RevenueFlex GAM Reporting

Privacy Policy

Effective date: September 5, 2026

This Privacy Policy describes how RevenueFlex ("we", "us") handles information in connection with RevenueFlex GAM Reporting (the "Application"), the application we operate at appmanager.revenueflex.com. It has two parts: the operations application, which runs and extracts reports from, and creates and maintains ad units in, the Google Ad Manager networks we run on behalf of our publishers; and the public service at appmanager.revenueflex.com/reports/, through which any Google Ad Manager user can download reports from, and manage the inventory of, their own network. This policy also covers visitors to these pages at revenueflex.com/gam-reporting/.

The privacy practices of RevenueFlex's marketing website and publisher panel are described separately in the RevenueFlex Privacy Policy. Where the two overlap, this policy governs the Application's use of Google APIs.

1. Who we are

RevenueFlex is an ad monetization service for mobile game and mobile app publishers. We operate a Google Ad Manager network and, through Google's Multiple Customer Management (MCM) program, manage the Ad Manager inventory of publishers who have delegated it to us. Contact: info@revenueflex.com.

2. Who uses the Application

Three kinds of people interact with it:

End users of publishers' apps never interact with the Application, and the Application collects nothing about them.

3. Google user data we access

The Application connects to Google through the Google Ad Manager API using the OAuth 2.0 scope https://www.googleapis.com/auth/admanager ("view and manage your Google Ad Manager networks"). The public service additionally requests the openid and email scopes so that it can tell its users apart; the operations application does not. With the authorizing person's consent, the Application accesses the following data from the Ad Manager networks that person can see:

DataExamplesPurpose
Network and account configurationNetwork code and name, child (MCM) publisher networks, teams, time zone, currencyIdentify which managed network a request concerns; keep our records of managed publishers current
Inventory configurationAd units and their hierarchy, placements, mobile apps registered in the network, unified pricing rules and floor prices, refresh settingsCreate ad units and placements for publishers' apps; verify that every ad unit a publisher runs exists, is active and is priced as intended
Reporting dataAd-unit, app and publisher-network level impressions, unfilled impressions, eCPM and revenue, by day and hour; for the public service, the report shapes of the catalogue and the user's own saved report definitionsOperations application: reconcile revenue for publisher payouts; report earnings to each publisher; detect ad units that stopped serving.
Public service: run the report the user asked for and stream the export to them
Authorization credentialsThe OAuth 2.0 refresh token Google issues at consent, and the short-lived access tokens minted from itMake API calls on the authorized network from our servers
Account identity (public service only)The Google account's e-mail address and account id (sub) from the openid and email scopesSign the user in and keep their network choice, API keys, download log and change log separate from everyone else's; answer their report requests

We do not access, request or store: the authorizing user's Google account password; the contents of Gmail, Drive, Calendar, Contacts or any other Google service; Google Analytics data; the user's name, profile picture or other profile information; or any personal data of the end users who see ads in a publisher's app. In the operations application the only information about the authorizing person that is kept is the refresh token itself, recorded against the network it was granted for. In the public service the Application keeps, for each Google account the user connects, the e-mail address, account id and refresh token described above, and nothing else about the person.

3a. What the public service does and does not keep

4. How we use Google user data

We use the data described above exclusively to provide and improve the Application's user-facing functionality. In the operations application that means reporting, revenue reconciliation, ad unit creation and verification on behalf of RevenueFlex and its publishers:

In the public service it means doing, on the user's own network and only when the user asks, what the user asked for:

We do not use Google user data for advertising to the authorizing user, for building user profiles, for credit-worthiness or lending purposes, or for any purpose unrelated to operating the managed Ad Manager networks. We do not sell it.

5. Google API Services User Data Policy — Limited Use

RevenueFlex GAM Reporting's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

6. How we store and protect it

7. How we share it

We do not sell, rent or trade Google user data. We share it only:

8. How long we keep it, and how to have it deleted

9. Revoking the Application's access to your Google data

Anyone who authorized the Application can withdraw that authorization at any time:

Once revoked, the stored refresh token no longer works and is deleted from our database; public-service downloads and changes then answer with an error until the user signs in again. Data already downloaded through the API is handled under Section 8.

10. Visitors to these pages

The pages at revenueflex.com/gam-reporting/ are static. They set no cookies, run no scripts, and use no analytics, tracking or advertising technology. Our hosting provider's web server records standard access logs (IP address, requested page, browser type, time) for security and operational purposes, which are kept for a limited time.

11. Publisher and public-service accounts

Public-service accounts consist only of what Section 3a lists, are created by the user's own Google sign-in and are deleted by the user from the account page. The Application's operator accounts and the publisher accounts it reports to are business accounts held by companies or sole proprietors under a commercial publisher agreement. The business information associated with those accounts (company name, business contact details, payment details, app and ad-unit identifiers, performance data) is processed under that agreement and the RevenueFlex Privacy Policy.

12. Children

The Application and these pages are not directed at children under 13 (or the age of digital consent where you live), and we do not knowingly collect information from children.

13. International transfers

RevenueFlex's servers are located in the European Union. Data obtained through Google APIs is processed there. If you access the Application from elsewhere, you understand that your data is transferred to and processed in the EU.

14. Your rights

Depending on where you live, you may have the right to access, correct, delete or restrict the processing of personal data we hold about you, to object to processing, and to data portability. Requests can be sent to info@revenueflex.com. We will respond within the time required by applicable law.

15. Changes to this policy

We may update this Privacy Policy from time to time. Changes are posted on this page with a new effective date. Material changes to how we handle Google user data will be notified to the authorizing administrators of affected networks before they take effect.

16. Contact

RevenueFlex · info@revenueflex.com · revenueflex.com