Legal
Privacy Policy
Applies to the AFF Impadx application at aff.impadx.com — Last updated: September 20, 2026
AFF Impadx ("we", "us") is an internal workspace for affiliate teams that manages projects and synchronises advertising data from Google Ads. This policy explains what data we collect, why we use it, and what rights you have over it.
1. Data we collect
- Account information: name, username, email address, avatar, role and workspace group.
- Operational data: projects, campaigns, notes, costs, revenue and activity logs entered by you or your teammates.
- Google Ads data: once you connect a Google account, we access advertising account (MCC) details, campaigns, ad groups and performance metrics such as cost, impressions, clicks and conversions.
- Technical data: IP address, sign-in timestamps and system logs kept for security purposes.
2. Use of Google API data
When you grant permission through Google's consent screen, AFF Impadx uses the Google Ads API to read data from your advertising accounts so that it can be displayed and reconciled inside the application. We do not create, modify or delete your advertising campaigns through this connection.
AFF Impadx's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not:
- Use Google user data to serve advertising, including personalised or retargeted advertising;
- Sell Google user data to third parties;
- Transfer Google user data to third parties, except as necessary to provide the service, to comply with applicable law, or with your consent;
- Allow humans to read Google user data, except with your consent for support purposes, when required to resolve a security issue, or where required by law.
3. Why we use your data
- To authenticate users and enforce access permissions inside your workspace.
- To display project performance: advertising cost, revenue and profit.
- To synchronise Google Ads data on a daily basis and detect missing days.
- To keep the system secure, detect unusual access and trace changes.
4. Storage and security
- Data is stored on servers we control and transmitted over encrypted HTTPS connections.
- Google access and refresh tokens are stored encrypted and used only to synchronise data.
- Passwords are stored as one-way hashes; two-factor authentication (2FA) is supported.
- Only accounts with the appropriate role can reach the corresponding data.
5. Sharing
We do not sell or trade user data. Data is shared only within your workspace group inside the application, or when lawfully requested by a competent authority.
6. Retention and your rights
- Data is retained for as long as your account remains active.
- You may request access to, correction of, or deletion of your personal data.
- You can disconnect Google at any time inside the application, or revoke access from the third-party access page of your Google Account. Once disconnected, we stop accessing your Google Ads data and delete the stored tokens.
7. Cookies
We use only the cookies required to keep you signed in and to protect forms against CSRF attacks. No advertising or behavioural tracking cookies are used.
8. Changes to this policy
If this policy changes, the updated version will be published on this page together with a new revision date. Continuing to use the service means you accept the updated policy.
9. Contact
For any question about privacy, please contact us at support@impadx.com.