Pixelgipfel AG · Pixelgipfel Northstar
Datenschutz & Privacy Policy
Diese Erklärung beschreibt, wie Pixelgipfel Northstar Google-Konto-, Google-Ads- und Search-Console-Daten für die interne Arbeit der Pixelgipfel AG verarbeitet.
Aktueller Status / Current status: Northstar läuft derzeit in einem abgeschotteten, schreibgeschützten Prüfmodus. Google-Provider-Abrufe, OAuth-Callbacks, Kampagnen- und Budgetänderungen, Automationen und KI-Funktionen können deaktiviert sein. Google-Daten werden nur verarbeitet, wenn der Kontoinhaber die Verbindung ausdrücklich autorisiert hat und die betreffende Funktion freigegeben ist.
Datenschutzerklärung (Deutsch)
1. Verantwortliche Stelle und Geltungsbereich
Verantwortlich ist die Pixelgipfel AG, Schweiz. Pixelgipfel Northstar ist eine First-Party-Anwendung für die interne Marketinganalyse und -steuerung der Pixelgipfel AG. Sie ist kein öffentlich angebotener Dienst. Zugriff erhalten nur autorisierte Mitarbeitende oder ausdrücklich beauftragte Personen.
2. Welche Google-Daten verarbeitet werden können
Nach einer ausdrücklichen OAuth- oder Kontofreigabe kann Northstar je nach aktivierter Verbindung verarbeiten:
- Google-Kontoinformationen, die zur Zuordnung und Autorisierung der Verbindung erforderlich sind;
- Google-Search-Console-Properties sowie Suchleistungsdaten wie Suchanfragen, Klicks, Impressionen, Klickrate und durchschnittliche Position;
- Google-Ads-Konto-, Kampagnen-, Anzeigen- und Leistungsdaten wie Impressionen, Klicks, Kosten und Conversions, soweit das verbundene Geschäftskonto diese bereitstellt;
- OAuth-Zugriffs- und Aktualisierungstoken, soweit diese für eine vom Kontoinhaber autorisierte Verbindung erforderlich sind.
Northstar fordert nur Daten und Berechtigungen an, die für die aktivierte interne Funktion erforderlich sind. Die tatsächliche Verfügbarkeit einzelner Verbindungen kann im aktuellen Prüfmodus eingeschränkt oder vollständig deaktiviert sein.
3. Zwecke
Die Daten dienen ausschliesslich der internen Auswertung von Marketing- und Suchleistung, der Erstellung von Berichten, der Erkennung von Optimierungsmöglichkeiten sowie der kontrollierten Planung und Dokumentation von Pixelgipfel-Kampagnen. Google-Nutzerdaten werden nicht zur Erstellung fremder Werbeprofile oder für vom Nutzer nicht autorisierte Zwecke verwendet.
4. OAuth, Speicherung und Zugriffsschutz
Eine Google-Verbindung wird vom berechtigten Kontoinhaber im Google-OAuth-Dialog autorisiert. OAuth-Zugangsdaten werden bei einer aktivierten Verbindung verschlüsselt gespeichert; die Übertragung erfolgt über HTTPS. Zugriff auf verbundene Daten ist auf autorisierte Pixelgipfel-Personen und technisch notwendige, weisungsgebundene Dienstleister beschränkt. Token und Google-Daten werden nicht in öffentlichen Seiten oder absichtlich in Anwendungsprotokollen offengelegt.
5. Keine Veräusserung, Weitergabe oder Modellschulung
Pixelgipfel verkauft oder vermietet Google-Nutzerdaten nicht und gibt sie nicht an Datenhändler, Werbenetzwerke oder andere unabhängige Dritte weiter. Google-Nutzerdaten werden nicht zum Trainieren allgemeiner KI- oder Machine-Learning-Modelle verwendet. Eine Verarbeitung durch notwendige Hosting-, Speicher- oder Sicherheitsdienstleister erfolgt nur im Auftrag von Pixelgipfel oder wenn eine gesetzliche Pflicht besteht.
6. Aufbewahrung, Widerruf und Löschung
Google-Nutzerdaten und OAuth-Token werden nur so lange aufbewahrt, wie die autorisierte Verbindung und der beschriebene interne Geschäftszweck bestehen. Der Kontoinhaber kann den Zugriff jederzeit in seinem Google-Konto widerrufen. Nach Trennung der Verbindung oder einer verifizierten Löschanfrage entfernt Pixelgipfel die zugehörigen Token und gespeicherten Google-Daten, soweit keine zwingende gesetzliche Aufbewahrungspflicht entgegensteht. Der konkrete Ablauf und Zeitrahmen werden nach Prüfung der Anfrage bestätigt. Die Anleitung steht unter /data-deletion.
7. Google API Services User Data Policy
Die Nutzung und Übertragung von Daten aus Google APIs durch Pixelgipfel Northstar an andere Anwendungen erfolgt gemäss der Google API Services User Data Policy, einschliesslich der Limited-Use-Anforderungen.
8. Kontakt
Fragen, Auskunfts- oder Löschanfragen: info@pixelgipfel.ch. Bitte keine Passwörter, API-Schlüssel, Zugriffstoken oder Wiederherstellungscodes per E-Mail senden.
Privacy Policy (English)
1. Controller and scope
Pixelgipfel AG, Switzerland, is the controller. Pixelgipfel Northstar is a first-party application used for Pixelgipfel AG's internal marketing analysis and control. It is not offered as a public service. Access is limited to authorized employees and specifically commissioned personnel.
2. Google data that may be processed
After explicit OAuth or account authorization, Northstar may process, depending on the enabled connection:
- Google account information required to identify and authorize the connection;
- Google Search Console properties and search performance data such as queries, clicks, impressions, click-through rate, and average position;
- Google Ads account, campaign, ad, and performance data such as impressions, clicks, cost, and conversions where supplied by the connected business account;
- OAuth access and refresh tokens where required for a connection authorized by the account owner.
Northstar requests only the data and permissions needed for the enabled internal function. Individual connections may be restricted or entirely disabled in the current inspection mode.
3. Purposes
Data is used only to analyze internal marketing and search performance, prepare reports, identify optimization opportunities, and support the controlled planning and documentation of Pixelgipfel campaigns. Google user data is not used to build advertising profiles for others or for purposes the user did not authorize.
4. OAuth, storage, and access controls
An eligible account owner authorizes a Google connection through Google's OAuth screen. When a connection is enabled, OAuth credentials are stored encrypted and transmitted over HTTPS. Access to connected data is limited to authorized Pixelgipfel personnel and technically necessary service providers acting under Pixelgipfel's instructions. Tokens and Google data are not exposed on public pages or intentionally placed in application logs.
5. No sale, independent sharing, or model training
Pixelgipfel does not sell or rent Google user data and does not disclose it to data brokers, advertising networks, or other independent third parties. Google user data is not used to train general-purpose AI or machine-learning models. Necessary hosting, storage, or security providers may process data only on Pixelgipfel's instructions, or where disclosure is legally required.
6. Retention, revocation, and deletion
Google user data and OAuth tokens are retained only while the authorized connection and the stated internal business purpose continue. The account owner can revoke access at any time through their Google Account. After disconnection or a verified deletion request, Pixelgipfel deletes the associated tokens and stored Google data unless mandatory law requires limited retention. Pixelgipfel confirms the applicable process and timeframe after reviewing the request. Instructions are available at /data-deletion.
7. Google API Services User Data Policy
Pixelgipfel Northstar's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Contact
For privacy, access, or deletion requests, email info@pixelgipfel.ch. Never send passwords, API keys, access tokens, or recovery codes by email.