Bloomhouse Ads Pipeline

Privacy Policy

Last updated 14 September 2026

This policy covers the Bloomhouse Ads Pipeline (“the application”), an internal reporting tool operated by Bloomhouse Marketing. The application is not offered to the public and has no public sign-up.

Who this affects

Users of the application are Bloomhouse Marketing staff. The application does not collect information from members of the public, does not serve advertising, and does not use tracking or advertising cookies.

What data the application accesses

With the authorisation of a Bloomhouse Marketing administrator, the application uses the Google Ads API to read advertising performance data for accounts under the Bloomhouse Marketing manager account. Specifically:

This is advertising reporting data. It does not include the personal information of anyone who saw or clicked an advert.

What the application does not do

Limited Use

The application’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Ads API is used solely to provide and improve the reporting features described on the home page, and is visible only to authorised Bloomhouse Marketing staff.

How data is stored

Reporting data is stored in a Postgres database hosted by Supabase, and the application runs on Vercel. Data is encrypted in transit and at rest by those providers. Database access is restricted to the application’s server-side code; the database is not reachable from a browser. The application itself is protected by authentication — there is no unauthenticated route that exposes client data.

Credentials

OAuth credentials authorising access to the Google Ads API are held as encrypted environment variables in the hosting platform. They are never written to the application’s source code, its logs, or its browser output. Authorisation can be revoked at any time from the Google Account that granted it, at myaccount.google.com/permissions, which immediately stops further access.

Retention

Reporting data is retained for as long as Bloomhouse Marketing manages the advertising account it relates to, so that historical performance remains comparable over time. When an account is no longer managed, its data is deleted on request from the account holder or the Bloomhouse team.

Sharing

Reporting data is shared only with the Bloomhouse Marketing staff who manage the account it belongs to, and with the client that owns that advertising account. It is not shared with anyone else, other than the infrastructure providers named above who process it on our behalf.

Planned integrations

Bloomhouse Marketing intends to extend the application to read call records from CallRail and admissions records from Monday.com for the same clients. That data is not accessed today. This policy will be updated before any such integration is enabled, and neither involves Google user data.

Contact

Questions about this policy, or requests relating to data held by the application, can be sent to hello@bloomhousemarketing.com.