zachevan.com

Privacy policy

This policy covers zachevan.com and the internal tools I use to manage client advertising accounts. Last updated 27 July 2026.

Who I am

I'm Zach Evans, an independent performance-media consultant operating as a sole proprietor in the United States. I manage Google Ads accounts and the measurement behind them for a small number of direct clients. I am the only person who operates this business and the only person with access to the systems described below.

Questions about this policy, or about data I hold: hello@zachevan.com.

This website

zachevan.com is a static site. It has no forms, no accounts, no logins, and no advertising or analytics tracking. It sets no cookies of its own.

My web host records standard server access logs — IP address, timestamp, requested page, browser user agent — as an ordinary part of serving the site and protecting it from abuse. I do not use those logs to build profiles, and I do not combine them with any other data.

If you email me, I keep the message and your email address for as long as needed to correspond with you and to keep a record of our business relationship.

Client advertising data

When a client engages me, they grant my Google Ads manager account access to their advertising account. I then read that account's campaign, budget, keyword, search-term and performance data in order to do the work they hired me for — reporting, budget pacing, and campaign management.

How that data is handled:

It stays with me

Client advertising data is stored on my own workstation and in the client's own Google Ads and Google Analytics accounts. It is never sold, rented, licensed, published, syndicated, or transferred to any third party.

It is never pooled

One client's data is never combined with another's, never aggregated across advertisers for benchmarking, and never used to inform any other advertiser's account.

It is not used for advertising or model training

I do not use client data for my own advertising, for retargeting, for building audience segments outside the client's own account, or to train machine-learning models.

It is deleted when the work ends

When an engagement ends, my manager-account access is removed and locally cached copies of that client's data are deleted, except where I am required to retain records for tax or legal purposes. A client can ask me to delete their data at any time by emailing me.

Google user data and Google APIs

I use an internal, single-user tool that connects to Google APIs — the Google Ads API, the Google Analytics APIs, and the Google Tag Manager API — to do the account work described above. The tool runs locally on one workstation. It is not distributed, sold, or made available to anyone else, and there is no hosted version of it.

Authorization is by OAuth 2.0. I sign in with my own Google account and grant the tool access to the accounts I already manage. It requests read access to advertising and analytics reporting data, and write access limited to managing campaigns and campaign budgets in accounts that have granted my manager account permission.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Limited use

Data obtained through Google APIs is used only to provide and improve the account-management services my clients have engaged me for. It is not transferred to others except as necessary to provide those services, to comply with applicable law, or as part of a merger or acquisition. It is not used for advertising purposes, and no humans read it other than me — no third party, contractor, or automated system outside my own tooling has access.

Storage and revocation

OAuth credentials are stored on my local machine only and are never shared. Access can be revoked at any time from the Google Account permissions page at myaccount.google.com/permissions, or by removing my manager account's access in Google Ads.

Security

Credentials and client data are held on an encrypted workstation protected by account authentication, and credentials are stored outside any source-code repository. Because I am a sole operator, no employees, contractors, or subprocessors have access to client data or to Google user data.

Your rights

You can ask me what data I hold about you or your business, ask for a copy of it, ask me to correct it, or ask me to delete it. Email hello@zachevan.com and I will respond within 30 days. There is no charge.

Children

This site and these services are directed at businesses, not individuals under 18, and I do not knowingly collect information from children.

Changes

If this policy changes, the updated version will be posted on this page with a new date at the top. Material changes affecting existing clients will also be sent by email.

Contact

Zach Evans, zachevan.com — hello@zachevan.com