Scope and Personal Information Processor
This Policy applies to the 2alignads ad management service provided through 2alignads.com, including the Google Ads account connection and ad management features made available there. This Policy is based primarily on the Personal Information Protection Law of the People's Republic of China and applies to the corresponding personal information processing activities carried out within mainland China. The site operator and personal information processor is 海口二艾科技有限公司 (2align LLC) ("we" in this Policy). Employees of 2align LLC participate in ad operations collaboration, and their access scope is described in "Storage, Recipients, and Sharing Purposes."
Personal data requests, business inquiries, and problem reports are all handled by our support team at support@2alignllc.com.
When we add new personal information processing purposes, categories, or permissions, we will first notify you in an appropriate way and, where required by law, obtain your consent again before starting the corresponding processing.
Accounts, Materials, and Usage Records
To let you sign in and use your workspace, we store your account identifier, display name, workspace membership and role, and the theme, language, and notification preferences you set.
When WeChat login is enabled, we receive from WeChat an identifier that identifies your account and your nickname (for your display name); we do not read your avatar, email, or similar data. For how WeChat handles this, see the WeChat Privacy Protection Guidelines.
When you create materials or ad campaigns, we store the names, text, images, videos, files, video links, and ad configuration you submit, along with the related account, operator, and time, to save drafts, organize materials, run internal reviews, and carry out your instructions. The materials and business data remain owned by you or the relevant rights holders; uploading does not transfer those rights to us.
We also store review comments, deployment tasks and results, error information, and the orders, amounts, transaction records, and notifications generated when you use the relevant features, to show the operation process, handle problems, and manage business records.
The site uses cookies, IP rate-limit records, and operational logs to maintain sessions, limit abnormal requests, and troubleshoot problems. Rate-limit records store only a hash of the IP address, not the raw IP, and expire after 60 seconds; logs may contain operation context and error information; material previews and upload validation use temporary signed links. Not every visit produces all of these records.
We process this information because it is necessary to provide the service you request, with your consent, and as necessary to comply with legal obligations or protect service security; we process it only to the extent needed for the purposes described in this Policy.
Protection of Minors
2alignads is intended solely for business users; business personnel must be at least 18 years old and authorized by their business. The service is not directed to minors under 18, we do not knowingly collect minors' personal information, and we do not promote the service as a product for minors.
If you find that a minor is using the service, or that a minor's personal information that should not be collected has been submitted to us, contact us at support@2alignllc.com. After verification, we will stop the relevant processing and delete the information as required by law or take other appropriate measures.
Google Authorization and Data Accessed
When you connect a Google Ads account, you first go to Google's authorization page. In line with how Google handles third-party apps, Google shows you which Google account data 2alignads is requesting, and you decide whether to grant access; only after you agree can 2alignads access anything, and only within the scope you authorize. You may also decline, but features that depend on the connection will then be unavailable. During connection, 2alignads never asks for or receives your Google password; Google handles it.
The permission 2alignads requests is used only to manage Google Ads advertising accounts, corresponding to Google's adwords permission (https://www.googleapis.com/auth/adwords). Through it, 2alignads can view the Google Ads accounts you can access and, on your instruction, create, modify, or pause ads and upload materials. To let you finish tasks you started after closing the page, the authorization includes offline access, and 2alignads encrypts and stores the token used to maintain the connection; you can remove this access in your Google Account at any time.
To show connectable accounts and check account type, 2alignads reads the Google Ads account IDs, account names, currencies, and manager account identifiers you can access; after you confirm the account to connect, it stores that account ID, currency, connection status, and time. Beyond this, 2alignads does not obtain any other data from your Google Account through this flow.
This connection flow does not request Gmail messages, Google Drive files, contacts, or calendar, nor your Google profile, email, avatar, or openid permissions. For how Google lets you view and remove third-party access to your account data, see Google's explanation and the Google Privacy Policy.
Use of Google Data and Ad Operations
We use data obtained from Google only for the account connection and ad management you request, and to keep these features secure and troubleshoot problems; we do not use it for unrelated purposes.
In short: the account list lets you choose which ad account to connect; the account ID, currency, and connection status let us identify which account you are working on, show the connection, and validate later tasks; the authorization token proves to Google that you have granted authorization.
Materials you upload are first stored in this platform's storage service. Saving a draft, in-site validation, and submitting for review do not upload videos to Google; only after operations review approval, and when you run a publishing task you authorized, is the needed video uploaded. Materials that already have a YouTube video ID can be referenced directly.
