This Privacy Policy explains how RunPPC ("RunPPC", "we", "us") collects, uses, and protects information in connection with the RunPPC service available at runppc.com and app.runppc.com (the "Service"). RunPPC is operated by an individual entrepreneur (entreprise individuelle) registered in France; see our Mentions légales for editor details.

RunPPC is a tool for freelance and agency advertisers. Its assistant builds Google Ads campaigns, proposes changes to existing ones, and applies a change to the connected account once the advertiser approves it. It also personalizes a customer's existing landing pages to match paid-ad search intent, captures the resulting conversions, and shows a cost-per-lead (CPL) / ROI dashboard. We do not build or host our customers' landing pages.

1. Who is the controller

For account and billing data, RunPPC is the data controller.

For data captured on our customers' landing pages (i.e. data about the customers' own website visitors), RunPPC acts as a data processor (sub-contractor) on behalf of the customer, who is the controller. The terms of that processing are set out in our Data Processing Addendum.

2. Information we process

a) Account & identity data

When you sign up, our authentication provider (Clerk) processes your name, email address, and authentication metadata. We use this to create your account, workspaces, and roles.

b) Google Ads data (and, later, Microsoft/Bing Ads)

If you connect a Google Ads account, you authorize RunPPC via Google OAuth (scope https://www.googleapis.com/auth/adwords, and, where you have asked us to send your leads back to Google, https://www.googleapis.com/auth/datamanager).

What we read:

We use this to generate a suggested personalization plan for your landing pages, to build and propose Google Ads changes and apply the version you approve, to compute your real cost-per-lead (CPL) and ROI in the dashboard, and to tell you when something in your account needs attention.

What we change, and only when you tell us to:

RunPPC's assistant can build a campaign, propose changes to an existing one, and set up conversion measurement inside your Google Ads account. When you approve a proposal, RunPPC applies that exact version through the Google Ads API. We do not install or edit the conversion tracking on your own website. Nothing is ever sent to your Google Ads account without your explicit approval of that exact version. Concretely:

What we send back to Google Ads:

When you ask us to, RunPPC creates a conversion action in your Google Ads account and sends the leads our snippet captured on your own website into it, through Google's Data Manager API. Each lead is sent with the Google click identifier (gclid) recorded when that visitor arrived from your ad, the time the lead happened, and a value of 1, so the action counts leads rather than money.

This is the only thing the datamanager scope is used for. Leads are sent only to the Google Ads account you connected, only into conversion actions created for that purpose, and never to any other destination, product or third party. A lead that carries no Google click identifier is never sent, because there is nothing for Google to attribute it to.

You can stop this at any time by disconnecting your Google Ads account, and you can remove the conversion action yourself in Google Ads.

We do not create or close Google Ads accounts.

Microsoft/Bing Ads integration is not yet available ("coming soon"). When released, the same principle will apply: we propose, you approve, and only then is the change applied.

c) Landing-page visitor & conversion data (processed on behalf of our customers)

Our JavaScript snippet, when installed by a customer on their landing page, processes:

The snippet is designed to be non-blocking: personalization runs locally from URL parameters, and telemetry is sent fire-and-forget (sendBeacon / fetch keepalive). The snippet does not read the content of third-party form iframes; it relies on provider events (e.g. Typeform, HubSpot, Calendly) or the confirmation page.

d) Site & technical data

Standard server/edge logs (IP address, user agent, timestamps) for security and operation, processed by our hosting provider Cloudflare. Our marketing site uses Google Analytics 4 for audience measurement, which is loaded only after you consent: until then no analytics script is requested and no analytics cookie is set. If you refuse, no measurement data is sent to Google. Separately from that choice, our pages load typefaces from Google Fonts on every visit, which discloses your IP address and user agent to Google regardless of your cookie choice. See the Cookie Policy for the cookies, their lifetimes, the font transfer, and how to withdraw.

3. How we use information

We do not sell personal data, and we do not use Google user data for advertising.

4. Google API Services: Limited Use disclosure

RunPPC's use and transfer to any other app of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google Ads is used only to provide and improve user-facing features of the Service (the personalization plan, the campaign assistant that proposes changes and applies the ones you approve, and the CPL/ROI dashboard); it is not sold, not used for advertising, not transferred to third parties except as necessary to provide the Service or for security/legal reasons, and not used to train generalized AI/ML models.

RunPPC generates the personalization plan using Anthropic (Claude) as an AI sub-processor. Where account-structure data is transmitted to Anthropic solely to produce your plan, it is processed under contractual terms that prohibit using your data to train their models, consistent with the Limited Use requirements above.

5. How we share information (sub-processors)

We share data with vetted service providers acting on our behalf:

A current list of sub-processors is maintained in our DPA. We do not otherwise sell or rent personal data.

6. Security

7. Data retention

We retain account data while your account is active and as required for legal/accounting purposes. Conversion and metrics data are retained to power the dashboard; you can request deletion of a workspace's data. On account closure, data is deleted or anonymized within a reasonable period.

8. International transfers

Our providers may process data in the EU and the US. Where data is transferred outside the EEA, it is covered by appropriate safeguards (e.g. EU Standard Contractual Clauses).

9. Your rights

Depending on your location (incl. GDPR for EU/EEA users), you may have rights to access, rectify, erase, restrict, or port your personal data, and to object to processing. To exercise these rights, contact privacy@runppc.com. For visitor data captured on a customer's landing page, requests are directed to that customer (the controller); we assist them as processor.

10. Children

The Service is for business use and not directed to children under 16.

11. Changes

We may update this Policy. Material changes will be posted here with a new "Last updated" date.

12. Contact

RunPPC, 15 rue Jean Moulin, 69300 Caluire-et-Cuire, France. Contact: privacy@runppc.com.