Privacy Policy
ConvertLab360 Dashboard ("the dashboard") is a reporting-only advertising analytics service. It connects to the advertising and analytics accounts you authorize, copies performance data into your own workspace, and shows it back to you as dashboards, reports and exports. It does not create, edit, pause or delete campaigns, ads, keywords, bids or budgets on any platform.
This policy explains what we collect, what we do with it, who else processes it, and how to get it deleted.
1. Who we are
ConvertLab360 operates the dashboard at dash.convertlab360.com. For questions about this policy or
to make a data request, write to hello@convertlab360.com.
2. What data we collect
- Account data — name, email address, a password hash (never the password itself), workspace and plan details.
- Connection credentials — OAuth tokens or API credentials for the platforms you choose to connect. These are encrypted before storage.
- Reporting data — advertising and analytics data retrieved from those platforms: account, campaign, ad group, ad, keyword and search-term identifiers and names, daily aggregated metrics, creative text and thumbnail URLs, and sync status. We do not request or store end-user, audience or individual-visitor data.
- Technical data — IP address, browser and device information, server logs and basic usage events, needed to operate and protect the service.
- Billing data — plan, subscription status and invoices. Card details are handled by our payment provider and never reach our servers.
3. Integrations you can connect
Each integration is a separate authorization that you grant and can revoke independently:
- Advertising — Google Ads, Meta Ads, Microsoft Advertising, TikTok Ads, LinkedIn Ads, OpenAI Ads.
- Analytics and supporting sources — Google Analytics 4, Google Search Console, Microsoft Clarity, Facebook Pages and Instagram organic reporting, and files you upload yourself.
Data from each source is labelled as coming from that source. Google Ads data is always identified as Google Ads data, is never presented as another platform's, and is never used to create or manage campaigns anywhere. Cross-channel views combine metrics only inside your own workspace, for the reporting you asked for.
4. Google user data
ConvertLab360's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request, and why
Scopes are requested per purpose, in separate consents — connecting Google Ads never asks for write access.
| Scope | Requested when | What it is used for |
|---|---|---|
.../auth/adwords |
Connecting Google Ads | Read-only reporting queries for campaign, ad group, ad, keyword, search-term and shopping performance, plus creative metadata. No mutate operations are ever issued. |
.../auth/analytics.readonly |
Connecting Google Ads or GA4 | Reads sessions, key events and revenue from the GA4 properties you select, to show alongside ad performance. |
.../auth/webmasters.readonly |
Connecting Search Console | Reads impressions, clicks, CTR and position for the sites you have verified, so organic search can be reported next to paid. |
.../auth/drive.file |
Only if you enable Google export | Creates a new Sheet or Doc in your own Drive when you click Export, and updates only the files it created
itself. It never reads or modifies files you already have. Export access granted earlier may also
cover .../auth/spreadsheets and .../auth/documents; renewing it replaces
that with the narrower scope. |
openid, email |
GA4 and Search Console consents | Shows which Google account a connection belongs to. |
What we do not do
- We do not sell Google user data, or any other customer data.
- We do not use Google user data for advertising, profiling, credit assessment or any purpose unrelated to the features you use.
- We do not use Google user data to train, fine-tune or otherwise develop generalized artificial-intelligence or machine-learning models, and we do not permit our providers to do so.
- We do not transfer Google user data to others except as described in section 7, and never to data brokers or information resellers.
5. Other platforms
Google is described at length above because its API programme requires it, not because it is treated differently. Everything in this policy applies to every platform: read-only use, no sale, no advertising or profiling, no AI training, encryption at rest, and deletion on request.
Each connection is authorized separately, and what we ask for is:
| Platform | How it is authorized | What we retrieve |
|---|---|---|
| Meta Ads | Facebook Login, permission ads_read |
Ad account, campaign, ad set and ad names and identifiers; daily metrics; creative text and
thumbnails. ads_read does not permit changing anything. |
| Facebook Pages & Instagram (organic) | A separate Facebook Login — pages_show_list, pages_read_engagement,
read_insights, instagram_basic, instagram_manage_insights |
Page and profile names, post metadata and aggregated insights for the pages and accounts you select. It is a distinct connection from Meta Ads and does not affect it. We do not read private messages, and we do not post. |
| Microsoft Advertising | Microsoft sign-in, scope msads.manage |
Account, campaign, ad group, ad and keyword reporting. Microsoft's API offers no read-only scope, so the consent screen names a broader permission than we use — we issue reporting calls only and never write. |
| LinkedIn Ads | LinkedIn sign-in, scopes r_ads and r_ads_reporting |
Sponsored account and campaign names and identifiers, and their reporting metrics. Both scopes are read-only. |
| TikTok Ads, OpenAI Ads, Microsoft Clarity | An access token or API key that you generate on that platform and paste into the dashboard | Reporting for the advertiser or property the key belongs to. The key is encrypted before storage and used only for reporting requests. We can never see more than the key you issued allows, and deleting the connection deletes the key. |
| File import | You upload a CSV or XLSX yourself | Only the rows in the file you chose to upload. |
No platform's data is used to create or manage campaigns on any platform, including its own. Revoking access at the platform, or disconnecting here, has the same effect described in section 10.
