Privacy Policy

Campaigner Agency — Client Connect Service
Last updated: May 2026

1. Who We Are

This privacy policy applies to the Campaigner Agency Client Connect service (the "Service"), operated by Campaigner Digital Agency. The Service enables clients to grant read-only access to their Google services for reporting purposes. Contact: dolev@campaigner.co.il

2. What Data We Collect

When you authorize the Service, we collect:

3. Which Google Services We Access

Depending on what you approve, we may request access to:

When you choose read-only access we only read data for reporting. When you choose management access we may modify, publish, or upload content, but only to carry out the specific work you have asked us to do as your agency. We never act outside the scope of our engagement with you.

Campaigner's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Store Your Data

Your OAuth token is encrypted immediately after capture using a hybrid RSA/AES scheme (RSA-OAEP-SHA256 + AES-256-GCM). The encrypted payload is stored temporarily and transferred to agency infrastructure. The decryption key never exists on the service server — only on the agency's internal systems.

After the token is collected and verified, the encrypted copy is purged from our servers. Raw (unencrypted) tokens are never written to disk or logs.

5. How We Use Your Data

We use your Google account access exclusively to prepare analytical reports and performance summaries for your business. We do not sell your data, share it with third parties, or use it for advertising purposes.

6. Data Retention

We retain your tokens and associated data for as long as you are a client of Campaigner Agency or until you revoke access. Audit logs (IP, timestamps, event types) are retained for up to 12 months for security purposes.

7. How to Revoke Access

You can revoke our access to your Google account at any time:

You can also contact us directly and we will revoke all stored credentials immediately: dolev@campaigner.co.il

8. Security

The Service uses HTTPS-only communication. Tokens are encrypted end-to-end. Single-use links are HMAC-signed and expire automatically. All sensitive operations are logged in an immutable audit trail. No secrets are stored in source code or version control.

9. Your Rights (GDPR / Israeli Privacy Law)

You have the right to access, correct, or delete any personal data we hold about you. To exercise these rights, contact us at:

Campaigner Digital Agency
Email: dolev@campaigner.co.il
We will respond to all requests within 30 days.