Privacy Policy
Last updated 19 September 2026
This policy explains what Limelight collects, why, how long we keep it, and how you get rid of it. Limelight is operated by PRODESK PTY LTD (ACN 702 132 910, ABN 22 702 132 910), a company registered in Queensland, Australia. In this policy, "we" and "us" mean PRODESK PTY LTD, and "you" means the person or business using Limelight.
We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth). Where you are in the United Kingdom or the European Economic Area, we also handle your data in line with the UK GDPR and EU GDPR.
1. What we collect
Information you give us
- Waitlist details — your email address, and optionally which category of user you are.
- Account details — when Limelight opens, your name, email address, business name and password (stored only as a one-way hash, never in readable form).
- Billing details — handled entirely by our payment provider. We never see or store your card number.
- What you tell us — anything you send us by email or through support.
Information from Google Ads
If you connect a Google Ads account, we access that account through the Google Ads API using credentials you authorise. What we read:
- Campaign, ad group, keyword and ad structure and settings
- Performance figures — impressions, clicks, cost, conversions, conversion value
- Search terms that triggered your ads
- Account and billing currency settings needed to report figures correctly
We do not read your Gmail, Drive, Contacts, Calendar, or any other Google service. We request the narrowest set of permissions the product needs.
Information collected automatically
- Server logs — IP address, browser type, pages requested, timestamps. Kept for up to 30 days for security and troubleshooting.
- Essential cookies only — to keep you signed in and to keep forms secure. We do not run advertising or cross-site tracking cookies on this site.
2. How we use Google user data
Limelight's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data we access from your Google Ads account is used only to:
- Show you your own account's performance inside Limelight
- Produce recommendations about your own account
- Apply changes to your own account that you have explicitly approved
We do not:
- Sell, rent or trade your Google data to anyone, ever
- Transfer it to third parties except the infrastructure providers listed below, or where law requires it
- Use it for advertising, ad targeting, or building marketing profiles
- Use it to train generalised artificial intelligence or machine learning models
- Allow humans to read it, except where you explicitly ask us to for support, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised so that it no longer identifies you or your business
3. Changes to your Google Ads account
Limelight does not make changes to your advertising account on its own. Every change — pausing a campaign, adding a negative keyword, adjusting a bid, creating an ad — is presented to you first and applied only after you approve it. Every applied change is recorded with what it was, which member of your account approved it, and when.
4. Enquiry data we handle for our customers
Limelight offers our customers a tracking tag and a hosted enquiry form. When a business puts these on their website, we receive and store the details that people submit to that business.
For this enquiry data, the business is the data controller and we are only the processor. We handle it on their instructions, to provide the service to them. It is their data, not ours.
What is collected
- What the enquirer types — typically name, email address, phone number and a description of the work they need.
- Which ad brought them — the Google click identifier (
gclid,gbraidorwbraid) and campaign tags from the link they arrived on, plus the page they landed on and the site that referred them.
The tracking tag sets no cookies, does not follow anyone across other websites, and sends nothing until a person submits an enquiry form. Click identifiers are held in the visitor's own browser for up to 90 days, which is the window Google allows for attributing a conversion.
What it is used for
One purpose only: telling the business which advertising produced which enquiry, and which enquiries became paid work. Where the business marks a job as booked, we send the click identifier, the time and the job value to Google Ads as an offline conversion. No name, email address, phone number or message is ever sent to Google.
We do not market to enquirers, sell their details, share them with anyone other than the business they contacted, or use them to train artificial intelligence models.
If you are an enquirer
If you contacted a business through a form powered by Limelight and want your details corrected or deleted, contact that business — they control the data. You can also write to privacy@limelight.mobi and we will act on the business's instruction and, where we can, help you reach them.
Enquiry data is deleted within 30 days of the business closing their Limelight account, or sooner at their instruction.
5. Who else touches your data
We keep this list short deliberately.
| Provider | What they do | Where |
|---|---|---|
| Cloudflare | Application hosting and database | Global edge network |
| Hostinger | Website and email hosting | Europe |
| Anthropic | Generates recommendation text and classifies search term intent | United States |
| The advertising platform itself, via the Google Ads API | Global |
Data sent to Anthropic for analysis is not used to train their models. Because some of these providers operate outside Australia, your information may be stored or processed overseas.
6. How we protect it
- All traffic is encrypted in transit using TLS
- Google access tokens are encrypted at rest and never exposed to your browser
- Passwords are stored only as one-way hashes
- Access to production systems is limited to people who need it
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
7. How long we keep it
- Waitlist emails — until you ask us to remove you, or 24 months after collection, whichever comes first
- Account and advertising data — while your account is open, then deleted within 30 days of closure
- Server logs — up to 30 days
- Records we must keep by law — invoices and tax records, for seven years
8. Your choices
You can, at any time:
- Disconnect Google Ads — from inside Limelight, or directly at myaccount.google.com/permissions. We delete the stored tokens and the account data we pulled.
- Get a copy of your data, or ask us to correct it
- Delete your account and everything in it
- Leave the waitlist — one email to us and you're off it
Email privacy@limelight.mobi and we will action it within 30 days. If you are in the UK or EEA, you also have the right to object to processing, to restrict it, and to data portability.
9. Children
Limelight is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
10. Changes to this policy
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
11. Contact and complaints
Privacy questions and requests: privacy@limelight.mobi
General contact: hello@limelight.mobi
Postal enquiries can be directed to PRODESK PTY LTD, Queensland, Australia.
If you are not satisfied with how we handle a privacy complaint, you can escalate it to the Office of the Australian Information Commissioner at oaic.gov.au. In the UK, to the Information Commissioner's Office at ico.org.uk.