Privacy policy
Last updated: 11 October 2026
stopfakeclicks protects Google Ads accounts from bots and repeat clickers. This page explains what data we handle, why, and for how long. It covers two groups of people: our customers, who run the ads, and the visitors who click those ads and land on our customers' websites.
Who we are
stopfakeclicks is a trading name of Silver Image Creation Ltd, a company registered in England and Wales (company number 07282315), registered office 8 Royal Parade, Hanger Lane, London W5 1ET. We are registered with the UK Information Commissioner's Office under number ZC231198. The service runs at stopfakeclicks.com and api.stopfakeclicks.com. You can reach us at hello@stopfakeclicks.com.
For customer accounts we are the controller. For data about visitors to a customer's website we act as a processor on the customer's behalf: the customer decides to install our tag, and we use the data only to protect that customer's ads.
Customers: what we keep
- Your email address, used to sign you in and to send the reports and alerts you choose.
- If you sign in with Google, we receive your verified email address from Google and nothing else is stored. We request only the basic sign-in scopes (openid, email, profile). We do not access your Gmail, Drive, contacts or Google Ads through this sign-in.
- Your settings: store address, blocking rules, report day and extra report recipients.
- Figures that our Google Ads script sends from your account: your account ID, currency, and daily clicks and cost per campaign and keyword. We use them to estimate what suspicious clicks cost you.
Visitors who click an ad: what the tag records
The tag reports a visit only when it arrives from a Google ad, recognised by the click ID Google adds to the link. Ordinary visitors who did not click an ad are not recorded. For a visit from an ad we record:
- IP address, country and network provider
- browser and device type, taken from the user agent
- the Google click ID, the landing page and the referring page
- whether the browser shows signs of automation, such as a headless browser
- whether the visitor then engaged with the page, added to cart or bought
The tag sets no cookies. It keeps one random visit ID in the browser's local storage for 30 days, so that a later purchase can mark the visitor as a real shopper. It does not read names, email addresses, form fields or payment details.
We use this data for one purpose: deciding whether a source of paid clicks is automated or repeat clicking, and excluding that IP address from the customer's ads. Shoppers who add to cart or buy are never blocked, and shared mobile network addresses are never blocked.
How long we keep it
- Raw click records, including IP addresses, are deleted after 90 days.
- An IP address on a customer's blocked or trusted list stays there until the customer removes it or closes the account.
- Sign-in links expire after 20 minutes. Sessions expire after 30 days.
- Account data is deleted when you ask us to close your account.
Cookies on stopfakeclicks.com
We set one cookie when you sign in, to keep you signed in, and a short-lived one during Google sign-in to protect against forged requests. Both are strictly necessary. We do not use advertising cookies.
Who processes data for us
- Cloudflare: API, database and email forwarding. The database is stored in Europe.
- Resend: sending sign-in emails and reports.
- Google: sign-in with Google, and the exclusion lists in the customer's own Google Ads account.
- Lovable: hosting of the website.
We do not sell data and we do not share it for advertising.
Customers' responsibilities
A customer who installs the tag must tell their visitors about it in their own privacy notice and have a lawful basis for it. Fraud prevention and protecting ad spend is usually a legitimate interest, but the customer decides this for their own website.
Your rights
Under the UK GDPR and EU GDPR you can ask to see, correct or delete your data, object to its use, or move it elsewhere. Write to hello@stopfakeclicks.com. If you visited one of our customers' websites, you can also contact that website directly. You can complain to the UK Information Commissioner's Office or to your local data protection authority.
Google user data
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
If we change this policy we will update the date at the top and tell customers by email about important changes.
Questions? hello@stopfakeclicks.com