Privacy Policy
This policy explains how EcomDrive handles account, ecommerce operations, customer messaging, and Google Ads data for merchants who use our platform.
Last updated: August 4, 2026
Overview
EcomDrive provides ecommerce operations software for merchants, including order management, customer support workflows, and integrations with merchant-authorized business assets.
EcomDrive processes data from connected platforms only after a merchant intentionally connects an account or business asset they own, manage, or are authorized to use. Current integrations include customer messaging channels and read-only Google Ads reporting.
Information We Process
- Merchant account details such as name, email address, business name, and user role.
- Connected business asset details such as selected Facebook Page ID, Page name, and integration status.
- Customer conversation data needed to display and manage support messages, including message text, sender identifiers, timestamps, and message status.
- Google Ads connection information such as the authorized Google account email, OAuth authorization status, and merchant-selected customer or manager-child accounts.
- Google Ads account, campaign, ad group, ad, status, currency, cost, impression, click, conversion, conversion-value, and related reporting data.
- Operational data such as orders, customer records, fulfillment status, support history, integration logs, and security audit records.
How Message Data Is Used
Message data is used only for merchant-authorized ecommerce support workflows, including:
- Displaying customer conversations to authorized merchant users.
- Allowing merchant support agents to reply to customers.
- Linking conversations to order and customer records.
- Maintaining support history for the merchant business.
- Improving the merchant support workflow and reliability of the messaging feature.
Google Ads Data and OAuth Access
A merchant can choose to connect Google Ads from the EcomDrive integrations page. EcomDrive requests the https://www.googleapis.com/auth/adwords OAuth scope. Google describes this scope broadly, but EcomDrive's current Google Ads integration uses it only for account discovery and read-only reporting. EcomDrive does not create, edit, pause, or delete Google Ads campaigns, budgets, ads, or conversions.
Google Ads data is used only for merchant-facing features, including:
- Listing Google Ads accounts that the authorized Google user can access so the merchant can choose which accounts to synchronize.
- Displaying account, campaign, ad-group, ad, cost, impression, click, conversion, and conversion-value reports.
- Creating advertising expense and profitability reports for the connected merchant business.
- Combining Google Ads reporting with the merchant’s own ecommerce order-attribution data inside EcomDrive.
- Maintaining connection status, synchronization history, diagnostics, security, and reliability for the integration.
Google User Data Sharing and Limited Use
EcomDrive does not sell Google user data, share it with advertisers or data brokers, use it for targeted advertising, or use it for purposes unrelated to the merchant-facing features described in this policy.
Google user data may be processed by service providers that host, secure, monitor, or support EcomDrive only as needed to operate the service and subject to appropriate confidentiality and security obligations. EcomDrive may also disclose data when required by law, to investigate abuse or security incidents, or when the user gives explicit consent. EcomDrive's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
What EcomDrive Does Not Do
- EcomDrive does not sell customer message data or Google user data.
- EcomDrive does not share customer message data or Google user data with advertisers.
- EcomDrive does not use connected-platform data for unrelated marketing or targeted advertising.
- EcomDrive does not access Pages, messaging channels, or business assets that the merchant has not selected and authorized.
- EcomDrive does not create or modify Google Ads campaigns, budgets, ads, or conversions through the current integration.
- EcomDrive does not provide bulk spam, scraping, unauthorized messaging, or auto-DM tools.
Data Protection Mechanisms for Sensitive Data
EcomDrive maintains security procedures designed to protect the confidentiality, integrity, and availability of Google user data and other sensitive information. These protections apply to Google OAuth credentials and synchronized Google Ads reporting data.
- Data transmitted between users, EcomDrive, and Google services is protected in transit using HTTPS and TLS encryption.
- Google OAuth refresh tokens are encrypted at rest using AES-256-GCM authenticated encryption and are processed only by EcomDrive’s server-side integration.
- Authentication and business-scoped authorization restrict Google user data to authorized users of the connected merchant business. Access is not shared across merchant businesses.
- Integration credentials are kept in protected server-side systems and are not returned to the browser, displayed to merchant users, or included in merchant-facing reports.
- EcomDrive uses least-privilege access, integration and security logs, and monitoring procedures to detect and investigate unauthorized access or misuse.
- Service providers that host, secure, monitor, or support EcomDrive are required to protect data through appropriate confidentiality and security safeguards.
Access, Retention, and Deletion
Connected-platform data is linked to the merchant business account and is available only to authorized users for that business.
We retain data for as long as needed to provide the service, meet legal obligations, resolve disputes, maintain security, and support merchant operations. Merchants may disconnect Google Ads at any time. Disconnecting removes EcomDrive's stored Google OAuth refresh token, disables the connection, and stops future synchronization. Previously synchronized reporting data may be retained for the purposes and period described above unless the merchant submits a verified deletion request.
Merchants can request deletion of connected-platform credentials and associated data as described on our Data Deletion page.
Contact
For privacy questions or deletion requests, contact [email protected].