Privacy Policy
Last updated: 3 October 2026
This policy explains what happens to personal data when you visit this website, contact us, or become a client of The Pineapple Studio. It also explains how we handle data we receive from Google and Meta when a client lets us connect their advertising and analytics accounts.
We keep it plain on purpose. If anything here is unclear, write to info@thepineapplestudio.com.
In short
- We collect only what we need to answer you and to run our clients’ marketing.
- We do not sell personal data, we do not share it for advertising, and we do not use it to train AI models.
- This website sets no tracking cookies and runs no analytics or advertising pixels.
- Data from clients’ Google and Meta accounts is used only for that client, and the client can revoke our access or have the data deleted at any time.
1. Who is responsible
The Pineapple Studio, owned and run by Hussein ElGhoul. Email: info@thepineapplestudio.com. See also the Imprint.
We are the controller of the personal data described in sections 2 and 3. For the advertising and analytics data of a client’s own business (section 4) we act on the client’s instructions. We apply the Swiss Federal Act on Data Protection and, for visitors in the European Economic Area and the United Kingdom, the GDPR, to the extent they apply to us.
2. When you visit this website
Our hosting provider, Cloudflare, processes technical data when your browser requests a page: IP address, date and time, requested page, browser and device type. This is needed to deliver the site securely, and is kept in short-lived server logs.
- We use your approximate country, taken from your IP address by Cloudflare at the time of the request, only to choose the language of the site. We do not store it.
- If you choose a language yourself, we remember that choice in one small cookie (see the Cookie Policy).
- We run no analytics, no tracking and no advertising scripts, and we load no third-party fonts or widgets.
3. When you contact us
If you send the contact form we receive your name, email address, message and the services you ticked, plus your business name and phone number if you add them. If you write to us, we receive your email address and what you send.
- Purpose: to reply to you and, if you want to work with us, to prepare a proposal. Legal basis: steps before a contract, and our legitimate interest in answering enquiries.
- The form is delivered by email through Cloudflare to our mailbox. We use that mailbox provider only to store and read our own email.
- We do not add you to a mailing list and do not send marketing without asking you first.
- A hidden field in the form catches automated spam. It collects nothing about you.
4. Client work: data from Google and Meta accounts
When a client hires us to run or report on their advertising, search or analytics, the client grants us access to their own accounts. We receive only the data those accounts hold, only the permissions below, and only for that client.
Google user data
We access the following through Google APIs, with the client’s consent, using OAuth:
| Service | What we read or do | Permission (scope) |
|---|---|---|
| Google Ads | Campaigns, ad groups, ads, keywords, budgets, costs, clicks, conversions and settings of the client’s Google Ads account. With the client’s approval we apply changes such as pausing a campaign or adjusting a budget. | https://www.googleapis.com/auth/adwords |
| Google Analytics 4 | Traffic, events and conversion reports of the client’s property. | https://www.googleapis.com/auth/analytics.readonly |
| Google Search Console | Search queries, clicks, impressions, rankings and indexing status of the client’s sites. | https://www.googleapis.com/auth/webmasters.readonly |
| Google Business Profile (only if the client chooses it) | Profile details, reviews and performance, and drafts of replies and posts that the client approves. | https://www.googleapis.com/auth/business.manage |
How we use it. To measure how the client’s marketing performs, to send the client a monthly report, to find and propose improvements, and, only with the client’s approval, to make those changes in the client’s own accounts. We do not use it for any other purpose.
Limited Use. The Pineapple Studio’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the reporting and ad-management features the client asked for.
- We do not transfer or sell Google user data, except where needed to provide those features, to comply with law, or as part of a merger or sale of the business with notice to the client.
- We do not use it for serving ads, for building profiles, or for advertising to anyone, including retargeting or interest-based advertising.
- No person reads the data except the owner of The Pineapple Studio, and only where needed to provide the service, for security, or to comply with law.
- We do not use it to develop, improve or train generalised artificial intelligence or machine-learning models. We may use AI-assisted tools to read reports and draft recommendations for the client, under terms and settings that do not allow our data to be used to train models.
Meta data
With the client’s consent, we connect to the client’s Meta advertising assets (Facebook and Instagram ad accounts and the Pages linked to them) through the Meta Marketing API, using the permissions ads_read, ads_management, business_management, pages_show_list and pages_read_engagement.
- We read campaigns, ad sets, ads, spend, results and audience statistics of that client, and, with the client’s approval, create or change ads in the client’s own ad account.
- We use this only to report on and manage the client’s advertising. We follow the Meta Platform Terms and Developer Policies.
- We do not sell it, do not give it to data brokers or advertisers, do not use it for surveillance, and do not combine it with data from other clients.
- We do not receive or store the private messages or personal profiles of the client’s customers or followers.
Where it is kept and who can see it
Data from client accounts is stored in a database on computers operated by us, not on this website. Access is limited to the owner. Access credentials are kept outside our source code and are never shared. Reports are shared only with the client they concern.
5. Who else receives data
We do not sell personal data and do not share it with advertisers or data brokers. Some of these providers run servers outside Switzerland and your country, including in the United States. They rely on safeguards such as standard contractual clauses.
- Cloudflare, Inc.: hosts this website and delivers contact-form emails.
- Our email provider: stores the mailbox that receives your messages.
- Google and Meta: they are the source of the account data in section 4. We send changes back to them only when a client approves them.
- Authorities, where the law requires it.
6. How long we keep it
| Data | How long |
|---|---|
| Contact form and email enquiries | Deleted 12 months after the enquiry is closed. |
| Server logs at our host | A short, rolling period set by the host, for security. |
| Language cookie | Up to 12 months, or until you delete it. |
| Data from client Google and Meta accounts | While we work for the client. Deleted within 30 days after access ends, or sooner on request. |
| Invoices and contracts | As long as the law requires us to keep accounting records. |
7. Security
Access to client data is limited to the owner, credentials are held outside our source code, access to client accounts uses the permissions listed above and nothing more, and every change to a client’s advertising account is reviewed and can be undone. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities where the law requires.
8. Your rights
You can ask us what we hold about you, ask us to correct or delete it, restrict or object to how we use it, receive a copy in a common format, and withdraw consent you gave. Email info@thepineapplestudio.com. We reply within 30 days. You can also complain to your data protection authority, for example the Swiss Federal Data Protection and Information Commissioner (FDPIC), or the authority in your country.
9. Revoking access and deleting your data
- Google: open myaccount.google.com/permissions, choose our app and select “Remove access”.
- Meta: open Facebook Settings, then “Business Integrations”, choose our app and select “Remove”.
- Or email us. The steps, and what we delete, are on the Data deletion page.
10. Children
This website and our services are for businesses. They are not directed at children under 16, and we do not knowingly collect their data.
11. Changes
If we change this policy we change the date at the top. For changes that matter to clients, we tell them by email. See also the Terms of Service.