Growth Agency OS
Effective July 31, 2026
Growth Agency OS processes agency and Client information to provide its operating-system, reporting, analytics, and governed recommendation features. Google account data is accessed only after an authorized user explicitly connects Google and selects the accounts and resources that Growth Agency OS may read.
Growth Agency OS uses openid and https://www.googleapis.com/auth/userinfo.email to identify the consenting Google account without requesting or storing its password. With Google Ads authorization, Growth Agency OS reads the selected advertising account structure and reporting data needed for paid-media analysis, including customer and campaign identifiers and names, campaign configuration and status, budgets, ads and creative metadata, keywords and search terms when available, audience and geographic reporting dimensions, impressions, clicks, cost, and provider-reported conversion metrics. Google Ads provides the https://www.googleapis.com/auth/adwords OAuth scope for Google Ads API access and does not provide a separate narrower read-only Google Ads OAuth scope. Growth Agency OS therefore requests that scope but enforces read-only product behavior: it selects only user-approved accounts and does not create, edit, pause, delete, or otherwise mutate Google Ads resources. With Google Analytics read-only authorization, Growth Agency OS requests https://www.googleapis.com/auth/analytics.readonly and reads selected account and property metadata and aggregate reporting dimensions and metrics such as dates, traffic sources, campaigns, pages, sessions, users, engagement, events, and provider-reported conversions. With Search Console read-only authorization, Growth Agency OS requests https://www.googleapis.com/auth/webmasters.readonly and reads selected site identities, queries, pages, dates, clicks, impressions, click-through rates, and average positions. For Google Business Profile, Growth Agency OS requests https://www.googleapis.com/auth/business.manage to discover user-selected accounts and locations and read authorized listing and review evidence. Public review publishing remains disabled until separate Google write approval and controlled live certification are complete. We use the minimum Google scopes that support these identity, reporting, search, local-presence, reputation, and recommendation workflows. Current production does not use these scopes to change Google Ads, Google Analytics, Search Console, or Business Profile resources.
We use the selected Google data to normalize evidence, populate Client and Agency reporting, detect material performance changes, prepare step-by-step optimization recommendations, and show accountable work and outcomes. Provider-reported conversions remain labeled as provider metrics unless separately reconciled to authorized business-outcome evidence.
We do not sell Google user data, use it for advertising, or share it with data brokers. Google data is disclosed only to authorized users in the connecting Agency and its explicitly permitted Client workspace; to infrastructure and model-processing service providers acting for Growth Agency OS under confidentiality, security, and data-processing obligations; when necessary to provide support requested by an authorized user; when required by law or to protect the service; or with the user's explicit consent. Service providers may process only the minimum data needed to deliver the contracted service and may not use it for their own advertising. Growth Agency OS's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google OAuth credentials are encrypted at rest using authenticated encryption and are transmitted over TLS. Growth Agency OS does not request or store Google passwords. Access is restricted by tenant, Workspace, Client, role, and selected-resource boundaries; sensitive connector administration requires reauthorization; production secrets are kept outside source code; and access, synchronization, failures, and governed decisions retain auditable evidence. We apply least-privilege scopes, bounded reporting windows, credential rotation and revocation controls, monitoring, backups, and incident-response procedures.
Authorized users can disconnect Google, revoke access through their Google Account, and request deletion of associated credentials and imported data. Credentials are revoked or made unusable when a connection is removed. Imported reporting data is retained only for the operating, reporting, audit, security, and legal periods applicable to the service; deletion requests are honored subject to required security, fraud-prevention, financial, and legal records.
Questions, access requests, and deletion requests may be sent to byron@lapolamedia.com.