Legal
Privacy Policy
Last updated: July 12, 2026 · Contact: privacy@advestigate.co.in
This policy describes how Advestigate (“we”, “us”), operated from advestigate.co.in, collects, uses, stores, and deletes information when you use our website and web application. It is written to be read, not skimmed past; if anything is unclear, email privacy@advestigate.co.in and we will answer plainly.
1. Information we collect
Account information. When you sign up: your name, email address, and a password (stored only as a salted scrypt hash — we cannot read it). If you select a plan, we record which plan and when.
Google user data (Google Ads reporting data). When you connect a Google Ads account via Google OAuth, we receive an access token and refresh token, and we read reporting data through the official Google Ads API: campaign, ad group, keyword, and ad performance; conversion action configuration; negative keywords; and account-level settings, over the trailing 90-day window. We do not receive or store your Google password. We request only the Google Ads API scope, and our platform uses it exclusively for read-only reporting queries — the product contains no functionality to create, modify, pause, or remove anything in your account.
White-label assets. If you configure white-labeling: your logo, brand color, and footer/prepared-by text.
Usage and technical data. Standard server logs (IP address, user agent, timestamps) kept for security and debugging, and rotated automatically. We do not run third-party advertising trackers on this site.
2. How we use information
We use your information to: (a) operate your account and authenticate you; (b) run the audits you request and generate reports; (c) store your audit history so you can compare results over time; (d) apply your white-label branding to reports; (e) respond to support requests; and (f) secure the service. That list is exhaustive.
We do not sell your data, share it with data brokers or advertisers, use it to build advertising profiles, use one customer's data to benchmark or inform another's, or use Google user data to train machine-learning models.
3. Google API Services User Data Policy — Limited Use disclosure
Advestigate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the audit features you see in the product; it is not transferred to third parties except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice to you; it is not used for advertising; and humans do not read it except with your explicit permission, for security purposes, or to comply with law.
4. Storage and security
OAuth refresh tokens are encrypted at rest using AES-256-GCM. All traffic uses TLS. Passwords are hashed with scrypt and unique salts. Session cookies are HTTP-only, signed, and expire after 30 days. Audit results are stored in our database, associated with your account, and are accessible only to you when signed in.
5. Data retention and deletion
Disconnecting a Google account: available at any time from the accounts page. Disconnecting revokes our token with Google and deletes the stored token from our database immediately. You can also revoke access from Google's side at myaccount.google.com/permissions, which cuts our access with equal effect.
Audit history: retained while your account is active, and for 30 days after cancellation, then deleted.
Full account deletion: email privacy@advestigate.co.in from your account email. We delete your account, connections, tokens, audit history, and white-label assets within 30 days and confirm when done, except records we must keep for legal or accounting reasons.
6. Third-party processors
We use a small number of infrastructure providers to run the service (hosting and email delivery). They process data on our instructions and cannot use it for their own purposes. The current list is available on request at privacy@advestigate.co.in.
7. Your rights
You may request access to, correction of, export of, or deletion of your personal data at any time by emailing privacy@advestigate.co.in. We respond within 30 days. Depending on your jurisdiction (including under India's DPDP Act and the EU/UK GDPR where applicable), you may have additional statutory rights; we honor requests regardless of where you live.
8. Cookies
We use one first-party cookie: the session cookie that keeps you signed in. A local-storage key remembers your light/dark theme choice. There are no third-party advertising or analytics cookies.
9. Children
The service is for business use and not directed at children under 18. We do not knowingly collect data from children.
10. Changes to this policy
If we change this policy materially, we will email registered users and note the change here at least 14 days before it takes effect. The “last updated” date at the top always reflects the current version.
11. Contact
Privacy questions and requests: privacy@advestigate.co.in
General support: support@advestigate.co.in