AdServeKit

Terms of use

What AdServeKit does, what it expects of you, and what it does not promise.

Last updated: September 19, 2026

Accounts

You create your account yourself, either by signing in with Google or by registering an email address and password. With Google, your identity is verified by Google and no password is held here; we request only basic profile scopes (openid, email, and profile) to authenticate you and create or link your user account. With an email address, you choose the password: it is stored only as an Argon2id hash, which cannot be reversed to recover it, and the address must be confirmed by a link we email you before the account becomes active. A deployment may close new registrations, in which case sign-up says so rather than creating an account. You are responsible for the security of whichever credential you sign in with, and for the activity of anyone you allow to use your session.

Your content and websites

Websites, campaigns, creatives, placements and reports belong to the workspace they were created in, and are not visible to other workspaces. Everyone you invite into a workspace can see its data, to the extent their role allows, and you can change or remove that access at any time. Two things deliberately cross that boundary, and only because you ask them to: a campaign connection, which shares agreed delivery and conversion figures with the partner you connect to, and a marketplace listing, which publishes what you choose to advertise about a property. You must own or be authorised to manage any website you connect, and any destination you advertise. Administrators of this deployment can see platform-wide operational data through separate, audited administrative views.

Acceptable use

Do not use AdServeKit to deliver unlawful, deceptive or malicious advertising, to run SEO audits against sites you do not control, to list a property you do not control, to misrepresent what a figure measures, or to attempt to reach another account’s data. Audits respectrobots.txtand are rate limited; circumventing those limits is a misuse of the platform.

The marketplace

Listing a property on the marketplace is opt-in and public. You may only list a website or profile you control, and control has to be proved through the platform itself — a verified domain, Search Console access, or signing in to the platform the profile is on. Pasting a URL is not a claim we will accept.

One live listing exists per real-world property. If another workspace has already verified and listed something you believe is yours, the listing is not transferred automatically — contact this deployment’s administrators, who can see the full history of every claim attempt. A claim is released only when the previous holder’s verification has lapsed.

Anything you write on a profile is your own description and is labelled as publisher-provided. Figures produced by a measuring system are labelled with that system. Presenting your own estimates as measured data, or a lifetime total as a recent period, is a misuse of the marketplace.

What a verification badge means

A verification badge states that the seller proved control of the property by the mechanism the badge names. That is its entire claim.

It is not an endorsement by AdServeKit or by the platform the profile is on, not a statement about audience authenticity, engagement quality or the value of the inventory, and not a guarantee of any outcome from buying it. Terms, delivery and payment are agreed directly between advertiser and publisher; AdServeKit provides the introduction and the evidence, and is not a party to the transaction.

Connected accounts

Connections to Google Search Console, YouTube and any other supported platform are read-only, optional, and revocable by you at any time — both here and in the provider’s own security settings. What each connection reads and why is set out in the Privacy Policy.

If a connection is removed or expires, properties verified through it stop being verified and their listings come off the marketplace. You can disconnect your Google services at any time from your account integrations, which revokes and deletes stored access and refresh tokens.

Data Protection and Google User Data

AdServeKit implements technical and organizational safeguards to protect personal information and Google user data against unauthorized access, disclosure, alteration, loss, or destruction. We maintain encryption in transit (HTTPS/TLS), encryption at rest for sensitive credentials (AES-256-GCM), least-privilege access controls, and secure credential handling.

AdServeKit’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • No sale or advertising use: Google user data is not sold, transferred to data brokers, or used for personalized advertising, retargeting, or determining creditworthiness.
  • AI and machine-learning restrictions: Google user data obtained through Google APIs is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
  • Human access restrictions: Human personnel are strictly prohibited from accessing or reading Google user data, except with your affirmative agreement for technical support, as strictly required for security investigations, to comply with applicable law, or when aggregated and anonymized for internal operations.
  • Revocation and deletion: You can disconnect your Google account at any time within the application or revoke permissions directly in your Google Account permissions. Disconnecting revokes and purges stored OAuth tokens. You can request deletion of all associated Google data at any time.

Deleting your account

You can request deletion of your own account from the account page. Deletion is scheduled rather than immediate: there is a recovery period during which you can cancel by signing in again. After it passes, your websites, campaigns, creatives, placements, analytics configuration, Search Console and social connections, marketplace properties and SEO audits are permanently removed, and your account record is anonymised.

Security and operational records — authentication events, administrative actions and platform incident logs — are retained after deletion. They are what makes an account compromise investigable, and they are not yours or ours to erase on request.

What is not promised

AdServeKit reports what it measures. SEO recommendations identify opportunities; they do not guarantee any ranking, traffic or revenue outcome. Advertising delivery depends on your own websites and traffic. A metric that could not be measured is shown as unavailable rather than as zero, and no figure on any report is a projection.

Changes

These terms describe the software as deployed. If the administrator of this deployment changes how it operates, this page is where that change is recorded.

Contact us

For questions regarding these Terms or to exercise any data protection rights, please contact us at support@adservekit.com or visit our support page.