How ROASt Labs handles your data
Last updated: 30 June 2026 · Effective: 30 June 2026
ROASt Labs (app.roast-labs.com) is a multi-platform paid-media portfolio management and budget optimisation tool covering Google Ads, Microsoft Advertising, Meta Ads, and TikTok Ads, operated by Thomas Edward Johnson, trading as ROASt Labs (“we”, “us”, “our”). This Privacy Policy explains how we collect, use, store, and protect your data when you use the ROASt Labs service.
By connecting any advertising or analytics account to ROASt Labs, you consent to the data practices described in this policy. The service is available at roast-labs.com (marketing site) and app.roast-labs.com (application).
When you connect a Google Ads, Microsoft Advertising, Meta Ads, or TikTok Ads account via OAuth 2.0, ROASt Labs accesses the following data through the relevant platform’s API:
We do not collect personal information about your ad viewers, click-level data tied to identifiable individuals, or any personally identifiable information (PII) from your advertising accounts.
If you choose to route a portfolio’s success metric to one of the following sources, ROASt Labs accesses the data required to compute that goal:
Each integration is opt-in. You can revoke any goal-source connection at any time from the Accounts tab.
roast_consent cookie at the .roast-labs.com root domain so the choice is shared between the marketing site and the application (see Section 6)Your advertising and goal-source data is used solely to:
We do not use your connected advertising-platform or goal-source data for advertising, profiling, remarketing, creditworthiness assessment, or any purpose other than providing the ROASt Labs service to you. (Separately, and only with your consent, our marketing site uses a Meta pixel to measure the ads that bring visitors to us — see Section 6b. That involves marketing-site visit data only, never your connected advertising-account or goal-source data.)
ROASt Labs offers an optional autonomous mode in which the optimisation engine runs nightly and applies recommended changes without per-change approval. This mode is disabled by default. When you enable it:
You remain responsible for the performance of your advertising campaigns. See our Terms of Service for the full responsibility allocation.
ROASt Labs requests only the OAuth scopes needed to provide the service. By platform:
https://www.googleapis.com/auth/adwords — read campaign data and push approved budget/target/keyword/asset changeshttps://www.googleapis.com/auth/analytics.readonly — read-only access to GA4 properties and reports for goal-source routinghttps://ads.microsoft.com/msads.manage — read campaign data and push approved changesads_read, ads_management, and pages_read_engagement — read campaign/ad/creative data, push approved changes, and read the name and ID of the Facebook Page(s) connected to your ad account (to confirm which Page your campaigns publish from; no Page content, followers, or insights are read). When you connect Meta, Facebook’s Login-for-Business flow additionally grants pages_show_list (permission to list the Pages you manage) as part of its Page-selection step; ROASt Labs uses this solely to let you choose which Page to confirm and does not otherwise enumerate, read, or store your list of Pagesread_orders — read-only order data for revenue attributioncrm.objects.deals.read — read-only deal data for revenue attributionYou can revoke any platform’s OAuth grant at any time from the relevant platform’s account settings (e.g. Google permissions) or by disconnecting the account from the ROASt Labs Accounts tab.
ROASt Labs’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We do not sell, rent, or share your advertising or goal-source data with any third parties for their own marketing or commercial purposes. Your data is accessible only to:
We use the following sub-processors. Each is bound by a written agreement that requires them to process your data only on our instructions and to apply appropriate security measures. (The exception is Meta: for the consent-gated marketing-site pixel, Meta acts as an independent controller of the page-visit data under its own terms, rather than as a processor acting solely on our instructions — see Section 6b.)
| Sub-processor | Purpose | Location |
|---|---|---|
| Render | Application hosting and managed Postgres database | EU (Frankfurt) |
| Stripe | Subscription billing and payment processing | USA / Ireland |
| Anthropic | AI agent (Flume) and report generation | USA |
| Google (Analytics) | Consent-gated sign-up / trial / purchase conversion measurement (see Section 6a) | USA |
| Meta (Facebook) | Consent-gated advertising measurement on the marketing site (Meta pixel) — see Section 6b | USA / EU |
| Cloudflare | Marketing site hosting (Pages), DNS, CDN, R2 encrypted backups | Global edge / EU |
We will provide reasonable advance notice via the ROASt Labs interface before adding any new sub-processor that materially changes how your data is processed.
ROASt Labs includes an in-app AI agent (Flume) and AI-generated reports. When you use these features, the following data may be sent to Anthropic’s API to generate the response or report:
These requests:
If you do not wish to use AI features, simply do not invoke the Flume agent or AI-generated reports. The rest of the service operates independently.
Some of our sub-processors (Stripe, Anthropic, Google, Meta) are located in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR Article 46, including the UK International Data Transfer Agreement (IDTA) and/or the European Commission’s Standard Contractual Clauses (SCCs), supplemented by the UK Addendum where applicable. Our sub-processors offer these mechanisms as standard. For the Meta pixel specifically, marketing-site measurement data transferred to Meta Platforms in the US relies on the EU–US Data Privacy Framework and its UK Extension. You can request copies of the relevant agreements by contacting us at the address in Section 11.
