Privacy Policy
Version 3.1 · Effective August 24, 2026 · Applies to all users of Bidhelm
We do not sell your personal data. We do not share it with advertisers. We only use it to provide the Service.
1. Who We Are
Bidhelm (“Bidhelm,” “we,” “us,” “our”) operates the Bidhelm platform, an AI-powered Google Ads optimization service accessible at bidhelm.com.
We act in two different roles, and which one applies depends on whose data it is.
- Our customers' data - we are the controller. Your account details, your Google Ads data, how you use the platform. We decide what is collected and why, and this policy governs it.
- Your customers' data - we are the processor and you are the controller. If you use a hosted landing page with a form, the people who fill it in are your prospects, not ours. You decide why their details are collected; we hold and forward them on your instructions. That relationship is governed by the Data Processing Addendum, not by this policy, and Section 3.1 below describes what we do with those details.
Privacy contact: privacy@bidhelm.com
2. Information We Collect
2.1 Account Information
- Email address and name (required for account creation)
- Company name (optional)
- Payment information - processed and stored by our payment provider; Bidhelm does not store full card details
2.2 Google Ads Data
When you connect your Google Ads account, we access and store:
- Campaign performance metrics (impressions, clicks, conversions, spend)
- Keyword and search term performance data
- Ad group, asset group, and campaign structure
- Asset and creative metadata (headlines, descriptions, image and video references, performance labels)
- Budget and bidding configuration
- Geographic and demographic targeting settings
- Performance Max channel and listing-group breakdowns (Search, Shopping, Display, YouTube)
- OAuth 2.0 access tokens (see Section 6)
2.3 Google Merchant Center Data (optional)
If you connect a Google Merchant Center account - required only to unlock Shopping and Performance Max product-feed optimization - we additionally access and store:
- Merchant Center account identifier and the linked Google Ads customer ID
- Product feed metadata (product titles, descriptions, prices, brands, categories, product IDs)
- Product status and disapproval reasons reported by Merchant Center
- Per-product performance from Shopping and Performance Max campaigns (impressions, clicks, cost, conversions)
Connecting Merchant Center is optional. You may use Bidhelm without it. The grant is requested through Google's incremental OAuth flow, scoped only to the Content for Shopping data described above, and can be revoked at any time at myaccount.google.com/permissions.
We do not access: your Google billing or payment methods, any Google service outside of Google Ads and (where you connect it) Merchant Center, your Google account password, or the visitors to your own website - we place nothing on it and read nothing from it beyond publicly available page content used to understand your business.
We do handle personal data about people who complete a form on a landing page we host for you. That is described in Section 2.6 and Section 3.1, and it is the one case where we are your processor rather than a controller.
2.4 Usage & Technical Data
- Platform usage patterns and feature interactions
- Log data including IP addresses, browser type, and timestamps
- Device information
- Optimization actions applied to your account and their recorded outcomes
2.5 Communications
If you contact us by email or chat, we retain those communications for support and compliance purposes.
Instructions you give the in-product assistant, and the context it keeps about your account between conversations, are stored with your account and retained on the same terms as the rest of your account data (Section 8). You can see and remove what it has kept, in the dashboard.
2.6 Leads Captured on a Hosted Landing Page (your data subjects)
Where we host a landing page for you and it carries a form, we store what the visitor submits so that you can act on it:
- The details they type - typically name, email address, phone number, company, message
- The Google advertising click identifier that brought them to the page
- Whether they agreed to be contacted, whether they separately agreed to advertising measurement, the exact wording they agreed to, and when
- Their IP address, used to rate-limit submissions and reject automated spam
You are the controller of this data and we are your processor. We do not use it for our own purposes, do not market to these people, and do not sell or share it beyond what Section 3.1 describes. It is held under the Data Processing Addendum, and it is deleted when you delete the page, the lead, or your account.
3. How We Use Your Information
- Providing the Service: Analyzing campaigns, generating recommendations, executing optimizations across Search, Shopping, and Performance Max - including channel and listing-group adjustments and product-feed health checks where Merchant Center is connected (Google Ads data, Merchant Center data, account data)
- Billing: Subscription management (account data, usage data, spend figures)
- Improvement: Improving Bidhelm's user-facing optimization features using aggregated, de-identified data only
- Notifications: Telling you what happened on your account. These are shown in the dashboard - the Service sends no lifecycle, report, or marketing email. Your email address is used to sign you in, to invite you to an organization, and to reach you about support or a legal or security matter
- Support: Customer support (account data, communications)
- Security: Fraud prevention and legal compliance (all data types as necessary)
Google user data: We may use aggregated and de-identified optimization outcome data to improve Bidhelm's user-facing optimization features. We do not sell Google user data and do not use it for advertising purposes. Google user data accessed through the Google Ads API is used solely to provide and improve the Service features you have authorized.
