Privacy Policy
Last updated: 4 August 2026
Privacy Notice
Pelling Marketing by Design UK Ltd (“Pelling”, “we”, “us” or “our”) is committed to protecting privacy and handling personal and Google account data responsibly. This notice explains how we handle information collected through our public website and through our private Pelling Marketing Tools service.
Information collected through our website
We may collect your name, email address, telephone number, website URL and any other information you provide through our contact or lead forms. We use this information to respond to enquiries, provide our services and improve our website.
Pelling Marketing Tools
Pelling Marketing Tools is a private internal service used only by authorised Pelling personnel for Pelling’s own advertising. It is not sold, licensed or made externally accessible, and it does not access or manage Google Ads accounts belonging to Pelling’s clients or other third parties.
Google Ads data we access
Depending on the task being performed, the service may access:
- Google Ads customer identity and account properties;
- campaign identity, status, channel and budget information;
- daily impressions, clicks, cost, conversions and conversion values;
- approved conversion-action performance;
- search terms and associated performance;
- Keyword Planning ideas and Audience Insights; and
- API error and request-status information needed for safety and troubleshooting.
Google Ads operations
The service performs reporting, search-term, Keyword Planning and Audience Insights reads. After an explicit current administrator approval, its write capability is restricted to creating or staging paused campaign budgets, Search campaigns, ad groups, targeting criteria, keywords, responsive search adverts and CampaignDrafts.
The application rejects enabling, promotion, removal and non-paused statuses. Publishing, enabling and CampaignDraft promotion remain manual actions performed by an authorised person in Google Ads. At the date of this notice, the installation’s database contains no Google Ads mutation-log records and therefore no evidence that it has executed a Google Ads write.
How we use Google Ads data
- To confirm the intended Google Ads account and operating environment.
- To research and plan Pelling’s advertising campaigns.
- To prepare paused campaign structures, adverts, keywords and targeting for human review.
- To import performance evidence, monitor results and make internal recommendations.
- To enforce approval, safety, audit and quality-control requirements.
- To diagnose failed, unsupported, unauthorised or retryable Google Ads API requests.
Storage and retention
The application stores Google Ads account and campaign references, aggregated daily metrics, search-term review rows, research requests and responses, approvals, recommendations, change sets and mutation audit payloads in its private application database.
Keyword Planning research is eligible for reuse for 30 days and Audience Insights research for 7 days. Expiry prevents the evidence from being reused but does not delete the stored record.
There is currently no general automatic PPC data-retention or pruning schedule. Records may remain in the private database until they are deliberately removed through an authorised administrative or database process, or until Pelling determines they are no longer required for the purposes described in this notice.
Deletion
The user interface does not provide a self-service deletion workflow for campaigns, metric snapshots, recommendations or mutation logs. OAuth revocation does not automatically delete associated stored records. Where deletion is appropriate, authorised administrators can arrange removal through a controlled administrative or database process; related records may also be removed through configured database relationships.
To request review or deletion of applicable stored information, contact us using the details below. Requests will be assessed in light of operational, security, audit and legal requirements.
Security and authorised access
The platform has no public registration route. Access requires a provisioned authenticated account and completed two-factor authentication. Provisioned users may view the internal panel; administrator status is required for approvals, research waivers, settings and Google Ads staging or apply operations.
Operational records are stored within Pelling-controlled private systems and protected by authentication, access controls and administrative safeguards. OAuth credentials, developer tokens and other secrets are handled separately and are not intended to appear in public content, screenshots, campaign records or routine logs.
External processors
Google OAuth and the Google Ads API process authentication and advertising data as necessary to connect to and use Google Ads.
OpenAI is the currently configured artificial-intelligence provider. Selected Google Ads-derived performance evidence may be sent to OpenAI for campaign strategy and advert or landing-page draft generation. This may include reporting dates, evidence freshness and provenance, impressions, clicks, cost, conversions, conversion value, cost per click, cost per acquisition and return on advertising spend, together with the approved campaign brief.
This AI processing path does not send Google credentials, raw Google Ads API responses or search-term text. Codex is used as the internal operating and control interface, so any Google Ads evidence deliberately presented to a Codex task should also be treated as reaching OpenAI.
The application contains optional Slack notification functionality, but no Slack webhook is currently configured. OpenDesign transfer is a manual human process rather than an application integration.
We do not sell Google Ads data or use it to provide advertising-management services to clients or other third parties.
Google API Services User Data Policy
Pelling’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Revoking Google access
An authorised Google user can review or revoke the service’s access through the Google Account connections page. A revoked or expired refresh token causes Google Ads operations to fail closed. The application records only a sanitised revocation or invalid-grant diagnostic and does not store the token in that diagnostic.
Reauthorisation and refresh-token replacement are manual. The service does not currently provide an automated disconnect control, credential-clearing workflow or automatic deletion of stored records following revocation.
Website data storage and sharing
Website enquiry data is stored securely and is not shared with third parties unless needed to provide our services, operate our systems, comply with law or protect our rights.
Your rights
You may request access to, correction of or deletion of your personal data where applicable. You may also object to or restrict certain processing. We may need to verify your identity before acting on a request.
Contact
Questions about this notice, Pelling Marketing Tools or a data request can be sent to hello@designbypelling.co.uk.
Updates
We may update this policy when our services or data practices change. The published page will show the date of the latest material update.