Last updated: 19 May 2026
Note for Project Plus website visitors: Project Plus is a brand of Project Plus Services Pty Ltd, the company that owns and operates this site.
About this policy
This privacy policy describes how Marketing Automation (the “Application”) collects, uses, and protects information when used by authorised personnel of Project Plus Services Pty Ltd (ABN 25 635 615 815) trading as Wet2Dry, Project Plus, and Scarabond.
The Application is an internal automation tool. It is not a public consumer service and is not available for use by third parties.
What the Application does
The Application connects to advertising and marketing platforms — currently Google Ads — owned or managed by the businesses listed above. It reads campaign performance data (impressions, clicks, conversions, cost, keyword performance, ad performance) and applies pre-authorised optimisation adjustments (campaign budget changes, negative keyword additions, bid adjustments) on those advertising accounts.
The Application’s purpose is to generate weekly and monthly performance reports for the business owner and to automate routine performance-management tasks across the managed accounts.
Information the Application accesses
When an authorised user signs in with their Google account, the Application requests permission to access the https://www.googleapis.com/auth/adwords scope. Granting this scope allows the Application to:
- Read the user’s accessible Google Ads customer accounts, campaigns, ad groups, keywords, ads, and conversion data.
- Update campaign budgets, negative keyword lists, and bid adjustments on those accounts.
The Application does not access any other Google services or scopes. It does not access Gmail, Drive, Calendar, Contacts, or any other Google product data.
Information the Application stores
The Application stores only:
- An OAuth refresh token — encrypted at the operating-system level with file-mode 600 (owner read/write only). This token is used to obtain short-lived access tokens for calls to the Google Ads API.
- Operational logs — timestamps and outcomes of API calls (e.g. “report generated at 09:00 AEST”, “budget adjusted on campaign X”) stored on the same private server for troubleshooting purposes only.
The Application does not store, transmit, or process any personally identifiable information about end consumers, ad viewers, or website visitors. It does not store full advertising data outside of the source platform’s own servers — performance numbers are read at runtime for report generation and not retained.
How the Application uses the information
Information accessed via the Application is used solely to:
- Generate performance reports for review by the business owner.
- Apply pre-authorised optimisation adjustments to the managed advertising accounts.
- Send internal alerts (via Telegram) to the business owner when key performance indicators move outside defined thresholds.
Compliance with the Google API Services User Data Policy
The Application’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- The Application does not transfer Google user data to artificial intelligence or machine learning models, nor use such data to train such models.
- The Application does not display advertising using Google user data.
- The Application does not sell, share, or transfer Google user data to any third party.
- Human access to Google user data is restricted to (a) the owner of the Application for security, debugging, and operational purposes, (b) the user themselves, and (c) operations required by law.
Who has access to the data
Access to the Application and the data it processes is restricted to:
- Jay Brockwell (the authorised user).
- The automated Application processes running on a private server.
The Application runs on a private server in Sydney, Australia, accessed only via Tailscale VPN and SSH key authentication.
How long data is retained
The OAuth refresh token is retained until the user revokes access via their Google account permissions page at https://myaccount.google.com/permissions. Operational logs are retained for up to 90 days for troubleshooting purposes and then automatically deleted.
Your rights
The authorised user may at any time:
- Revoke the Application’s access to their Google account via https://myaccount.google.com/permissions.
- Request deletion of any stored refresh token and operational logs by contacting the email address below.
- Request information about what data is stored about them.
Changes to this policy
This policy may be updated from time to time to reflect changes in the Application’s operation or in applicable Google policies. Material changes will be communicated to the authorised user via email.
Contact
Questions about this policy can be sent to:
Jay Brockwell
Email: jay.brockwell@project-plus.com.au
Phone: 1800 PROPLUS