Diffls

privacy

Diffls Marketing Control Privacy Policy

Last updated: 26 July 2026

This policy applies specifically to Diffls Marketing Control. It does not replace the customer privacy policy for the Diffls storefront.

Storefront customer privacy policy

1. Introduction

This policy describes how DIFFLS LTD accesses, uses, stores and shares information through Diffls Marketing Control.

Diffls Marketing Control is a private internal tool used only for DIFFLS LTD’s own advertising accounts. It is not a public product and is not offered to customers, agencies or other advertisers.

2. Google user data accessed

After an authorised DIFFLS LTD user grants OAuth access, the application may access Google Ads information such as:

  • Google Ads customer and manager account identifiers
  • Campaign and advertising configuration
  • Campaign, ad group, ad, asset and keyword information
  • Search-term reporting
  • Impressions, clicks, cost and conversion metrics
  • Conversion values
  • Recommendations
  • Change history
  • Merchant or product-advertising information where available through approved APIs

The application requests only the Google API scopes required to operate its stated functionality.

3. Why the data is used

Google Ads information is used to:

  • Monitor advertising performance
  • Reconcile advertising results with analytics and paid Shopify orders
  • Calculate CPA, contribution profit and safe spending limits
  • Detect tracking failures and material reporting discrepancies
  • Identify irrelevant traffic and inefficient spend
  • Produce recommendations and controlled account actions
  • Maintain audit and rollback records
  • Protect DIFFLS LTD from excessive advertising spend and inventory risk

4. Other business data combined with Google Ads information

Google Ads data may be analysed alongside:

  • Consented GA4 funnel information
  • Shopify paid-order and refund information
  • Product prices and costs
  • Inventory levels
  • Fulfilment-source costs
  • Merchant Center product status

The purpose is internal commercial analysis for DIFFLS LTD’s own operations.

5. Data not required

The application is not designed to collect or import:

  • Google Account passwords
  • Customer payment-card information
  • Complete customer postal addresses
  • Unrelated Gmail, Drive, Calendar or personal Google Account content
  • Customer names, email addresses or telephone numbers for unrelated profiling

6. Storage and security

  • OAuth credentials and API secrets are not placed in public source code.
  • Production credentials are intended to be stored using access-controlled secret storage provided by the application’s hosting infrastructure.
  • Operational advertising records may be stored in an access-controlled Cloudflare D1 database.
  • Access to the internal dashboard is restricted to authorised DIFFLS LTD personnel.
  • Logs should avoid containing access tokens, refresh tokens, client secrets, developer tokens or unnecessary customer personal information.
  • Reasonable technical and organisational controls are used to protect the confidentiality and integrity of the information.

This policy does not claim formal security certifications.

7. Sharing and disclosure

DIFFLS LTD does not sell Google user data.

Data may be processed by infrastructure or service providers only where required to operate the application, such as:

  • Google
  • Cloudflare
  • Shopify
  • Approved analytics or language-model infrastructure used by the application

Such processing is limited to providing the application’s stated internal functions. Information may also be disclosed where legally required or necessary to protect legal rights and system security.

8. Language-model processing

Selected performance data may be supplied to a language model to generate explanations or recommendations.

  • Unnecessary customer personal information should be excluded.
  • The language model does not directly receive unrestricted account-mutation authority.
  • Proposed actions must pass deterministic policy checks.
  • Account credentials and secret tokens must not be included in prompts.

9. Retention

Operational data is retained only for as long as reasonably needed for reporting, audit, security, legal compliance, performance comparison and rollback evaluation. Retention periods may vary by data category.

10. Revoking access

An authorised user can revoke the application’s Google access through their Google Account’s third-party connections or by removing the application’s access to the relevant Google Ads account.

Revocation prevents future access but may not automatically delete records already retained for legitimate audit, legal or security purposes.

11. Google API data policy

DIFFLS LTD’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

12. Rights and contact

Questions concerning the application or its data handling can be sent to hello@diffls.com.

DIFFLS LTD
Company number 16285040
Office 5889
58 Peregrine Road
Ilford
England
IG6 3SZ
United Kingdom

13. Changes to this policy

This policy may be updated when application functionality, APIs, infrastructure or legal requirements change. The revised date will be displayed at the top of this page.

Related pages: Diffls Marketing Control · Diffls storefront

Cookies & privacy

We use necessary cookies to run the shop. Optional analytics and advertising cookies help us improve Diffls and measure campaigns — only if you allow them.