When a publishing task runs, 2alignads sends Google the configuration and materials you selected (such as ad name, budget, bids, status, country/region, language and age targeting, landing page, text, images, and video) to create ad assets. Publishing tasks can run automatically after operations review approval or be executed manually by operations staff; both require review approval first.
When a video needs to be uploaded, we use YouTube API Services to send Google's video service the video file, the filename (as the title), and the configuration needed for the upload, and to read the processing status and the returned YouTube video ID. Uploads currently use the "unlisted" (UNLISTED) setting; anyone with the link may still view it, so it is not the same as a private video. YouTube uploads and Google data use are also governed by the YouTube Terms of Service and the Google Privacy Policy respectively. We do not use materials for public display or sharing unrelated to this Policy.
2alignads stores the campaign and asset group identifiers returned by Google to associate deployment results and carry out the pause or resume you request; the returned video information is used for that ad material. Budget and billing records on this site do not mean that actual spend, impressions, clicks, or conversions have been obtained from Google.
Limits on the Use of Google Data
We do not sell customer data or authorized Google data, and we do not give data obtained from Google to data brokers or information resellers. We do not use this data (or its aggregated, anonymized, or otherwise derived results) to train internal or external AI/machine-learning models, or provide it to third parties for such training. We do not use authorized Google data to build cross-customer advertising profiles, and we do not run targeted advertising or remarketing for ourselves or other customers that is unrelated to this authorization.
2alignads's use of information received from Google APIs, and any transfer of that information to other apps or services, adheres to the Google API Services User Data Policy, including the applicable Limited Use requirements. These restrictions apply to the raw data and to its aggregated, anonymized, or otherwise derived data.
If the service genuinely needs staff to view specific data received from Google APIs, we will first explain what will be viewed and why, and obtain your explicit consent; access required for necessary security investigations or by applicable law is excepted.
Storage, Recipients, and Sharing Purposes
The service runs on Alibaba Cloud (Aliyun), and the database and file storage are also deployed on Aliyun. Account data, ad configuration, business records, and encrypted authorization tokens are stored in the database, and uploaded files in object storage; these services run the site, store data, and execute your requests. For how Aliyun handles information, see the Alibaba Cloud Legal Statement and Privacy Policy.
Google receives authorization requests, authorization credentials, and the account information, materials, and configuration needed for ad management, and processes them under its rules; when videos are uploaded, the content is also sent to YouTube through Google's YouTube API Services.
This information is sent over the network to Google and YouTube to carry out the ad management and video uploads you request, and may be processed outside mainland China due to their global architecture. Except to provide those features and for necessary security or legal requirements, we do not transfer data to other parties outside the mainland. Our own database and file storage are deployed on Aliyun; where personal information is to be transferred across borders, we will first complete the compliance procedures required by law before transferring it.
Members of the same workspace can view the business data needed for collaboration according to their roles. When completing the ad management you request, 2align LLC's ad operations staff may view, within their duties, materials you submit that do not contain personally identifying information; we do not arrange for them to routinely view customers' names, contacts, or identity documents. Do not submit personal data unrelated to advertising in your materials.
The support team handles your questions and data requests through the support email, using the contact details, account clues, and problem content you provide to reach you, verify, and reply. When manual viewing of Google data is needed, the limits in the previous section also apply.
In the relevant flows, the browser only connects to these external origins: WeChat login (open.weixin.qq.com), Google Ads authorization (accounts.google.com), and YouTube previews on the materials page (youtube.com/embed). Except for the services described in this Policy, necessary security handling, and applicable legal requirements, we will not disclose authorized Google data to others for other purposes.
Google's handling of data in Google services is also governed by the Google Privacy Policy.
Third-Party Services and Sharing List
To provide the service, we share necessary information with the third-party providers listed below, and only to the extent needed for the purposes described in this Policy; each handles it under its own privacy policy.
WeChat (Tencent)
Used for WeChat login; we receive only the account identifier and nickname from WeChat.
Alibaba Cloud (Aliyun)
Provides servers, database, and object storage to run the site, store data, and execute your requests.
Used for Google Ads authorization and ad management; we send it authorization credentials, account information, ad configuration, and materials.
YouTube
Used for ad video uploads; we send it the video file and title.
Data Protection Measures
The site and Google authorization and API requests all use HTTPS encryption. Google Ads authorization tokens are encrypted with AES-256-GCM before being stored in the database; the decryption key is managed separately on the server and is not stored with the token, and only the server can read the token.
