Privacy

Privacy Policy

Effective August 23, 2026

Caught is a private, agency-operated marketing reporting application. This policy explains the information Caught processes when an agency operator connects authorized client sources, records business outcomes, and prepares reports.

Information we process

  • Operator account information, such as name, email address, authentication data, and agency settings.
  • Client business and contact information supplied by the operator.
  • OAuth authorization details and encrypted refresh tokens needed to access authorized Google services.
  • Reporting data from connected Google Ads, Google Analytics 4, Search Console, and Google Business Profile resources.
  • Manual or CSV reporting data, website-health results, recorded customer inquiries, and operator-reviewed business outcomes.
  • Operational records such as connection status, synchronization attempts, errors, report versions, and delivery history.

How information is used

Caught uses information to authenticate the operator, connect approved sources, retrieve and normalize reporting data, reconcile provider activity with separately recorded business outcomes, prepare dashboards and reports, maintain audit history, troubleshoot errors, and protect the service.

Google user data and Limited Use

Caught accesses Google data only after an authorized operator grants access and configures a client resource. Google data is used to provide reporting, analysis, synchronization status, and finalized client reports. Caught’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Caught does not sell Google user data, use it for advertising, or expose OAuth credentials or Google Ads controls in client-facing reports.

Sharing and service providers

Information may be processed by infrastructure and delivery providers used to operate Caught, such as hosting, database, email, and messaging services. A client may receive only the finalized, client-scoped report approved for that client. Information may also be disclosed when required by law or necessary to protect the service, its users, or others.

Data retention and deletion

Reporting records are retained while needed to operate the service, preserve finalized historical reports, meet legitimate recordkeeping needs, and resolve security or support issues. Disconnecting a source stops future retrieval but does not automatically erase historical records or finalized reports. An authorized operator may request access correction or deletion by contacting Caught. Requests are evaluated against client authorization, security, and legitimate recordkeeping obligations.

Security

Caught uses access controls, server-side credential handling, encryption for stored Google refresh tokens, and narrowly scoped public report views. No method of storage or transmission is completely secure, and Caught does not guarantee absolute security.

Client report links

A finalized report may be shared through an unlisted, unguessable link. Anyone who obtains that link may be able to view the report, so recipients should not forward it beyond the intended audience. Draft reports and agency controls are not available through public report links.

Changes and contact

This policy may be updated as Caught’s reporting sources or practices change. Material changes will be reflected by a new effective date. Questions, access requests, or deletion requests may be sent to google-ads-api@caughtreporting.com.