Legal · Google API
Google API Services User Data Policy Disclosure
Last updated: 19 September 2026 · Version 2026-09-19
This disclosure describes exactly what Lucreo accesses through the Google Ads API and the Google Merchant Center API, how that data is used and stored, and how you can revoke access. It forms part of our Privacy Policy.
1. Limited Use commitment
Lucreo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Lucreo is operated by Advance and Beyond LLC. This page is the authoritative description of how Lucreo accesses, uses, stores and shares Google user data, and supplements our Privacy Policy.
2. Scopes we request and why
| Scope | Why Lucreo needs it |
|---|---|
https://www.googleapis.com/auth/adwords | Read-only reporting access to the Google Ads accounts you select: to list the accounts your login can reach, and to run reporting queries that return product-level cost, impressions, clicks, conversions and conversion value plus Merchant Center offer identifiers. This is the minimum scope Google publishes for the Google Ads API; Google does not offer a narrower read-only variant. |
https://www.googleapis.com/auth/content | Requested only if you choose to connect Google Merchant Center, and added incrementally so your existing Google Ads authorisation is not disturbed. Lucreo uses it to list the Merchant Center accounts and sub-accounts your login can reach, to read the configuration of your primary product feeds (feed label, content language and target countries), and to read product (offer) identifiers so advertising spend can be attributed to the right feed and market. This is the only Merchant Center scope Google publishes; there is no read-only variant. Google classifies this scope as sensitive, so Lucreo's use of it is subject to Google's OAuth app verification review. This scope grants both read and write access to your Merchant Center account. Lucreo performs read operations only today. A later feature will use write access to apply changes such as per-offer country exclusions, and only when you explicitly request a specific change in Lucreo — never automatically, never in the background, and never as part of a routine sync. |
openid, email | Only when you choose "Continue with Google" to sign in: to identify your Lucreo account by email address. Not requested by the Google Ads connection flow. |
Although the adwords scope technically permits writes, Lucreo issues read-only reporting queries exclusively. Lucreo never creates, edits, pauses or deletes campaigns, ad groups, ads, keywords, bids, budgets or conversion settings, and never spends money on your behalf.
The content scope likewise grants write access. Lucreo currently issues read requests only: it does not create, edit or delete products, feeds, supplemental data sources, exclusions or account settings in Merchant Center. Any future write will be tied to an explicit action you take in Lucreo for a change you have reviewed. Because Google treats this scope as sensitive, Lucreo's Merchant Center connection is reviewed by Google under its OAuth verification process before it is made generally available.
3. Data accessed from Google
- The list of Google Ads customer IDs accessible to the authorising login, and whether each is a manager account.
- The customer ID, descriptive name, currency and time zone of the account you select.
- Product-level shopping performance: Merchant Center offer (product) ID, product title, brand, product type, and the metrics cost, impressions, clicks, conversions and conversion value, aggregated over 7, 14, 30 and 90-day windows.
- Account-level daily totals for cost, clicks, impressions, conversions and conversion value, for trend charts.
- If you connect Merchant Center: the account and sub-account IDs and names your login can reach; for each primary product feed its resource name, display name, feed label, content language and the target countries Merchant Center declares; and product (offer) identifiers with the feed they belong to. Lucreo does not mirror your product catalogue content, and reads no customer, order or personal data from Merchant Center.
- The OAuth refresh tokens and short-lived access tokens issued to Lucreo. The Google Ads and Merchant Center refresh tokens are stored as separate records so either can be deleted without affecting the other.
4. How Google user data is used
Google Ads data is used solely to provide the user-facing features you signed up for:
- matching advertising spend to Shopify products and variants;
- computing true profit, margin, break-even ROAS and contribution per product;
- surfacing underperforming products and profit-and-loss reporting in your workspace;
- displaying spend, ROAS and conversion trends on your dashboards.
We do not:
- transfer, sell, license or rent Google user data to third parties;
- use it for advertising, retargeting, audience building or lead generation;
- use it to train, fine-tune or improve generalised artificial intelligence or machine learning models, or allow any third party to do so;
- allow humans to read it, except with your explicit permission for a support request you raise, where required by law, for security investigations, or on aggregated anonymised data used for internal operations;
- combine it with data from other Lucreo customers.
5. Storage, security and isolation
- Your Google OAuth refresh token is encrypted at rest with AES-256-GCM under a key held outside the database as a managed secret. It is decrypted in memory only, inside a server-side job, for the duration of an API call.
- Tokens are never transmitted to the browser and never appear in logs or error messages.
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Reporting data is stored in a managed PostgreSQL database with row-level security, so a request can only reach rows belonging to workspaces the authenticated user is a member of.
- Connection and disconnection events are recorded in an append-only audit log.
7. Revoking access and deleting Google data
You can end Lucreo's access to your Google Ads or Merchant Center data at any time, in either direction:
- In Lucreo: go to Connections and choose Disconnect on the Google Ads card. This deletes the encrypted refresh token immediately and stops all future syncs. Disconnecting Merchant Center deletes only the Merchant Center token and stops only its jobs; your Google Ads connection keeps working. Neither action revokes Lucreo's access at Google — use the step below for that.
- In your Google Account: visit myaccount.google.com/permissions, select Lucreo and choose Remove access. Existing tokens become invalid instantly.
Performance data already imported into your workspace remains available to you so your historical reporting stays intact. To have it erased, delete your account or email privacy@lucreo.io — see the data deletion page. Deletion completes within 30 days, with encrypted backups purged within 90 days.
8. Retention of Google user data
- Refresh tokens (Google Ads and, separately, Merchant Center): until you disconnect that connection, revoke access at Google, or delete your account.
- Merchant Center account, feed and offer-mapping records: until you disconnect Merchant Center, at which point they are deleted with the connection.
- Access tokens: held in memory for the life of a request; never persisted.
- Reporting data: retained while your account is active; deleted within 30 days of account deletion.
- Encrypted backups: purged within 90 days.
9. Questions
For questions about this disclosure or Lucreo's Google API usage, email privacy@lucreo.io. See also our Privacy Policy, Terms of Service and security overview.