All data in transit is encrypted via HTTPS (TLS). The application database (Postgres on Render) is encrypted at rest. Encrypted backups are stored in Cloudflare R2 with AES-256-GCM application-side encryption (the encryption key is held only by us, not by the storage provider). See Section 7 for full security details.
Data deletion: You can disconnect any platform (Google Ads, Microsoft Advertising, Meta Ads, TikTok Ads, GA4, Shopify, HubSpot) at any time from the Accounts tab. Disconnecting a platform removes that platform’s OAuth tokens and the synced data scoped to that platform (campaigns, daily metrics, conversion actions, account configuration). Other connected platforms in the same workspace stay intact. Once you disconnect the last remaining platform on a workspace, all per-workspace synced data is wiped from our servers. To erase your entire account at once instead, use the self-service deletion flow described in Section 8.
app.roast-labs.com)The application uses the following strictly-necessary browser storage at all times:
roast_consent cookie recording your cookie choices (Analytics, and — if set on the marketing site — Advertising). It is set at the .roast-labs.com root domain so a choice made on the marketing site is honoured in the application too (and vice versa) — you are only asked once. The application itself uses only the Analytics choice; it runs no advertising pixels.With your consent, the application also uses Google Analytics 4 (measurement ID G-WQJHG1ZPSD, the same property as the marketing site) to measure how people sign up, start a trial, and subscribe, so we can understand which marketing efforts work and improve the product. The analytics tag loads only after you accept analytics cookies — either via the marketing-site banner or the consent banner shown in the application if you have not already chosen. If you reject or have not yet decided, no analytics tag loads and no analytics cookies are set.
_ga and _ga_* cookies for visitor and session identification. We send only non-identifying conversion events (for example, that a sign-up or trial start occurred, and the method used) — never your name, email, workspace, campaign, or advertising data — and we disable Google’s advertising and remarketing signals. Data is processed by Google; see Google’s Privacy Policy._ga client-id and, where available, your analytics session id) together with the subscription amount, currency, plan name, and a transaction reference (the Stripe checkout-session id, used so the same purchase is never counted twice) — never your name, email, workspace, or account details. To attribute the payment correctly, this pseudonymous identifier is passed to Google via Stripe (our payment processor) in the checkout session, so Google and Stripe are both recipients of this identifier. It is sent only if you had accepted analytics cookies at the moment you started checkout; if you had not, no identifier is captured and no purchase conversion is sent.roast_consent cookie in your browser (the consent banner will then ask again), or by rejecting analytics on the marketing-site consent panel. Withdrawing consent clears existing _ga* cookies.The application loads no advertising or retargeting pixels, sets no advertising cookies of its own, and uses no browser fingerprinting. (The shared roast_consent cookie records your marketing-site Advertising choice, but it is a strictly-necessary preference cookie, not a tracking cookie, and the application does not act on it.)
roast-labs.com)The marketing site offers two optional cookie categories, controlled by the consent banner shown on first visit and re-openable at any time via the “Cookie settings” link in the footer:
G-WQJHG1ZPSD). We use Google Consent Mode. Before you decide, and if you reject, GA4 sends only cookieless, aggregated pings — no _ga cookie is set and your IP address is anonymised — so we can count visits in aggregate (no cookies are stored on your device in this state). If you accept Analytics, GA4 additionally sets _ga and _ga_* cookies for visitor and session identification. Google’s advertising and remarketing signals are disabled in both states. Data is processed by Google; see Google’s Privacy Policy.994077340088555). Loaded only if you accept Advertising cookies. It then sets Meta’s _fbp cookie (and, for visitors arriving from a Facebook or Instagram ad, _fbc) and sends Meta a page-view event, so we can measure and improve the ads we run on Facebook and Instagram. If you reject or have not yet decided, the Meta pixel does not load, no Meta cookie is set, and no request is made to Meta. Data is processed by Meta Platforms; see Meta’s Privacy Policy._ga* cookies; withdrawing Advertising clears Meta’s _fb* cookies. Only the strictly-necessary cookies (such as your consent preference itself) are always stored.In the event of a data breach affecting your Google Ads data or account credentials, we will:
You can at any time:
We process your Google Ads data under the following legal bases:
ROASt Labs is a business-to-business tool designed for professional advertisers and agencies. The service is not directed at children under the age of 16 (or 13 where applicable). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes to how we use your Google Ads data, we will notify you via the ROASt Labs interface and prompt you to consent to the updated policy before continuing to use your data in any new way.
We encourage you to review this page periodically. The “Last updated” date at the top indicates when the policy was most recently revised.
For privacy questions, data access requests, or concerns about how we handle your data, contact us at:
If you are located in the UK or EU and are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO).