentication method
security events
multi-factor authentication status
access and permission changes.
We use this information for authentication, fraud prevention, security monitoring, account protection, troubleshooting, and audit purposes.
2. Project and Workspace Information
Claditly allows users to create Projects and Workspaces.
Depending on the features used, we may process:
Project names
Project configuration
integrations associated with a Project
Team memberships and permissions
workflow configuration
report configuration
dashboard configuration
alert and automation settings.
Client operational information is designed to be logically and, where implemented, physically isolated from other customer environments.
3. Google Account and Google Ads Data
If you choose to connect Google Ads to Claditly, Claditly uses Google's OAuth 2.0 authorization process.
Claditly does not request or receive your Google Account password.
After you explicitly authorize Claditly, we may receive and process information including:
Google Account identifier
Google Account email address
OAuth authorization information
Google Ads customer IDs
Google Ads Manager Account relationships
account names and account hierarchy
account status
currency and time zone information
campaign information
advertising performance data
budgets
ads and assets
conversion and reporting information
other Google Ads information necessary to provide features you request.
The exact information processed depends on the Claditly features you use.
4. Google OAuth Credentials
When long-term access to Google Ads is required, Google may issue Claditly an OAuth refresh token.
Claditly:
stores OAuth credentials only where necessary to maintain an authorized integration
protects stored refresh tokens using server-side encryption
does not expose refresh tokens to the browser
does not intentionally include OAuth access tokens or refresh tokens in application logs
does not sell OAuth credentials
does not use your Google credentials to access accounts you have not authorized.
Users may disconnect an integration through Claditly or revoke access through their Google Account settings.
5. Google API Services User Data
Claditly's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve user-facing functionality requested by the user, including features such as:
connecting Google Ads accounts
displaying advertising account structures
dashboards and reports
advertising analytics
monitoring
alerts
diagnostics
PPC workflow functionality
other clearly presented advertising-management features.
Claditly does not use Google user data for unrelated advertising purposes.
Claditly does not sell Google user data.
Claditly does not use Google user data to create advertising profiles unrelated to the functionality requested by the user.
Claditly does not transfer Google user data except where required to provide or improve user-facing features, where the user has provided appropriate authorization, where required by law, or where otherwise permitted under Google's applicable policies.
Google requires applications using its APIs to clearly disclose how Google user data is accessed, used, stored and shared.
6. How We Use Information
We may use information processed through Claditly to:
provide the Service
authenticate users
maintain user sessions
create and manage Projects
connect authorized third-party integrations
retrieve advertising data
create reports and dashboards
provide analytics and monitoring
operate alerts and workflows
maintain connector health
detect technical failures
protect accounts
prevent unauthorized access
maintain audit records
provide customer support
improve reliability, usability, and performance
enforce our Terms of Service
comply with legal obligations.
We limit processing to purposes related to providing, securing, maintaining, or improving Claditly.
7. Third-Party Integrations
Claditly may allow users to connect third-party services.
These may include, now or in the future:
Google Ads
Meta
TikTok
Google Analytics
Google Merchant Center
Google Drive
Microsoft OneDrive
other advertising, analytics, reporting, or storage providers.
A third-party integration is activated only when authorized or configured by an appropriate user.
Information received from third-party platforms may also be subject to the privacy policies and terms of those providers.
8. Service Providers and Infrastructure
We may use service providers to operate Claditly infrastructure.
These providers may process limited information on our behalf only as necessary to provide their services.
Infrastructure providers may include services used for:
hosting
networking
databases
security
monitoring
error reporting
email delivery
billing
authentication.
Our infrastructure currently includes Cloudflare services for relevant hosting, application, security, networking, and data-processing functions.
We require service providers to handle information in accordance with applicable contractual and legal requirements.
9. Tenant Isolation
Claditly is designed with tenant isolation as an important security principle.
Where supported by the relevant architecture, customer operational information may be stored in an isolated tenant environment rather than in a shared operational database.
Our platform-level administrative systems are designed primarily to process operational metadata such as:
service health
subscription state
infrastructure status
connector health
safe error codes
technical diagnostics.
