Scope
This policy explains how Mucers handles data used in advertising operations, including Google Ads API data, OAuth authorization state, Amazon Attribution references, and Amazon product (ASIN) operating data. It applies to the Mucers operator console and this public website.
Data we process
- Google Ads account identifiers — customer IDs and login-customer-id used to call the Google Ads API on your behalf.
- OAuth authorization state — the fact that an authorization exists, its expiry metadata, and audit events. We never display raw OAuth tokens.
- Keyword Planner data — keyword ideas, volumes, and forecasts returned by the Google Ads API.
- Google Ads reports — read-only performance data (cost, clicks, impressions, conversions) used for attribution and profit analysis.
- Amazon Attribution tags and ASIN operating data — used to connect Google Ads spend to Amazon outcomes.
Credential handling
Developer tokens, OAuth client secrets, refresh tokens, access tokens, and other secrets are stored only in AWS Secrets Manager or an equivalent encrypted store. Secrets are never written to logs, CSV exports, web pages, or support messages. The operator console shows only masked credential status (present / missing / expired).
How data is used
Mucers uses authorized data to prepare keyword planning, read-only reporting, attribution recalculation, profit analysis, report synchronization, and validate-only request preparation. Data is not sold, not shared with third parties for marketing, and not used to train models outside your account scope.
Google Ads Data Manager API
Mucers G2A uses the Google Ads Data Manager API (https://www.googleapis.com/auth/datamanager) for a single purpose: uploading offline conversion events (click conversions keyed by Google Click ID, a.k.a. gclid) to the advertiser's own Google Ads account (customer ID 563-937-3300), so that ad clicks can be matched with the resulting Amazon orders for measurement.
- What we send: gclid, conversion action name, conversion timestamp, and conversion value. No Amazon customer PII (no names, addresses, emails, or phone numbers) is ever included.
- What we do not do: we do not read audience lists, do not build user segments, do not access any Google account other than the advertiser's own, and do not store Google user data beyond the OAuth credentials required to operate the upload.
- Control: every upload batch is operator-approved and reconciled against Data Manager request statuses; the pipeline runs in validate-only mode unless explicitly enabled by the account owner.
- Revocation: access can be revoked at any time at myaccount.google.com/permissions; revocation takes effect on the next scheduled sync (≤ 5 minutes).
Retention and deletion
Operational artifacts are retained only as long as needed for account operations and audit. You may request deletion of stored data and revocation of OAuth authorization at any time via vip@mucers.com. Deleting authorization immediately stops all Google Ads API access; queued plans remain in a paused, non-executable state.
Security
Mucers separates public website pages from operator console workflows. Raw secrets never reach the browser. Access to production data requires authenticated operator sessions, and all account-changing actions require manual approval with an audit trail.
Data Protection Mechanisms for Sensitive Data
1. Encryption.
- In transit: all data exchanged between your browser, our servers, Google APIs, and Amazon APIs is encrypted with TLS 1.2 or higher. Plain-HTTP endpoints are not exposed.
- At rest: OAuth refresh tokens, API credentials, and advertising data are stored encrypted. Credentials are held exclusively in AWS Secrets Manager (KMS-backed encryption at rest); application databases and backups are encrypted at rest.
2. Access control.
- Least privilege: the application requests only the OAuth scopes required for the features you enable (Google Ads management and offline-conversion upload).
- Production access to systems holding sensitive data is restricted to authenticated administrative sessions, is logged, and any account-level change requires human approval with an audit trail.
- Sensitive data is never written to application logs, CSV exports, or web pages; consoles display masked status only.
3. Data minimization and use limitation.
- Google Ads data (campaigns, keywords, performance metrics) and conversion events are accessed solely to provide the advertising-management and attribution features you requested, and are never sold, shared with third parties for their own purposes, or used for advertising to you.
4. Retention and deletion.
- OAuth refresh tokens: retained until you disconnect the integration or request deletion; revoked and purged within 30 days of disconnection.
- Advertising performance and conversion data: retained while your account is active; deleted or irreversibly anonymized within 90 days of account closure or upon your emailed deletion request to support@mucers.com.
- You may revoke access at any time at myaccount.google.com/permissions.
5. Incident response.
- If a breach affecting your sensitive data is confirmed, we will notify affected users by email without undue delay and no later than 72 hours after confirmation, describing the scope, impact, and remediation steps.
6. Sub-processors.
- Amazon Web Services (hosting, encrypted storage, Secrets Manager).
- Google APIs (solely to execute the operations you initiate).
- No other third party receives your sensitive data.
Contact
For privacy, API access, or data deletion requests, contact vip@mucers.com. See also our Google Ads API Use disclosure and Terms of Service.