Legal
Privacy Policy
GhostClicks helps advertisers identify invalid clicks on their Google Ads campaigns. This policy explains what we collect, why, and what we do not do with it. We have written it to be read, not to be skimmed past.
1. Who this covers
Two different groups, with different data:
- Our customers — advertisers and agencies who create a GhostClicks account.
- Visitors to our customers' websites — people who click an ad and land on a page carrying our measurement tag. We act as a processor on our customer's behalf for this data.
2. What we collect from website visitors
When our measurement tag runs on a customer's landing page, it records signals about the visit. It does not record anything typed into a form.
| Category | Examples | Why |
|---|---|---|
| Ad attribution | Google click identifier (gclid), campaign and source parameters, referring page | To connect a visit to the paid click that produced it |
| Device configuration | Browser and version, screen size, timezone, language, graphics renderer, a hash derived from canvas rendering | To recognise when the same device returns repeatedly |
| Behaviour counts | Number of mouse movements, number of keystrokes, scroll depth reached, time on page | To distinguish an automated script from a person reading the page |
| Network | IP address, and the network operator it belongs to | To identify hosting and VPN origins, and to build exclusion lists |
What we deliberately do not collect.
- The content of anything typed. We count keystrokes. We do not record which keys, so names, phone numbers, emails and messages typed into forms never reach us.
- Names, email addresses or phone numbers of website visitors.
- Payment or financial information of website visitors.
- Browsing activity on other websites. Our tag only runs on pages where our customer has installed it. We do not track people across the web.
- Screen recordings or session replay. We do not reconstruct what a visitor saw or did.
Cookies
Our measurement tag does not set cookies and does not use browser storage. Each visit is assessed on its own, using a device fingerprint derived from configuration values the browser already exposes to every website.
3. What we access in a customer's Google Ads account
With the customer's explicit authorisation through Google's standard consent screen, we access their Google Ads account using the Google Ads API. We ask for the minimum needed to do the job:
- Read: campaign performance, spend, click counts, Google's own invalid-click figures, search terms, and click identifiers.
- Write (only where the customer enables blocking): IP exclusions on campaigns the customer has nominated.
We do not create, pause, or edit campaigns; we do not change budgets or bids; and we do not access billing or payment details in the advertising account. Access can be withdrawn at any time from Google Account permissions, which immediately stops all access.
Google API Services User Data Policy. GhostClicks' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with the customer's explicit permission, for security purposes, or where required by law.
4. What we collect from customers
Name, work email, company name, and a password stored only as a salted hash — we cannot see or recover it. Payments are processed by Razorpay; card and UPI details go directly to them and never reach our servers.
5. How long we keep data
- Click and visit data: 13 months, then deleted.
- Account data: for the life of the account, then deleted within 90 days of closure.
- Invoices: retained as long as Indian tax law requires.
6. Who we share it with
We do not sell data. We share it only with services required to operate:
- Google — to read campaign data and apply exclusions the customer has authorised.
- Razorpay — payment processing.
- Our hosting provider — DigitalOcean, Bangalore, India.
- MaxMind — if enabled, to identify the network an address belongs to.
We also disclose data where required by law, and will tell the affected customer unless prohibited from doing so.
7. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed with a per-user salt using a deliberately slow algorithm.
- IP addresses are additionally stored as salted hashes.
- Each customer's data is isolated; every request is checked against account ownership.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay, along with what happened and what we are doing about it.
8. Your rights
Under India's Digital Personal Data Protection Act, 2023, you may request access to your data, correction of inaccuracies, deletion, or withdrawal of consent. Write to support@ghostclicks.in and we will respond within 30 days.
If you are a visitor to a customer's website rather than a customer yourself, that business decides what happens to data collected on its site. Contact them first; we will assist them in responding to you.
9. For our customers: your obligations
If you install our measurement tag, you are responsible for disclosing it in your own privacy policy and obtaining any consent your jurisdiction requires. We will provide wording you can adapt.
10. Changes
If we make a material change we will email account holders before it takes effect. The date at the top of this page always reflects the current version.
Plain-English summary of the same ground: what we can and can’t see. Questions? support@ghostclicks.in · Terms of Service