GhostClicks helps advertisers identify invalid clicks on their Google Ads campaigns. This policy explains what we collect, why, and what we do not do with it. We have written it to be read, not to be skimmed past.
Two different groups, with different data:
When our measurement tag runs on a customer's landing page, it records signals about the visit. It does not record anything typed into a form.
| Category | Examples | Why |
|---|---|---|
| Ad attribution | Google click identifier (gclid), campaign and source parameters, referring page | To connect a visit to the paid click that produced it |
| Device configuration | Browser and version, screen size, timezone, language, graphics renderer, a hash derived from canvas rendering | To recognise when the same device returns repeatedly |
| Behaviour counts | Number of mouse movements, number of keystrokes, scroll depth reached, time on page | To distinguish an automated script from a person reading the page |
| Network | IP address, and the network operator it belongs to | To identify hosting and VPN origins, and to build exclusion lists |
What we deliberately do not collect.
Our measurement tag does not set cookies and does not use browser storage. Each visit is assessed on its own, using a device fingerprint derived from configuration values the browser already exposes to every website.
With the customer's explicit authorisation through Google's standard consent screen, we access their Google Ads account using the Google Ads API. We ask for the minimum needed to do the job:
We do not create, pause, or edit campaigns; we do not change budgets or bids; and we do not access billing or payment details in the advertising account. Access can be withdrawn at any time from Google Account permissions, which immediately stops all access.
Google API Services User Data Policy. GhostClicks' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with the customer's explicit permission, for security purposes, or where required by law.
Name, work email, company name, and a password stored only as a salted hash — we cannot see or recover it. Payments are processed by Razorpay; card and UPI details go directly to them and never reach our servers.
We do not sell data. We share it only with services required to operate:
We also disclose data where required by law, and will tell the affected customer unless prohibited from doing so.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay, along with what happened and what we are doing about it.
Under India's Digital Personal Data Protection Act, 2023, you may request access to your data, correction of inaccuracies, deletion, or withdrawal of consent. Write to support@ghostclicks.in and we will respond within 30 days.
If you are a visitor to a customer's website rather than a customer yourself, that business decides what happens to data collected on its site. Contact them first; we will assist them in responding to you.
If you install our measurement tag, you are responsible for disclosing it in your own privacy policy and obtaining any consent your jurisdiction requires. We will provide wording you can adapt.
If we make a material change we will email account holders before it takes effect. The date at the top of this page always reflects the current version.
Krent Enterprises
Hyderabad, Telangana, India
Grievance Officer: Deepti
support@ghostclicks.in