Google Ads Compliance Summary
Kliqbot™ Google Ads Compliance & Advertiser Protection Summary
Version 1.1
Last Updated: July 15, 2026
Purpose
This summary is provided to assist Google reviewers in quickly locating evidence of Kliqbot LLC’s compliance with the Google Ads API Terms and Conditions, Google API Services User Data Policy, and related standards for responsible third-party ad management tools. It focuses on advertiser protection, data minimization, transparency, and control.
Kliqbot LLC operates under a Manager Client Center (MCC) architecture with strict tenant isolation, Row-Level Security, AES-256-GCM credential encryption, and an operation outbox pattern for all mutations. All core safeguards described below are implemented in production.
1. Advertiser Retains Ultimate Control – No Surprise Spend
Google expects third-party tools to ensure advertisers are never surprised by charges or unauthorized changes.
How Kliqbot Addresses It:
- Strict three-tier autonomy model with human oversight on all spend-impacting actions.
- Tier 3 actions (budget changes, new keywords in live campaigns, enabling new ads, campaign activation) always require explicit Approval in the dashboard before execution.
- Tier 1 actions are limited to protective measures that can only reduce or safeguard spend.
- Tier 2 actions are bounded by user-configurable guardrails; exceeding them escalates to Tier 3.
- Emergency spend protection circuit breaker automatically pauses campaigns if spend significantly exceeds the configured budget. This is a protective safeguard only and requires human Approval to resume.
- Budget Integrity: Kliqbot spends exactly the budget the advertiser sets. The AI cannot increase spend or activate campaigns without explicit Approval.
Document References:
- Terms of Service v1.3, Section 5 (especially 5.1–5.3: Three-Tier Autonomy Model, No Surprise Spend Guarantee, Budget Integrity)
- Privacy Policy v1.2, Section 3 (Google Ads Account Data and Advertiser Controls – full description of three-tier model, emergency protection, and limited use)
2. Full Transparency of Automated Decisions
Google expects clear visibility into AI-driven changes.
How Kliqbot Addresses It:
- Every AI recommendation and executed action is logged in plain English in an immutable Audit Trail visible to the advertiser in the dashboard.
- The Audit Trail shows what changed, why, when, before/after values, expected impact, autonomy tier, and (where applicable) who Approved it and verification that the change took effect.
- Manual edits are “locked” — the AI never overrides them.
Document References:
- Terms of Service v1.3, Section 5.4 (Transparency and Audit Trail)
- Privacy Policy v1.2, Section 3 (Transparency and Audit Trail) and Section 6 (Automated Decision-Making and Human Oversight)
3. Easy Opt-Out / Disconnect (Within 3 Business Days – Here: Instant)
Google requires that users can disconnect a third-party tool quickly and safely.
How Kliqbot Addresses It:
- One-click Disconnect via Settings immediately revokes OAuth access.
- All active campaigns are automatically paused upon Disconnect as a safety measure.
- Cached data is cleared; historical data export remains available for a reasonable period.
- Disconnect is available at any time with no notice period required from the advertiser.
Document References:
- Terms of Service v1.3, Section 3 (Google Ads OAuth Connection – Disconnect mechanics)
- Privacy Policy v1.2, Section 3 (Instant Disconnect)
4. Limited Use of Google User Data & No Data Selling
Google API Services User Data Policy requires data to be used only for the authorized service and prohibits selling or unauthorized secondary uses.
How Kliqbot Addresses It:
- Google user data is accessed and used only to the minimum extent necessary to deliver the features the advertiser has authorized and only within the three-tier autonomy model.
- No use for serving ads, retargeting, building profiles for third parties, or any purpose inconsistent with the advertiser’s authorization.
- We do not sell personal information and do not share it for cross-context behavioral advertising.
- Conversion uploads via Data Manager API respect consent signals: hashed PII is used only when consent is granted; otherwise only click identifiers are used.
Document References:
- Privacy Policy v1.2, Section 3 (Limited Use and Purpose; consent-gated conversion uploads)
- Privacy Policy v1.2, Section 7 (How We Share and Disclose Information – explicit no-sale / no cross-context behavioral advertising statement)
- Data Processing Addendum (Schedule B) v1.1, Section 3 (Processor Obligations – processing only on documented instructions, including the three-tier approval model)
5. Sensitive Category Blocking at Onboarding
Google prohibits certain sensitive verticals.
