1. Scope and operator
This policy applies to HeyJinn Marketing Manager (the “Service”), a private paid-media operations platform provided by HeyJinn for authorized business users. It covers the public website, authenticated workspace, and integrations used to plan, approve, publish, schedule, and monitor advertising campaigns.
Questions or privacy requests can be sent to ben@heyjinn.com.
2. Information we collect
Depending on how the Service is used, we process the following categories:
- Account and access data: business email address, user role, company membership, authentication session records, and security/audit events.
- Campaign operations data: plans, approvals, creative files and copy, schedules, budgets, campaign mappings, upload status, and operational notes.
- Google Ads integration data: OAuth authorization, Google Ads customer and manager account identifiers, campaign and ad-group identifiers, advertising asset and ad identifiers, status information, timestamps, and sanitized API responses needed to operate or troubleshoot the integration.
- Technical data: IP address and request metadata used for security, rate limiting, reliability, and error diagnosis. We do not intentionally log OAuth tokens, passwords, client secrets, or raw authorization headers.
3. Google API data and permissions
The Service requests the Google Ads permission scope https://www.googleapis.com/auth/adwords. An authorized user grants this access through Google OAuth. The Service uses the authorization only to manage Google Ads accounts that the user already has permission to access.
Specifically, the integration may:
- upload approved image and video assets;
- create or locate campaign-related assets, ad groups, and ads;
- activate, pause, or otherwise update advertising delivery status;
- read the identifiers and status responses required to confirm those actions; and
- retain operational results so authorized users can audit and troubleshoot publishing.
The Service does not use the Google Ads authorization to access Gmail, Google Drive, contacts, calendars, or unrelated Google profile content. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
4. How we use information
- provide and secure the authenticated Marketing Manager workspace;
- prepare, review, approve, publish, schedule, and monitor paid-media activity;
- authenticate with connected advertising platforms and perform user-requested actions;
- prevent duplicate publishing, enforce permissions, and maintain an operational audit trail;
- diagnose failures, protect the Service from abuse, and improve reliability; and
- comply with legal obligations and enforce applicable agreements.
5. Storage, security, and retention
OAuth client credentials and refresh tokens are stored in access-controlled server configuration and are not exposed to the browser. Short-lived access tokens are generated server-side as needed. Operational campaign records are stored in the Service database and creative files are stored in controlled application storage.
We use access controls, company-scoped authorization, encrypted network transport, secret redaction, and restricted server access to protect information. No system can guarantee absolute security, but we review and limit access according to operational need.
Integration credentials are retained until they are replaced, revoked, or the integration is disconnected. Campaign and audit records are retained while needed for the business workflow, security, troubleshooting, or legal obligations, and are deleted or de-identified after the applicable business need ends or following a valid deletion request, subject to backup and legal-retention requirements.
6. Sharing and disclosure
We do not sell personal information or Google user data.
Information is shared only as necessary with:
- Google and connected advertising platforms to perform actions explicitly requested through the Service;
- infrastructure providers that host or secure the Service under appropriate confidentiality and data-protection obligations;
- authorized members of the applicable business workspace according to their assigned roles; or
- legal or safety recipients when required by law or reasonably necessary to protect rights, users, or the Service.
7. Your choices and deletion requests
You can revoke HeyJinn's Google authorization at any time from your Google Account third-party connections. Revocation prevents future Google Ads API access but does not automatically delete campaign records already required for audit, security, or legal purposes.
To request access, correction, disconnection, or deletion of information controlled by HeyJinn, email ben@heyjinn.com. We may need to verify the requester's identity and authority over the relevant workspace before fulfilling a request.
8. Cookies and public pages
The public homepage and this policy do not require an account. The authenticated application uses a secure session cookie to keep signed-in users authenticated. We do not use the public pages for behavioral advertising or cross-site tracking.
9. Children, international use, and changes
The Service is a business tool and is not directed to children. Users and connected advertising accounts may be located in different countries, so information may be processed where the Service and its providers operate, subject to applicable safeguards.
We may update this policy when the Service, integrations, or legal requirements change. The current version and effective date will remain available at this URL.