Privacy Policy for Waravel
Your trust is paramount. This policy outlines how we collect, use, and protect your data when you use the Waravel platform—a powerful Laravel dashboard owned and operated by Workers Direct LTD.
Last Updated: July 2024
1. About Waravel & Data Processing
Waravel is a Laravel dashboard package designed by Workers Direct LTD to manage content and media within your Laravel application. As a self-hosted solution, you are the primary data controller. Waravel processes data based on your configuration and commands.
The package operates on your servers, under your domain. We do not access, store, or process your application's data unless you explicitly send it to us for support purposes.
7. Google API Disclosure
Our PagePromoter plugin provides integration with the Google Ads API to help you manage your advertising campaigns directly from your dashboard.
- Data Usage: We only access your Google Ads campaign performance data and settings to provide reporting and automation features.
- Data Protection: We never share your Google User Data with third parties or use it for any purpose other than providing the campaign management features you have activated.
- Policy Compliance: This application adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Google API Services — Data Disclosure & Protection
Waravel's PagePromoter plugin integrates with the Google Ads API and Google Search Console API. This section discloses exactly how we handle the data obtained through these integrations, in compliance with Google API Services User Data Policy.
What Data We Access
- Google Ads campaign performance metrics (spend, clicks, impressions, cost-per-click)
- Google Ads campaign, ad group, ad, and keyword configuration data
- Google Ads conversion actions and search term reports
- Google Search Console keyword rankings and click-through data
- OAuth tokens required to authenticate API requests on your behalf
How We Use This Data
- To display your Google Ads performance data inside the Waravel dashboard
- To allow you to create, edit, pause, and manage your campaigns and ad groups
- To manage negative keywords at campaign and ad group level
- To display search term and conversion reports
- Data obtained via Google APIs is never used for advertising, profiling, or any purpose beyond providing the features you have activated
Data Protection Mechanisms
- Encryption in transit: All communication between Waravel and Google APIs is conducted exclusively over HTTPS/TLS 1.2 or higher. No data is transmitted over unencrypted connections.
- Encryption at rest: OAuth access tokens and refresh tokens are stored in your application's database. We recommend (and document) the use of encrypted database storage and server-level disk encryption.
- Access controls: Google API credentials are scoped to the authenticated user's account only. No other user within the Waravel platform can access another user's Google data. Access is enforced at both the application and API level.
- Token security: OAuth refresh tokens are stored server-side and are never exposed to the browser or client-side JavaScript. Access tokens are short-lived and refreshed automatically.
- Data minimisation: We only request the minimum scopes necessary (
auth/adwords) to provide the features described above. We do not request access to Gmail, Google Drive, or any other unrelated Google services. - No third-party sharing: Google User Data is never sold, rented, transferred to, or shared with any third party for any purpose whatsoever.
- Data retention: Campaign performance data fetched from Google Ads is displayed in real time and is not stored persistently in our databases. OAuth tokens are retained only while the integration is active and are deleted immediately upon disconnection.
Revoking Access
You may disconnect the Google Ads integration at any time via your Waravel Integrations settings page. Upon disconnection, all stored tokens are permanently deleted. You may also revoke access directly via your Google Account permissions page.
8. Your Rights (Regarding Your Users' Data)
As the data controller for your Laravel application, you are responsible for complying with data protection laws (like GDPR, CCPA). Waravel provides tools to help you manage data:
Access & Portability
All content is stored in your database. You can export it via standard SQL tools.
Deletion
Use the Waravel dashboard to permanently delete pages, media items, or admin users.
Correction
Edit any page or media metadata directly within the zero-code dashboard.
Data Controller Contact
The legal entity responsible for the processing of data on waravel.com is:
Workers Direct LTD
344-348 High Road, Ilford, IG1 1QP, United Kingdom.
Contact: [email protected]