This notice supplements the Spider Labs Privacy Policy (the “Privacy Policy”) and describes how Spider AF’s optional integrations with third-party advertising and analytics platforms access, receive, store, transmit and delete information. It applies when a customer connects a supported platform account to Spider AF. If a platform-specific disclosure in this notice directly conflicts with a general statement in the Privacy Policy, the platform-specific disclosure controls for that integration.
Effective date: August 13, 2026
Version: 1.0
| Item | Details |
|---|---|
| Status | Generally available. |
| Authorization / scopes | Google OAuth; Google Ads API scope. Spider AF’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. |
| Data accessed & stored | Account, campaign, placement, performance, cost and configuration data reasonably necessary for the enabled features. Audience-list metadata only: resource name, list ID/name/description, membership status, list size and size range, list type, closing/access reasons, account user-list status, read-only flag, integration code, membership lifespan, search/display eligibility, match-rate percentage, rule definitions (for rule-based lists), and metadata about customer-run CRM-list uploads and similar-audience seed references. We do not access individual list members or end-user identifiers. |
| Data written back | Tracking templates; fraud-related exclusions (IPs, placements, audiences) — automated where auto-update is enabled. |
| Purpose | Ad-fraud detection, reporting, and customer-directed exclusions. |
| Revocation | Disconnect in Spider AF; additionally revocable at Google Account → Security → Third-party access. |
| Item | Details |
|---|---|
| Status | Generally available. |
| Authorization / scopes | OAuth 2.0 via Yahoo! JAPAN Business ID; single scope yahooads. We store the OAuth access and refresh tokens and revoke them on disconnection. We never receive or store your Yahoo! JAPAN password. |
| Data accessed & stored | Account, campaign, ad-group and placement configuration, and daily performance and cost reports (impressions, cost, clicks, conversions, invalid-click metrics, delivery URLs / placement names) via the Yahoo! Ads Display & Search Ads APIs — the same categories as our Google Ads integration. No end-user identifier uploads; audience-related operations do not access individual members. |
| Data written back | Two fraud-related write-backs, both applied only after you enable the feature: (1) an audience-exclusion list (“SAFIVT”) that we create and apply as an exclusion to your campaigns, and (2) for Display Ads only, placement-URL deny-lists for blocked placements. The SAFIVT list is populated on the platform side from tag/pixel events on your own site when invalid traffic is detected — we do not upload identifiers or IP addresses to build it. Ongoing synchronization is automated (daily / 6-hourly); we do not write tracking templates or IP exclusions for Yahoo! JAPAN Ads. |
| Purpose | Ad-fraud detection, reporting, exclusions. |
| Revocation | Disconnect in Spider AF (tokens revoked); additionally revocable in your Yahoo! JAPAN Business ID settings. |
| Item | Details |
|---|---|
| Status | Generally available. |
| Authorization / scopes | Meta Marketing API via Meta’s OAuth dialog; permission ads_management. We store the OAuth access and refresh tokens and revoke them on disconnection. |
| Data accessed & stored | Ad-account list, campaign and ad-set configuration, pixel and custom-audience lists (IDs and names only), and performance reports via the Insights API (impressions, clicks, spend, reach, CPM, actions) — the same categories as our Google Ads and Yahoo! integrations. We never access Custom Audience membership and never upload end-user identifiers (no email addresses, telephone numbers or device IDs anywhere in the integration). |
| Data written back | Limited to objects we create: we create one custom audience (“SAFIVT [1-click-setup]”), attach or detach it as an exclusion on ad-set targeting, and delete it when you offboard. The audience is a pixel-rule-based website audience populated by Meta from your own pixel events (180-day retention on Meta’s side). We never modify or delete your pixel, and we write no placement blocks or tracking templates. Initial setup is manual; ongoing synchronization is an automated daily job. |
| Purpose | Ad-fraud detection, reporting, exclusions. |
| Revocation | Disconnect in Spider AF; additionally at Facebook Settings → Business Integrations. |
To request deletion of data obtained through a platform integration:
This section serves as the data-deletion instructions for platform app-review purposes (e.g., Meta’s Data Deletion Instructions URL).
We may update this notice as integrations change or as platform review requirements evolve. The effective date and version history appear at the top of this notice. Material changes will be handled in accordance with the change provisions of the Privacy Policy.
Questions and deletion requests: dpo@spideraf.com (general inquiries: info@spideraf.com)