Privacy Policy
Last updated: 9 September 2026
This policy explains what personal data AssistPPC collects when you use the Service, why we collect it, who we share it with, and what rights you have over it. It applies to app.assistppc.com and the AssistPPC feed sync service.
1. Who we are
The data controller is AssistPPC Group Ltd, a company registered in England & Wales (company no. 14555473), registered address Saxon House, 27 Duke Street, Chelmsford, England, CM1 1HT (“we”, “us”, “our”).
For any privacy question, or to exercise your rights, contact help@assistppc.com.
2. What we collect
2.1 Account data
When you create an account we collect your name, email address and, if you sign up with a password, a hashed password (we never store the password itself). If you sign in with Google we instead store your Google account identifier and the email address Google returns, and we record that the address is verified. We also record the date your account was created.
2.2 Connected account data
If you connect a Google Merchant Center account, we store the OAuth access and refresh tokens Google issues, the scope granted, and the email address of the Google account used. Tokens are encrypted at rest and are used only to read your Merchant Center product data on your behalf. We also store the Merchant Center account ID and account name you select.
Where you connect a source by feed URL instead, we store that URL. Where you supply SFTP destination credentials or an OpenAI Ads API key, those are stored encrypted at rest and used only to push your feed and to create ad groups at your instruction.
2.3 Feed and product data
We fetch, store and process the product data from the source you connect — titles, descriptions, prices, availability, images, identifiers and other attributes — along with any manual overrides and ad group configuration you create. This is normally business data about products rather than personal data, but it is your content and we treat it as confidential. It is stored so we can build, validate and push your feed on a schedule.
2.4 Billing data
Subscriptions are handled by Stripe. Card details are entered directly with Stripe and never reach our servers. We store the Stripe customer ID, subscription status and the identifiers of billing events, so we know which feeds are active.
2.5 Technical and usage data
Our servers keep application and error logs containing timestamps, the action performed, feed and user identifiers, and error messages. Our hosting provider keeps standard web server logs, which include IP addresses. We also collect analytics about how the site is used — see section 5.
3. Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and securing your account; signing you in | Account data | Performance of a contract |
| Building your feed and pushing it to OpenAI; creating ad groups at your request | Connected account data, feed and product data | Performance of a contract |
| Taking payment and managing subscriptions | Account data, billing data | Performance of a contract |
| Keeping records for accounting and tax | Billing data | Legal obligation |
| Diagnosing faults, preventing abuse, securing the Service | Technical data, logs | Legitimate interests (running a secure, working service) |
| Service emails about your account, feeds or billing | Account data | Performance of a contract |
| Analytics and measuring which pages and sign-up routes work | Usage data, cookies | Consent |
We do not sell your personal data, and we do not use your product data to train models or to build advertising audiences of our own.
4. Who we share it with
We share data only with the providers needed to run the Service:
- OpenAI — your built product feed is transmitted to OpenAI over SFTP, and ad group requests are sent to the OpenAI Ads API, so your products can appear on OpenAI surfaces. This is the core purpose of the Service.
- Google — for sign-in and to read your Merchant Center data through the Merchant API, and for analytics and tag management (see section 5).
- Stripe — payment processing and subscription management.
- Our hosting provider — servers and storage on which the Service runs.
- myWebhero — our operating agency, which provides site analytics and technical support and may access data in the course of maintaining the Service.
We may also disclose data where required by law, to enforce our Terms, or in connection with a sale or reorganisation of the business.
5. Cookies and analytics
Essential cookies. We set a session cookie named assistppc. It keeps you signed in and protects forms against cross-site request forgery. It is secure, HTTP-only and expires when you close your browser. The Service cannot work without it, so it is not subject to consent.
Analytics. We use Google Tag Manager, which loads Google Analytics, and an analytics script provided by myWebhero. These set cookies and record pages viewed, referrer, approximate location derived from IP address, device and browser type, and key actions such as creating an account, creating a feed, pushing a feed and completing a subscription. These events are sent with an internal identifier and are used to understand which parts of the product and which sign-up routes work; we do not send your name, email address or product data to analytics.
Fonts. Pages load a webfont from Google Fonts, which means your IP address is disclosed to Google when a page renders.
You can block or delete cookies in your browser, and can opt out of Google Analytics using Google's browser add-on. Blocking analytics cookies does not affect your use of the Service.
6. International transfers
OpenAI, Stripe and Google process data outside the UK, principally in the United States. Where personal data is transferred outside the UK we rely on the UK Government's adequacy regulations where they apply, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards including encryption in transit.
7. How long we keep it
- Account data — for as long as your account is open, and for up to 12 months after you close it, so we can deal with any follow-up query.
- Feed and product data — deleting a feed removes its stored products, overrides and ad group configuration. Product data is otherwise refreshed on each sync rather than accumulated.
- Connected credentials — OAuth tokens, SFTP credentials and API keys are deleted when you disconnect the source, delete the feed, or close your account. You can also revoke our access to your Google account at any time from your Google account permissions page.
- Billing records — six years from the end of the accounting period, as required by UK tax law.
- Application and server logs — typically up to 12 months.
8. Security
The Service is served over HTTPS. Passwords are stored as salted hashes and are never recoverable. OAuth tokens, SFTP passwords and API keys are encrypted at rest with a key held outside the database. Access to production systems is restricted to the people who need it. No system is perfectly secure, but we take these measures seriously and will notify you and the ICO where we are legally required to do so after a breach.
9. Your rights
Under UK data protection law you have the right to: access a copy of your personal data; have inaccurate data corrected; have your data erased; restrict or object to processing; and receive your data in a portable format. Where we rely on consent, you can withdraw it at any time.
To exercise any of these rights — including deleting your account and the data associated with it — email help@assistppc.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
10. Children
The Service is for businesses and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. Material changes will be notified by email or in-app before they take effect.
12. Contact
Privacy questions and rights requests: help@assistppc.com, or write to AssistPPC Group Ltd, Saxon House, 27 Duke Street, Chelmsford, England, CM1 1HT.
See also our Terms & Conditions.