PaceWise connects to real advertising accounts and real client budgets, so security isn't an afterthought - it's built into how the product works. This page covers the specifics: what we access, how it's stored, and what we never touch.
We never see your Google Ads, Microsoft Advertising or TikTok Ads login credentials - and PaceWise can't act on your campaigns unless you explicitly tell it to.
You authorize each ad account directly on Google, Microsoft or TikTok's own login screen via OAuth. PaceWise receives a scoped access token - never your username or password - and you can revoke that access from the platform's own settings at any time.
The access tokens we do store are encrypted with AES-256-GCM before they ever touch the database - not stored as plain text, and not readable even with direct database access.
PaceWise is read-only by default. Pausing a campaign, shifting budget or editing a daily budget each require an explicit, in-product confirmation that shows exactly what will change - PaceWise never writes to a live campaign on its own.
Any change PaceWise does make to a connected account - with your confirmation - is recorded in change history, so there's always a clear record of what changed, when, and who approved it.
If you sign up with email and password, your password is hashed with bcrypt before it's stored - nobody at PaceWise, including us, can see your actual password. You can also sign in with Google, Microsoft or Facebook SSO instead, which skips password storage entirely.
Invite your team with the right level of access - Owner, Admin, Manager or Viewer - instead of sharing one login. Viewers can see pacing and reports without being able to connect accounts, invite others or change budgets.
Billing runs entirely through Stripe, one of the most widely used and heavily audited payment processors online.
When you upgrade to a paid plan, you're taken to a payment page hosted directly by Stripe - your card number is typed into Stripe's own checkout, not ours. PaceWise's servers never receive, process or store your full card number, so there's nothing for a breach on our end to expose in the first place.
Every connection to PaceWise - the website, the app, and every request in between - is encrypted in transit with TLS. There's no unencrypted path into the product.
Sign-up and public forms are protected with Cloudflare Turnstile, so automated bots can't flood the system with fake accounts or spam submissions.
We don't sell your data or your clients' advertising data to third parties, and we don't use your connected ad account data to train third-party AI or machine-learning models. We use it for exactly one purpose: calculating pacing, detecting anomalies and building your reports.
Want to delete your account and its data? Email support@pacewise.app or see our data deletion instructions. For the full legal detail on what we collect and why, read our Privacy Policy.
PaceWise is a next-generation, AI-powered PPC budget pacing and management platform for agencies and in-house teams. It brings spend visibility, pacing alerts and budget control across Google Ads, Microsoft Ads and TikTok Ads — with Meta coming soon.