Legal

Privacy policy

Last updated 7 August 2026

Who we are

Acronym Marketing ("Acronym", "we", "us") audits, manages and plans paid media for business owners. This policy covers acronymmarketing.com, the audit reports we publish at private share links, and the internal workspace our team uses to produce them.

If you want to reach a person about anything on this page, email help@acronymmarketing.com.

The short version

We collect very little from people who visit this website. There are no advertising pixels and no analytics cookies here.

Most of the personal data we hold belongs to clients, and it is data you give us on purpose so we can audit an advertising account: read-only access to your Google Ads account, and your answers to our intake questions. We use it to do the work you hired us for, and for nothing else.

We do not sell personal data, and we never have.

What we collect

If you only read this site, our hosting provider records the usual server-log detail — IP address, browser type, the pages requested and when. That is used to keep the site up and to spot abuse, and nothing on this site tracks you across other websites.

If you email us, we hold what you write, along with your name and address, so we can reply and keep a record of the conversation.

If you become a client, we hold the information you give us to run the audit:

  • Your intake answers — business goals, what a customer is worth to you, margins, budgets, target areas, and how the account has been run so far.
  • Google Ads data read from your account through Google's official API — account settings, campaign, ad group, keyword, search-term, ad-copy, extension and asset, audience, location-targeting, conversion-tracking, change-history, recommendation and asset-performance data for the account being audited. We only read this data; the one exception is the manager-account link request described below, which you approve yourself. This can include the business names and contact details that appear in your own ads and assets.
  • Your website address, which our tooling may fetch and review as part of the audit, in the same way any visitor would.
  • The finished report, including our scores and written recommendations.

What we do not ask for

We do not ask for your Google Ads username or password. We send a manager-account link request to your Google Ads account, and you approve or decline it yourself inside Google Ads, at Tools → Linked accounts. Everything else about how we access the account — campaigns, budgets, keywords, settings, spend — is read-only; the link request is the one exception, and it only takes effect if you approve it.

We do not ask for payment card details through this website, and we do not collect special-category data — health, biometrics, political or religious views and the like.

Cookies

The public site sets no cookies. Neither do the report pages we share with clients.

The staff sign-in area sets a small number of strictly necessary cookies that keep a team member logged in. They are not used for tracking or advertising, and they are never set on a page you can reach without a password-free sign-in link that we issued to a member of our team.

How we use it

To run audits and deliver the services you asked for; to answer enquiries; to keep our systems secure and working; and to meet our legal and accounting obligations.

Where the law asks us to name a legal basis, it is the performance of our contract with you for client data, our legitimate interest in running and securing the business for site logs and enquiries, and your consent where you have given it.

How AI is used in an audit

Our audit tool sends the account data read from Google Ads and your intake answers to Anthropic's Claude API, which scores each item in our rubric and drafts the written findings. Anthropic processes that data as our service provider and does not use commercial API data to train its models.

Every draft is reviewed and edited by a person before it reaches you. The judgement in the report is ours, not the model's.

Nothing a website visitor does is fed to an AI model.

Who else touches the data

We use a small set of service providers, each under contract and each processing data only on our instructions:

  • Vercel — website and application hosting, and the server logs that come with it.
  • Supabase — the database where intake answers and reports are kept, and the sign-in system for our team.
  • Anthropic — the AI scoring and drafting described above.

Who we do not share it with

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not pass client account data to other clients or to third parties for their own purposes.

We would disclose data if the law compelled us to, or to establish or defend a legal claim. If that ever happens and we are permitted to tell you, we will.

How long we keep it

We keep client account data and the reports built from it for as long as we are working together, and for up to 24 months afterwards, so we can answer questions about work we have done and compare an account against its own history.

Enquiry emails are kept for up to 24 months. Server logs are kept for a short period by our hosting provider.

Ask us to delete your data sooner and we will, unless we are required to keep a record for tax or legal reasons.

Keeping it safe

Data is encrypted in transit and at rest by our hosting and database providers. Access to the workspace is limited to named members of our team, who sign in with one-time links sent to an approved address — there are no shared passwords.

No system is perfect. If a breach ever affects your data, we will tell you and the relevant regulator as quickly as the law requires.

Where the data lives

Our providers store and process data in the United States. If you are in the UK or the EEA, that means your data is transferred outside your region, and those transfers rely on the standard contractual clauses our providers offer.

Your rights

Depending on where you live, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, or ask for it in a portable format.

If you are in California, you also have the right to know what we collect and to have it deleted. We do not sell or share personal data, so there is nothing for you to opt out of, and we will not treat you differently for exercising any of these rights.

Email help@acronymmarketing.com and we will answer within 30 days. If you are unhappy with our answer, you can complain to the data protection authority for the country you live in.

Children

This site and our services are meant for businesses. They are not directed at children, and we do not knowingly collect data about anyone under 16.

Changes to this policy

When we change how we handle data, we update this page and the date at the top of it. If a change is significant and you are a client, we will tell you directly rather than leaving you to notice.

Questions about any of this, or a request about your own data: help@acronymmarketing.com.