This policy is published by Conner Herlehy, doing business as Herlehy Development (“we”, “us”), based in Chicago, IL. It covers two things:
- This website, which describes our services and past work.
- The client analytics dashboard we build and operate, including the data it accesses through the Meta Marketing API and the Google Ads API.
Summary
- This website has no analytics, no cookies, no forms and no accounts.
- The dashboard reads advertising performance totals from one client’s own ad accounts. It retrieves no personal data about any individual through the Meta or Google APIs.
- Advertising data is used only to report results to the ad account’s owner. It is never sold, rented, or shared for anyone else’s use.
- The ad account owner can revoke our access at any time.
1. This website
This website does not use analytics, advertising or tracking tools, and it sets no cookies. It has no forms, sign-ups or user accounts. Fonts and images are served from this website itself, not loaded from third-party services.
The only way to contact us from the site is an email link, which opens your own email app. If you email us, we receive your email address and whatever you choose to include, and we use it only to reply to you.
Hosting and request logs
This website is hosted by Vercel Inc. Like any web host, Vercel processes each request to the site and records standard request data in its logs, including your IP address, browser user agent, the page requested and the time of the request. This is used to deliver and secure the site. We do not use these logs to identify, profile or track visitors, and we do not combine them with any other data. See Vercel’s privacy policy.
2. The client analytics dashboard
We build and operate an internal marketing-analytics and CRM dashboard for a single client, a Chicago-area home improvement company. It is private: only the client’s authorized staff and we, as its developer, can sign in. It is not available to the public and is not offered or sold to anyone else.
The dashboard reads advertising performance data from the client’s own ad accounts on Meta and Google and shows it next to the client’s own lead and sales records. For example, it calculates cost per lead by dividing advertising spend by the number of leads the client recorded in the same period. Advertising data and CRM records are combined only as totals like this, never at the level of an individual person.
2.1 Data accessed through the Meta Marketing API
- Permission used:
ads_read. - What is requested: the Insights endpoint of the client’s ad account (
/act_{ad-account-id}/insights), at campaign level, broken down by day, for the last 30 days. - Data points retrieved, per campaign per day: campaign ID, campaign name, date, amount spent, impressions, clicks, cost per click (CPC), cost per 1,000 impressions (CPM), and action counts (aggregate numbers of on-ad actions by type, such as link clicks or lead events).
- What is not accessed: no information about individual people. That means no names, profiles, contact details, lead-form submissions, audiences or user-level data.
- Read-only: the dashboard never creates, edits, pauses or deletes campaigns, ads or audiences.
2.2 Data accessed through the Google Ads API
- Authorization: OAuth with the Google Ads scope (
https://www.googleapis.com/auth/adwords), used for read-only reporting through Google Ads search queries. - Data points retrieved, per campaign per day, for the last 30 days: campaign ID, campaign name, date, impressions, clicks, cost, conversions (a count), and the account’s currency code.
- What is not accessed: no information about individual people. The dashboard does not use Customer Match or audience lists, and it does not upload conversions or any other data to Google.
- Read-only: the dashboard makes no changes to campaigns, budgets, bids, ads or account settings.
- Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
2.3 How advertising data is used and protected
- Purpose: reporting advertising results to the owner of the ad account. We do not use it for any other purpose. It is not used for advertising, profiling, reselling or training AI models.
- No selling or sharing: we do not sell, rent or share this data with third parties. It is stored and processed only by the infrastructure providers that host the dashboard, Vercel (application hosting) and Supabase (database), acting on our behalf.
- Access: inside the dashboard, advertising data is restricted to the client’s authorized managers. API credentials are kept on the server as secrets and are never sent to anyone’s browser. All traffic is encrypted with HTTPS.
- Nothing flows back: no CRM or customer data is sent to Meta or Google.
2.4 Revoking access
The owner of the ad account can revoke our access at any time. After that, the dashboard can no longer retrieve any data.
- Meta: remove the app or our access in Meta Business Settings, or under Settings & privacy → Business integrations in the Facebook account that granted it.
- Google: remove our access at myaccount.google.com/permissions, or remove our user or manager-account link under Admin → Access and security in Google Ads.
2.5 The client’s own business records
Separately from the advertising data above, the dashboard stores the client’s own business records, such as leads, customers, appointments and sales. These come from the client’s own systems (call tracking and sales software), not from Meta or Google. They belong to the client, are handled only on the client’s instructions for running its business, and are never sent to Meta or Google. The statements in sections 2.1 to 2.4 about “no personal data” refer to data accessed through the Meta and Google APIs.
3. Data retention
- Advertising data is kept in the dashboard’s database while the client uses the dashboard, so it can show trends over time. We delete it within 30 days of the ad account owner revoking access, ending the engagement, or asking us to delete it.
- Emails you send us are kept as ordinary business correspondence and deleted on request.
- Website request logs are held by Vercel under its own retention settings. We do not export or keep copies.
4. Data deletion and privacy requests
To ask what data we hold, or to request deletion, email conner@herlehy.dev with the subject “Privacy request”. If the request concerns advertising data, tell us which ad account it relates to. We will confirm when the request is complete, and we complete deletion requests within 30 days. Revoking access as described in section 2.4 stops all further data retrieval immediately.
5. Children
This website and the dashboard are not directed at children, and we do not knowingly collect information from children.
6. Changes to this policy
If our practices change, we will update this page and the “Last updated” date at the top.
7. Contact
Conner Herlehy, doing business as Herlehy Development
Chicago, IL
conner@herlehy.dev