Product Guides

Ads data & deletion

What Meta and Google Ads data Blind Spot uses, how it is protected, and how to disconnect or request deletion.

Updated 2026-08-16Edit on GitHub

The short version

Ads Guardrails uses the minimum account and campaign information needed to let you select an explicit allowlist and safely pause or recover those campaigns during a verified incident. It does not use provider data for ad targeting, audience building, resale, data brokerage, or cross-merchant advertising benchmarks.

What Blind Spot uses

Meta Ads

  • Your connecting Meta user ID and display name
  • Accessible ad-account ID and name
  • Campaign ID, name, status, and effective status
  • The account, campaigns, and Blind Spot trigger monitors you select
  • Encrypted access token and token expiration
  • Shadow/Armed mode, consent, kill-switch, pause, recovery, and audit state
  • Google Ads customer IDs directly accessible to the connecting user
  • Campaign ID, name, and status
  • The customer, campaigns, and Blind Spot trigger monitors you select
  • Encrypted refresh token
  • Shadow/Armed mode, consent, kill-switch, pause, recovery, and audit state

Google requests offline access because Blind Spot monitoring and incident recovery run in the background when you may not be using the app.

What Blind Spot does not need

Blind Spot does not need or intentionally collect:

  • ad creative, images, or ad copy;
  • audiences or audience membership;
  • leads or advertising end-user personal data;
  • clicks or conversion records;
  • budgets, bids, keywords, or targeting; or
  • Google profile data.

How credentials are protected

  • OAuth happens through the provider's authorization flow.
  • Tokens are handled server-side and encrypted at rest using AWS Key Management Service.
  • Stored tokens are not returned to the browser after connection.
  • The merchant's authenticated Shopify shop scopes the connection.
  • Background workers decrypt credentials only when a provider request is required.

Disconnect Meta or Google Ads

  1. 1

    Recover any Blind Spot-paused campaigns

    Open Automations. If the provider card shows campaigns Blind Spot paused, request recovery and confirm they are active. The app blocks disconnect while that recorded paused set remains.

  2. 2

    Disable and disconnect

    Disable the automation and choose Disconnect. Blind Spot requests provider-side token revocation and removes the active provider connection, including its encrypted token and selected account/campaign configuration.

  3. 3

    Revoke at the provider

    Verify BlindSpot Monitor no longer appears in your Google Account third-party connections or Meta Business Integrations. If provider revocation could not be confirmed, remove it there.

Limited incident action metadata may remain where needed for security, support, legal compliance, or proof of prior authorized activity. It does not contain your provider credential.

Request deletion

Email support@blindspotapps.com from an address associated with your business. Include your Shopify shop domain, the provider involved, and whether you want a specific connection or the shop's eligible data deleted. Never send a password, token, client secret, or recovery code.

See the public Privacy Policy and Data Deletion instructions for the complete disclosure.

Google Limited Use

Blind Spot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Was this page helpful?

Ask AI anything