Platform operators are not intended to have routine standing access to customer business data.
10. Support Access
Claditly may in the future offer customer-authorized support access for troubleshooting.
Where implemented, support access is intended to be:
explicitly authorized by the customer
limited in duration
limited in scope
auditable
revocable.
Claditly does not intend to provide routine unrestricted administrative impersonation of customer accounts.
11. Information Sharing
We may disclose information only where reasonably necessary in circumstances such as:
providing infrastructure or technical services through processors
fulfilling a user's requested integration
complying with applicable law or valid legal process
protecting the security of Claditly, our users, or others
preventing fraud or abuse
completing a merger, acquisition, financing, restructuring, or sale, subject to applicable legal requirements.
We do not sell personal information for monetary consideration.
We do not sell Google user data.
12. Data Retention
We retain information only for as long as reasonably necessary for:
providing the Service
maintaining an active account
maintaining authorized integrations
security
fraud prevention
audit requirements
legal obligations
dispute resolution
backup and recovery requirements.
Different categories of information may have different retention periods.
OAuth credentials associated with a disconnected or revoked integration are disabled, deleted, revoked, or otherwise rendered unusable according to the applicable integration lifecycle and technical requirements.
Customer operational data may remain for a limited retention period after termination where necessary for recovery, legal compliance, security, or contractual obligations.
We intend to document more specific retention periods as the production Service and compliance program mature.
13. Data Deletion and Revocation
Users may disconnect third-party integrations within Claditly where the feature is available.
Users may also revoke Google access directly through their Google Account permissions.
Users may request deletion of eligible account information by contacting us.
A deletion request may be subject to:
identity verification
legal retention obligations
security requirements
billing requirements
backup retention cycles.
Where deletion is required, we will take reasonable steps to remove or de-identify eligible information.
14. Data Security
We use administrative, organizational, and technical measures designed to protect information.
Depending on the system and information involved, these measures may include:
encrypted network connections
server-side authorization
tenant isolation
encryption of sensitive credentials
least-privilege access
multi-factor authentication
secure session management
audit logging
rate limiting
infrastructure monitoring
security headers
secrets management
controlled administrative access
access revocation
incident monitoring.
No system can guarantee absolute security.
15. Administrative Access
Claditly is being designed according to a no-standing-access principle for customer operational information.
Platform administration is intended primarily for:
subscription management
platform health
service availability
infrastructure monitoring
safe technical diagnostics.
Where exceptional access to customer information is necessary for security, legal, or support reasons, access should be appropriately authorized, limited, and audited.
16. International Processing
Claditly and its service providers may process information in jurisdictions different from the user's location.
Where applicable, we will use appropriate legal and contractual mechanisms for international data transfers.
17. European and Other Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, including rights to:
access
correction
deletion
restriction
objection
portability
withdrawal of consent where processing is based on consent
lodge a complaint with an appropriate supervisory authority.
These rights may be subject to exceptions under applicable law.
18. Children's Privacy
Claditly is a professional advertising and analytics platform and is not intended for children.
Users must meet the minimum age and legal-capacity requirements applicable to entering into agreements and using the Service in their jurisdiction.
19. Automated Processing and AI
Claditly may provide analytical, automation, or AI-assisted functionality.
If such functionality processes customer advertising information, it will be used to provide features requested by the customer and subject to applicable privacy requirements.
Claditly will not use Google user data for training generalized artificial intelligence or machine-learning models unless such processing is explicitly permitted by applicable Google policies and the user has been provided any required disclosures and consent mechanisms.
This is especially important because Google's current verification requirements impose specific notice and consent obligations where Google user data is transferred for AI-model training.
20. Changes to This Privacy Policy
We may update this Privacy Policy as Claditly changes.
When changes are material, we may provide notice through:
the Service
our website
another appropriate method.
The "Last updated" date at the top indicates the latest revision.
21. Contact Us
Questions about this Privacy Policy or requests concerning personal information may be directed to:
Claditly
Email: analytics@claditly.com
Website: https://claditly.com
Additional legal entity and postal contact information will be provided as required by applicable law.