How Kliqbot Addresses It:
- Businesses in prohibited sensitive verticals are blocked at onboarding via AI classification and content screening.
- No workarounds exist. Blocked tenants receive status
blocked_sensitive_verticaland cannot proceed.
Document References:
- Terms of Service v1.3, Section 6 (Acceptable Use Policy – full canonical list)
- Privacy Policy v1.2, Section 2 (Information We Collect – sensitive verticals prohibition)
- Agency OS Addendum, Section 4 (Compliance Obligations – agencies warrant they will not manage prohibited verticals)
Canonical Prohibited List (identical across documents):
Gambling / casinos / sports betting; adult content / sexual entertainment; cannabis / marijuana dispensaries; firearms / weapons dealers; political campaigns / PACs; addiction treatment / rehab facilities; bail bonds / payday loans / debt collection.
6. Security, Credential Protection, and Tenant Isolation
How Kliqbot Addresses It:
- Google Ads credentials encrypted at rest with AES-256-GCM.
- Refresh tokens never stored in plaintext; access tokens cached in Redis with short TTL.
- Strict Row-Level Security (RLS) and tenant isolation at the database layer.
- Cross-account guards prevent any operation on an account not belonging to the tenant.
- Health monitoring with automatic credential invalidation on authentication errors and graceful recovery.
Document References:
- Privacy Policy v1.2, Section 8 (Data Security)
- Data Processing Addendum (Schedule B) v1.1, Section 4 and Annex II (Technical and Organizational Security Measures)
- Google Ads developer token compliance summary (technical architecture reference)
7. Performance Claims and Disclaimers
Google scrutinizes misleading performance claims.
How Kliqbot Addresses It:
- Strong standalone Performance Disclaimer stating that no specific results (leads, CPL, ROAS, Quality Score, conversion rates, etc.) are guaranteed.
- Results depend on many external factors. AI tools are assistive only.
- The disclaimer is incorporated by reference in the Terms of Service and linked from relevant surfaces.
Document References:
- Terms of Service v1.3, Section 8 (Disclaimers) and incorporation of Performance Disclaimer
- Terms of Service v1.3, Section 8.2 and Exhibit E – AI Acceptable Use Policy & Disclaimers
- Standalone Kliqbot Performance Disclaimer (full conservative text)
8. Agency OS – Proper Client Authorization and Data Isolation
How Kliqbot Addresses It:
- Agencies must warrant they have all necessary authority from each Client.
- Each Client Account is treated as a separate tenant with logical data isolation.
- Agencies are responsible for Client compliance with Google Ads policies and applicable law.
Document References:
- Terms of Service v1.3, Section 13 (Agency OS Specific Provisions)
- Agency OS Addendum (full document – authority warranties, data isolation, compliance obligations, liability shift)
9. Sub-processors and Transparency
Document References:
- Privacy Policy v1.2, Section 7 (Sub-processors reference to Annex III)
- Data Processing Addendum (Schedule B) v1.1, Section 5 and Annex III
- Annex III – List of Sub-processors (current list including Google LLC, with purposes and locations)
10. Additional Safeguards
- Instant Disconnect with automatic campaign pause (see Section 3 above).
- 7-day operation expiry and graceful credential blocking/restoration for resilience.
- Partial failure handling on every Google Ads mutate response.
- Rate limit respect via operation queue and exact
Retry-Aftercompliance. - Full immutable Audit Trail of every AI decision (see Section 2 above).
Document Availability
The full current versions of the following documents are published in the Legal Center:
- Terms of Service v1.3
- Privacy Policy v1.2
- Data Processing Addendum (Schedule B) v1.1
- Agency OS Addendum
- Exhibit E – AI Acceptable Use Policy & Disclaimers
- Performance Disclaimer
- Annex III – List of Sub-processors
- Cookie Notice v1.1
Contact for Google Review or Compliance Questions
Elena Voss, J.D. – Principal Legal Counsel
legal@kliqbot.com | privacy@kliqbot.com