Stronghold Roofing
Internal application

Stronghold Roofing — Google Ads Conversion Sync

An internal OAuth application used by Stronghold Roofing staff to report lead conversions from our website to our own Google Ads account.

Last updated: September 21, 2026

1. What this application does

This page describes an internal OAuth application operated by Stronghold Roofing LLC (Lakeland, Florida). The application uploads lead-conversion events from strongholdroofing.com to our own Google Ads account using the Google Ads Data Manager API, so paid-search reporting reflects real leads instead of only form fills.

It is used by Stronghold Roofing staff on our own Google Ads account only. It is not offered to the public and does not process data on behalf of any other business.

2. Who operates it

3. What Google user data it accesses

When a Stronghold staff member connects the application, Google prompts them to grant these scopes:

  • openid and email — so the internal dashboard can show which Google account is currently connected.
  • https://www.googleapis.com/auth/datamanager — to upload lead conversion events to our own Google Ads account via the Google Ads Data Manager API.
  • https://www.googleapis.com/auth/adwords — to read the names and ids of the Google Ads accounts this staff member can access, so they can choose which account receives this website's conversions. The application does not change campaigns, bids, or budgets.

We store the refresh token and the chosen Ads account id. We do not store Google Ads campaign data, and we do not request any other Google user data.

4. How the data is used

The application uploads conversion events for leads that submitted our own website contact forms or called our own tracked phone numbers. Personal identifiers (email, phone, name, address) are hashed with SHA-256 before upload, per Google's Enhanced Conversions requirements. No Google user data is used to train models, sold, transferred, or shared with any third party.

5. How the data is stored

The Google-issued refresh token is stored server-only in Cloudflare Workers KV, encrypted at rest, and is never sent to the browser. Access tokens are minted on demand and are short-lived. Uploaded conversion events themselves are not stored by the application beyond the transient request needed to send them to Google.

6. How to disconnect or delete

Any Stronghold staff member with dashboard access can revoke the grant from the internal dashboard's "Disconnect Google Ads" button, which removes the refresh token from Cloudflare KV.

The grant can also be revoked at any time from myaccount.google.com → Security → Third-party access. To request deletion of any residual data, email info@strongholdroofing.com.

7. Limited Use

Stronghold Roofing's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. More information

This page is intentionally not indexed by search engines. It exists to satisfy Google's OAuth application verification requirements.

Call 24/7