/ Legal
Privacy policy
Last reviewed 21 September 2026
This policy explains what personal data GUYRO DIGITAL collects, why we collect it, how long we keep it, who else processes it and what you can ask us to do about it. It covers this website, and it covers the data we access through the client accounts connected to our internal advertising platform, GUYRO ADS.
1. Who is responsible for your data
The data controller is Guy Rotberg, trading as GUYRO DIGITAL, a licensed business (Osek Murshe) no. 027108737, at 85 Ahavat Adam St., Kfar Yona 4034353, Israel. You can reach us at guy@guyro.digital or on +972-54-624-0534. We have not appointed a data protection officer, as we are not required to; enquiries go to the address above and are answered by the person who runs the business.
2. What we collect
Information you send us through the contact form
The form on our homepage asks for your name, work email address and company, and for a description of the problem you want help with. It also offers optional fields: your store URL, a monthly revenue range, your ecommerce platform, and a set of tick boxes for the kinds of work you are interested in. Only the name, email, company and message fields are required.
Please do not send us special category data, customer lists, payment details or anything confidential through this form. It is a first-contact form, not a secure channel.
Information collected automatically
Our host records standard server logs when a page is requested, including the IP address, the time of the request, the page requested and the browser user agent. That is all. This site runs no analytics, no tracking pixels and no advertising tags, so nothing else about your visit is recorded.
3. Data accessed through the GUYRO ADS platform
GUYRO ADS is the internal reporting platform we use to report on the advertising we run for our clients. It is described in full on our GUYRO ADS platform page. It is an internal tool. Clients do not log in to it, there is no self-signup, and it is not sold or licensed.
Whose accounts are involved. The Google accounts that grant GUYRO ADS access belong to GUYRO DIGITAL personnel and to the client businesses that engage us. GUYRO ADS is not used by, and does not collect data from, members of the public.
What we access, and under which Google API scope. Access is granted by the account holder through Google's own OAuth consent screen, and only for the accounts named in the engagement.
- https://www.googleapis.com/auth/adwords Google Ads. We read advertising performance data at account, campaign and ad group level: spend, impressions, clicks, conversions and conversion value. We read performance data only and do not create, edit or delete anything in Google Ads.
Why we access it. For one purpose only: deciding how a client's advertising budget should be spent, and reporting on what it produced. We combine advertising data with the client's own commerce data to compute blended acquisition cost and contribution margin, because that is the number that decides whether the advertising is making the business money.
How we store it. In access-controlled systems operated by GUYRO DIGITAL. The platform database is hosted in the European Union, in Frankfurt. Application hosting and our other processors are listed in section 7, and where any of them is located in or transfers data to a country outside the European Economic Area, the safeguards described in section 8 apply. Credentials are held encrypted.
How long we keep it. Only as long as the work requires. Data belonging to an engagement is deleted within 30 days of that engagement ending, as set out in section 4. Access itself ends at the same point, and the client can revoke it at any time from their own Google account security settings.
What we do not do with it. We do not sell it. We do not share it with third parties other than the processors listed in section 7. We do not pool it into any cross-client dataset offered to anyone. We do not use it to advertise to third parties. We do not use it to train any model, and we do not allow it to be used to train any model, including any artificial intelligence or machine learning model, whether ours or a third party's. We do not transfer it to others except as required to provide the service the client has asked for, or where the law requires it.
Limited Use. GUYRO ADS' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Non-Google sources. GUYRO ADS also connects, with the same client permission and on the same terms set out above, to Meta Ads for advertising performance data and to the client's Shopify store for order, refund and product data.
AI-assisted ad copy. When a member of our staff asks GUYRO ADS to draft ad copy or a brand profile for a client, the client's product titles, descriptions, prices and tags from their Shopify catalogue, the store name and the brand profile our staff wrote are sent to Anthropic's text-generation API and a text is returned for our staff to edit. No Google Ads data, no Meta Ads data, no customer data and no order data is sent. Anthropic acts as our processor and is listed in section 7; its terms prohibit it from training any model on what we send.
4. How we secure and protect Google user data
GUYRO ADS, our internal reporting tool, connects to Google Ads on behalf of clients who authorise us through Google's OAuth consent screen. We protect that data as follows.
Encryption in transit. Every connection between our systems and Google APIs, and between our own services, uses TLS 1.2 or higher. No Google user data travels over unencrypted channels.
Encryption at rest. OAuth refresh tokens are encrypted with AES-256-GCM before they are written to our database, using a key that is held outside the database as an environment secret on our hosting provider and is never stored alongside the data it protects. The database itself (PostgreSQL, hosted by Supabase in the European Union) is encrypted at rest by the provider. Performance metrics retrieved from Google Ads are stored as aggregated daily figures per campaign; we do not retrieve or store end-user personal data from Google Ads.
