Privacy Policy

Last updated: September 18, 2026

This Privacy Policy explains how Wolamart Marketing Monitor (also referred to as “Google Ads Monitor”; the “Application”, “we”, “us”), operated by Wolamart and available at https://googleads.wolamart.com, collects, uses, stores, and protects information. The Application is an internal monitoring tool used by our own team to monitor the health and performance of marketing properties that we ourselves own and manage:

  • Google Ads accounts under our own Google Ads Manager Account (MCC);
  • Google Analytics 4 properties for our own websites;
  • Instagram Business/Creator accounts owned by our own Meta Business Manager and linked to Facebook Pages we manage.

It is not a public consumer product, has no public sign-up, and does not provide services to third parties. Only our own authorized staff can log in.

1. Information We Collect

1.1 Google Ads data (via the Google Ads API)

With authorized access granted through Google OAuth 2.0, we retrieve read-only data from the Google Ads accounts under our own Manager Account. This includes:

  • Account identifiers, descriptive names, status, currency, and time zone.
  • Campaign, ad group, and ad identifiers, ad type, status, and policy/approval status.
  • Performance metrics (impressions, clicks, cost, and conversions) aggregated by day.

We request read-only access only. The Application does not create, modify, pause, or delete any campaigns, ads, budgets, or account settings.

1.2 Google Analytics data (via the Google Analytics Data API)

Using a Google Cloud Service Account granted read-only access to our own GA4 properties, we retrieve aggregated website metrics: sessions, users, page views, traffic channel groupings, conversion event counts (such as WhatsApp link clicks), landing page paths, and outbound link URLs. These are aggregate statistics; we do not retrieve individual visitor identities.

1.3 Instagram data (via the Instagram Graph API)

Using a Meta Business Manager System User access token, we retrieve read-only data for Instagram Business/Creator accounts that our own Business Manager owns. This includes:

  • Account information: Instagram account ID, username, display name, follower and following counts, media count, and the linked Facebook Page ID and name.
  • Aggregated account insights: reach, views, profile link taps, accounts engaged, total interactions, likes, comments, saves, shares, and daily new-follower counts.
  • Content data for posts and Reels published by those accounts: media ID, media type, caption text, permalink, thumbnail URL, publish time, and per-content metrics (reach, views, likes, comment counts, saves, shares, and average watch time).

We explicitly do not collect: the identities or profiles of followers, direct messages, the text content of comments, hashtag or mention data, or any personal information about individuals who interact with our accounts. Insights are received from Meta only in aggregate, anonymized form. The Application never publishes, replies, deletes, or modifies anything on Instagram or Facebook — access is strictly read-only.

1.4 Telegram notification data

If a team member chooses to receive alerts, we store the Telegram chat ID and display name of the chat or group that opts in (by sending a pairing command to our notification bot). This is used solely to deliver alert messages and can be removed at any time.

1.5 Technical data

Our server keeps standard operational logs (timestamps and error messages) for reliability and troubleshooting. The Application does not use advertising cookies or third-party tracking and does not collect personal data from website visitors.

2. How We Use the Information

  • To detect problems across our Google Ads accounts — ads that stopped serving, disapproved ads, status changes, account suspensions, and significant week-over-week performance declines.
  • To detect declines in organic search traffic to our own websites.
  • To measure the performance of our own Instagram accounts and content, so our team can see which posts and Reels worked.
  • To display dashboards and historical trends to our authorized internal team.
  • To send alert notifications to opted-in Telegram recipients.

We do not use this information for advertising, profiling, or any unrelated purpose.

3. How We Protect Your Data

  • All data is stored in a private PostgreSQL database on a server we control; it is not publicly exposed.
  • All web traffic is served over encrypted HTTPS/TLS.
  • OAuth credentials and bot tokens are kept in protected configuration and are stored encrypted at rest; they are never displayed in the interface or shared.
  • Access to the Application and its data is restricted to authorized members of our team.
  • We retain daily performance snapshots for a limited period (approximately 35 days) needed for detection and trend analysis; older data is automatically deleted.

4. Information Sharing and Third Parties

We do not sell, rent, trade, or otherwise share your information with any third parties for their own purposes. Data is only processed through the following service providers strictly to operate the Application:

  • Google (Google Ads API) — the source from which we read our own Google Ads data, under Google’s terms.
  • Google (Google Analytics Data API) — the source from which we read our own website analytics, under Google’s terms.
  • Meta Platforms (Instagram Graph API) — the source from which we read insights for our own Instagram accounts, under Meta’s Platform Terms.
  • Telegram (Telegram Bot API) — used to deliver alert notifications to recipients who have opted in. Only the alert content and the recipient’s chat ID are transmitted.
  • Anthropic (Claude API) — an optional in-app assistant that converts a staff member’s typed question into a link to the correct internal report. Only the typed question and the list of our own account/property names are sent; no Google Ads, Analytics, or Instagram metrics are transmitted.

We may disclose information if required to do so by law or valid legal process. We do not transfer data to any other external party.

5. Google API Services — Limited Use Disclosure

Google Ads Monitor’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Ads API is used only to provide and improve the monitoring features described in this policy, is not used for advertising, and is not sold or shared with third parties for unrelated purposes.

6. Meta Platform Data

Our use of data obtained from the Instagram Graph API complies with the Meta Platform Terms and Developer Policies. Specifically:

  • We access only Instagram Business/Creator accounts owned by our own Meta Business Manager, using a System User access token. We do not request access to accounts belonging to anyone else, and the Application has no public login or authorization flow.
  • Platform Data is used solely to display internal performance reports to our own staff. It is never sold, licensed, transferred, or used for advertising, profiling, or building audience segments.
  • Platform Data is not combined with data from other sources to identify individuals. We receive insights in aggregate form only.
  • Access is read-only. We never publish, modify, or delete content, and we never read direct messages or comment content.

7. Data Retention and Deletion

Google Ads daily performance snapshots are retained for approximately 35 days and then automatically purged. Monthly summaries (Google Ads, Google Analytics, and Instagram) and Instagram content metrics are retained for as long as they are useful for year-over-year trend analysis, because the source platforms themselves delete older insight data and it cannot be re-fetched afterwards. Alert records are kept for operational history.

You may request deletion of stored data at any time — see our Data Deletion Instructions. To revoke Google authorization, visit your Google Account permissions. To revoke Instagram access, remove the System User’s asset permissions or delete the app in Meta Business Manager. Telegram recipients can stop receiving messages and remove their data by sending /stop to the bot.

8. Children’s Privacy

The Application is an internal business tool and is not directed to children under the age of 13, and we do not knowingly collect data from them.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised “Last updated” date.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, contact us at wolaassistant@gmail.com.