How Your Google Ads Data is Protected

We take access seriously. Here's exactly what we can and cannot do.

Read Access vs Write Access

Having a key to view your bank balance is different from having a key to transfer funds.

Analyse

All plans

All connections use the same Google Ads API scope. viaCMO reads campaigns, keywords, conversions, and change history to generate reports and grades.

Execute

Action plan only

VIA sessions can execute approved changes via the API. Changes are queued, reviewed in a batch summary, and only run after you click CONFIRM.

What viaCMO Can See

Campaigns, ad groups, keywords, ads
Audiences and targeting settings
Conversion tracking configuration
Performance metrics (impressions, clicks, conversions, costs)
Change history (who changed what, when)

This is Google Ads data only. The same data you'd see in your own Google Ads dashboard.

What viaCMO Cannot See

Billing information or payment methods
Customer personal data or email addresses
Google Analytics (GA4) data
Gmail, Google Drive, or other Google services
Any data outside your Google Ads account

Our OAuth scope is limited specifically to Google Ads. We cannot access any other Google service.

How Write Access Works

VIA sessions can execute changes in your account, and are only available on Action and Agency plans. Nothing executes without your confirmation of the full batch.

1VIA presents a recommendation with evidence
2You decide what happens with each recommendation
3After all decisions, you confirm or deny the full batch
4VIA re-validates every change against your live account before executing. Stale changes are blocked automatically

Nothing runs until you click CONFIRM. Not a single keyword. Not a single bid change.

Revoke Access in 10 Seconds

You control access. Remove viaCMO anytime through your Google account settings.

1Go to myaccount.google.com
2Navigate to Security → Third-party apps
3Find viaCMO and click "Remove Access"

Once revoked, we can no longer read any data from your account. Your historical reports remain in your dashboard.

How Your Data is Stored

Encrypted credentials

AES-256

OAuth tokens encrypted at rest by our database infrastructure

Account isolation

Isolated

Data locked to your user account, inaccessible to others

Enterprise infrastructure

SOC 2

Supabase (database), Vercel (hosting), both SOC 2 compliant

TLS 1.3

TLS 1.3

All connections encrypted in transit

Australian Privacy Law

viaCMO complies with the Australian Privacy Act 1988.

Collect only data necessary to provide the service
Never sell, share, or use your data for advertising
Delete your data on request. Email support@viacmo.com.au

Questions About Security

Find Out What Your Google Ads Are Actually Doing

Free 25-point health check. No credit card. Results in minutes.

Get Your Free Audit

Nothing changes without your approval.