Privacy Policy

Last updated: September 15, 2026

This Privacy Policy describes how MediaHost ("we", "us", or "our") collects, uses, and discloses information when you use the MediaHost Orders Portal (the "Service"), including when you connect third-party advertising accounts such as Google Ads, Google YouTube, Meta (Facebook), and TikTok.

1. Information We Collect

When you connect a third-party advertising account to the Service, we collect and store:

  • OAuth access and refresh tokens required to communicate with the connected platform's API on your behalf.
  • Basic account identifiers (e.g., advertising account/customer IDs, account names) needed to create and manage campaigns.
  • The granted OAuth scopes for the connection (e.g., adwords, youtube.upload, youtube.readonly).
  • Company and user identifiers from your MediaHost account so that connected accounts can be associated with the correct company.

2. How We Use Information

Information collected is used solely to:

  • Authenticate and communicate with the connected advertising platform's API (Google Ads, Meta, TikTok) on your behalf.
  • Create, retrieve, and manage advertising campaigns, ad groups, budgets, and creative assets that you explicitly request through the Service.
  • Upload video content to YouTube when you explicitly submit a video as part of a campaign you create in the Service.
  • Display the status of your connected accounts and campaigns within the Service.

We do not sell your data, and we do not use your advertising account data for any purpose other than operating the Service on your behalf.

3. Data Storage and Security

OAuth tokens and account identifiers are stored in our secured database and are only accessible to the Service's backend for the purpose of making authorized API calls. Access to this data is restricted to authorized MediaHost personnel and systems required to operate the Service.

4. Data Sharing

We do not share your connected account data with third parties, except as required to communicate with the advertising platform APIs you have explicitly connected (Google, Meta, TikTok), or as required by law.

5. Data Retention and Revocation

Connected account credentials are retained until you disconnect the account within the Service, or until you revoke access directly from the third-party platform (for example, via Google Account Permissions). Revoking access will prevent the Service from making further API calls on your behalf.

6. Google API Services User Data Policy

MediaHost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Contact Us

If you have questions about this Privacy Policy, please contact your MediaHost account administrator or the support contact provided to your organization.