Product data
Xaere Codes stores the organisation, project, code lifecycle, access credentials and operational audit data needed to issue and resolve codes. XR Audience is a separate service: it accepts only verified, minimised interaction events when an integrator has established a lawful consent flow. The technical data-boundary notice lists each current input, exclusion and deletion path.
Google Ads data used by XR Ads
When an organisation owner explicitly connects a Google Ads account, XR Ads requests the Google Ads API scope to read the accessible customer-account identifiers, account name, currency, time zone, campaign, ad group, ad, keyword and aggregated delivery-performance data needed for the reporting and attribution features shown in the XR Ads Console. XR Ads does not use this authorization to create or change campaigns, ads, bids or budgets.
XR Ads uses a separate Xaere-controlled service account for Google Data Manager conversion delivery. The public Google OAuth flow does not request the Data Manager scope. Confirmed first-party conversion events may include an advertising click identifier and event time and are sent only to the Google Ads destination selected by that organisation.
Google data handling
Google Ads data is used only to provide and improve the connected organisation's reporting, attribution and confirmed-conversion features. It is not sold, used for lending, or shared with data brokers or unrelated advertisers. Processing providers may handle encrypted infrastructure data only to operate Xaere under contractual confidentiality and security obligations.
Google refresh tokens are encrypted at rest with authenticated encryption, access is tenant-scoped and least-privilege, and operational access is logged and restricted. Transport uses HTTPS. Google data is retained only while the connection and tenant are active and for the configured reporting history; an organisation owner can disconnect the integration or request deletion through the contact page. Tenant closure deletes stored credentials, imported Google Ads reporting data and related integration state, subject only to legal or security records that must be retained.
What the receiver does not do
The Flutter receiver SDK does not create a persistent device identifier and contains no publisher or Audience secret. Audience reporting is optional and starts only after host consent. Advertising and personalization are separate host choices and have no SDK data flow. A random in-memory measurement token rotates every 30 minutes by default, is never stored on disk and disappears when the receiver is disposed.
Retention and tenant closure
Audience retention is configured per integration. An organisation owner can permanently close a tenant from the Console after MFA and explicit confirmation. This removes its Core workspace data and transactionally purges its verified events, replay state, integration secrets and legacy aggregates from the separate Audience database. Provider accounting or support records that must be retained externally remain governed by that provider and applicable law.
Requests
Access, correction or deletion requests can be sent through the contact page. Xaere does not use Google user data to train general-purpose AI or machine-learning models. Google API data is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements where applicable.