Compliance

Google API Services — data use and compliance

This page describes, in English, how Marketing Workspace uses Google APIs (Google Ads API and Google Analytics APIs), what data we access, and the commitments we make about that data. It is intended both for our users and for Google reviewers.

About the tool

  • Tool: Marketing Workspace — a multi-tenant web application available at https://marketing.roition.com.
  • Developer: Roition, a Polish business-process automation agency — https://roition.com.
  • Contact: kontakt@roition.com (monitored company address).
  • Who uses it: both internal users (Roition employees and contractors managing marketing on behalf of clients) and external users (our clients — business owners and their marketing staff), each within their own isolated organization (tenant). A user only ever sees and manages Google accounts that were explicitly authorized within their own organization.
  • What it does: users connect their own Google Ads and Google Analytics 4 accounts, receive AI-assisted performance analysis, and — for Google Ads — apply recommended optimizations that they individually review and approve in the panel.

OAuth scopes we request

FeatureScopeWhy we need it
Sign-inopenid, email, profileAccount creation and authentication only. Grants no access to advertising or analytics data.
Google Ads modulehttps://www.googleapis.com/auth/adwordsReading campaign reporting data for analysis, and applying only those changes that the user has explicitly approved in the panel.
GA4 moduleanalytics.readonlyRead-only reporting. The same read-only scope is used to list the user's GA4 accounts and properties during setup; we never modify GA4 configuration.

We never ask for or store Google account passwords. Authorization uses Google OAuth 2.0; refresh tokens are encrypted at rest and scoped to the user's organization.

Scopes are requested incrementally and per module: a user who only uses the GA4 module is never asked for the Google Ads scope. When a second module is connected on the same Google account, we use incremental authorization, so the previously granted scope is preserved rather than replaced.

Sign-in, the Google Ads module and the GA4 module are served by a single OAuth client in a single Google Cloud project owned by Roition; the application refuses to start if it is configured with a client from any other project.

How we use the Google Ads API

The tool operates in two modes: analyze (read-only reporting) and optimize (applying user-approved changes). The API surface is intentionally narrow: reporting reads plus a bounded set of management operations.

  • User-initiated only. Every API call — read or write — is triggered by an action of a signed-in user. There is no scheduled crawling, bulk export, background synchronization, or autonomous optimization.
  • Human-in-the-loop writes. The AI assistant proposes a change; the user sees the exact resource, field, current value and new value, and must explicitly approve each item before anything is sent to Google. Approved changes are applied, verified by reading them back, and recorded in a per-organization audit trail (who, what, when, before → after).
  • Bounded changes. Only budgets, bids, status (pause/enable) and negative keywords can be changed. Budget and bid changes are capped per action. The tool favors pausing over deletion — the tool performs no delete/remove operations at all. Executed changes per organization are capped per day, proposals expire after 24 hours, and the live value is re-read immediately before execution (execution is withheld if it changed since the proposal). All supported changes are reversible by the account owner.
  • Manager accounts. Accounts can be connected directly or through a manager account; only enabled, non-manager accounts are offered as selectable targets.
  • Volume. Each analysis performs a small number of targeted reporting reads and each optimization applies a small number of user-approved operations — well within our access-level limits.

How we use Google Analytics APIs

  • read-only reporting queries executed when the user asks a question or generates a report,
  • listing accessible accounts and properties during setup uses the same read-only scope,
  • no write operations against GA4 configuration of any kind.

Limited Use disclosure

Marketing Workspace's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, data obtained through Google APIs is:

  • used only to provide the user-facing features described on this page (analysis, reports, user-approved optimizations),
  • shown only to the user's own authorized organization — never sold, never transferred to third parties for advertising, market research, or creditworthiness purposes,
  • never used for serving advertisements or building advertising profiles,
  • never used to train generalized artificial-intelligence or machine-learning models. Data is passed to our AI provider solely to generate the specific response requested by the user, under API terms that prohibit training on that data,
  • not read by humans at Roition, except with the user's explicit consent (e.g. a support request), for security/abuse investigation, or where required by law.

Data handling and security

  • all traffic is encrypted in transit (HTTPS/TLS),
  • OAuth refresh tokens are encrypted at rest and never exposed to the frontend or written to logs,
  • every request is authorized against the user's organization membership; cross-tenant access is prevented at the API layer,
  • role-based access within organizations (owner, admin, specialist with per-module access),
  • every applied Google Ads change is logged with before/after values and the acting user,
  • the codebase undergoes regular automated security scanning, and the service is continuously monitored and backed up.

Retention, revocation and deletion

  • Tokens: stored until the user disconnects the account in the panel or revokes access at myaccount.google.com/permissions — in both cases access ends immediately and the stored token is deleted.
  • Reports and chat history: kept for the organization while the account is active; deleted upon account deletion or on request.
  • Technical logs: retained for a limited period for security purposes, then deleted.
  • Deletion requests: kontakt@roition.com.

Related documents

  1. Privacy policy (Polish; includes the Limited Use disclosure).
  2. Terms of service (Polish).
  3. Full user documentation (Polish).