Liga SoftwareLiga Software
← Back to Liga Software

Privacy Policy

Last updated: 13 August 2026

This policy explains what personal information Liga Pty Ltd collects, how we use it, and the choices you have. It covers Liga Software, Liga Hosting, Liga OpsPilot, and any third-party account you choose to connect to them.

Who we are

Liga Pty Ltd (ABN 27 168 627 334), trading as Liga Software, Liga Hosting and Liga OpsPilot, is the data controller for the personal information described in this policy. We are based in Australia and handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

Information we collect

  • Account information — your name, email address, business details and password, or the identifier supplied by Google or Microsoft if you sign in with them.
  • Service information — the domains, hosting, email, servers and SSL products you buy, and the agent instances we run for you.
  • Billing information — invoices, subscription status and payment records. Card details are handled by our payment processor and are never stored on our systems.
  • Support information — the tickets, messages and attachments you send us.
  • Connected account data — where you link a third-party account, the data described under “Connected third-party accounts” below.
  • Technical information — IP address, browser type and log data, used to operate and secure the service.

Connected third-party accounts

If you choose to connect an external account so your Liga OpsPilot agents can work with it, this section explains exactly what that means. Connecting is always optional, and the service works without it.

Platforms you can connect:

  • Google — your Google Ads accounts, for performance reporting and campaign drafting.
  • Meta (Facebook and Instagram) — advertising accounts, for campaign drafting and performance reporting.
  • Microsoft Advertising — advertising accounts, for performance reporting and campaign drafting.

How connecting works. You authorise us on the platform's own website — never by giving us your username or password. During that step you choose which of your assets (for example, which advertising accounts) to share. The platform then issues us an access credential scoped to what you approved.

What we access. Only what your chosen features need — your advertising accounts, the campaigns and ads within them, and their performance statistics. We do not access your personal profile, your contacts, your private messages, or anything belonging to an account you did not select.

Google user data

When you connect a Google account, we ask for the following access, and nothing else:

  • Google Ads (https://www.googleapis.com/auth/adwords) — to list the Google Ads accounts you manage, and to read campaign, ad and performance data for the accounts you selected, so your agents can report on them and draft changes for your approval.
  • Your email address and Google account identifier (openid, email) — to identify which Google account a connection belongs to, so you can tell your connections apart and disconnect the right one.

Google publishes no read-only permission for Google Ads, so its consent screen describes the single available permission as “see, edit, create and delete” your Google Ads accounts and data. Our use is narrower than that wording: agents read data and may draft paused campaigns, and cannot activate an advertisement, change the budget of a live advertisement, cause money to be spent, or delete anything. This limit is enforced in our software, not merely promised.

Liga's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide or improve the features you asked for, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and we do not sell it.

How the credential is stored. The access credential is held in a dedicated, isolated Liga service. It is encrypted at rest using a per-customer key held in Azure Key Vault, and it is stored in one place only. It is not copied into your agent's environment, and it is not visible to Liga staff. Access credentials are never sold, shared with other customers, or used for any purpose other than operating the features you asked for.

Every action is logged. We record each call we make to a connected platform on your behalf — what was called, when, and whether it succeeded — so that both you and we can audit what your agents did.

Disconnecting. You can disconnect at any time from your instance settings in the portal, or by revoking Liga's access in the platform's own security settings — for Google, at myaccount.google.com/permissions. When you disconnect, we destroy the stored credential immediately. The activity log is retained as described under “How long we keep it”.

How your AI agents act on your behalf

Liga OpsPilot agents perform tasks using the connections you have authorised. What they are permitted to do is deliberately limited.

  • Agents draft; people approve. For advertising, agents may create campaigns, ad sets and ads, and every one of them is created paused. An agent cannot activate an advertisement, cannot change the budget of a live advertisement, and cannot cause money to be spent on your account. A human must review and activate.
  • Reading is unrestricted within what you shared. Agents may read performance data for the accounts you connected, in order to report and make recommendations.
  • Nothing is published without you. Agents do not post to your social profiles or pages under this policy version. If we add publishing features, we will update this policy and, where required, ask you to authorise the additional access.

We do not use your connected-account data, or the content your agents produce for you, to train general-purpose AI models.

How we use your information

  • To provide, operate and support the services you have bought.
  • To provision, configure and maintain your hosting products and agent instances.
  • To take payment, issue invoices and manage subscriptions.
  • To respond to your support requests.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To meet our legal, tax and regulatory obligations.

Who we share information with

We do not sell your personal information. We share it only with service providers who help us run the service, and only to the extent they need it:

  • Dreamscape Networks — our wholesale provider for domains, hosting, email and SSL. Registrant details for domains are also passed to the relevant registry as required by ICANN and auDA policy.
  • Stripe — payment processing and subscription billing.
  • Microsoft Azure — cloud hosting and secret management, in the Azure Australia East region.
  • Email delivery providers — to send transactional email such as invoices, password resets and service notices.
  • Platforms you have connected — requests we make on your behalf go to that platform, in accordance with its own terms and privacy policy.

We may also disclose information where required by law, or to protect the rights, safety or property of Liga, our customers or the public.

How we protect your information

  • All traffic to our services is encrypted in transit using TLS.
  • Third-party access credentials are encrypted at rest with per-customer keys held in Azure Key Vault, and are isolated from the systems that run your agents.
  • Passwords are stored only as salted hashes; we cannot recover them.
  • Customer data is separated so that one customer cannot reach another's data, and administrative access is restricted and logged.
  • Secrets are excluded from logs and error reports by design.

How long we keep it

  • Access credentials — until you disconnect, or the platform expires them, at which point they are destroyed.
  • Account and service records — for as long as your account is active.
  • Billing and tax records — seven years, as required by Australian law.
  • Activity and audit logs — up to twelve months, then deleted.

Your rights

You may ask us to:

  • give you a copy of the personal information we hold about you;
  • correct information that is wrong or out of date;
  • delete your information, where we are not required to keep it;
  • disconnect any third-party account you have linked.

Email privacy@liga.net.au and we will respond within 30 days. If you are unhappy with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Cookies and tracking

We use cookies that are necessary to run the portal — keeping you signed in and protecting against cross-site request forgery. We do not use advertising cookies and we do not track you across other websites.

Changes to this policy

We will update this page when our practices change, and revise the date at the top. If a change materially affects how we handle your information, we will tell you by email or through the portal before it takes effect.

Contact us

Questions about this policy, or about the information we hold on you, can be sent to privacy@liga.net.au.