Trust, Access & Data
This page exists so a provider can see exactly what we can and cannot do before granting any access, what is collected about the families who inquire, and where that data goes. It is written in plain terms on purpose – restraint made visible, not a permission hidden in a longer document.
What this costs
The practice pays Google directly for advertising. ABAOps is paid per ad inquiry – a phone call of 30 seconds or longer, or a completed intake form, produced by the ads – with no retainer, no minimum and no percentage of media. The rate is quoted on a call. The agreement runs month to month and either side may end it on 30 days' notice.
The access model
Access is granted through Google's own permission system, at the level the practice chooses, and each level is a separate, explicit grant. Read-only access is available for an initial review; managed access is what the work itself needs.
For an initial review, if the practice chooses to start there
Google's read-only access level
Can
- View campaigns, ad groups, keywords, ads, and search-term reports
- View conversion actions and how they are currently configured
- View account structure, budgets, and bidding settings as they exist today
- Verify whether calls and form submissions are being counted, and counted correctly
Cannot
- Change any setting, budget, bid, ad, or keyword
- Spend any part of the advertising budget
- Edit billing information or make a payment
- Add or remove users on the account
For the work described in the agreement
Google's standard access level
Can
- Build or repair campaigns, ad groups, keywords, ads, and negative-keyword lists
- Configure and correct conversion tracking
- Adjust budgets and bids within the monthly media cap and scope agreed with the practice
- Make changes by hand and list every one in the weekly pulse and the monthly report
Cannot
- Edit billing information or change the payment method – that stays with the provider and Google
- Change who owns the account
- Prevent the provider from removing our access at any time
Ownership, revocation, and offboarding
The Google Ads account is – and stays – the provider's. If it already exists, ownership never moves. If it is created fresh, it is created under the provider's own Google identity, so ownership sits with them from the first step.
What we are given is a short, revocable invitation – not a transfer of ownership. It can be withdrawn at any time from the account's own access settings, and removal takes effect immediately.
Offboarding: if an engagement ends, revoking access removes every level at once. The account keeps every campaign, ad, negative-keyword list, and change history exactly as we left it. Practice data we hold is handled per the retention terms below.
What the provider is responsible for
ABAOps does the account work. A provider is responsible for six things:
- –Name at least one person who can answer intake questions accurately, and describe how calls and form submissions are handled.
- –Keep the landing pages, phone numbers and intake form working, and tell ABAOps before changing them – the thank-you page after the form is how form inquiries are counted.
- –Install the Google tag and Google's website call tracking as ABAOps specifies, within 7 days of the start, and keep them in place.
- –Decide, as the owner of the website, the HIPAA basis for its tags and call tracking; nothing that sends form contents, names, diagnoses or insurance details to Google is ever configured by either side.
- –Make the landing-page changes ABAOps recommends, or say why not.
- –Agree the monthly media cap and scope by email, and check new ad copy for factual errors within three business days.
Data we collect
Call records
When a call from an ad happened, how long it lasted, and the caller's area code. Never the phone number.
Form conversions
How many intake forms were submitted each day, by campaign. Never the form contents.
Search terms and campaign metrics
The searches that triggered ads, clicks, spend, conversion counts.
Account settings and change history
To check daily that nothing has drifted.
Data we do not collect
- –No caller phone numbers, form contents, call logs, form exports or intake records – ABAOps does not ask for them and does not accept them.
- –No clinical data, diagnoses or insurance member numbers.
- –We do not collect clinical records, patient files, or data from any provider system unrelated to advertising. Account sign-in, business-profile, and website-usage data are described in the Privacy Policy.
Retention
- –Account data is retained while the account is active.
- –The Google Ads API billing record – counts by day, campaign and conversion action, and the times, durations and area codes of counted calls – is kept to verify invoices; aggregate counts are kept for reporting. A practice can request deletion at any time.
Subprocessors
The services below process data on our behalf. This list is kept current – it is the same list published on our privacy policy.
DataForSEO
Google Ads Keyword Planner data, collected as monthly market snapshots. No provider or family data is shared.
Clerk
Account sign-in.
Vercel
Application hosting.
Neon
Managed database hosting for application records – counts, aggregates and call records with time, duration and area code; never caller identities.
Anthropic and OpenAI
Automated classification of advertising search terms and preparation of account recommendations. Sent via commercial APIs, which under each provider’s API terms is not used to train their models. No family or patient contact information is sent.
Google Ads API
Reading campaign, keyword, and conversion data from accounts a provider connects or invites us into. Requests are scoped to that account's own data.
Resend
Setup and report email delivery.
Microsoft 365
Business email. The one provider that could receive information a practice sends by mistake; covered by Microsoft's business associate terms.
AI processing and PHI posture
AI classifies search intent, detects measurement failures and waste, and prepares account recommendations. Doing that work sends business profile details (practice name, location, services) and advertising search-term text to Anthropic and OpenAI over their commercial APIs. Under each provider's API terms, that data is not used to train their models. No family or patient contact information is sent to any AI provider.
ABAOps is designed so that no clinical information enters the system: we do not ask for or store diagnoses, clinical records, or insurance member numbers. A provider is responsible for ensuring their own use of the product complies with the privacy requirements that apply to their practice. ABAOps does not make a HIPAA-compliance certification claim.
ABAOps signs a business associate agreement with each practice, and by policy never obtains caller phone numbers, call logs, form exports or intake records.
Every change to the account's settings is made by a person. Where ABAOps chooses one of Google's automated bidding strategies, Google adjusts individual bids inside it – that is the only automation, and the practice is told in the weekly pulse. ABAOps does not accept Google's automated recommendations on a practice's behalf.
Work begins once access is confirmed. Launch timing depends on account condition, website tracking, billing, and Google verification.
Security contact
Questions about access, data, or a security concern: support@abaops.ai
Who runs this
ABAOps was founded by Rohit Verma.
Questions before you grant anything?
A conversation first – no access required to talk it through.
Talk through your account