1. Introduction
This policy describes how DIFFLS LTD accesses, uses, stores and shares information through Diffls Marketing Control.
Diffls Marketing Control is a private internal tool used only for DIFFLS LTD’s own advertising accounts. It is not a public product and is not offered to customers, agencies or other advertisers.
2. Google user data accessed
After an authorised DIFFLS LTD user grants OAuth access, the application may access Google Ads information such as:
- Google Ads customer and manager account identifiers
- Campaign and advertising configuration
- Campaign, ad group, ad, asset and keyword information
- Search-term reporting
- Impressions, clicks, cost and conversion metrics
- Conversion values
- Recommendations
- Change history
- Merchant or product-advertising information where available through approved APIs
The application requests only the Google API scopes required to operate its stated functionality.
3. Why the data is used
Google Ads information is used to:
- Monitor advertising performance
- Reconcile advertising results with analytics and paid Shopify orders
- Calculate CPA, contribution profit and safe spending limits
- Detect tracking failures and material reporting discrepancies
- Identify irrelevant traffic and inefficient spend
- Produce recommendations and controlled account actions
- Maintain audit and rollback records
- Protect DIFFLS LTD from excessive advertising spend and inventory risk
4. Other business data combined with Google Ads information
Google Ads data may be analysed alongside:
- Consented GA4 funnel information
- Shopify paid-order and refund information
- Product prices and costs
- Inventory levels
- Fulfilment-source costs
- Merchant Center product status
The purpose is internal commercial analysis for DIFFLS LTD’s own operations.
5. Data not required
The application is not designed to collect or import:
- Google Account passwords
- Customer payment-card information
- Complete customer postal addresses
- Unrelated Gmail, Drive, Calendar or personal Google Account content
- Customer names, email addresses or telephone numbers for unrelated profiling
6. Storage and security
- OAuth credentials and API secrets are not placed in public source code.
- Production credentials are intended to be stored using access-controlled secret storage provided by the application’s hosting infrastructure.
- Operational advertising records may be stored in an access-controlled Cloudflare D1 database.
- Access to the internal dashboard is restricted to authorised DIFFLS LTD personnel.
- Logs should avoid containing access tokens, refresh tokens, client secrets, developer tokens or unnecessary customer personal information.
- Reasonable technical and organisational controls are used to protect the confidentiality and integrity of the information.
This policy does not claim formal security certifications.
7. Sharing and disclosure
DIFFLS LTD does not sell Google user data.
Data may be processed by infrastructure or service providers only where required to operate the application, such as:
- Cloudflare
- Shopify
- Approved analytics or language-model infrastructure used by the application
Such processing is limited to providing the application’s stated internal functions. Information may also be disclosed where legally required or necessary to protect legal rights and system security.
8. Language-model processing
Selected performance data may be supplied to a language model to generate explanations or recommendations.
- Unnecessary customer personal information should be excluded.
- The language model does not directly receive unrestricted account-mutation authority.
- Proposed actions must pass deterministic policy checks.
- Account credentials and secret tokens must not be included in prompts.
9. Retention
Operational data is retained only for as long as reasonably needed for reporting, audit, security, legal compliance, performance comparison and rollback evaluation. Retention periods may vary by data category.
10. Revoking access
An authorised user can revoke the application’s Google access through their Google Account’s third-party connections or by removing the application’s access to the relevant Google Ads account.
Revocation prevents future access but may not automatically delete records already retained for legitimate audit, legal or security purposes.
11. Google API data policy
DIFFLS LTD’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
12. Rights and contact
Questions concerning the application or its data handling can be sent to hello@diffls.com.
DIFFLS LTDCompany number 16285040
Office 5889
58 Peregrine Road
Ilford
England
IG6 3SZ
United Kingdom
13. Changes to this policy
This policy may be updated when application functionality, APIs, infrastructure or legal requirements change. The revised date will be displayed at the top of this page.
Related pages: Diffls Marketing Control · Diffls storefront