Privacy Policy

Last updated: 30 August 2026.

This policy explains how PrepRun processes personal data and how its limited internal Google Ads API tool uses Google account data.

Data controller: BUSINESS SAFETY COACHING INTERNATIONAL sp. z o.o., ul. Romana Dmowskiego 22/112, 43-100 Tychy, Poland — VAT (NIP): PL6463026358. Contact: preprun@outlook.com.

1. Google Ads API and Google user data

PrepRun uses the Google Ads API only through an internal first-party tool operated by authorised staff of the data controller. The OAuth grant is used to access the controller's own Google Ads account. The tool reads campaign identifiers, configuration, status and bounded cost information for one pre-created Search campaign, and may change only that campaign's status between enabled and paused.

The authorised Google account holder can revoke access through their Google Account security settings. The controller can also delete the internal OAuth credentials. Requests may be sent to preprun@outlook.com. The tool is described at PrepRun Google Ads API Internal Tool.

2. Other data PrepRun processes

3. Purposes and legal bases

We process data to provide accounts and services (contract), secure and improve PrepRun through bounded aggregate analysis (legitimate interests), send marketing and perform optional Google Ads purchase measurement only after the relevant explicit consent, and meet accounting or legal duties. Automated tools do not make legal or similarly significant decisions about individuals.

4. Processors

We use Supabase for authentication/database/server functions, OpenAI for requested AI functionality and bounded analysis, Stripe for payments, Resend for email, Cloudflare for hosting and cookieless analytics, and Google Ads for the internal campaign-control purpose described above and, only after explicit opt-in, purchase conversion measurement. Providers process data under their applicable contractual and data-protection terms.

5. Cookies and local storage

PrepRun uses essential browser storage for sign-in, settings, progress and security tokens, plus cookieless analytics. The Google Ads tag is not requested and no Google Ads measurement data is sent before you explicitly opt in. If you opt in, Google may set or read advertising-measurement storage to attribute a purchase; personalised advertising, customer-list targeting, remarketing and lookalike audiences remain disabled. You can refuse without losing any PrepRun functionality and withdraw later in Settings.

6. Retention and security

Account and selected progress records are kept while the account is active. Expired or abandoned EPSO practice sessions are deleted after 30 days and completed EPSO sessions after 365 days; EPSO Tutor metadata-only events are deleted after 30 days. Temporary security hashes are deleted within 36–48 hours; anonymous candidate-demand data within 90 days; public-community discovery metadata within 30 days; interview vacancy text within 90 days; and optionally retained CV text within 30 days. Non-personal security, reconciliation and audit receipts may be retained to prove safe operation. Access is restricted according to role and protected in transit and at rest.

7. Your rights

Under the GDPR you may request access, correction, deletion, portability or restriction, and object where applicable. You may withdraw consent at any time and complain to the Polish UODO or the supervisory authority in your EU country. Contact preprun@outlook.com.

8. Changes

Material changes will be communicated in the application or by email where appropriate. The current version and update date remain available on this page.