Back to homepage

Privacy Policy

Effective date: 10 August 2026

This Privacy Policy explains how Aquila Marketing OS, operated by Aquila ("Aquila", "we", "us"), accesses, uses, stores, protects, and discloses information when authorized internal users use the application.

1. Application and audience

Aquila Marketing OS is a private marketing operations platform for Aquila owners, employees, and authorized contractors. It is not offered to the general public or external clients.

2. Information we process

We process application identity and access information such as the identity-provider subject, name or email where supplied, organization and brand memberships, roles, server-side session records, security events, and audit records.

When a user authorizes Google Ads access, we may process:

We do not receive or store the user's Google password.

3. How Google user data is used

Google user data is used only to provide or improve user-facing functionality requested by an authorized user: connecting a Google Ads account, discovering accessible accounts, associating an account with an Aquila brand, displaying campaign information and reports, preparing controlled changes, executing approved campaign actions, verifying results, preventing abuse, and maintaining security and auditability.

Aquila Marketing OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Sharing and disclosure

We do not sell Google user data, use it for advertising unrelated to the application's functionality, or disclose it to data brokers. Access is limited to authorized Aquila personnel and service components required to operate and secure the application. We may disclose information when required by applicable law, to investigate security incidents, or at the user's explicit direction. OAuth credentials and the Google Ads developer token are never exposed to AI prompts, browser JavaScript, or application users.

5. Storage and security

Production traffic uses HTTPS. OAuth credentials are encrypted at rest and bound to the relevant organization, brand, and connection. Browser sessions use secure HTTP-only cookies. Access is restricted through role-based authorization, live membership checks, database row-level security, protected infrastructure, audit logging, and separate database roles. No method of storage or transmission is completely risk-free, but we apply safeguards proportionate to the sensitivity of the data.

6. Retention and deletion

OAuth credentials are retained only while the Google Ads connection is active or as needed to provide the requested service. A user may revoke the grant through Google Account permissions at any time. Authorized users may request disconnection and deletion by contacting us. We will remove active credentials and operational Google user data within 30 days of a verified request, except for limited security, audit, backup, or legal records that must be retained. Audit records are retained only for legitimate security, compliance, and dispute-resolution purposes and are then securely deleted or anonymized. Backup copies expire through the applicable backup-retention cycle.

7. User choices and rights

Authorized users can decline OAuth consent, revoke Google access, request correction or deletion of their application data, or request information about its processing. Revoking Google access prevents future API access but may not remove audit records that must be retained for security or legal purposes.

8. Changes to this policy

We may update this policy when the application or legal requirements change. The current version and effective date will remain available at this URL. Material changes affecting Google user data will be communicated to affected users where required.

9. Contact

Questions, access requests, and deletion requests may be sent to kapiro@ukr.net.