Privacy Policy
This policy explains what LSA Auditor accesses, why, where it is stored, and how to get it deleted. It covers data obtained through the Google Ads API.
Who we are
LSA Auditor is operated by Bauman Apps LLC, a limited liability company based in West Caldwell, New Jersey, United States. In this policy, "we" and "us" mean Bauman Apps LLC, and "you" means the marketing agency or business using the service.
Contact: [email protected]
What LSA Auditor does
LSA Auditor is a tool for marketing agencies that manage Google Local Services Ads on behalf of home-services businesses. It reads Local Services lead data from Google Ads accounts you are authorized to access, classifies leads for review, and — only when a person at your agency explicitly confirms it — submits lead feedback back to Google.
Data we collect
Account and identity data
When you sign in with Google, we receive and store your name, email address, profile image URL, and Google account identifier. We use this only to identify you, keep you signed in, and associate your actions with your agency.
Google Ads data
When you connect a Google Ads account, we read data about Local Services leads and the accounts containing them. This may include:
- Lead identifiers, creation timestamps, lead type and service category
- Charge status, charged amount, credit state and credit amount
- Whether feedback has already been submitted for a lead
- Contact details attached to a lead, which may include a consumer's name and phone number
- Conversation details attached to a lead, including call duration and message text
- Account name, time zone, currency and customer identifiers
Some of this is personal information about consumers who contacted your client's business. We process it on your behalf, solely to provide the service described here. We do not contact those consumers, and we do not use their information for any purpose of our own.
Data you create in the app
Your review decisions, the feedback reasons you select, comments you choose to send to Google, private notes you write, and the timestamps and user identity attached to those actions.
What we do not collect
- We do not collect payment card details. We do not currently charge for the service.
- We do not use advertising trackers, third-party analytics or advertising cookies on the application.
- We do not request or store your Google password. Access is by OAuth token only.
Google user data and Limited Use
LSA Auditor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through the Google Ads API is used only to provide and improve the features described in this policy. We do not sell it, we do not transfer it to third parties except as necessary to operate the service, we do not use it for advertising, and we do not use it to train generalized artificial intelligence or machine learning models. Humans do not read your Google user data except where you have given explicit permission for a specific support request, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymized.
Scopes we request, and why
| Scope | Why |
|---|---|
openid, email, profile | To sign you in and identify your account. Requested separately from Google Ads access. |
.../auth/adwords | To read Local Services lead and account data, and to submit lead feedback when you confirm it. Google does not offer a read-only variant of this scope. |
We request the minimum scopes needed. We read only Local Services lead and account data. We do not read, create or modify campaigns, budgets, bids, keywords, creatives or billing information.
What we write back to Google
The only data LSA Auditor ever sends to Google is lead feedback: a dissatisfied survey answer, a reason from Google's supported list, and — where you enter one — a comment intended for Google.
This is subject to three independent controls. The account must be connected to live data; feedback sending must be switched on for that specific account by an authorized user; and a person must confirm each individual submission on a screen that names the account, the lead and the reason. Feedback sending is off by default.
Private notes are never sent to Google. Notes you write for your own team are stored in a separate field from the comment field and are excluded from every submission.
Where data is stored
Data is stored in a PostgreSQL database hosted by Neon, and the application is hosted on Vercel. Both are located in the United States. If you are outside the United States, your data will be transferred to and processed there.
Google OAuth refresh tokens are encrypted at rest using AES-256-GCM before being written to the database. They are never displayed in the application, never returned to your browser, and never written to logs.
Service providers
| Provider | Purpose |
|---|---|
| Google LLC | Sign-in, and the Google Ads API that supplies lead data |
| Neon Inc. | Managed PostgreSQL database hosting |
| Vercel Inc. | Application hosting |
These providers process data on our behalf under their own terms. We do not sell personal information, and we do not share it with advertisers, data brokers, or any party for their own marketing.
How long we keep data
- Lead data is retained while your account is active, so historical reviews stay auditable.
- Feedback submission records are retained as an audit trail of what was sent to Google and when.
- Sign-in sessions expire after 60 days of inactivity and are deleted.
- OAuth tokens are deleted when you disconnect a Google Ads account or delete your account.
When you delete your account, we delete your identity data, your OAuth tokens, and the lead data synced under it within 30 days, except where we are required to retain records by law.
Your choices and rights
- Disconnect at any time. Use the disconnect control in the application, or revoke access directly at myaccount.google.com/permissions. Revoking stops all further access immediately.
- Request deletion. Email [email protected] and we will delete your data within 30 days.
- Request a copy of the personal data we hold about you.
- Correct inaccurate information we hold about you.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing or to lodge a complaint with a supervisory authority. We do not sell or share personal information as those terms are defined under the CCPA.
Security
Access requires authentication. Credentials are encrypted at rest. Each agency's data is scoped so that one customer cannot access another's records. Traffic is served over HTTPS.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will notify you promptly at the email address associated with your account.
Children
LSA Auditor is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.
Beta status
LSA Auditor is in private beta. Features described here may change. We will not reduce the protections in this policy without notifying you first.
Changes to this policy
If we make a material change, we will update the date at the top of this page and notify account holders by email before the change takes effect.
Contact
Bauman Apps LLC
West Caldwell, New Jersey, United States
[email protected]