Privacy Policy
This Privacy Policy describes how RevenueFlex ("we", "us") handles information in connection with RevenueFlex GAM Reporting (the "Application"), the application we operate at appmanager.revenueflex.com. It has two parts: the operations application, which runs and extracts reports from, and creates and maintains ad units in, the Google Ad Manager networks we run on behalf of our publishers; and the public service at appmanager.revenueflex.com/reports/, through which any Google Ad Manager user can download reports from, and manage the inventory of, their own network. This policy also covers visitors to these pages at revenueflex.com/gam-reporting/.
The privacy practices of RevenueFlex's marketing website and publisher panel are described separately in the RevenueFlex Privacy Policy. Where the two overlap, this policy governs the Application's use of Google APIs.
1. Who we are
RevenueFlex is an ad monetization service for mobile game and mobile app publishers. We operate a Google Ad Manager network and, through Google's Multiple Customer Management (MCM) program, manage the Ad Manager inventory of publishers who have delegated it to us. Contact: info@revenueflex.com.
2. Who uses the Application
Three kinds of people interact with it:
- RevenueFlex operators, who sign in to the operations application with a RevenueFlex account to run reports and create or check ad units in the networks RevenueFlex manages.
- Google Ad Manager network administrators (RevenueFlex's own staff, or a managed publisher's administrator), who authorize the operations application to access a managed network through Google's OAuth 2.0 consent screen.
- External users of the public service — anyone with a Google account that has access to a Google Ad Manager network — who sign in with Google at
appmanager.revenueflex.com/reports/to download reports from, and optionally manage, their own network.
End users of publishers' apps never interact with the Application, and the Application collects nothing about them.
3. Google user data we access
The Application connects to Google through the Google Ad Manager API using the OAuth 2.0 scope https://www.googleapis.com/auth/admanager ("view and manage your Google Ad Manager networks"). The public service additionally requests the openid and email scopes so that it can tell its users apart; the operations application does not. With the authorizing person's consent, the Application accesses the following data from the Ad Manager networks that person can see:
| Data | Examples | Purpose |
|---|---|---|
| Network and account configuration | Network code and name, child (MCM) publisher networks, teams, time zone, currency | Identify which managed network a request concerns; keep our records of managed publishers current |
| Inventory configuration | Ad units and their hierarchy, placements, mobile apps registered in the network, unified pricing rules and floor prices, refresh settings | Create ad units and placements for publishers' apps; verify that every ad unit a publisher runs exists, is active and is priced as intended |
| Reporting data | Ad-unit, app and publisher-network level impressions, unfilled impressions, eCPM and revenue, by day and hour; for the public service, the report shapes of the catalogue and the user's own saved report definitions | Operations application: reconcile revenue for publisher payouts; report earnings to each publisher; detect ad units that stopped serving. Public service: run the report the user asked for and stream the export to them |
| Authorization credentials | The OAuth 2.0 refresh token Google issues at consent, and the short-lived access tokens minted from it | Make API calls on the authorized network from our servers |
| Account identity (public service only) | The Google account's e-mail address and account id (sub) from the openid and email scopes | Sign the user in and keep their network choice, API keys, download log and change log separate from everyone else's; answer their report requests |
We do not access, request or store: the authorizing user's Google account password; the contents of Gmail, Drive, Calendar, Contacts or any other Google service; Google Analytics data; the user's name, profile picture or other profile information; or any personal data of the end users who see ads in a publisher's app. In the operations application the only information about the authorizing person that is kept is the refresh token itself, recorded against the network it was granted for. In the public service the Application keeps, for each Google account the user connects, the e-mail address, account id and refresh token described above, and nothing else about the person.
3a. What the public service does and does not keep
- Report content is never stored. A report the user asks for is run in their Ad Manager network and its export is streamed from Google through our server to the user's browser or program. It is not written to disk or to the database. What is kept is one log line per download: which report (or which saved report id), which network, which date range and format, how many rows and bytes were sent, when, whether it succeeded, and whether it was asked for on the page or with which API key.