3.1 AI Model Providers
The Service is built on large language models, and it cannot analyse your account or write anything for you without sending the relevant material to the model. So, plainly:
- Account data is sent to third-party AI providers to be processed. Depending on the task, this can include campaign and keyword performance, search terms, spend figures, your website's public content, and your instructions in chat. The providers are named on the Sub-processors page.
- It is not used to train their models. We use these providers under enterprise API terms that prohibit training on the data we send, and we do not train models of our own on your data or on Google user data.
- Nothing is sent for advertising purposes, and no personal data about your leads is sent to a model as part of processing a form submission.
“Processed but not trained on” is the distinction that matters here, and we state it this way round because the first half is what an earlier version of this policy failed to say.
We do not use your data for advertising profiling, selling to third parties, or any purpose not listed above.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data under the following legal bases:
- Contract performance - processing necessary to provide the Service you subscribed to (primary basis)
- Legitimate interests - platform improvement, fraud prevention, and security, where not overridden by your rights
- Legal obligation - compliance with applicable laws
- Consent - for optional communications and non-essential cookies; withdrawable at any time without affecting prior processing
5. Data Sharing
We do not sell, rent, or trade your personal information. We share data only in these limited circumstances:
- Service providers: Trusted vendors processing data on our behalf (hosting, payment processing, analytics, customer support), each bound by data processing agreements restricting use to the specified service only.
- Google: Data sent to Google APIs as necessary to read and write your Google Ads account per your authorization.
- Legal requirements: When required by valid legal process, court order, or applicable law. We notify you where legally permitted.
- Business transfers: If Bidhelm is acquired or merges, data may transfer to the successor. We will notify users of any such change.
6. Authentication Tokens & Credentials
To maintain access to your Google Ads account - and, if you connect it, your Google Merchant Center account - Bidhelm stores OAuth 2.0 access and refresh tokens issued by Google. These allow the Service to operate without requiring re-authentication on every action.
Bidhelm requests the minimum scopes needed for the features you use:
- Google Ads - required for all users; permits reading and writing campaigns, assets, and budgets on accounts you authorize
- Content for Shopping - optional; granted separately through Google's incremental authorization flow when you connect Merchant Center; permits reading product feed and per-product performance data
- We store only the OAuth token - never your Google account password
- Tokens are held in a managed database that is encrypted at rest, are never exposed to the browser, and are transmitted only over TLS. The Security page sets out the measures in full
- You may revoke either scope independently at any time at myaccount.google.com/permissions
- All stored tokens are permanently purged upon account deletion
7. Data Security
We implement industry-standard security including TLS/SSL for data in transit, encryption at rest for sensitive data, access controls limiting data to authorized personnel, and regular security monitoring. No method of transmission or storage is 100% secure. In the event of a personal data breach affecting your rights, we will notify affected users without undue delay and within the timeframes required by applicable law - including notification to relevant supervisory authorities within 72 hours where required under GDPR, and to affected California residents in accordance with CCPA breach notification requirements.
8. Data Retention
- Active accounts: Retained for the duration of your account and for 12 months after your last active use
- Cancelled accounts: Cancelling a plan stops the Service; it does not by itself delete anything. Your data is kept so that you can come back to it, and campaign history stays available for at least 30 days. To have it deleted, ask us - see the next line. Anonymized aggregate data may be retained longer for platform analytics.
- Deletion requests: Email privacy@bidhelm.com from the address on the account and we delete it, along with the stored Google tokens, within 30 days. You do not have to cancel first and you do not have to give a reason.
- Legal hold: Certain data may be retained longer if required by law or for legitimate legal defense
- Payment records: Retained 7 years as required by financial regulations
9. Your Rights
Regardless of location, you have the right to: access a copy of your data, correct inaccurate data, request deletion of your account and data, request data in a machine-readable format, disconnect Google Ads access at any time, and unsubscribe from non-essential communications. Email privacy@bidhelm.com to exercise any right - that address is the route for all of them, and we respond within 30 days. Disconnecting Google Ads is immediate and self-serve, at myaccount.google.com/permissions or in your dashboard.
10. GDPR - European Users
If you are in the EEA, United Kingdom, or Switzerland, you have additional rights under GDPR:
- Right to object to processing based on legitimate interests
- Right to restrict processing in certain circumstances
- Right to withdraw consent where processing is consent-based, at any time
- Right to lodge a complaint with your local supervisory authority
International transfers: Where we transfer your personal data outside the EEA or UK, we do so under Standard Contractual Clauses (SCCs) approved by the European Commission. We do not rely on consent as a transfer mechanism. If we later certify to the EU-US Data Privacy Framework, this policy will be updated accordingly.
