Grapebox

Privacy Policy

Effective date: [DATE] · Operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Singapore

Draft. This policy is pending legal review. Items in [square brackets] are still to be confirmed.

Grapebox is a connector that lets AI assistants work with your Google Ads account on your instruction. This policy explains what information Grapebox accesses, why, and what it does not do. Contact us at admin@grapebox.ai with any question.

1. Information Grapebox accesses

Google Ads account data. When you authorize Grapebox, it requests access to your Google Ads account using the Google Ads API scope https://www.googleapis.com/auth/adwords. Through that access, Grapebox can read and, where you instruct it, change data such as campaigns, ad groups, ads, keywords, budgets, bidding settings, conversion action settings, performance metrics, and account change history.

This data describes your advertising activity. It is not, in general, personal information about an individual. The change history can include the email addresses of the people on your own team who made changes in the account.

Authorization credentials. To keep the connection working, an OAuth refresh token is held for each account you connect. [CONFIRM BEFORE PUBLISHING: where tokens are stored — on your own device, or encrypted on Grapebox-operated servers — and how they are protected.]

Usage information. [CONFIRM: whether Grapebox keeps any logs of tool requests, what they contain, and for how long. If none are kept, say so here.]

2. How Grapebox uses it

Only to provide the service you asked for: returning your reports and carrying out the changes you instruct. Grapebox does not sell your data, does not use it for advertising, and does not use it to build profiles or train models.

Google API Services User Data Policy. Grapebox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Who data is shared with

4. Your customers' personal data

Grapebox does not process, store, or transmit the personal data of your own customers. This covers offline conversion uploads (names, emails, phone numbers matched to ad clicks) and Customer Match audience lists. This is a policy, not a missing feature. If you ask for help with these, Grapebox will tell you so and guide you through Google's own import tools, so that your file goes directly from you to Google and not through Grapebox.

5. Retention and deletion

[CONFIRM: how long tokens and any logs are kept, and how deletion works.] You can revoke Grapebox's access at any time at myaccount.google.com/permissions. Revoking access stops Grapebox from reading or changing your account immediately. To ask us to delete any information we hold about you, email admin@grapebox.ai.

6. Security

[CONFIRM AND DESCRIBE THE ACTUAL PRACTICES: how credentials are protected, who can access them, and how access is controlled. Avoid claims that are not yet true.]

7. Your rights

Under Singapore's Personal Data Protection Act, you can ask what personal data we hold about you, ask us to correct it, and withdraw consent to our use of it. Email admin@grapebox.ai and we will respond within a reasonable time. [CONFIRM: Data Protection Officer contact, if appointed.]

8. Children

Grapebox is a business tool and is not directed at children. We do not knowingly collect information from children.

9. International transfers

Google and your AI assistant provider operate internationally, so information may be processed outside Singapore. [CONFIRM once hosting is decided.]

10. Changes to this policy

If we change this policy, we will update the effective date above and, for material changes, notify connected users by email.

11. Contact

[LEGAL ENTITY NAME] · admin@grapebox.ai