Business data access is controlled by workspace membership and role permissions, and file uploads and previews use temporary signed addresses. Anyone who obtains a signed link can access the file during its validity period, so do not forward it to people without access. No measure can guarantee absolute security; if you notice anything abnormal, contact us through the support email.
Cookies and Temporary Links
The session cookie keeps you signed in; the account-selection cookie (piper_acc) remembers your current workspace and lasts 365 days. The login cookie lasts up to about 400 days. Clearing cookies or logging out does not automatically delete data stored on the server.
Material preview links are valid for 1 hour and upload-validation links for 60 seconds; rate-limit records are kept for 60 seconds. The validity periods of cookies, scan status, and temporary links do not represent the retention period of other data or logs.
Retention and Cleanup
Under the Personal Information Protection Law and other applicable requirements, we keep personal information only for the shortest time needed for the purposes described in this Policy, unless the law provides otherwise. The actual period depends on the use of the data, whether the service is still provided, whether the relevant task or issue is resolved, and legal requirements.
Account and connection data maintain the service you request; materials and ad configuration are used to save drafts, review, and deploy; operation records, logs, and support messages are used to complete requests, handle problems, and for necessary security.
Today, the only short-lived credentials that expire automatically are WeChat scan login sessions (120 seconds, extended to 600 seconds after scanning) and IP rate-limit records (60 seconds). Apart from these, we have no automatic cleanup for account data, materials, logs, or backups; deletion is handled manually through the support email.
When the purpose is achieved, cannot be achieved, or is no longer necessary, or the service stops, the retention period ends, or you withdraw consent or request account closure or deletion, we will manually review what must still be kept and what can be handled, and the support team will coordinate deletion of data that should be deleted and reply to you. Withdrawing consent does not affect processing already carried out before the withdrawal.
Disconnecting a Google Ads connection does not automatically delete saved authorization tokens, account associations, or ad records. You can ask us to delete them; revoking Google authorization stops further access but does not automatically clear data already stored on this site.
There is currently no one-click or automatic cleanup covering all data. Deleting a material on a page only removes the database record; stored files, logs, and backups must be handled separately; ads and materials already sent to Google are not removed by deleting records on this site.
If the statutory retention period has not ended, or deleting personal information is technically difficult, we will keep it only and take necessary security measures and stop other processing, and explain the retained scope and reason in our reply.
Disconnecting, Revoking Authorization, and Managing Data
You can change your display name, theme, language, and notification preferences in settings. Referenced materials cannot currently be deleted from a page; to delete personal information, contact the support email. There is no one-click account closure yet; you can request manual handling by email.
After you disconnect a Google Ads connection, later tasks cannot use it; tasks already running may still finish. Disconnecting does not automatically revoke Google permissions, delete tokens, or pause ads already running on Google; logging out only ends the current session and is not the same as deleting the account or saved data.
To revoke Google authorization, go to your Google Account's third-party connections and remove 2alignads's access; after revocation, connections and background tasks that depend on it will not run normally, and if you also want to clear data stored on this site, submit a separate deletion request.
Personal Data Requests
To access, copy, correct, or delete personal data, withdraw authorization, or request account closure, tell us your request and the relevant account, page, or material at support@2alignllc.com. The support team handles it manually, verifies, coordinates, and replies; deletion requests for Google Ads connection data and authorization tokens also use this channel.
You can also use this channel to request supplementing or restricting processing, to transfer personal information where conditions are met, or to learn the processing rules.
Before processing, we verify the request scope and identity, preferring to check the existing account, original contact channel, and operation records, and we do not by default require identity documents. Do not send passwords, keys, login tokens, or ID photos.
We handle requests promptly; if we cannot satisfy all or part of a request, we will explain why and what can be done next. If you have questions or believe your rights are infringed, you may object via that email, or complain to the competent authority or seek judicial remedies under the law.
How data is stored, the scope of deletion, and retention circumstances are described in "Retention and Cleanup."
Policy Updates
When the operator, data handling methods, external services, or contact channels change, we will update this Policy and its date. When the purposes, methods, or categories of personal information processing change, we will provide the corresponding notice and, where required by law, obtain consent again. Before adding new Google data categories or purposes, we will provide the corresponding notice and obtain the corresponding consent; adding Google permissions also requires completing the corresponding Google authorization.
Personal data requests and business inquiries: support@2alignllc.com