Last updated: 10 September 2026
Privacy Policy
This Privacy Policy explains how SDKH LLC (“we”, “us”, “our”) collects, uses, and protects your personal data when you use PPC Black Box, including the marketing website at ppcblackbox.com (the “Site”) and the application at app.ppcblackbox.ai (the “App”).
By using the Site or App, you agree to the practices described in this policy. If you do not agree, do not use the services.
1. Who we are
PPC Black Box is operated by SDKH LLC, a Mississippi limited liability company.
- Legal entity SDKH LLC
- Registered address 775 E. Fortification Street
Jackson, Mississippi 39202
United States - Contact email hello@skddataanalytics.com
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, SDKH LLC is the data controller for the personal data described in this policy. For residents of California, SDKH LLC is the business under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
We have not appointed a Data Protection Officer. Direct all privacy enquiries to the contact email above.
2. What personal data we collect
We collect different data depending on whether you visit the marketing Site or use the App.
2.1 Data collected on the marketing Site
When you visit ppcblackbox.com, we and our analytics providers automatically collect:
- Usage data Pages viewed, time on page, referral source, approximate geographic location (country/region derived from IP address), device type, browser type, and screen resolution.
- Session recordings Mouse movements, clicks, scroll depth, and page interactions, collected via Microsoft Clarity to help us understand how the Site is used.
- Checkout data If you click the checkout button, you are redirected to Stripe. Stripe collects your email address, payment card details, and billing information. We receive your email address and the fact that a payment was made; we never receive or store your card number.
2.2 Data collected when you use the App
When you create an account and use the App, we collect:
- Account data Your name, email address, and a hashed password. Your email is used to verify your account and send transactional messages.
- Session data Your IP address and browser user agent, stored with each login session for security and fraud prevention.
- Billing data Your Stripe customer identifier, subscription plan, subscription status, and billing renewal date. Payment card details are held by Stripe, not by us.
- Build inputs The landing page URLs, keywords, brand name, target location, and any competitor URLs you submit when creating a campaign build.
- Scraped page content The content of the landing pages you submit, including page text, headings, meta tags, navigation links, and contact information displayed on those pages (such as phone numbers). This is fetched from the web and cached for up to 7 days.
- SERP data Search engine results page data for the keywords and locations you target, including competitor ad copy and organic search results. This is fetched from DataForSEO and cached for up to 7 days.
- Generated campaign content The Google Ads campaign assets produced by the pipeline, including headlines, descriptions, keywords, and negative keywords.
- Usage and credit data The number of builds you have run, credits remaining, and token usage metadata for internal cost accounting.
- Support data The subject and content of any support tickets you create, along with your name and email address. If Discord integration is enabled, this information is also sent to a private Discord channel accessible to our support team.
- Organisation data Tags and custom names you assign to builds to organise your work.
2.3 Sensitive data
We do not knowingly collect special categories of personal data under GDPR Article 9, such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data. If you believe we have received such data inadvertently, contact us and we will delete it.
3. How we use your data
We use your personal data for the following purposes:
- Service delivery To build Google Ads campaigns from the landing pages and keywords you provide. This includes scraping the pages you submit, querying search results, and sending the collected content to OpenAI for campaign generation.
- Account management To create and manage your account, authenticate your sessions, and verify your email address.
- Billing and subscriptions To process payments through Stripe, manage your subscription, track credit balances, and send billing-related communications.
- Support To respond to your support enquiries and resolve issues you report.
- Product improvement To understand how the Site is used (via analytics and session recordings) and to improve the product over time.
- Security and fraud prevention To monitor sessions, detect unauthorised access, and protect the service against abuse.
- Legal compliance To meet our legal obligations and respond to lawful requests from authorities.
4. Legal basis for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract (GDPR Article 6(1)(b)) — processing your account data, build inputs, and billing data to deliver the service you signed up for.
- Legitimate interests (GDPR Article 6(1)(f)) — collecting analytics data on the marketing Site to improve the product, recording session data for security, and processing support tickets to resolve issues. These interests are balanced against your rights and expectations.
- Consent (GDPR Article 6(1)(a)) — setting non-essential cookies on the marketing Site, such as analytics and session recording cookies. You can withdraw consent at any time through your browser settings.
- Legal obligation (GDPR Article 6(1)(c)) — retaining billing records and responding to lawful requests where required.
