Legal

Privacy Policy

Effective date: 2 October 2026

1. Who we are

yshipp ("yshipp", "we", "us") is an independent pay-per-click (PPC) advertising practice operated by Yonatan Shippin, based in Israel. This policy covers the website yshipp.com and the software applications and internal tools that yshipp operates to manage and report on advertising accounts, including applications that connect to Google APIs (such as the Google Ads API) and Meta APIs (such as the Meta Marketing API) (together, the "Apps").

Contact for any privacy matter: yonatan@yshipp.com.

2. Who the Apps are for

The Apps are business tools. They are used only by yshipp and by clients who have engaged yshipp to manage their advertising, and only for ad accounts that the client owns or is authorized to manage. The Apps are not offered to the general public or to children.

3. Data we collect

Website visitors. When you use the contact form we receive the name, email address, phone number (optional) and message you submit. Our hosting provider (Cloudflare) processes standard technical data such as IP address and browser type to deliver and secure the site. We do not use advertising cookies or tracking pixels on this website.

When you connect a Google account. With your consent through Google's sign-in screen, the Apps may access:

  • Basic profile information: your name, email address and Google account ID, used to identify who authorized the connection.
  • Google Ads data for the accounts you grant access to: account structure, campaigns, ad groups, ads, keywords, audiences, budgets, bids, conversion settings and performance metrics (impressions, clicks, cost, conversions).
  • Any other Google data only as specifically listed on the consent screen at the time you authorize, and only for the purpose described there.

When you connect a Meta (Facebook/Instagram) account. With your consent through Facebook Login, the Apps may access:

  • Basic profile information: your name and Meta user ID.
  • Ad accounts, Business Manager assets, Pages, campaigns, ad sets, ads, creatives, audiences, budgets and performance insights for the assets you grant access to.
  • Where you grant lead-retrieval permission, the contents of leads submitted through your Meta lead forms (for example a lead's name, phone number and email), which are your customers' data that we process only on your behalf.

Access tokens. We store the OAuth access and refresh tokens that Google and Meta issue so the Apps can act on the accounts you authorized. We never see or store your Google or Meta password.

4. How we use the data

We use data received from Google and Meta only to provide the advertising management and reporting services you asked for, which are:

  • Reporting: showing leads, spend, cost per lead and other performance metrics in dashboards and reports.
  • Account management: making changes to the ad accounts you authorized, such as creating, editing, pausing or enabling campaigns, ad sets, ads, keywords and audiences, and adjusting budgets, bids and targeting.
  • Analysis and recommendations: reviewing performance to recommend and carry out optimizations.
  • Security and support: keeping the connection working, troubleshooting and preventing misuse.

Changes to an ad account are made only on accounts that the account owner has authorized, and only within the scope of the services agreed with that client. You can see every change in the change history of Google Ads and Meta Ads Manager.

We do not sell data, use it for advertising to you or anyone else, use it to build profiles of individuals, use it to determine creditworthiness or for lending, or combine one client's data with another client's.

5. Use of AI assistants

yshipp uses AI assistants, currently Claude by Anthropic, to help analyze account data, draft recommendations and carry out account changes through the Google and Meta APIs. When this happens:

  • The AI assistant acts only on the specific instructions of yshipp, for an account the owner has authorized. It does not operate on its own initiative.
  • Only the data needed for the task is sent to the AI provider, through its commercial API.
  • Under the provider's commercial terms, data sent through the API is not used to train its models.
  • We do not use data received from Google or Meta APIs to develop, improve or train generalized or non-personalized AI or machine-learning models.

6. Google API Services: Limited Use

yshipp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide or improve the user-facing features described in this policy. We transfer it to others only as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you. We do not allow humans to read it unless you have given consent for specific data, it is needed for security purposes or to comply with law, or the data has been aggregated and anonymized for internal operations.

7. Meta Platform data

We process data received from Meta in line with the Meta Platform Terms and Developer Policies. We use it only for the purposes described in this policy, keep it no longer than necessary for those purposes, and delete it when you ask us to or when you remove the App's access (see section 11).

8. Who we share data with

We do not sell or rent data. We share it only with the service providers that help us run the Apps, under contracts or terms that require them to protect it:

  • Google and Meta: to read and update the ad accounts you authorized, through their APIs.
  • Anthropic: AI assistant processing, as described in section 5.
  • Cloudflare: website hosting, email routing and security.
  • Google Workspace / Gmail: business email and storage of reports we send to you.

We may also disclose data if the law requires it, or to protect the rights and safety of yshipp, our clients or others.

9. Storage and security

Data is stored on yshipp's own encrypted computers and on the infrastructure of the providers above. Access tokens and credentials are kept in restricted, non-public storage and are never published or shared. Data is encrypted in transit (HTTPS/TLS). Access is limited to Yonatan Shippin. Some providers store data outside Israel, including in the United States and the European Union.

10. How long we keep data

  • Access tokens: until you revoke access or our engagement ends, after which they are deleted within 30 days.
  • Advertising performance data and reports: for as long as we work together and up to 24 months afterwards, so that historical reporting stays available, unless you ask us to delete it sooner.
  • Lead contents from Meta lead forms: no longer than 90 days, unless you instruct otherwise in writing.
  • Contact-form messages: for as long as needed to answer and follow up on your enquiry.

11. Revoking access and deleting your data

You can stop the Apps from accessing your accounts at any time:

  • Google: go to myaccount.google.com/permissions, select the yshipp app and choose "Remove access". You can also remove yshipp's user access in Google Ads under Admin → Access and security.
  • Meta: go to Facebook Settings → Apps and Websites (facebook.com/settings?tab=applications), select the yshipp app and choose "Remove". You can also remove the app or partner from Business Settings in Meta Business Suite.

To delete your data, email yonatan@yshipp.com with the subject "Data deletion request" and the account or email address involved. We will confirm receipt, delete the stored tokens and data received through Google and Meta APIs within 30 days, and confirm when it is done. We may keep only what the law requires us to keep, such as invoices.

Deleting data from yshipp does not delete anything from your Google Ads or Meta ad accounts themselves.

12. Your rights

Under the Israeli Protection of Privacy Law and, where it applies, the EU GDPR, you may ask to see the personal data we hold about you, correct it, delete it, or object to how it is used. Email us and we will reply within 30 days. You may also complain to the Israeli Privacy Protection Authority or your local data protection authority.

13. Changes to this policy

If we change this policy we will update the effective date above, and notify active clients by email of any significant change before it takes effect.

14. Contact

Yonatan Shippin, yshipp · yonatan@yshipp.com · Israel

The Hebrew version of this policy is a translation. If the versions differ, the English version applies.