Access control. Google user data is accessible only to GUYRO DIGITAL staff who work on the relevant client account. Access to production systems requires individual credentials and multi-factor authentication. Tokens are never displayed in any interface, log or report. Clients do not have logins to GUYRO ADS.
Minimum access. We request a single Google API scope and use it read-only. A staff member selects exactly one Google Ads customer account per client; manager accounts cannot be selected. Nothing in the tool creates, edits or deletes anything in a Google account.
Retention and deletion. We keep the refresh token for as long as the client relationship is active. When a client is disconnected, when they revoke access at https://myaccount.google.com/permissions, or when Google invalidates the token, the token is deleted from our database. Aggregated performance metrics are retained for the duration of the engagement and deleted within 30 days of its termination, unless we are legally required to keep them longer. Clients may request deletion at any time by emailing the address in the Contact section.
No sale, no unrelated use. We do not sell Google user data, do not use it for advertising to anyone, do not use it to train machine learning or AI models, and do not transfer it to third parties except to the sub-processors that host our infrastructure (Supabase, Render, Vercel), each bound by a data processing agreement.
Incident response. If we become aware of a security incident affecting Google user data we will investigate promptly, notify affected clients without undue delay and in any case within 72 hours of confirming the incident, and take corrective action.
Limited Use. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Why we use it, and our lawful basis
- To answer your enquiry and to scope possible work. Lawful basis: steps taken at your request before entering into a contract, GDPR Article 6(1)(b).
- To keep the website secure and working. Server logs are processed on the basis of our legitimate interest in operating and protecting the site, GDPR Article 6(1)(f).
- To meet legal and accounting obligations once you become a client. Lawful basis: compliance with a legal obligation, GDPR Article 6(1)(c).
We do not use your data for automated decision-making or profiling, and we do not send marketing emails. There is no newsletter and no drip sequence.
6. How long we keep it
- Enquiries that do not become work: deleted within 12 months of the last message between us.
- Enquiries that become an engagement: kept for the life of the engagement and then for as long as tax and company law requires us to keep the related records, which in Israel is seven years.
- Server logs: retained by our host on a rolling short-term basis.
7. Who else processes it
We use a small number of service providers, each acting as our processor:
- Netlify
- Website hosting and form delivery. Processes requests to this site and its server logs.
- Google Workspace
- Business email and document storage. Enquiries arrive and are stored here.
- Supabase
- Database and authentication for the GUYRO ADS platform. The project is hosted in the European Union, in Frankfurt.
- Render
- Application and background job hosting for the GUYRO ADS platform.
- Vercel
- Dashboard hosting for the GUYRO ADS platform.
- Anthropic
- Text generation for the AI Studio in the GUYRO ADS platform. Receives a client's product titles, descriptions, prices and tags, the store name and the brand profile our staff wrote, and returns draft ad copy. No customer, order or ad-account data is sent. Processes it under its commercial terms and data processing addendum, which prohibit training any model on it. Based in the United States; see section 8.
We do not sell, rent or trade personal data, and we do not share it with third parties for their own marketing. We will disclose data if we are legally required to.
8. International transfers
We are based in Israel and our processors are based in, or transfer data to, the United States. Transfers from the European Economic Area to Israel rely on the European Commission's adequacy decision for Israel. Transfers to our United States processors rely on the European Commission's standard contractual clauses, on the EU-US Data Privacy Framework where the provider is certified under it, and on the safeguards in each provider's data processing terms. Anthropic processes text-generation requests in the United States; that transfer is covered by the standard contractual clauses in Anthropic's data processing addendum.
9. Your rights
If the GDPR applies to you, you have the right to access your data, to have inaccurate data corrected, to have your data erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where we rely on it. You can also complain to your national supervisory authority.
Under the Israeli Protection of Privacy Law, 5741-1981, you have the right to inspect data we hold about you and to ask for it to be corrected or deleted if it is incorrect, incomplete or out of date. If we refuse, you may appeal to a court. Israel's supervisory authority is the Privacy Protection Authority.
To exercise any of these rights, email guy@guyro.digital. We will respond within 30 days. We may ask you to confirm your identity first.
10. Cookies and browser storage
This site sets no cookies at all. It keeps exactly one value in your browser's local storage:
your choice of light or dark theme, under the key guyro-theme, written only when
you press the theme toggle in the navigation. It contains no personal data, is never sent
anywhere, and disappears when you clear the site's data. Nothing else is stored, and there is
no consent banner because a display preference you set yourself is not something to consent
to. If we ever add analytics or another tool that sets cookies, we will update this policy
and ask for your consent before it loads.
11. Changes to this policy
If we change this policy we will update the review date at the top of this page. Material changes affecting people who have already contacted us will be notified by email.
12. Contact
Questions or complaints about privacy: guy@guyro.digital, or write to GUYRO DIGITAL, 85 Ahavat Adam St., Kfar Yona 4034353, Israel.