Last updated: March 24, 2026
1. Product Overview
ClickVault is a click fraud detection platform built for Google Ads advertisers. We help small and mid-sized businesses in Brazil identify and block fraudulent clicks on their paid search campaigns, protecting ad budgets from waste.
ClickVault operates on a monthly subscription model. Subscribers connect their Google Ads accounts through a secure OAuth 2.0 flow, and our platform continuously monitors incoming clicks for signs of fraud. When suspicious activity is detected, ClickVault automatically excludes the offending IP addresses from the advertiser's campaigns.
2. How We Use the Google Ads API
ClickVault integrates with the Google Ads API for two narrowly scoped purposes:
-
Reading campaign metadata — We retrieve campaign names, IDs, and statuses so that detected clicks can be correctly associated with the campaigns they originated from. This read-only access provides the context our fraud detection engine needs to operate.
-
Managing IP exclusions — When our system identifies a fraudulent IP address, we add it to the relevant campaign's IP exclusion list using the
CampaignCriterionresource. If an IP is later determined to be legitimate, we remove it from the exclusion list. This is the only write operation we perform.
Our platform syncs with the Google Ads API approximately every 5 minutes to keep campaign data current and exclusion lists up to date.
What We Do Not Do
ClickVault does not use the Google Ads API to:
- Create, edit, pause, or delete campaigns, ad groups, or ads
- Manage or modify budgets or bidding strategies
- Access or modify billing or payment information
- Create or manage Google Ads accounts
- Access keyword planning or forecasting tools
- Set up or modify conversion tracking
- Create or manage remarketing audiences
Our integration is strictly limited to reading campaign metadata and managing IP exclusion lists for fraud prevention.
3. API Capabilities Used
| Capability | Purpose | API Resource |
|---|---|---|
| Campaign Reading | Read campaign names, IDs, and status to associate clicks with campaigns | Campaign |
| IP Exclusion Management | Add and remove IP addresses from campaign exclusion lists | CampaignCriterion |
4. API Capabilities Not Used
The following Google Ads API capabilities are not accessed or used by ClickVault:
- Account Creation and Management — We do not create, modify, or manage Google Ads accounts.
- Campaign Creation — We do not create ads, ad groups, keywords, budgets, or bidding strategies.
- Keyword Planning Services — We do not access keyword ideas, search volume data, or forecasting tools.
- Conversion Tracking API — We do not set up or modify conversion actions or tracking.
- Remarketing API — We do not create or manage remarketing lists or audiences.
- Billing and Payments API — We do not access, view, or modify any billing or payment information.
5. Data Handling and Security
Authentication and Token Storage
ClickVault uses OAuth 2.0 for authentication. When a user connects their Google Ads account, we obtain access and refresh tokens through the standard Google OAuth consent flow. These tokens are encrypted using AES-256-GCM before being stored in our database.
Token storage is managed through Supabase with Row Level Security (RLS) enabled, ensuring that each user's tokens are accessible only to their own authenticated session. No other user or internal process can access another account's credentials.
Limited Use Compliance
ClickVault's use of Google Ads API data is strictly limited to providing click fraud detection and IP exclusion services. Specifically:
- We only read campaign metadata and manage IP exclusion lists.
- We do not use Google Ads data for any purpose other than fraud detection and prevention.
- We do not sell, rent, lease, or otherwise share Google Ads data with third parties.
- We do not use Google Ads data for advertising, market research, or profiling purposes.
- We do not permit human review of Google Ads data except where necessary to provide support requested by the account holder, to comply with legal obligations, or for security purposes such as investigating abuse.
Data Protection
ClickVault is fully compliant with Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018). We have a named Data Protection Officer and maintain organizational and technical measures to protect all personal and account data processed by our platform.
6. Google API Services User Data Policy Compliance
ClickVault's use and transfer to any other product of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For full details on how we collect, process, and protect your data:
7. Contact Information
- Company: ClickVault (45.597.034 Jonh Wilian Mariano Catalunha)
- CNPJ: 45.597.034/0001-43
- Email: contato@clickvault.com.br
- Data Protection Officer (DPO): Jonh Wilian Mariano Catalunha — dpo@clickvault.com.br
- Website: https://www.clickvault.com.br