Legal
Privacy Policy
Effective May 1, 2026
This Privacy Policy explains how The Web Guys, a division of OK Uniforms and Healthcare Ltd. ("we," "us," or "Draper") collects, uses, stores, shares, and protects information when you use Draper, available at draper.thewebguys.ca (the "Service"). We aim to be plain-spoken: this document tells you exactly what we touch and what we don't.
1. Who we are
Draper is operated by The Web Guys, a division of OK Uniforms and Healthcare Ltd., located at 655 W 13th Ave, Vancouver, BC V5Z 1N3, Canada. For any privacy question, data request, or complaint, contact us at thewebguyscanada@gmail.com.
2. Information we collect
2.1 Account information
When you sign in with Google, we receive your name, email address, and profile picture from Google. We store this so we can authenticate you and address you in the product.
2.2 Google Ads authorization
Draper requests the OAuth scope https://www.googleapis.com/auth/adwords. This scope lets Draper read and modify your Google Ads account on your behalf. With your authorization, Google issues us a refresh token, which we store encrypted at rest using AES-256-CBC. We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google product.
2.3 Business and campaign data
When you connect a business, we collect the website URL you provide, publicly available content from that URL (which we read to draft keywords and ads), the daily budget you set, your campaign goal, and any text you write inside the product. From your Google Ads account we read campaigns, ad groups, keywords, ad copy, conversion actions, and performance metrics (impressions, clicks, cost, conversions).
2.4 Audit logs
Every Google Ads API call Draper makes on your behalf is logged with a timestamp, the action taken, and the request and response payloads. We retain these logs for security, debugging, and compliance with Google's API terms.
2.5 Technical data
We collect standard server logs (IP address, user agent, request path, timestamp) for security and abuse prevention. We do not run third-party advertising trackers on the Service.
3. How we use information
- To authenticate you and operate your account.
- To build, launch, and optimize Google Ads campaigns inside the Google Ads account you connect.
- To generate ad copy and keyword suggestions using the Anthropic Claude API. We send only the data necessary for the task at hand (your business URL content, your goals, performance metrics). We do not send your Google account credentials or refresh tokens.
- To produce reports and recommendations for you inside the dashboard.
- To prevent fraud, abuse, and security incidents.
- To comply with legal obligations and the Google API Services User Data Policy, including the Limited Use requirements.
4. Google API Services User Data Policy
Draper's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google Ads data to provide and improve user-facing features within Draper.
- We do not transfer Google Ads data to third parties except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use Google Ads data for advertising purposes.
- No humans read your Google Ads data except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.
5. How we share information
We share information only with the following categories of sub-processors, and only as necessary to operate the Service:
- Vercel Inc. — application hosting (United States).
- Neon Inc. — managed Postgres database hosting (United States).
- Anthropic, PBC — large language model provider for generating ad copy and analysis (United States). Anthropic does not train its models on data submitted via the API.
- Google LLC — when you authorize Draper to access Google Ads, your requests reach the Google Ads API.
We do not sell, rent, or trade your personal information. We do not share your Google Ads data with advertising networks, data brokers, or analytics services.
6. Data retention
We retain account information and campaign data for as long as your account is active. Audit logs are retained for at least 24 months for compliance. When you close your account, we delete your encrypted refresh token and disconnect your Google Ads account from Draper within 30 days, and we delete or anonymize remaining personal data within 90 days, except where retention is required by law.
7. How to revoke access
You can disconnect Draper at any time using either method:
- Inside Draper, go to Settings and click "Disconnect Google Ads." This deletes our encrypted copy of your refresh token and stops all future API access.
- Visit myaccount.google.com/permissions, find "Draper," and click "Remove Access." This revokes the refresh token at Google's end immediately.
To delete your Draper account entirely, email thewebguyscanada@gmail.com with the subject "Account deletion request." We will confirm and process within 30 days.
8. Security
Refresh tokens are encrypted at rest with AES-256-CBC. Database connections use TLS. Application traffic is served over HTTPS. We restrict employee access to production data on a need-to-know basis and review access regularly. No system is perfectly secure; if a breach affects your data, we will notify you and applicable regulators as required by law.
9. Your rights
Depending on your jurisdiction (including British Columbia under PIPA, the rest of Canada under PIPEDA, the EEA/UK under GDPR, and California under CCPA), you may have the right to access, correct, delete, port, or restrict processing of your personal information, and the right to withdraw consent. To exercise any of these rights, email thewebguyscanada@gmail.com. We will respond within 30 days.
10. Children
Draper is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
11. International transfers
Our infrastructure providers operate in the United States. By using the Service, you understand that your information will be processed in the United States and Canada. We rely on standard contractual clauses and appropriate safeguards for cross-border transfers.
12. Changes to this policy
We may update this Privacy Policy. If changes are material, we will notify you by email or in-product notice at least 14 days before they take effect. The "Effective" date at the top of this page reflects the most recent update.
13. Contact
Questions, requests, or complaints?
The Web Guys, a division of OK Uniforms and Healthcare Ltd.
655 W 13th Ave, Vancouver, BC V5Z 1N3, Canada
thewebguyscanada@gmail.com