6. AI features
Some features generate written summaries and client reports — for example an AI summary of a report table, the weekly digest, or the in-app assistant. These run only when you ask for them.
When you do, the report context required to produce that specific output — aggregated metrics and entity names from the report you are looking at — is sent to Anthropic (Claude), which acts as our processor and returns the text. The output is shown to you and stored in your workspace. Anthropic does not use this content to train its models.
The separate AI Visibility feature checks whether the brands and topics you configure appear in answers from public AI assistants. It sends the brand names and questions you entered — not your advertising data — to OpenAI, Google (Gemini), Perplexity and, for search-results data, DataForSEO.
No advertising or analytics data is sent to any AI provider except as described in this section.
7. Service providers
We do not sell personal data. We share the minimum necessary with providers that operate the service:
| Provider | Purpose | What it can see |
|---|---|---|
| Hostinger | Virtual server hosting for the application and database | All stored data, at rest on their infrastructure |
| Backblaze B2 | Off-site database backups | Only client-side encrypted archives |
| Anthropic | Generating AI summaries and reports you request | The report context for that request (section 6) |
| OpenAI, Google, Perplexity, DataForSEO | AI Visibility checks | The brands and questions you configured (section 6) |
| Creem | Subscription billing | Billing contact and payment details, which we never receive |
| Google (Gmail SMTP) | Sending service email | Message contents and your email address |
We may also disclose information where required by law, to protect rights and safety, or to enforce our terms.
8. Access by our personnel
Authorized ConvertLab360 personnel may access a customer workspace only when it is necessary for support you have requested, for security investigation, or to keep the service running — for example diagnosing a failing sync. Access is limited to the people who need it for that purpose and is subject to our internal controls. We do not browse customer data otherwise.
9. Storage, security and isolation
- Every stored row is bound to a workspace, and PostgreSQL Row-Level Security enforces that one customer cannot read another's data.
- OAuth and API credentials are encrypted with AES-256-GCM before storage and decrypted only inside the server-side sync worker.
- Traffic to the dashboard is served over TLS 1.2 or TLS 1.3; earlier versions are refused.
- Database backups are encrypted before they leave our servers.
- No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Retention and deletion
These are three different actions with three different effects:
- Disconnecting an integration deletes the stored credentials for it immediately and stops all further syncing. Reporting data already copied into your workspace stays until you remove it or delete the account, so your historical reports keep working.
- Revoking access at the provider — for example in your Google Account's security settings — invalidates the token from their side. Our copy stops working; the stored reporting data is unaffected.
- Deleting your account removes the workspace and cascades removal of its stored reporting data and credentials.
On a verified account-deletion request we delete or anonymize your personal data within 30 days. Encrypted backups are kept for up to 90 days, so deleted data disappears from backups as those rotate out. Aggregated, anonymized data that cannot be linked to you or your accounts may be retained after that. We otherwise keep data while your account is active and as needed to meet legal obligations, resolve disputes and enforce agreements.
11. Cookies and browser storage
Signing in sets two cookies on dash.convertlab360.com: cl360_session, which is
httpOnly and holds your session, and cl360_csrf, which is readable by the page and
exists only so the application can prove a request came from it. Both are strictly necessary to sign in and
stay signed in, and both are cleared at sign-out.
The dashboard also keeps a small amount of state in the browser's localStorage and
sessionStorage — a session token under cl360_token during the ongoing migration to
cookie-only sessions, plus interface preferences such as your plan identifier, chosen language, column widths
and saved filters. None of it is shared with third parties.
We do not use advertising cookies, and we run no third-party analytics or tracking scripts on the dashboard.
12. Your choices and rights
You can disconnect any integration from Settings → Connections, revoke access directly at the provider, export your reports at any time, and request correction or deletion of your data by writing to us. Depending on where you live you may also have rights of access, portability, restriction and objection; we honour these on verified request. If you are in the European Union you may lodge a complaint with your local data protection authority.
13. Changes to this policy
We update this policy when the product changes. The date at the top is the date of the current version; material changes will be announced in the dashboard.
14. Governing law
This Privacy Policy is governed by the laws of Ukraine. Any disputes arising from this policy are resolved in the courts of Kyiv, Ukraine, unless otherwise required by the applicable law of your jurisdiction.
15. Contact
For privacy questions or data requests, contact us at hello@convertlab360.com.
See also: Terms of Service · Refund Policy · Українська версія