Privacy Policy

Privacy Policy for Waravel

Your trust is paramount. This policy outlines how we collect, use, and protect your data when you use the Waravel platform—a powerful Laravel dashboard owned and operated by Workers Direct LTD.

Last Updated: July 2024

1. About Waravel & Data Processing

Waravel is a Laravel dashboard package designed by Workers Direct LTD to manage content and media within your Laravel application. As a self-hosted solution, you are the primary data controller. Waravel processes data based on your configuration and commands.

The package operates on your servers, under your domain. We do not access, store, or process your application's data unless you explicitly send it to us for support purposes.

7. Google API Disclosure

Our PagePromoter plugin provides integration with the Google Ads API to help you manage your advertising campaigns directly from your dashboard.

  • Data Usage: We only access your Google Ads campaign performance data and settings to provide reporting and automation features.
  • Data Protection: We never share your Google User Data with third parties or use it for any purpose other than providing the campaign management features you have activated.
  • Policy Compliance: This application adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Google API Services — Data Disclosure & Protection

Waravel's PagePromoter plugin integrates with the Google Ads API and Google Search Console API. This section discloses exactly how we handle the data obtained through these integrations, in compliance with Google API Services User Data Policy.

What Data We Access

  • Google Ads campaign performance metrics (spend, clicks, impressions, cost-per-click)
  • Google Ads campaign, ad group, ad, and keyword configuration data
  • Google Ads conversion actions and search term reports
  • Google Search Console keyword rankings and click-through data
  • OAuth tokens required to authenticate API requests on your behalf

How We Use This Data

  • To display your Google Ads performance data inside the Waravel dashboard
  • To allow you to create, edit, pause, and manage your campaigns and ad groups
  • To manage negative keywords at campaign and ad group level
  • To display search term and conversion reports
  • Data obtained via Google APIs is never used for advertising, profiling, or any purpose beyond providing the features you have activated

Data Protection Mechanisms

  • Encryption in transit: All communication between Waravel and Google APIs is conducted exclusively over HTTPS/TLS 1.2 or higher. No data is transmitted over unencrypted connections.
  • Encryption at rest: OAuth access tokens and refresh tokens are stored in your application's database. We recommend (and document) the use of encrypted database storage and server-level disk encryption.
  • Access controls: Google API credentials are scoped to the authenticated user's account only. No other user within the Waravel platform can access another user's Google data. Access is enforced at both the application and API level.
  • Token security: OAuth refresh tokens are stored server-side and are never exposed to the browser or client-side JavaScript. Access tokens are short-lived and refreshed automatically.
  • Data minimisation: We only request the minimum scopes necessary (auth/adwords) to provide the features described above. We do not request access to Gmail, Google Drive, or any other unrelated Google services.
  • No third-party sharing: Google User Data is never sold, rented, transferred to, or shared with any third party for any purpose whatsoever.
  • Data retention: Campaign performance data fetched from Google Ads is displayed in real time and is not stored persistently in our databases. OAuth tokens are retained only while the integration is active and are deleted immediately upon disconnection.

Revoking Access

You may disconnect the Google Ads integration at any time via your Waravel Integrations settings page. Upon disconnection, all stored tokens are permanently deleted. You may also revoke access directly via your Google Account permissions page.

Limited Use Compliance: Waravel's use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalised AI/ML models.

8. Your Rights (Regarding Your Users' Data)

As the data controller for your Laravel application, you are responsible for complying with data protection laws (like GDPR, CCPA). Waravel provides tools to help you manage data:

Access & Portability

All content is stored in your database. You can export it via standard SQL tools.

Deletion

Use the Waravel dashboard to permanently delete pages, media items, or admin users.

Correction

Edit any page or media metadata directly within the zero-code dashboard.

Data Controller Contact

The legal entity responsible for the processing of data on waravel.com is:
Workers Direct LTD
344-348 High Road, Ilford, IG1 1QP, United Kingdom.
Contact: [email protected]

5.0 out of 5 (1 rating)