Skip to main content
Your Privacy Matters

Privacy Policy

We're committed to protecting your privacy and being transparent about how we handle your data.

Effective: August 28, 2026 · Last updated: August 28, 2026
Jump to Google user data sharing disclosures

Our Privacy Commitments

Core principles that guide how we handle your information

Security First

Your data is protected with enterprise-grade security measures and encryption.

Full Transparency

We clearly explain what data we collect, how we use it, and who we share it with.

Your Control

You have rights over your data including access, correction, and deletion.

1

Information We Collect

Browser cohort signals: On normal site visits (and when you use Browser check), we may store browser capability / fingerprint cohort signals (user agent and Client Hints, screen, languages, timezone, WebGL vendor/renderer, canvas hash), coarse geo (country/region from the request IP), and a timestamp. We rate-limit how often the same browser contributes. We do not store passwords, cross-site cookies, or LAN WebRTC IP addresses. These cohorts improve Botlord profile presets.

Account Information

Email, name, billing details, and support messages you provide

Usage Data

How you interact with our services, features used, and performance metrics

Technical Data

Device info, IP address, browser type, and analytics cookies

Google user data (Shield)

If you connect Google Ads, we process OAuth tokens, your Ads customer ID, campaign IDs, and IP exclusion writes. Details below.

2

How We Use Information

Provide and improve our services and customer support

Process payments and prevent fraud or abuse

Communicate updates, offers, and important product news

Comply with legal obligations and protect our rights

3

Cookies and Tracking

We use cookies, local storage, and similar technologies for core functionality, analytics, and personalization. You can manage cookie preferences in your browser settings.

4

Google User Data (Botlord Shield)

Botlord Shield can connect to Google Ads so we can push invalid-click IP exclusions to campaigns you choose. This uses the OAuth scope https://www.googleapis.com/auth/adwords. We do not request Gmail, Drive, Calendar, Chat, Photos, YouTube, or other Google Workspace scopes.

Data access — what Google user data we access

Raw data: OAuth access and refresh tokens; the Google Ads customer ID you enter; the campaign ID used for IP exclusions; connection status and last-sync timestamps; and the IP addresses Shield writes as negative campaign IP-block criteria via the Google Ads API (campaignCriteria:mutate). We do not read your Gmail, Drive files, contacts, ad creatives, conversion lists, or bidding strategies.

Aggregated / anonymized data: We may store operational counts on your Shield dashboard (for example, how many IPs were queued or pushed). We do not build cross-customer profiles from Google Ads API data, and we do not sell or license aggregated Google user data.

Data use — how Google user data is used

We use this data only to provide and improve user-facing Shield features: authenticate to the Google Ads account you connected, apply or refresh IP exclusions on the campaigns you designate, show connection and sync status in your dashboard, and troubleshoot failures you report. We do not use Google user data (raw or aggregated) for targeted advertising, personalized ads, lending decisions, or any purpose unrelated to Shield.

Data transfer — with whom we share, transfer, or disclose Google user data

We do not sell, rent, or trade Google user data. We share or transfer Google user data only to the parties below, and only to operate Shield for you:

  • Google LLCThe user's own Google Ads account (API write-back). Data: IP exclusion (campaign criterion) writes, OAuth token refresh requests. Purpose: Apply invalid-click IP exclusions to the Google Ads campaigns the user connected, and refresh access tokens.
  • Supabase, Inc.Infrastructure subprocessor (database hosting). Data: Encrypted OAuth refresh tokens, Google Ads customer IDs, campaign IDs, connection status, sync timestamps. Purpose: Store the connection so Shield can sync exclusions after the user leaves the OAuth consent screen.
  • Vercel Inc.Infrastructure subprocessor (application hosting). Data: OAuth callback traffic, Google Ads API request/response processing in memory. Purpose: Host thebotlord.com, run OAuth callbacks, and execute Shield's Google Ads API calls.
  • Legal and safety disclosuresWe may disclose Google user data if required by law, regulation, legal process, or a valid government request, or to prevent fraud, abuse, or security incidents.
  • Business transfersIf The Bot Lord is involved in a merger, acquisition, or asset sale, Google user data may transfer to the successor, who will remain bound by this policy (or a successor policy with equivalent protections). We will notify you of a change of control that affects this data.

We do not share, transfer, or disclose Google user data (raw or aggregated/anonymized) with:

  • OpenAI, Anthropic, or any other AI/ML model provider
  • IPQualityScore or other threat-intel vendors (those receive website visitor IPs from Shield site beacons, not Google Ads API data)
  • Lemon Squeezy, Stripe, or other payment processors
  • Advertisers, ad networks, data brokers, or analytics companies
  • Any party for targeted advertising, lending, or selling user data

Data protection — how Google user data is secured

OAuth traffic and Google Ads API calls use HTTPS/TLS. Refresh tokens are encrypted at rest with AES-256-GCM before they are stored in our database. Tokens are used only by the Shield backend; they are not sent to the browser after the OAuth callback. Access to production systems is limited to operators who need it to run the service. Employees and contractors do not read Google user data unless you ask for support, we are investigating a security incident, or the law requires it.

Data retention and deletion

We keep Google OAuth tokens and connection records only while your Google Ads account stays connected to Shield (or as needed to complete a pending sync, resolve a dispute, or meet a legal obligation). Disconnecting the account from the Shield dashboard deletes the stored connection row, including the encrypted refresh token. You can also revoke Shield at Google Account permissions. To delete remaining Shield records (IP exclusion history, site keys, scored events), email support@thebotlord.com or use Contact. IP exclusions already written into your Google Ads account remain there until you remove them in Google Ads.

Limited Use and AI/ML

Botlord Shield's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Shield does not use raw or aggregated/anonymized Google user data to develop, improve, or train generalized AI/ML models. We do not transfer Google user data to third-party AI/ML services (including OpenAI, which we may use only for unrelated site features such as marketing content). We do not request Workspace or Photos APIs.

Full policy: Google API Services User Data Policy.

5

Data Sharing & Security

We protect your data

We use TLS in transit, restrict production access, and encrypt OAuth refresh tokens at rest. We never sell your personal information.

Besides Google user data (section 4), other personal information may be processed by these types of parties: payment processors (Lemon Squeezy, Stripe, NOWPayments) for billing; IPQualityScore for website-visitor IP reputation used in Shield scoring (not Google Ads API data); error monitoring (Sentry); live-chat vendors if you start a chat; and Cloudflare for CDN and file delivery. Each processes only what they need to provide that service.

Your rights

You can request access, correction, deletion, or restriction of your personal information. Contact us for any privacy-related requests.

Note: Transaction data on blockchain is immutable and cannot be deleted. We can remove payment logs from our database, but blockchain records remain public.

6

Data Retention

We keep account, billing, and Shield records as long as needed to provide the service, comply with law, and resolve disputes. Google Ads OAuth tokens are deleted when you disconnect Shield. After account closure we delete or anonymize remaining personal data within 90 days unless a longer legal hold applies.

7

International Transfers

Your information may be processed in countries with different laws, including the United States (for example Vercel, Supabase, and Google). We use contractual and technical protections appropriate to the transfer.

8

Children's Privacy

Our services are not directed to children under 13. We do not knowingly collect data from children.

Questions About Privacy?

We're here to help. Contact our privacy team with any questions or requests.

Contact us