5. Third-party processors and data sharing
We share personal data with the following third parties, each acting as a processor or sub-processor. We do not sell your personal data.
- OpenAI Receives the content of landing pages you submit (as scraped markdown), keywords, competitor ad copy, and SERP data, for the purpose of generating campaign assets. We set
store: falseon every API call, which instructs OpenAI not to retain the input or output for model training. OpenAI is based in the United States. - Stripe Processes your payment card details and billing information when you subscribe. Stripe is the data controller for your card data; we receive only your email, name, and subscription identifiers. Stripe is based in the United States. See Stripe’s Privacy Policy.
- DataForSEO Receives the keywords and location names you target, for the purpose of retrieving search engine results page data. DataForSEO is based in the United States. See DataForSEO’s Privacy Policy.
- Firecrawl Receives the landing page URLs you submit when a direct fetch fails (for example, if the page is behind a bot challenge or is a JavaScript-rendered single-page application). Firecrawl fetches the page content on our behalf. Firecrawl is based in the United States.
- Brevo Sends transactional emails on our behalf (welcome emails, password reset emails, subscription confirmations). Brevo receives your email address and name. Brevo is based in France. See Brevo’s Privacy Policy.
- Discord If you create a support ticket and Discord integration is enabled, your name, email address, ticket subject, and message content are sent to a private Discord channel accessible to our team. Discord is based in the United States. See Discord’s Privacy Policy.
- Google (Google Tag Manager & Google Analytics 4) Collects usage data on the marketing Site via cookies and JavaScript tags. Google may use this data subject to its own policies. Google is based in the United States. See Google’s Privacy Policy.
- Microsoft (Clarity) Collects session recordings and interaction data on the marketing Site. Microsoft is based in the United States. See Microsoft’s Privacy Statement.
- Database hosting (Supabase / Railway) Hosts the PostgreSQL database that stores your account, build, billing, and support data. The hosting provider has access to the infrastructure but not to the application-level data. Supabase is based in the United States; Railway is based in the United States.
5.1 International data transfers
Your personal data is processed in the United States and potentially in other countries where our processors operate. When data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards agreed with the processor, or we rely on an exception under GDPR Article 49.
For California residents, we do not share personal information with third parties for cross-context behavioural advertising, and we do not sell or share personal information as those terms are defined under the CCPA.
5.2 Google API Services & User Data Policy
When you use features of PPC Black Box that integrate with Google APIs (such as Google Sign-In or connecting your Google Ads account to audit campaigns and export data), PPC Black Box accesses, collects, and processes specific Google user data strictly to deliver and improve those features:
- Google Account Data When authenticating with Google OAuth, we access your basic profile information (such as your email address, name, and profile picture) to create, authenticate, and verify your user account.
- Google Ads Data If you connect your Google Ads account, we access campaign configurations, ad groups, keywords, assets, and performance metrics solely to analyze your campaigns, generate audit recommendations, and allow you to deploy optimized campaigns directly to your Google Ads account.
- Data Storage & Security Google user data is transmitted securely via TLS and encrypted at rest in our database. We retain Google account and campaign tokens only for as long as your account remains connected and active.
- No Selling or Advertising We do not sell your Google user data to any third party. We do not use or transfer Google user data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
- No AI Model Training PPC Black Box does not use Google user data (or any confidential data received via Google APIs) to train, retrain, fine-tune, or improve generalized or foundational artificial intelligence (AI) or machine learning (ML) models.
- Human Access Restrictions Our personnel do not access your Google user data unless you provide explicit consent to resolve a specific support issue, or where required to investigate security incidents or comply with applicable legal obligations.
- Access Revocation & Deletion You can revoke PPC Black Box's access to your Google account at any time through the Google Security Permissions Settings. You may also request complete deletion of all stored Google data by emailing hello@skddataanalytics.com with the subject “Google Data Deletion Request”. Upon request, your data will be permanently deleted from our servers within 30 days.
Limited Use Disclosure: PPC Black Box’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Cookies and tracking technologies
The marketing Site uses cookies and similar technologies. The App uses a single essential session cookie and does not set any analytics or tracking cookies.
- Essential cookies The App sets a session cookie (
better-auth.session_token) to keep you logged in. This cookie is strictly necessary for the service to function and cannot be disabled. - Analytics cookies The marketing Site loads Google Analytics 4 via Google Tag Manager. These cookies collect usage data such as page views and session duration. You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on.
