Privacy Policy
How Nexus Ads Manager handles data and authorized access to Google Ads accounts.
Last update: September 1, 2026.
1. About this policy
This Privacy Policy explains how Nexus Tecnologia treats data related to Nexus Ads Manager, an internal panel used exclusively by previously approved employees and service providers to manage, create and optimize Google Ads campaigns for clients who have authorized this work. Customers do not access the dashboard.
Access to a Google Ads account only occurs after valid authorization from the respective client or a representative empowered to grant it.
2. Data we may process
Depending on the permissions granted and the functions actually used, Nexus Ads Manager can handle:
- internal user identification and authentication data, such as name, corporate email, role, access records and permissions;
- Google and Google Ads account identifiers, such as customer ID, linked admin account, and information needed to confirm the connected account;
- data necessary for advertising management made available by the Google Ads API, such as account settings, campaigns, budgets, bids, ad groups, ads, targeting criteria, keywords, audiences, conversions, performance metrics and change history, when applicable;
- OAuth technical credentials, including access and refresh tokens, in addition to authorized scopes;
- technical, audit and security records such as date and time, action taken, responsible user, integration failures and misuse protection events.
The panel requests only the permissions necessary for the functionalities used. Nexus does not request Google account passwords and should not store them.
3. Google Ads API Permission
For campaign management functions, Nexus Ads Manager can request the Google Ads API OAuth scope https://www.googleapis.com/auth/adwords. This scope allows you to view and manage the Google Ads accounts that the authorizing user has access to. Nexus uses authorization only on accounts and customer identifiers covered by the authorized service.
Scope authorization does not transfer ownership of the Google Ads account to Nexus and does not authorize the use of data for purposes independent of the contracted service.
4. How we use data
The data is used to:
- authenticate authorized internal users and manage their access levels;
- connect authorized Google Ads accounts and carry out actions requested or provided for in the service contracted by the customer;
- create, edit, pause, monitor and optimize campaigns and their components;
- produce analyzes and reports related to authorized campaigns;
- record operations, prevent fraud, investigate incidents and maintain the security and integrity of the dashboard;
- comply with contracts, legal obligations and valid requests from authorities.
We do not sell data obtained through Google APIs. We also do not use them to create independent profiles, trade data, monitor users, train general artificial intelligence models or serve advertising outside of authorized customer campaigns.
5. OAuth, Google APIs and limited use
Nexus Ads Manager uses OAuth 2.0 to receive access authorization without obtaining the Google account password. The user sees the requested permissions in the Google flow and can accept or decline the connection.
The use of information received from Google APIs observes the Google API Services User Data Policy, including Limited Use requirements where applicable. This data is used only to provide or improve the visible and authorized features of Nexus Ads Manager.
Human access to data is limited to employees and approved providers who require this information to perform the service, provide support, protect the environment or comply with legal obligations. Everyone must observe duties of confidentiality and the restrictions of this policy.
6. Sharing
Data can only be shared:
- with the client himself and his authorized representatives;
- with approved employees and providers, to the extent necessary for their functions;
- with infrastructure, security, hosting and support providers who act under confidentiality and data protection obligations;
- with Google as necessary to operate OAuth and the Google Ads APIs;
- when required by law, valid order or to protect rights and prevent abuse.
We do not transfer or sell Google user data to data brokers, advertising platforms or other third parties for their own purposes.
7. Security and credentials
Your app credentials, Google Ads API developer token, and OAuth tokens are sensitive information and should be protected like passwords, never embedded in public code or transmitted in plain text. The production environment must use HTTPS connection, protected storage, encryption at rest for tokens and limited access control to people who need them for their functions.
Internal permissions should be reviewed when roles or employment relationships change. Known or suspected incidents involving Google data must be investigated, contained, and reported in accordance with applicable obligations.
8. Retention and deletion
Data and tokens are retained only for as long as necessary to operate the panel, fulfill authorized service, protect security, enforce contracts, and observe legal obligations. When a connection is no longer necessary, authorization must be revoked and the corresponding tokens securely deleted, except for records that need to be maintained due to legal obligation, audit, fraud prevention or exercise of rights.
Residual records in backups remain protected and are deleted according to the regular retention cycle. Aggregated or anonymized data may be retained when it does not allow the identification of a specific person or account.
9. Customer revocation, disassociation and control
The account holder or authorized representative can revoke Nexus Ads Manager access in the Google Account security settings or request Nexus to disconnect. Upon valid customer request, Nexus must delink its management permissions and return exclusive control of the Google Ads account to the customer within three business days.
Revocation prevents new access through the revoked token, but does not automatically delete records that must be retained under the terms of this policy.
10. Rights and requests
Within the limits of applicable legislation, the holder may request confirmation of processing, access, correction, information on sharing, revocation of consent and deletion. Some requests may require validation of identity or authority over the Google Ads account involved.
11. Internal access and responsibilities
The dashboard is not offered to the public or customers. Each internal access is individual and cannot be shared. Authorized users must use accounts only within the scope approved by the customer, respect confidentiality, keep their devices secure and immediately report any suspicion of improper access.
12. Updates to this policy
This policy may be updated to reflect changes to the dashboard, APIs used, legislation or security practices. The date of the most recent version will be indicated at the top of the page. Material changes will be communicated to affected internal users before the data is used for a new purpose incompatible with the previous authorization.
13. Contact
For questions, privacy requests, revocation or deletion related to Nexus Ads Manager, please contact us via email info@nexusimmersive.com.