Privacy Policy — The Otter Place

Last updated: September 11, 2026

The Otter Place ("OtterPlace," "we," "us") is a campaign management tool used internally by our team to manage advertising campaigns, creative assets, and client work. This policy explains what data we process, why, and how — including our use of the Google Ads API.

Data controller: Otter Place, Riga, Latvia Contact: support@otterplace.eu

1. Who this policy covers

OtterPlace is an internal tool used by our own team members — it is not a public product with self-service sign-up. This policy covers:

- Our team members who have accounts in OtterPlace.

- Client contacts whose details our team enters into OtterPlace as part of managing that client's campaigns.

- Anyone who opens a creative-approval link we send them (no account or personal information required to view or respond).

2. What data we process

Team accounts: name, email address, profile photo (optional), role, and time-tracking records tied to campaign work.

Client and campaign data: client company names and contacts, campaign details, budgets, spend logs, and internal notes — entered by our team as part of day-to-day account management, not collected directly from your website or customers.

Creative approvals: when we send a client a review link for an ad creative, that page shows the creative and lets them approve or leave feedback. It does not ask for a name, email, or any account — we don't collect personal data through it beyond standard web server logs (see Section 6).

3. Our use of the Google Ads API

With a client's or our own authorization, OtterPlace connects to a Google Ads account via OAuth 2.0 to display real campaign performance inside our tool. This integration is strictly read-only:

- We only ever call Google's read endpoints (`Search`/`SearchStream`, account listing). We never call any endpoint that creates, edits, pauses, or deletes anything in a connected Google Ads account.

- Data read includes campaign performance metrics (impressions, clicks, cost, conversions), audience breakdowns (age range, gender), and — where available — asset-level performance labels.

- This data is used only to display analytics inside OtterPlace for authorized members of our team who manage that account. We do not use data obtained via Google APIs to serve advertisements, for credit scoring, or to train machine-learning or AI models.

- This data is stored in our own private database, refreshed on a schedule.

- Our team members and engineers do not read or inspect this data beyond what's needed to run the product, except where required for security, to comply with the law, or with the relevant user's explicit agreement (e.g. troubleshooting a support request).

- We do not sell this data, and we do not share it with any third party outside our own team.

- Data is retained only for as long as the Google Ads connection remains active for that account, and is deleted if the connection is removed.

- Access can be revoked at any time by removing OtterPlace's permissions from the Google Account that granted them, or via [Google Account → Security → Third-party access](https://myaccount.google.com/permissions).

OtterPlace's use and transfer to any other app of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

4. Other third-party services

We may also connect OtterPlace to other advertising or SEO platforms (e.g. Meta, LinkedIn, or SEO data providers) under the same read-only principle described above, where technically supported by that platform.

5. Legal basis for processing (GDPR)

We process team and client data on the basis of:

- Contract performance — to deliver the campaign management services our clients engage us for.

- Legitimate interest — to run our internal operations (time tracking, task management, reporting).

- Consent — where a Google Ads (or other platform) connection is authorized by the account owner.

6. Infrastructure, authentication & security

- Authentication: team members sign in with an authentication token stored in their browser (not a tracking cookie), used solely to keep them logged in. We don't use advertising or analytics cookies.

- Passwords: stored hashed, never in plain text.

- Server logs: standard technical logs (IP address, timestamp, requested page) are kept only as long as needed for security and troubleshooting.

- Access control: client and campaign data is only accessible to authenticated team members.

7. Your rights

If you are an EU/EEA resident whose data we process, you have the right to request access to, correction of, or deletion of your data, to object to or restrict processing, and to receive a copy of your data in a portable format. To exercise any of these, contact us at support@otterplace.eu. You also have the right to lodge a complaint with your national data protection authority (in Latvia: the [Data State Inspectorate](https://www.dvi.gov.lv/)).

8. Data retention

We retain team and client data for as long as the business relationship continues, plus any period required by law (e.g. accounting records). Data tied to a specific campaign or platform connection is removed when that connection is deactivated.

9. Changes to this policy

We may update this policy as OtterPlace's features change. Material changes will be reflected by updating the date at the top of this page.

10. Contact

Questions about this policy or your data: support@otterplace.eu