- Session recording cookies The marketing Site loads Microsoft Clarity, which uses cookies and localStorage to record sessions. You can opt out of Clarity by blocking third-party cookies in your browser settings.
- Stripe cookies The Stripe checkout page sets its own cookies for fraud prevention. These are governed by Stripe’s privacy policy.
You can control cookies through your browser settings. Blocking all cookies will not affect your ability to read the marketing Site, but you will not be able to log in to the App without the session cookie.
7. Data retention
We retain personal data for as long as necessary to fulfil the purposes described above:
- Account data Retained for the life of your account. When you request account deletion, we remove your name, email, and password within 30 days.
- Session data Retained until the session expires or you log out, after which the session record is deleted.
- Build data Retained until you archive or delete a build. Archived builds are excluded from your dashboard but remain in the database until you request permanent deletion.
- Scraped page content Cached for up to 7 days, after which it is refetched or expires.
- SERP data Cached for up to 7 days, after which it is refetched or expires.
- Billing data Retained for as long as required by tax and financial regulations, typically 7 years.
- Support data Retained for the life of your account plus 12 months after account deletion, to allow reference to resolved issues.
- Analytics data Retained by Google Analytics for up to 14 months, and by Microsoft Clarity for up to 18 months, subject to their respective retention policies.
8. Your rights
8.1 Rights under GDPR (EEA, UK, Switzerland)
If you are in the EEA, UK, or Switzerland, you have the following rights:
- Access Request a copy of the personal data we hold about you.
- Rectification Request correction of inaccurate or incomplete personal data.
- Erasure Request deletion of your personal data (the “right to be forgotten”).
- Restriction Request that we limit processing of your personal data in certain circumstances.
- Portability Receive your personal data in a structured, machine-readable format and transmit it to another controller.
- Objection Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent Withdraw consent for processing that relies on it (such as analytics cookies) at any time, without affecting the lawfulness of processing before withdrawal.
- Complain Lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office. In the EU, contact your member state’s data protection authority.
8.2 Rights under CCPA/CPRA (California)
If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:
- Know Request the categories and specific pieces of personal information we collect, the purpose of collection, and the third parties to whom it is disclosed.
- Delete Request deletion of your personal information, subject to certain exceptions.
- Correct Request correction of inaccurate personal information.
- Opt out You have the right to opt out of the sale or sharing of your personal information. We do not sell or share your personal information, so no opt-out is necessary.
- Non-discrimination We will not discriminate against you for exercising any of these rights.
To exercise these rights, email hello@skddataanalytics.com with the subject line “Privacy Request”. We will verify your identity before responding. We respond to verifiable requests within 45 days.
8.3 Rights in other jurisdictions
- Canada (PIPEDA) You have the right to access your personal information, challenge its accuracy, and withdraw consent. Contact us to exercise these rights.
- Other US states If your state has a consumer privacy law (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA), you may have rights similar to those described above. Contact us to exercise them.
- Australia (Privacy Act) You have the right to access and correct your personal information. Contact us or lodge a complaint with the Office of the Australian Information Commissioner.
9. Security
We take reasonable technical and organisational measures to protect your personal data:
- Passwords are stored as scrypt hashes, never in plaintext.
- API keys and secrets are encrypted at rest in the database.
- All data in transit is encrypted using TLS.
- Access to the database and admin functions is restricted to authorised personnel and protected by authentication and role-based access control.
- OpenAI API calls are made with
store: false, instructing OpenAI not to retain input or output data. - Stripe webhook payloads are cryptographically verified to prevent unauthorised access.
No method of transmission or storage is fully secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by applicable law.
10. Children’s privacy
The Site and App are not directed at children under 16 (under 13 in the United States under COPPA, under 16 under the GDPR age of consent in most EU member states and the UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. If we make material changes that affect your rights, we will notify you by email (if we have your address) or by a prominent notice on the Site before the changes take effect.
Continued use of the Site or App after a change takes effect constitutes acceptance of the updated policy.
12. Contact
If you have questions about this Privacy Policy or want to exercise any of your rights, email hello@skddataanalytics.com with the subject line “Privacy Request”.
If you are not satisfied with our response, you have the right to complain to your local data protection authority. In the UK, this is the Information Commissioner’s Office (ico.org.uk). In the EU, contact your member state’s supervisory authority. In California, contact the California Attorney General.