Privacy Policy
We're committed to protecting your privacy and being transparent about how we handle your data.
Our Privacy Commitments
Core principles that guide how we handle your information
Security First
Your data is protected with enterprise-grade security measures and encryption.
Full Transparency
We clearly explain what data we collect, how we use it, and who we share it with.
Your Control
You have rights over your data including access, correction, and deletion.
Information We Collect
Browser cohort signals: On normal site visits (and when you use Browser check), we may store browser capability / fingerprint cohort signals (user agent and Client Hints, screen, languages, timezone, WebGL vendor/renderer, canvas hash), coarse geo (country/region from the request IP), and a timestamp. We rate-limit how often the same browser contributes. We do not store passwords, cross-site cookies, or LAN WebRTC IP addresses. These cohorts improve Botlord profile presets.
Account Information
Email, name, billing details, and support messages you provide
Usage Data
How you interact with our services, features used, and performance metrics
Technical Data
Device info, IP address, browser type, and analytics cookies
Google user data (Shield)
If you connect Google Ads, we process OAuth tokens, your Ads customer ID, campaign IDs, and IP exclusion writes. Details below.
How We Use Information
Provide and improve our services and customer support
Process payments and prevent fraud or abuse
Communicate updates, offers, and important product news
Comply with legal obligations and protect our rights
Cookies and Tracking
We use cookies, local storage, and similar technologies for core functionality, analytics, and personalization. You can manage cookie preferences in your browser settings.
Google User Data (Botlord Shield)
Botlord Shield can connect to Google Ads so we can push invalid-click IP exclusions to campaigns you choose. This uses the OAuth scope https://www.googleapis.com/auth/adwords. We do not request Gmail, Drive, Calendar, Chat, Photos, YouTube, or other Google Workspace scopes.
Data access — what Google user data we access
Raw data: OAuth access and refresh tokens; the Google Ads customer ID you enter; the campaign ID used for IP exclusions; connection status and last-sync timestamps; and the IP addresses Shield writes as negative campaign IP-block criteria via the Google Ads API (campaignCriteria:mutate). We do not read your Gmail, Drive files, contacts, ad creatives, conversion lists, or bidding strategies.
Aggregated / anonymized data: We may store operational counts on your Shield dashboard (for example, how many IPs were queued or pushed). We do not build cross-customer profiles from Google Ads API data, and we do not sell or license aggregated Google user data.
Data use — how Google user data is used
We use this data only to provide and improve user-facing Shield features: authenticate to the Google Ads account you connected, apply or refresh IP exclusions on the campaigns you designate, show connection and sync status in your dashboard, and troubleshoot failures you report. We do not use Google user data (raw or aggregated) for targeted advertising, personalized ads, lending decisions, or any purpose unrelated to Shield.
Data transfer — with whom we share, transfer, or disclose Google user data
We do not sell, rent, or trade Google user data. We share or transfer Google user data only to the parties below, and only to operate Shield for you:
- Google LLC — The user's own Google Ads account (API write-back). Data: IP exclusion (campaign criterion) writes, OAuth token refresh requests. Purpose: Apply invalid-click IP exclusions to the Google Ads campaigns the user connected, and refresh access tokens.
- Supabase, Inc. — Infrastructure subprocessor (database hosting). Data: Encrypted OAuth refresh tokens, Google Ads customer IDs, campaign IDs, connection status, sync timestamps. Purpose: Store the connection so Shield can sync exclusions after the user leaves the OAuth consent screen.
- Vercel Inc. — Infrastructure subprocessor (application hosting). Data: OAuth callback traffic, Google Ads API request/response processing in memory. Purpose: Host thebotlord.com, run OAuth callbacks, and execute Shield's Google Ads API calls.
- Legal and safety disclosures — We may disclose Google user data if required by law, regulation, legal process, or a valid government request, or to prevent fraud, abuse, or security incidents.
- Business transfers — If The Bot Lord is involved in a merger, acquisition, or asset sale, Google user data may transfer to the successor, who will remain bound by this policy (or a successor policy with equivalent protections). We will notify you of a change of control that affects this data.
We do not share, transfer, or disclose Google user data (raw or aggregated/anonymized) with:
- OpenAI, Anthropic, or any other AI/ML model provider
- IPQualityScore or other threat-intel vendors (those receive website visitor IPs from Shield site beacons, not Google Ads API data)
- Lemon Squeezy, Stripe, or other payment processors
- Advertisers, ad networks, data brokers, or analytics companies
- Any party for targeted advertising, lending, or selling user data
Data protection — how Google user data is secured
OAuth traffic and Google Ads API calls use HTTPS/TLS. Refresh tokens are encrypted at rest with AES-256-GCM before they are stored in our database. Tokens are used only by the Shield backend; they are not sent to the browser after the OAuth callback. Access to production systems is limited to operators who need it to run the service. Employees and contractors do not read Google user data unless you ask for support, we are investigating a security incident, or the law requires it.
Data retention and deletion
We keep Google OAuth tokens and connection records only while your Google Ads account stays connected to Shield (or as needed to complete a pending sync, resolve a dispute, or meet a legal obligation). Disconnecting the account from the Shield dashboard deletes the stored connection row, including the encrypted refresh token. You can also revoke Shield at Google Account permissions. To delete remaining Shield records (IP exclusion history, site keys, scored events), email support@thebotlord.com or use Contact. IP exclusions already written into your Google Ads account remain there until you remove them in Google Ads.
Limited Use and AI/ML
Botlord Shield's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Shield does not use raw or aggregated/anonymized Google user data to develop, improve, or train generalized AI/ML models. We do not transfer Google user data to third-party AI/ML services (including OpenAI, which we may use only for unrelated site features such as marketing content). We do not request Workspace or Photos APIs.
Full policy: Google API Services User Data Policy.
Data Sharing & Security
We protect your data
We use TLS in transit, restrict production access, and encrypt OAuth refresh tokens at rest. We never sell your personal information.
Besides Google user data (section 4), other personal information may be processed by these types of parties: payment processors (Lemon Squeezy, Stripe, NOWPayments) for billing; IPQualityScore for website-visitor IP reputation used in Shield scoring (not Google Ads API data); error monitoring (Sentry); live-chat vendors if you start a chat; and Cloudflare for CDN and file delivery. Each processes only what they need to provide that service.
Your rights
You can request access, correction, deletion, or restriction of your personal information. Contact us for any privacy-related requests.
Note: Transaction data on blockchain is immutable and cannot be deleted. We can remove payment logs from our database, but blockchain records remain public.
Data Retention
We keep account, billing, and Shield records as long as needed to provide the service, comply with law, and resolve disputes. Google Ads OAuth tokens are deleted when you disconnect Shield. After account closure we delete or anonymize remaining personal data within 90 days unless a longer legal hold applies.
International Transfers
Your information may be processed in countries with different laws, including the United States (for example Vercel, Supabase, and Google). We use contractual and technical protections appropriate to the transfer.
Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect data from children.
Questions About Privacy?
We're here to help. Contact our privacy team with any questions or requests.
Contact us