Project information
Privacy Policy
How data related to this website and PaxelCode Ads Connector, an internal integration for the project, is handled.
Last updated: October 10, 2026.
1. Responsibility and scope
Felipe Moura Shurrab, the individual who operates the PaxelCode project, is responsible for the processing described in this policy. For privacy matters, contact paxelcode@gmail.com. PaxelCode is the project's name, not a registered company.
This policy covers the PaxelCode website and PaxelCode Ads Connector, an internal integration for managing and evaluating advertising on authorized Meta and Google Ads assets, monitoring operations and organizing market research evidence. The website and connector do not provide consumer registration or login.
Meta, Google and ClickBank systems, as well as the product supplier's checkout, have their own practices. This policy does not replace the privacy information provided by those services or third-party products.
2. Data and purposes
Meta. The integration may retrieve identifiers and names of authorized ad accounts and Pages, permissions, campaign, ad set and ad configurations and content, budgets, schedules, targeting, statuses and metrics such as spending, impressions and clicks.
Google Ads. It may retrieve authorized accounts, currency and time zone, campaigns, ad groups, ads and keywords, destinations, bids, budgets, schedules, targeting, statuses and explanations made available by the platform. Reports may include platform-disclosed search terms, geography, devices, networks and metrics for impressions, clicks, cost, aggregate conversions and aggregate conversion values, when available. Aggregate conversions combine different actions and do not, by themselves, establish a purchase, retained commission or profit.
Information received from Google's APIs is used for the functions described in this policy. Processing is subject to the Google API Services User Data Policy and the Limited Use requirements applicable to the scopes used.
These data support preparing, validating and operating authorized ads, monitoring limits, evaluating available results, investigating failures and retaining evidence of decisions. The integration's advertising queries do not seek named lists of people who clicked, private messages or lead forms. Identifiers, names, search terms and other records may contain personal data; aggregate metrics do not, by themselves, identify buyers.
Market research. The local process retrieves Google Keyword Planner estimates through the authorized Google Ads API and can also import official exports supplied by the project owner. Original responses and files are retained with keywords, periods, targeting and estimates, and cached research can be reused to avoid unnecessary queries. Missing information remains unknown; search history and bid ranges do not establish ad delivery or profitability.
ClickBank. Authorized queries may receive transaction records transiently to check financial information for the queried scope. This financial workflow returns aggregated results and does not retain buyer names, contact details, receipts or other individual buyer details in its financial outputs. Platform-reported values are not automatically bank receipts or reconciled profit.
Operational records. Work messages and responses related to operations may form part of the local history. Content entered by the project owner may include personal information and should be limited to what is necessary for the analysis.
Contact and website visits. Someone sending an email may provide an email address, name and message content to address a matter or request. These pages contain no forms, analytics scripts, external fonts or trackers added by the project. The hosting provider may process technical access data as described below.
3. Campaign tracking and destinations
Ads use destinations and tracking parameters configured for the operation. On campaign pages prepared for this purpose, Google's click identifier (gclid), when present in the URL, may accompany the link sent to ClickBank for attribution.
These parameters are distinct from a list of buyers and do not establish that a purchase or conversion occurred. The product supplier and sales platform operate checkout and payment. Tracking configuration does not give the connector unrestricted access to those systems' data.
4. Sharing and supporting services
Operations needed for the integration are transmitted to Meta and Google through their APIs. ClickBank receives visits to purchase destinations and parameters forwarded in campaign workflows; authorized financial queries receive the data available for that purpose. The public contact address uses Google's email service.
HYPD. Authorized account information and market research inputs may also be processed through HYPD, which connects selected advertising accounts and supplies research and analysis tools under the permissions set for the connection. Research can include search results and competitor information supplied through Google and third-party data sources.
Some operational analysis uses local tools, including Ollama. Selected operational information, excluding tokens, keys and credential files, may also be reviewed with external AI assistance, including OpenAI Codex.
These pages are hosted on Cloudflare Pages. The provider may process technical access data, such as IP addresses, browser information and records needed to deliver and secure the pages, under its own practices.
Meta, Google, ClickBank, HYPD, OpenAI and Cloudflare may operate in other countries. Each service's processing is also subject to that provider's own practices and terms. Using these services does not give the integration access to data held exclusively by the product supplier.
5. Retention and security
The operation uses Meta access tokens, Google Ads service account credentials, HYPD OAuth authorization and ClickBank read-only API keys for authentication. Locally stored credentials are held in restricted files, outside the code repository, and are not part of the website's public files. Authorizations managed by supporting services are also subject to those services' controls.
There is no single retention period or automatic deletion process for all integration records. Metrics, evidence, research exports, operational records and backups are kept in local databases and files for the purposes described, security and evidence of decisions and spending.
The need for retention depends on the data category and purpose. Deletion requests are assessed considering existing records, backups and legal grounds for retention. Revoking a credential or authorization stops access that depends on it, but does not automatically delete earlier records.
Access to credential files is restricted, and the integration reduces token exposure in diagnostics. No technical control eliminates every risk.
6. Data requests
Requests for information, access, correction or deletion concerning data processed within this scope may be sent to paxelcode@gmail.com. The project owner will review the request, may verify the requester's identity proportionately, and will explain the action taken or the grounds for any continued retention.
Requests concerning data processed exclusively by Meta, Google, ClickBank or the product supplier may need to be directed to those parties' channels.
7. Updates
This policy will be reviewed when there is a material change to purposes, data categories, supporting services or hosting. The contact address above may be used to ask about the current version.