- Inventory data is read on request only. When the user searches or opens ad units, placements, teams, apps or child publishers, the answer is passed straight through to them and not stored.
- Changes are logged. When the user creates or changes something in their network (an ad unit, a placement, its membership or teams, a child-publisher invitation or agreement), one log line records the action, its target (an id or name), the network, when, through the page or which API key, whether Ad Manager accepted it and, if not, its reason — and, for an ad unit or placement change, the state the object had just before (its status, team ids or member ad unit ids), so the user can reverse the change. The log exists so that the user can see everything that was done with their account and keys, and undo it.
- API keys are stored as hashes. A key is shown once, at creation; the server keeps only a SHA-256 hash, the key's name, its creation, expiry and revocation dates, the time it was last used, and the capabilities it was given. A key cannot be recovered from what we store.
- The refresh token is encrypted at rest (AES-256-GCM) with a key held outside the database, and is decrypted only to mint short-lived access tokens for the user's own requests.
- Several Google accounts, each consented separately. A user may connect more than one Google account to their service account; each one goes through Google's consent screen on its own and is stored as its own row (e-mail address, account id, encrypted refresh token). For each connected account the service keeps the list of Ad Manager networks it can see — network code, name and time zone, as Ad Manager last listed them — so that a request naming a network can be sent through the account that has access to it. A Google account can be disconnected on its own, which deletes its token and its network list.
- API keys may be pinned to one network. When a key is created with a network, that network code is stored with the key and the key can work on no other.
- Report requests sent through the contact form (subject and message) are stored with the user's e-mail address so that we can answer them.
4. How we use Google user data
We use the data described above exclusively to provide and improve the Application's user-facing functionality. In the operations application that means reporting, revenue reconciliation, ad unit creation and verification on behalf of RevenueFlex and its publishers:
- Reports are stored and aggregated so that each publisher's earnings can be calculated, paid and shown to that publisher.
- Ad unit and placement configuration is read back after creation, and periodically afterwards, so that missing, inactive or mispriced ad units are found and reported.
- Reporting data is extracted and stored so that RevenueFlex operators and each publisher can see the performance of the publisher's ad units and apps over time.
In the public service it means doing, on the user's own network and only when the user asks, what the user asked for:
- listing the networks the user's account can see, and remembering which one they chose;
- running the catalogue report or saved report the user selected and streaming the export to them;
- reading, and — when the user acts on the page or uses an API key to which they gave a write capability — creating or changing ad units, placements, placement membership, team assignment and MCM child-publisher invitations in that network. The public service never changes a network on its own initiative or on a schedule, and it never uses one user's credential for another user or for RevenueFlex's own operations.
We do not use Google user data for advertising to the authorizing user, for building user profiles, for credit-worthiness or lending purposes, or for any purpose unrelated to operating the managed Ad Manager networks. We do not sell it.
5. Google API Services User Data Policy — Limited Use
RevenueFlex GAM Reporting's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide or improve the user-facing features of the Application described in Section 4.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with prior notice to the user.
- We do not use or transfer Google user data to serve advertisements, including retargeting, personalized or interest-based advertising.
- We do not allow humans to read Google user data unless we have the user's affirmative agreement for specific data, it is necessary for security purposes (such as investigating abuse), it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
- We do not use Google user data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
6. How we store and protect it
- All data obtained through Google APIs is stored in RevenueFlex's own private database on servers RevenueFlex controls. It is not stored on third-party analytics or marketing platforms.
- OAuth tokens are kept server-side only. They are never sent to a browser, embedded in a page, shared with publishers or with any third party, and are used solely for server-to-server calls to the Google Ad Manager API over HTTPS. Public-service refresh tokens are additionally encrypted at rest as described in Section 3a.
- Access to the operations application requires an authenticated RevenueFlex operator login; access to the public service requires the user's own Google sign-in or one of their own API keys; access to the servers and database is limited to RevenueFlex staff who administer the service.
