Security & trust
Built to be trusted with your accounts.
Matchfyre reads sensitive advertising data, so the security posture is part of the product,
not an afterthought. Here is exactly how it works.
Read-only Google Ads access
We connect via Google OAuth on a read-only basis (scope adwords). Matchfyre never modifies your account, places bids, or changes budgets. We read account structure and cost metrics only, to build your plan and compute CPL.
Ads tokens encrypted at rest
Google (and, later, Microsoft) OAuth tokens are encrypted at rest with AES-GCM and never stored in plaintext. Access is least-privilege and limited to operating the Service.
Tenant isolation by workspace
Every query is scoped by workspace_id. One workspace is the boundary between your clients, so data never leaks across tenants.
The snippet never blocks your page
Personalization runs locally from URL parameters. Telemetry is sent fire-and-forget (sendBeacon or fetch keepalive). The snippet is designed to fail safe and minimize what it collects.
We share data only with vetted providers acting on our behalf. The current list is also kept
in our DPA.