Legal
Privacy Policy
Last updated: August 24, 2026
Shield (https://shield.tokdijital.com) is Google Ads click-monitoring software (SaaS) operated by TOK Dijital. This Privacy Policy explains how we collect, protect, use, and delete account data, click/session signals, and data accessed through Google Ads OAuth. Shield is under continuous development; this text may be updated.
1. Data controller & contact
- Controller: TOK Dijital
- Address: Istanbul / Turkey
- Email: info@shield.tokdijital.com
- Web: https://shield.tokdijital.com · https://tokdijital.com
- Privacy requests: email us with subject line “Privacy Request”.
2. Categories of data we process
We process the following only as needed to provide the service:
- Account & identity: name, email, company, phone, panel session records
- Authentication: password hashes (plain-text passwords are never stored), optional Google sign-in data
- Payment: Polar (polar.sh) transaction results; customer / subscription IDs (full card numbers are not stored on Shield servers)
- Click & session signals (sensitive): IP address, user-agent, referrer, gclid, device/browser attributes, approximate geo location, risk scores, blocking decisions
- Google Ads / OAuth data (sensitive): only with your explicit consent — Google OAuth access and refresh tokens, linked Google Ads customer/campaign IDs, campaign names, location targets, IP exclusion lists, and other Google Ads API responses required by the service
- Support & security: support correspondence, error/security logs (personal data kept to a minimum)
3. Google user data & Limited Use
Shield complies with the Google API Services User Data Policy (Limited Use). Data received from Google is used only to:
- Connect to and maintain your Google Ads account link
- Detect invalid clicks / bot traffic, provide reporting, and optional Google Ads sync (IP exclusions, campaign/location settings, etc.)
- Display information in your account dashboard and act on your instructions
We do not use Google user data to:
- Serve general advertising or retargeting
- Sell, rent, or license user data
- Determine creditworthiness or for lending purposes
- Train artificial intelligence / machine learning models (including general or third-party models)
- Any purpose outside the features described for Shield
When you disconnect Google Ads in the panel or revoke app access in your Google Account, stored OAuth tokens and connection records are deleted or invalidated within a reasonable period.
3.1 Google OAuth scopes we request
Shield requests only the following Google OAuth scopes; each supports a specific feature:
https://www.googleapis.com/auth/adwords— connect to your Google Ads account; list campaigns, sync IP exclusions, location/filter settings, and optional protection workflowsemail— display the linked Google account in the panel and verify account mappingprofile— display the linked Google account name in the panel (authentication and support)openid— optional “Sign in with Google” only; does not grant advertising data access
We do not request scopes beyond those listed. Google Ads API access is enabled only when you connect in the Shield panel.
4. Purposes & legal bases
- Contract performance: Shield subscription, panel access, monitoring and protection
- Legitimate interests: fraud prevention, service security, abuse detection
- Legal obligation: accounting, tax, and regulatory requests
- Consent: linking Google Ads (OAuth) — you may disconnect at any time
5. Sharing & subprocessors
We do not sell personal data and do not transfer it to ad networks for profiling.
Data may be shared only as needed with:
- Hosting / infrastructure: servers, databases, backups
- Polar: payment processing and card tokenization (Polar / Stripe Connect)
- Email infrastructure: notifications and support
- Google LLC: only when you authorize OAuth for Google Ads API and authentication
Subprocessors are bound by confidentiality and security obligations.
6. Data protection mechanisms for sensitive data
Shield applies the following technical and organizational measures to protect sensitive data (Google OAuth tokens, Google Ads account data, IP/click records):
6.1 Encryption in transit
- All web traffic is encrypted with HTTPS (TLS 1.2 or higher)
- Google Ads API and OAuth communication uses only Google’s official TLS endpoints
- Payment data is sent via Polar’s secure encrypted channels; full card numbers are not stored on Shield servers
6.2 Storage security
- Data is stored in restricted server and database environments
- User passwords are stored using one-way hashing (industry-standard password hashing); plain-text passwords are never stored
- Google OAuth access/refresh tokens are stored server-side only, linked to the relevant user record; they are not kept in client-side code or publicly accessible files
- Database backups are kept in access-controlled environments
6.3 Access control & authentication
- Panel access requires authenticated sessions
- Google Ads data is accessible only to authorized users of the linked account
- Production system access follows least-privilege principles
- OAuth tokens are not shared via support email or with third parties
6.4 Network & application security
- Firewalls and closure of unnecessary ports
- Application-layer controls against SQL injection, XSS, and unauthorized access
- Logging and monitoring of security events and suspicious activity
- Regular software updates and security patches
6.5 Data minimization
- We request only Google Ads API scopes required for Shield’s stated features
- Google data is limited to the minimum fields needed for the service
- Tokens and access logs are not expanded beyond operational need
6.6 Incident response
If we suspect a data breach, we follow procedures to notify users and authorities as required by applicable law.
7. Retention & deletion
- Account data: while your account is active; deleted or anonymized within a reasonable period after account deletion (typically within 30 days)
- Click / session records: for as long as needed for service and reporting; deleted when a project is removed or upon request
- Google OAuth tokens: deleted when the connection is removed; all token records removed on account closure
- Payment records: may be retained as required by commercial and tax law
- Security logs: limited period (typically up to 12 months or shorter)
Deletion requests: info@shield.tokdijital.com
8. Your rights
Depending on applicable law (including KVKK in Turkey), you may have the right to:
- Know whether your data is processed
- Request information about processed data
- Request correction of inaccurate data
- Request deletion or restriction
- Object to processing and request remedies for harm
Contact info@shield.tokdijital.com — we respond within legal timeframes.
9. International transfers
Using Google LLC (USA) OAuth/API may transfer data to Google infrastructure under Google’s privacy and security commitments. Some hosting providers may be outside Turkey or the EEA; appropriate safeguards are applied.
10. Children
Shield is not directed at anyone under 18 and we do not knowingly collect data from children.
11. Policy changes
We may update this policy. Material changes will update the date above and may be notified via the panel or email. The current version is always at https://shield.tokdijital.com/index.php?page=privacy
12. Revoking Google OAuth access
To remove Google Ads access:
- Disconnect Google Ads in the Shield panel, and/or
- Remove Shield at Google Account → Third-party apps
Either method prevents further use of OAuth tokens.