- An API key of the public service can only do what the capabilities chosen at its creation allow, and only in the network its owner chose. It cannot create or revoke keys, change the network or delete the account.
- Reasonable administrative, technical and physical safeguards are in place to protect the data against unauthorized access, alteration, disclosure or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. How we share it
We do not sell, rent or trade Google user data. We share it only:
- With the publisher it belongs to. A managed publisher sees the reporting and configuration data of its own ad units and apps. A publisher never sees another publisher's data. A public-service user sees only what their own Google account can see in Ad Manager, and only their own logs and keys.
- With service providers that host our servers and database, who process it only on our instructions and only as needed to run the Application.
- With Google, in the form of the API requests the Application makes to the networks it is authorized on.
- When required by law, or to protect the rights, property or safety of RevenueFlex, its publishers or others.
8. How long we keep it, and how to have it deleted
- Reporting and inventory data is retained for as long as it is needed for revenue reconciliation, publisher payouts and the financial record-keeping that applies to them, and is pruned by routine database maintenance after that. Detailed per-day report rows are generally kept for a limited number of months; aggregated revenue figures are kept for the duration of the publisher relationship and any period required by tax or accounting rules.
- OAuth tokens are kept until the authorization is revoked (see Section 9) or the network is no longer managed by RevenueFlex, and are then deleted.
- Public-service accounts (e-mail address, account id and encrypted refresh token of each connected Google account, the networks each can see, hashed API keys, download log, change log, report requests) are kept for as long as the account exists. The user can disconnect a single Google account, delete the Google access of all of them (Disconnect Google access) or the whole account with everything listed (Delete my account) on their account page at any time; deletion is immediate. Download log lines carry no report content; change log lines record the change and the prior state of the changed ad unit or placement (its status, team ids or member ad unit ids) so it can be reversed — no report content. Both are deleted with the account.
- An authorizing administrator or a managed publisher can request deletion of the data the Application holds about their network by writing to info@revenueflex.com. We will delete it within 30 days, except for records we are legally required to retain.
9. Revoking the Application's access to your Google data
Anyone who authorized the Application can withdraw that authorization at any time:
- from their Google Account, under Third-party apps & services — remove "RevenueFlex GAM Reporting";
- for the public service, with Disconnect Google access or Delete my account on the account page; or
- by e-mailing info@revenueflex.com.
Once revoked, the stored refresh token no longer works and is deleted from our database; public-service downloads and changes then answer with an error until the user signs in again. Data already downloaded through the API is handled under Section 8.
10. Visitors to these pages
The pages at revenueflex.com/gam-reporting/ are static. They set no cookies, run no scripts, and use no analytics, tracking or advertising technology. Our hosting provider's web server records standard access logs (IP address, requested page, browser type, time) for security and operational purposes, which are kept for a limited time.
11. Publisher and public-service accounts
Public-service accounts consist only of what Section 3a lists, are created by the user's own Google sign-in and are deleted by the user from the account page. The Application's operator accounts and the publisher accounts it reports to are business accounts held by companies or sole proprietors under a commercial publisher agreement. The business information associated with those accounts (company name, business contact details, payment details, app and ad-unit identifiers, performance data) is processed under that agreement and the RevenueFlex Privacy Policy.
12. Children
The Application and these pages are not directed at children under 13 (or the age of digital consent where you live), and we do not knowingly collect information from children.
13. International transfers
RevenueFlex's servers are located in the European Union. Data obtained through Google APIs is processed there. If you access the Application from elsewhere, you understand that your data is transferred to and processed in the EU.
14. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the processing of personal data we hold about you, to object to processing, and to data portability. Requests can be sent to info@revenueflex.com. We will respond within the time required by applicable law.
15. Changes to this policy
We may update this Privacy Policy from time to time. Changes are posted on this page with a new effective date. Material changes to how we handle Google user data will be notified to the authorizing administrators of affected networks before they take effect.
16. Contact
RevenueFlex · info@revenueflex.com · revenueflex.com