11. CCPA - California Users
If you are a California resident, the CCPA as amended by CPRA grants you:
- Right to know - categories and specific pieces of personal information we have collected
- Right to delete - deletion of personal information, subject to exceptions
- Right to correct - correction of inaccurate personal information we hold about you
- Right to opt-out of sale or sharing - we do not sell or share personal information for cross-context behavioral advertising; there is nothing to opt out of
- Right to limit use of sensitive personal information (SPI) - Bidhelm does not collect sensitive personal information as defined under CPRA (e.g., Social Security numbers, financial account numbers, health data, or precise geolocation). If this changes, we will update this policy and California users may exercise this right accordingly.
- Right to non-discrimination - we will not discriminate against you for exercising CCPA rights
To submit a CCPA/CPRA request, email privacy@bidhelm.com from the address on the account. Response within 45 days. We do not charge for a request and do not require an account to be closed in order to make one.
Categories of personal information collected in the past 12 months: Identifiers (name, email, IP address), commercial information (transaction history and ad spend data), internet or network activity (platform usage), and professional information (company name). We do not collect sensitive personal information as defined under CPRA.
12. Cookies & Tracking
Full details are in our Cookie Policy. Summary:
- Essential cookies: Required for login and session management, and for remembering your cookie answer. Always active - the Service cannot work without them.
- Advertising measurement: Google Ads conversion tracking on this website, and the only thing this website asks permission for. In the EEA, the UK and Switzerland it is off until you allow it. Elsewhere it runs until you turn it off, which those laws permit - and Cookie preferences at the bottom of every page is how. An answer you give is honoured wherever you are.
- Website analytics: cookieless - it writes nothing to your device, so no permission is needed. See the Cookie Policy for how that works.
- Product analytics inside the dashboard: first-party cookies tied to your account, run on the basis of our legitimate interest in operating the Service. No advertising cookie is ever set inside the product.
Manage this from Cookie preferences at the bottom of any page, or in your browser settings.
13. Third-Party Services
We use the following categories of third-party services, each bound by a data processing agreement. The current providers are named individually, with their locations, on the Sub-processors page - which is where changes are published, so that a provider can be replaced without amending this policy.
- Google Ads API: Campaign data access and automation - governed by Google's Privacy Policy and API Terms
- Google Merchant Center / Content for Shopping API: Product feed and Shopping/PMax performance data - only when you connect Merchant Center; governed by Google's Privacy Policy and API Terms
- Payment provider: Secure payment handling and tax collection - stores card details and processes recurring charges; we do not store full card numbers
- AI model providers: Analysis, drafting, and chat - see Section 3.1; contractually prohibited from training on the data sent
- Identity provider: Sign-in and session management
- Analytics: Cookieless website analytics, and product analytics inside the dashboard - neither is shared with advertisers or third-party ad networks
- Advertising measurement: Google Ads conversion tracking on our own website, which runs only where cookie consent permits it (Section 12)
- Logging and error monitoring: Operating and debugging the Service
- Customer support chat: Support communications only - data limited to support context
- Cloud infrastructure: Hosting and data storage. Both the database holding your account and campaign data and the servers that run the Service are in the European Union. Locations per provider are on the Sub-processors page
14. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently done so, contactprivacy@bidhelm.com and we will delete it promptly.
15. International Data Transfers
Your account and campaign data is stored and processed in the European Union. The database is in Frankfurt and the servers that run the Service are in the Netherlands. So the core of it does not leave the EU at all. What does leave is narrower than the infrastructure: several of the providers listed on the Sub-processors page process data in the United States, the AI model providers among them.
Where personal data moves out of the EEA or the UK, that transfer is made under Standard Contractual Clauses approved by the European Commission, together with the UK Addendum where the UK GDPR applies. We do not rely on consent as a transfer mechanism. If we later certify to the EU-US Data Privacy Framework, this policy will be updated accordingly.
For all other international users, by accessing the Service you acknowledge that your data may be processed in the United States and the European Union, where data protection laws may differ from those in your own country.
16. Changes to This Policy
We may update this Privacy Policy at any time. Every version carries a version number and an effective date at the top of this page.
Material changes are notified in the dashboard at least 30 days before they take effect, and the notice stays until it has been seen. Notice is given in the product rather than by email, because the Service sends no lifecycle email. Continued use after the effective date constitutes acceptance; if a change is one you are not willing to accept, you can cancel and ask us to delete your data under Section 8.
17. Contact
Privacy inquiries: privacy@bidhelm.com
General support: support@bidhelm.com
We respond to all privacy inquiries within 72 hours and resolve data requests within 30 days.