Privacy Policy

Last updated: 22 September 2026.

ConvertLab360 Dashboard ("the dashboard") is a reporting-only advertising analytics service. It connects to the advertising and analytics accounts you authorize, copies performance data into your own workspace, and shows it back to you as dashboards, reports and exports. It does not create, edit, pause or delete campaigns, ads, keywords, bids or budgets on any platform.

This policy explains what we collect, what we do with it, who else processes it, and how to get it deleted.

1. Who we are

ConvertLab360 operates the dashboard at dash.convertlab360.com. For questions about this policy or to make a data request, write to hello@convertlab360.com.

2. What data we collect

3. Integrations you can connect

Each integration is a separate authorization that you grant and can revoke independently:

Data from each source is labelled as coming from that source. Google Ads data is always identified as Google Ads data, is never presented as another platform's, and is never used to create or manage campaigns anywhere. Cross-channel views combine metrics only inside your own workspace, for the reporting you asked for.

4. Google user data

ConvertLab360's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes we request, and why

Scopes are requested per purpose, in separate consents — connecting Google Ads never asks for write access.

ScopeRequested whenWhat it is used for
.../auth/adwords Connecting Google Ads Read-only reporting queries for campaign, ad group, ad, keyword, search-term and shopping performance, plus creative metadata. No mutate operations are ever issued.
.../auth/analytics.readonly Connecting Google Ads or GA4 Reads sessions, key events and revenue from the GA4 properties you select, to show alongside ad performance.
.../auth/webmasters.readonly Connecting Search Console Reads impressions, clicks, CTR and position for the sites you have verified, so organic search can be reported next to paid.
.../auth/drive.file Only if you enable Google export Creates a new Sheet or Doc in your own Drive when you click Export, and updates only the files it created itself. It never reads or modifies files you already have. Export access granted earlier may also cover .../auth/spreadsheets and .../auth/documents; renewing it replaces that with the narrower scope.
openid, email GA4 and Search Console consents Shows which Google account a connection belongs to.

What we do not do

5. Other platforms

Google is described at length above because its API programme requires it, not because it is treated differently. Everything in this policy applies to every platform: read-only use, no sale, no advertising or profiling, no AI training, encryption at rest, and deletion on request.

Each connection is authorized separately, and what we ask for is:

PlatformHow it is authorizedWhat we retrieve
Meta Ads Facebook Login, permission ads_read Ad account, campaign, ad set and ad names and identifiers; daily metrics; creative text and thumbnails. ads_read does not permit changing anything.
Facebook Pages & Instagram (organic) A separate Facebook Login — pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights Page and profile names, post metadata and aggregated insights for the pages and accounts you select. It is a distinct connection from Meta Ads and does not affect it. We do not read private messages, and we do not post.
Microsoft Advertising Microsoft sign-in, scope msads.manage Account, campaign, ad group, ad and keyword reporting. Microsoft's API offers no read-only scope, so the consent screen names a broader permission than we use — we issue reporting calls only and never write.
LinkedIn Ads LinkedIn sign-in, scopes r_ads and r_ads_reporting Sponsored account and campaign names and identifiers, and their reporting metrics. Both scopes are read-only.
TikTok Ads, OpenAI Ads, Microsoft Clarity An access token or API key that you generate on that platform and paste into the dashboard Reporting for the advertiser or property the key belongs to. The key is encrypted before storage and used only for reporting requests. We can never see more than the key you issued allows, and deleting the connection deletes the key.
File import You upload a CSV or XLSX yourself Only the rows in the file you chose to upload.

No platform's data is used to create or manage campaigns on any platform, including its own. Revoking access at the platform, or disconnecting here, has the same effect described in section 10.

6. AI features

Some features generate written summaries and client reports — for example an AI summary of a report table, the weekly digest, or the in-app assistant. These run only when you ask for them.

When you do, the report context required to produce that specific output — aggregated metrics and entity names from the report you are looking at — is sent to Anthropic (Claude), which acts as our processor and returns the text. The output is shown to you and stored in your workspace. Anthropic does not use this content to train its models.

The separate AI Visibility feature checks whether the brands and topics you configure appear in answers from public AI assistants. It sends the brand names and questions you entered — not your advertising data — to OpenAI, Google (Gemini), Perplexity and, for search-results data, DataForSEO.

No advertising or analytics data is sent to any AI provider except as described in this section.

7. Service providers

We do not sell personal data. We share the minimum necessary with providers that operate the service:

ProviderPurposeWhat it can see
HostingerVirtual server hosting for the application and databaseAll stored data, at rest on their infrastructure
Backblaze B2Off-site database backupsOnly client-side encrypted archives
AnthropicGenerating AI summaries and reports you requestThe report context for that request (section 6)
OpenAI, Google, Perplexity, DataForSEOAI Visibility checksThe brands and questions you configured (section 6)
CreemSubscription billingBilling contact and payment details, which we never receive
Google (Gmail SMTP)Sending service emailMessage contents and your email address

We may also disclose information where required by law, to protect rights and safety, or to enforce our terms.

8. Access by our personnel

Authorized ConvertLab360 personnel may access a customer workspace only when it is necessary for support you have requested, for security investigation, or to keep the service running — for example diagnosing a failing sync. Access is limited to the people who need it for that purpose and is subject to our internal controls. We do not browse customer data otherwise.

9. Storage, security and isolation

10. Retention and deletion

These are three different actions with three different effects:

On a verified account-deletion request we delete or anonymize your personal data within 30 days. Encrypted backups are kept for up to 90 days, so deleted data disappears from backups as those rotate out. Aggregated, anonymized data that cannot be linked to you or your accounts may be retained after that. We otherwise keep data while your account is active and as needed to meet legal obligations, resolve disputes and enforce agreements.

11. Cookies and browser storage

Signing in sets two cookies on dash.convertlab360.com: cl360_session, which is httpOnly and holds your session, and cl360_csrf, which is readable by the page and exists only so the application can prove a request came from it. Both are strictly necessary to sign in and stay signed in, and both are cleared at sign-out.

The dashboard also keeps a small amount of state in the browser's localStorage and sessionStorage — a session token under cl360_token during the ongoing migration to cookie-only sessions, plus interface preferences such as your plan identifier, chosen language, column widths and saved filters. None of it is shared with third parties.

We do not use advertising cookies, and we run no third-party analytics or tracking scripts on the dashboard.

12. Your choices and rights

You can disconnect any integration from Settings → Connections, revoke access directly at the provider, export your reports at any time, and request correction or deletion of your data by writing to us. Depending on where you live you may also have rights of access, portability, restriction and objection; we honour these on verified request. If you are in the European Union you may lodge a complaint with your local data protection authority.

13. Changes to this policy

We update this policy when the product changes. The date at the top is the date of the current version; material changes will be announced in the dashboard.

14. Governing law

This Privacy Policy is governed by the laws of Ukraine. Any disputes arising from this policy are resolved in the courts of Kyiv, Ukraine, unless otherwise required by the applicable law of your jurisdiction.

15. Contact

For privacy questions or data requests, contact us at hello@convertlab360.com.

See also: Terms of Service · Refund Policy · Українська версія